{"id":2607,"date":"2019-10-22T17:12:28","date_gmt":"2019-10-22T09:12:28","guid":{"rendered":"https:\/\/www.mondoze.com\/guide\/?post_type=kb&#038;p=2607"},"modified":"2022-10-05T08:02:47","modified_gmt":"2022-10-05T00:02:47","slug":"configuring-caa-records","status":"publish","type":"kb","link":"https:\/\/www.mondoze.com\/guide\/kb\/configuring-caa-records","title":{"rendered":"HOW TO :Configuring CAA Records"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"2607\" class=\"elementor elementor-2607\" data-elementor-settings=\"[]\">\n\t\t\t\t\t\t<div class=\"elementor-inner\">\n\t\t\t\t\t\t\t<div class=\"elementor-section-wrap\">\n\t\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1b84ee54 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"1b84ee54\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t\t\t<div class=\"elementor-row\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-3e585252\" data-id=\"3e585252\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-column-wrap elementor-element-populated\">\n\t\t\t\t\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-ac6be6b elementor-widget elementor-widget-heading\" data-id=\"ac6be6b\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">How To Configure CAA Records<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5d6736ad elementor-widget elementor-widget-text-editor\" data-id=\"5d6736ad\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\">\n\t\t\t\t<h3><strong>When using Universal SSL, do not configure CAA records<\/strong><\/h3><p>When you enable Universal SSL and add CAA records via the Cloudflare\u00a0<strong>DNS<\/strong>\u00a0app, Cloudflare automatically adds three additional CAA DNS records for each of our Universal SSL CA providers (currently comodoca.com, digicert.com, and globalsign.com). \u00a0Cloudflare does not append additional CAA records if Universal SSL is disabled or if no CAA records are added via the\u00a0<strong>DNS<\/strong>\u00a0app.<\/p><p>These CAA DNS records do not display in the Cloudflare dashboard\u00a0<strong>DNS<\/strong>\u00a0app. However, if you run \u00a0a command line query using\u00a0<em>dig<\/em>, any existing CAA records will show, including the ones added by Cloudflare Universal SSL.<\/p><p>If you don&#8217;t want or need Cloudflare Universal SSL, you can disable it in your Cloudflare\u00a0<strong>Crypto<\/strong>\u00a0settings. Disabling SSL automatically deletes the CAA DNS records for our official providers, mentioned above.<\/p><p>Disabling Universal SSL leaves your Cloudflare-enabled DNS records without SSL support, unless you upload a custom SSL certificate (available for Cloudflare Business and Enterprise customers).<\/p><hr \/><h3><strong>When using your own certificate, configure your CAA records<\/strong><\/h3><p>If you&#8217;re using your own origin server SSL certificate (that is, a certificate that was not provisioned by Cloudflare), you need to manually add a CAA DNS record for each Certificate Authority (CA) that you plan to use for your domain.<\/p><p>Configuring\u00a0 only applies to certificates issued by a CA. You cannot add CAA records if you&#8217;re using a self-signed certificate in your origin web server.<\/p><p>To add a CAA record:<\/p><p>1. Log in to the Cloudflare dashboard.<\/p><p>2. Ensure the website you want to update is selected.<\/p><p>3. Click the\u00a0<strong>DNS<\/strong>\u00a0app.<\/p><p>4. In the\u00a0<strong>DNS Records<\/strong>\u00a0panel, click the record type dropdown to select\u00a0<em>CAA<\/em>.<\/p><p>5. In the\u00a0<strong>Name<\/strong>\u00a0text box, type your domain.<\/p><p>6. Then in the\u00a0<strong>Click to configure<\/strong>\u00a0text box, click to enter configuration details.<\/p><p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-medium wp-image-2608\" src=\"https:\/\/www.mondoze.com\/guide\/wp-content\/uploads\/2021\/03\/add1-300x153.png\" alt=\"\" width=\"300\" height=\"153\" \/><\/p><p>7. In the\u00a0<strong>Add Record: CAA content\u00a0<\/strong>dialog, select a\u00a0<strong>Tag<\/strong>: either\u00a0<em>Only allow specific hostnames<\/em>\u00a0or\u00a0<em>Only allow wildcards<\/em>, as appropriate. The default tag is\u00a0<em>Only allow specific hostnames<\/em>.<\/p><p>8. For\u00a0<strong>Value<\/strong>, enter the CA name.<\/p><p>9. Click\u00a0<strong>OK<\/strong>\u00a0to close the dialog.<\/p><p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-medium wp-image-2610\" src=\"https:\/\/www.mondoze.com\/guide\/wp-content\/uploads\/2021\/03\/add2-300x136.png\" alt=\"\" width=\"300\" height=\"136\" \/><\/p><p>10. Back in the\u00a0<strong>DNS Records<\/strong>\u00a0panel, verify that the information you entered is correct and then, click\u00a0<strong>Add Record<\/strong>\u00a0to save your changes.<\/p><p>You can repeat the steps above for each CA to associate with your domain. \u00a0Once you have finished creating all the records, you can review them in the list of records appearing under the\u00a0<strong>DNS Records<\/strong>\u00a0panel.<\/p><p>A CA queries the authoritative DNS . \u00a0Therefore, CAA records added to the Cloudflare <strong>DNS<\/strong>\u00a0app for a domain on a CNAME setup are not used.<\/p>\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>How To Configure CAA Records When using Universal SSL, do not configure CAA records When you enable Universal SSL and add CAA records via the Cloudflare\u00a0DNS\u00a0app, Cloudflare automatically adds three additional CAA DNS records for each of our Universal SSL CA providers (currently comodoca.com, digicert.com, and globalsign.com). \u00a0Cloudflare does not append additional CAA records if &hellip;<\/p>\n<p class=\"read-more\"> <a class=\"\" href=\"https:\/\/www.mondoze.com\/guide\/kb\/configuring-caa-records\"> <span class=\"screen-reader-text\">HOW TO :Configuring CAA Records<\/span> Read More \u00bb<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""}}},"kbtopic":[53],"kbtag":[110],"mkb_version":[],"_links":{"self":[{"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/kb\/2607"}],"collection":[{"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/kb"}],"about":[{"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/types\/kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/comments?post=2607"}],"version-history":[{"count":11,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/kb\/2607\/revisions"}],"predecessor-version":[{"id":18332,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/kb\/2607\/revisions\/18332"}],"wp:attachment":[{"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/media?parent=2607"}],"wp:term":[{"taxonomy":"kbtopic","embeddable":true,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/kbtopic?post=2607"},{"taxonomy":"kbtag","embeddable":true,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/kbtag?post=2607"},{"taxonomy":"mkb_version","embeddable":true,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/mkb_version?post=2607"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}