DNS & CAA Checker

When DNS validation never passes or issuance fails on CAA, paste the host name your CA asks for to see what 5 public resolvers return and which CAs may issue.

Paste the full host name from your CA, such as _acme-challenge.example.com or _dnsauth.example.com, then pick the record type. CAA is checked on the domain left after removing the leading validation labels.

What gets checked

TXT / CNAME records

Looks up validation records like _acme-challenge or _dnsauth to confirm they're right and whether they point elsewhere.

CAA records

Walks up the domain tree the way CAs do and tells you which CAs may issue regular and wildcard certificates.

Multiple public resolvers

Queries Cloudflare, Google, Quad9, AliDNS and DNSPod at once and lists each answer, so you can see whether records have propagated.

When to check DNS and CAA

Issuance fails with a CAA error

Let's Encrypt says "CAA record for example.com prevents issuance" or another CA reports a failed CAA check: the CAA records on the domain or a parent don't allow that CA. See which level's records apply, which CAs they allow, and the exact line to add.

DNS validation keeps failing

certbot or acme.sh reports "No TXT record found" or "Incorrect TXT record", or DigiCert, Sectigo or another CA just won't validate. Paste the validation host name to see whether the record exists, carries the latest value, or points elsewhere with a CNAME.

Just changed DNS and not sure it's live

Query Cloudflare, Google, Quad9, AliDNS and DNSPod at once and see at a glance whether they agree — no need to run dig against each one.

FAQ

What is a CAA record, and what if I don't have one?
A CAA record declares which CAs may issue certificates for a domain, and every public CA must check it before issuing. Without CAA records any CA can issue — that's the default for most domains, and you don't need to add one just to get a certificate. Once set, only the listed CAs can issue, so update it when you switch CAs.
How do I add a CAA record that allows Let's Encrypt?
On the domain level that already has CAA records (the result shows which one), add a CAA record in your DNS provider's console: flag 0, tag issue, value letsencrypt.org. Wildcards check issuewild first: if issuewild records already exist, add the same record with tag issuewild too. In zone file format: example.com. CAA 0 issue "letsencrypt.org" example.com. CAA 0 issuewild "letsencrypt.org" If the domain has no CAA records at all, there's nothing to add — any CA can issue.
My subdomain has no CAA records. Why is it still blocked?
CAs start at the name being issued and walk up the tree, using the first CAA record set they find, so CAA on the apex applies to every subdomain. And if the subdomain is a CNAME to a CDN, the CA reads the CAA records of the CNAME target, which only the CDN provider can change — or use the certificate from the CDN console. The result shows which level the records come from and whether a CNAME is involved.
Why can't I find my _acme-challenge record?
ACME clients normally add the record right before validation and remove it afterwards, so not finding it is normal. If validation is in progress and it's missing, the usual culprit is the host name: most DNS consoles expect it without the zone, so use _acme-challenge for example.com and _acme-challenge.www for www.example.com. Entering _acme-challenge.www.example.com creates _acme-challenge.www.example.com.example.com.
Can I check DNS validation records for DigiCert, Sectigo and other CAs?
Yes. Paste the full host name your CA gave you and pick the matching record type. Common ones are DigiCert's _dnsauth (TXT), Certum's _certum (TXT), and Sectigo's underscore-prefixed hash (CNAME). Some CAs want the TXT record on the domain itself; just enter the domain and query TXT.
How long do DNS changes take, and why do resolvers disagree?
New records are usually on the authoritative nameservers within seconds, but public resolvers cache previous answers — including "no such record" — until the TTL runs out. CAs query authoritative nameservers directly and generally see new records sooner. Have your ACME client wait a bit after adding the record, for example with acme.sh's --dnssleep.
What is DNS delegation (CNAME validation)?
You point _acme-challenge with a CNAME at another name that exists only to hold validation records, and the CA follows the CNAME to read the TXT there. From then on validation records are written over there: your own DNS never changes and you don't give DNS API keys to your ACME client. acme.sh's --challenge-alias and acme-dns both work this way. See HTTP-01 vs DNS-01 vs DNS delegation for how the methods compare.
What are the equivalent dig commands?
dig CAA example.com +short dig TXT _acme-challenge.example.com +short dig CNAME _acme-challenge.example.com +short Add @8.8.8.8 to query a specific public resolver. Note that dig doesn't walk up the tree for CAA; if a subdomain returns nothing, query its parents yourself.

One CNAME, and renewals never touch your DNS again

LapseZero validates through DNS delegation: add one CNAME when you add the domain, and issuance, renewal and deployment run on their own from then on — no DNS API keys to hand over, no waiting for records to propagate each time. Start on the free plan.

Start for free