A CAA (Certification Authority Authorization) record tells browsers and certificate authorities which CAs are allowed to issue SSL certificates for your domain. It is a simple but effective way to prevent unauthorised certificates.
Why Use a CAA Record
Without a CAA record, any certificate authority can technically issue a certificate for your domain. A CAA record restricts this to the ones you trust, reducing the risk of mis-issuance.
Adding a CAA Record in cPanel
- Log in to cPanel
- Go to Domains → Zone Editor
- Click Manage next to your domain
- Click Add Record and choose CAA
- Fill in the fields:
- Name: your domain (e.g.
yourdomain.co.ke) - Tag:
issue - Value: the CA you authorise, e.g.
letsencrypt.org
- Name: your domain (e.g.
- Save
Recommended Values for NairoHost
Because NairoHost uses AutoSSL powered by Let's Encrypt, authorise:
0 issue "letsencrypt.org"
If you also use Cloudflare or another provider, add a CAA record for each, otherwise their certificates will fail to issue.
Important Caution
Only add a CAA record if you understand which CAs you use. An incorrect record can block AutoSSL renewals, causing your SSL to expire. If unsure, leave CAA unset, which keeps the default of allowing any CA.
After adding the record, allow time for DNS propagation before requesting a new certificate.