How to Set Up a CAA Record to Control SSL Issuance

Add a CAA DNS record in cPanel to specify which certificate authorities may issue SSL certificates for your domain, improving security.

· Updated · 543 views

A CAA (Certification Authority Authorization) record tells browsers and certificate authorities which CAs are allowed to issue SSL certificates for your domain. It is a simple but effective way to prevent unauthorised certificates.

Why Use a CAA Record

Without a CAA record, any certificate authority can technically issue a certificate for your domain. A CAA record restricts this to the ones you trust, reducing the risk of mis-issuance.

Adding a CAA Record in cPanel

  1. Log in to cPanel
  2. Go to Domains → Zone Editor
  3. Click Manage next to your domain
  4. Click Add Record and choose CAA
  5. Fill in the fields:
    • Name: your domain (e.g. yourdomain.co.ke)
    • Tag: issue
    • Value: the CA you authorise, e.g. letsencrypt.org
  6. Save

Recommended Values for NairoHost

Because NairoHost uses AutoSSL powered by Let's Encrypt, authorise:

0 issue "letsencrypt.org"

If you also use Cloudflare or another provider, add a CAA record for each, otherwise their certificates will fail to issue.

Important Caution

Only add a CAA record if you understand which CAs you use. An incorrect record can block AutoSSL renewals, causing your SSL to expire. If unsure, leave CAA unset, which keeps the default of allowing any CA.

After adding the record, allow time for DNS propagation before requesting a new certificate.

Was this article helpful?

Your feedback helps us improve our documentation.

Still Need Help?

Our support team is available 24/7 to assist you.