Issuance fails with a CAA error
Let's Encrypt says "CAA record for example.com prevents issuance" or another CA reports a failed CAA check: the CAA records on the domain or a parent don't allow that CA. See which level's records apply, which CAs they allow, and the exact line to add.
DNS validation keeps failing
certbot or acme.sh reports "No TXT record found" or "Incorrect TXT record", or DigiCert, Sectigo or another CA just won't validate. Paste the validation host name to see whether the record exists, carries the latest value, or points elsewhere with a CNAME.
Just changed DNS and not sure it's live
Query Cloudflare, Google, Quad9, AliDNS and DNSPod at once and see at a glance whether they agree — no need to run dig against each one.
- What is a CAA record, and what if I don't have one?
- A CAA record declares which CAs may issue certificates for a domain, and every public CA must check it before issuing. Without CAA records any CA can issue — that's the default for most domains, and you don't need to add one just to get a certificate. Once set, only the listed CAs can issue, so update it when you switch CAs.
- How do I add a CAA record that allows Let's Encrypt?
- On the domain level that already has CAA records (the result shows which one), add a CAA record in your DNS provider's console: flag 0, tag issue, value letsencrypt.org. Wildcards check issuewild first: if issuewild records already exist, add the same record with tag issuewild too. In zone file format:
example.com. CAA 0 issue "letsencrypt.org"
example.com. CAA 0 issuewild "letsencrypt.org"
If the domain has no CAA records at all, there's nothing to add — any CA can issue.
- My subdomain has no CAA records. Why is it still blocked?
- CAs start at the name being issued and walk up the tree, using the first CAA record set they find, so CAA on the apex applies to every subdomain. And if the subdomain is a CNAME to a CDN, the CA reads the CAA records of the CNAME target, which only the CDN provider can change — or use the certificate from the CDN console. The result shows which level the records come from and whether a CNAME is involved.
- Why can't I find my _acme-challenge record?
- ACME clients normally add the record right before validation and remove it afterwards, so not finding it is normal. If validation is in progress and it's missing, the usual culprit is the host name: most DNS consoles expect it without the zone, so use _acme-challenge for example.com and _acme-challenge.www for www.example.com. Entering _acme-challenge.www.example.com creates _acme-challenge.www.example.com.example.com.
- Can I check DNS validation records for DigiCert, Sectigo and other CAs?
- Yes. Paste the full host name your CA gave you and pick the matching record type. Common ones are DigiCert's _dnsauth (TXT), Certum's _certum (TXT), and Sectigo's underscore-prefixed hash (CNAME). Some CAs want the TXT record on the domain itself; just enter the domain and query TXT.
- How long do DNS changes take, and why do resolvers disagree?
- New records are usually on the authoritative nameservers within seconds, but public resolvers cache previous answers — including "no such record" — until the TTL runs out. CAs query authoritative nameservers directly and generally see new records sooner. Have your ACME client wait a bit after adding the record, for example with acme.sh's --dnssleep.
- What is DNS delegation (CNAME validation)?
- You point _acme-challenge with a CNAME at another name that exists only to hold validation records, and the CA follows the CNAME to read the TXT there. From then on validation records are written over there: your own DNS never changes and you don't give DNS API keys to your ACME client. acme.sh's --challenge-alias and acme-dns both work this way. See HTTP-01 vs DNS-01 vs DNS delegation for how the methods compare.
- What are the equivalent dig commands?
- dig CAA example.com +short
dig TXT _acme-challenge.example.com +short
dig CNAME _acme-challenge.example.com +short
Add @8.8.8.8 to query a specific public resolver. Note that dig doesn't walk up the tree for CAA; if a subdomain returns nothing, query its parents yourself.