RFC 9495: Certification Authority Authorization (CAA) Processing for Email Addresses
In plain English — editorial summary, not part of the RFC
The Certification Authority Authorization (CAA) DNS resource record (RR) provides a mechanism for domains to express the allowed set of Certification Authorities that are authorized to issue certificates for the domain. RFC 8659 contains the core CAA specification, where Property Tags that restrict the issuance of certificates that certify domain names are defined. This specification defines a Property Tag that grants authorization to Certification Authorities to issue certificates that contain the id-kp-emailProtection key purpose in the extendedKeyUsage extension and at least one rfc822Name value or otherName value of type id-on-SmtpUTF8Mailbox that includes the domain name in the subjectAltName extension.
Document record
- Document ID
- RFC9495
- Published
- October 2023
- Authors
- C. Bonnell
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 8
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9598Internationalized Email Addresses in X.509 CertificatesCurrent
May 2024
- RFC 9799Automated Certificate Management Environment (ACME) Extensions for ".onion" Special-Use Domain NamesCurrent
June 2025
- RFC 6068The 'mailto' URI SchemeCurrent
October 2010
- RFC 9493Subject Identifiers for Security Event TokensCurrent
December 2023
- RFC 9483Lightweight Certificate Management Protocol (CMP) ProfileCurrent
November 2023
- RFC 9482Constrained Application Protocol (CoAP) Transfer for the Certificate Management ProtocolCurrent
November 2023
- RFC 9481Certificate Management Protocol (CMP) AlgorithmsCurrent
November 2023
- RFC 9509X.509 Certificate Extended Key Usage (EKU) for 5G Network FunctionsCurrent
March 2024
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?