DNS Certification Authority Authorization
| Abbreviation | CAA | 
|---|---|
| Status | Proposed Standard | 
| First published | October 18, 2010 | 
| Latest version | RFC 8659 November 2019 | 
| Organization | IETF | 
| Authors | 
 | 
| Base standards | Domain Name System | 
| Domain | Internet security | 
DNS Certification Authority Authorization (CAA) is an Internet security policy mechanism for domain name registrants to indicate to certificate authorities whether they are authorized to issue digital certificates for a particular domain name. Registrants publish a "CAA" Domain Name System (DNS) resource record which compliant certificate authorities check for before issuing digital certificates.
CAA was drafted by computer scientists Phillip Hallam-Baker and Rob Stradling in response to increasing concerns about the security of publicly trusted certificate authorities. It is an Internet Engineering Task Force (IETF) proposed standard.