Overview
Certification Authority Authorization (CAA) is an Internet security policy that lets a website owner specify which Certificate Authorities (CAs) are authorized to issue SSL/TLS certificates for a domain, preventing malicious users from creating false certificates. Add a CAA record to control which CAs can issue a Let's Encrypt SSL certificate for your domain at DreamHost.
How do I configure CAA records?
This section explains how to configure a CAA record for a Let's Encrypt SSL certificate, depending on where your domain nameservers are pointing.
Nameservers are pointing to DreamHost
If your nameservers are pointing to DreamHost, you can add it in your panel. See this article for instructions.
Nameservers are not pointing to DreamHost
If your nameservers are NOT pointing to DreamHost, you must create it at the company where they currently point.
Adding a CAA record at your current hosting company
Before adding a Let's Encrypt SSL certificate to your domain, ensure the CAA records configured at your current hosting company are compatible with DreamHost. There are two options:
- Option 1 — Completely remove your CAA records at your current hosting company.
-
Option 2 — Retain your CAA records at your current hosting company, but remove any conflicting CAA records before adding an SSL certificate in the DreamHost panel. If you choose this option, make sure you only use the record shown below.
letsencrypt.org