CAA record
termcryptographyISP & telecom
A DNS record in which a domain owner declares which certificate authorities are permitted to issue certificates for that domain, and where to report violations.
It is the one control that narrows the flat trust list down to the authorities you actually chose - compliant CAs must check it before issuing. Its limits are honest ones: it binds authorities that follow the rules rather than one that has been compromised, and it depends on DNS answers being genuine. Used with Certificate Transparency monitoring it gives a domain owner both a preventive control and a detective one, which is about as much as this ecosystem currently offers to the people whose names are at stake.
Also known as: certification authority authorization, dns caa, issue tag