Explore New Dedicated Server Configurations

English

Home

Blog

How To Create CAA DNS Record for SSL Cer...

How To Create CAA DNS Record for SSL Certificate Validation

How To Create CAA DNS Record for SSL Certificate Validation

NetShop ISP

NetShop ISP · Blog Author

Nov 06, 2025 · Technical Tutorials

CAA stands for Certification Authority Authorization and it’s a standard that allows you to control which certificate authorities (CAs) are permitted to issue certificates for your domain.

In this article we explain the purpose of a CAA DNS record and how to create one for the purpose of validating your single domain or wildcard SSL Certificate.

What is CAA DNS Record

Using CAA helps reduce the risk of vulnerabilities within certificate authority validation systems while ensuring that your organization’s certificate issuance policies are properly enforced.

Putting it simply, CAA is a type of DNS record that allows site owners to specify which Certificate Authorities (CAs) are allowed to issue certificates containing their domain names.

All Certificate Authorities were mandated to check CAA DNS records for SSL certificates starting on September 8, 2017. Some providers began enforcing CAA lookups more strictly in recent years, such as Sectigo in 2024.

How to Create a CAA Record

Purchasing a Sectigo SSL Certificate will require creating a CAA DNS record as part of the Domain verification process.

Steps to Create a CAA DNS Record in cPanel

Assuming the nameservers of your domain name point to your cPanel server, proceed as follows to create the CAA record for your domain name. In our example, the domain is lg.netshop.global and we will create a CAA for Wildcard Sectigo SSL certificate.

You may also be interested in these two guides:

Login to cPanel and click Zone Editor.

Create a CAA DNS Record in cPanel - Step 1

Then click Manage to access the Zone editor for your domain name.

Create a CAA DNS Record in cPanel - Step 2

Click + Add Record and choose Add “CAA” Record from the drop-down menu.

Create a CAA DNS Record in cPanel - Step 3

Complete the fields as follows (screenshot below):

  • Name: lg.netshop.global. (here it goes your domain name)
  • TTL: 14400 (or lower if supported)
  • Type: CAA
  • Record:
    • Issuer Critical Flag: 0
    • Tag: issuewild (this is for wildcard certificates. If you are creating a single-domain SSL, then choose issue
    • Value: sectigo.com (this value depends on the Certificate Authority issuing your SSL Certificate)

Click Save Record.

Create a CAA DNS Record in cPanel - Step 4

Steps to Create a CAA DNS Record in GoDaddy

If your domain is registered with GoDaddy and the nameservers point there then follow these steps.

  • Log in to your GoDaddy Domain Control Center.
  • Select the domain you wish to add a CAA for to access the Domain Settings page.
  • Click the DNS tab
  • Click the Add New Record button
  • Select CAA as the Record type.

The necessary fields are similar to the cPanel Zone editor, fill them up as follows:

  • Name: @ for root domain (e.g. example.com) or www for www.example.com.
  • TTL: 1/2 hour (or lowest possible).
  • Flags: 0
  • Tag: issuewild if you are using this for a wildcard SSL certificate, or issue for single domain SSL.
  • Domain: sectigo.com if you are using an SSL issued by Sectigo.

Congratulations! if you’ve followed the above steps then you have successfully create the CAA DNS Record. You will now need to wait for global DNS propagation and then wait for the domain validation to be completed by your SSL certificate issuing provider.

Still Need Help? Get SSL from NetShop ISP in minutes

At NetShop ISP we like to get the job done. No matter if your domain has not been purchased with us, or if the nameservers point somewhere else, we can help customers with an SSL purchased from us.

Once you complete your SSL order, contact our support team via ticket or live chat for further assistance on your SSL Certificate activation.

Press Releases
90

Free VPS Trial

No Credit Card Required.

Recent Posts

How To Create CAA DNS Record for SSL Certificate Validation

How To Create CAA DNS Record for SSL Certificate Validation

06 November, 2025

NetShop ISP Featured in InBusiness Magazine: Leading Cyprus’ Digital Transformation Journey

NetShop ISP Featured in InBusiness Magazine: Leading Cyprus’ Digital Transformation Journey

03 November, 2025

Curaçao’s Prime Minister Takes Control of Gambling Regulation

Curaçao’s Prime Minister Takes Control of Gambling Regulation

14 October, 2025

How To Install WordPress with LAMP (Apache,  MariaDB, PHP) on AlmaLinux 9 Server

How To Install WordPress with LAMP (Apache, MariaDB, PHP) on AlmaLinux 9 Server

08 October, 2025

NetShop ISP Attends Forex Expo Dubai 2025 to Showcase XConnect Low-latency Connectivity Solution

NetShop ISP Attends Forex Expo Dubai 2025 to Showcase XConnect Low-latency Connectivity Solution

29 September, 2025

#letushostyou

Award Winning Hosting Provider established in 2004.

120 Faneromenis Avenue, Imperial Tower, 2nd Floor, Larnaca 6031, Cyprus

Products

Bare Metal Servers

Customized Servers

Virtual / Cloud Servers

Forex VPS

cPanel Web Hosting

Reseller Web Hosting

Colocation

Low-latency Connectivitynew

by XConnect

Addons

Premium DNS

Email Hosting

Cloud Backup

DDoS Protection

Licenses

SSL Certificates

Domain Names

Premium SLAs

About Us

Data Center Locations

Looking Glass

Our Company

Contact Us

Careers in Cyprus

Become a Partner

Awards

Certifications

© 2025 S.S. NetShop Internet Services Ltd. All rights reserved.  Terms & Conditions  |  Privacy Policy
CY Reg. Number: HE 217340 | EU VAT Number: CY10217340J

Visa
Mastercard
PayPal
Bitcoin
Tether
Ethereum
Litecoin
Wise
Revolut
Wire Transfer