---
name: azion-restrict-issuers-with-a-caa-record
description: >-
  Add a CAA record to an Edge DNS zone so that only the certificate authorities you name may issue certificates for your domain, from Azion Console or the API.
---

# Restrict issuers with a CAA record

You can restrict which certificate authorities (CAs) may issue certificates for your domain with a CAA record in [Edge DNS](/en/documentation/platform/edge-dns/), from Azion Console, the Azion CLI, or the Azion API. The record below, `0 issue "letsencrypt.org"` on the apex `@`, names Let's Encrypt as the CA allowed to issue for `example.com`. For every CAA tag and value format, refer to [Record types](/en/documentation/platform/edge-dns/record-types/#caa).

---

Your choice of interface sets the prerequisites and the steps to add the record.

## Prerequisites

- A zone for your domain in Edge DNS. To create one, refer to [Create, edit, or delete a zone](/en/documentation/guides/application-security/dns/edge-dns-configure-main-settings/).
- No CNAME record on the name that takes the CAA record. A CNAME blocks every other record type on its name.
- The **Edit Edge DNS** permission. Refer to [Teams permissions](/en/documentation/fundamentals/teams-permissions/).

**Console**

- Access to Azion Console. To sign in, refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**CLI**

- The [Azion CLI](/en/documentation/devtools/cli/) installed and authorized.

**API**

- A [personal token](/en/documentation/guides/platform/account-and-billing/personal-tokens/) and `curl`.

---

## Add the CAA record

The record goes on `@`, the apex, so it covers `example.com`. Replace `example.com` with your domain and `letsencrypt.org` with the CA you allow.

Certificate Manager requests a workload's certificates from Let's Encrypt. While it issues certificates for your domain, keep `letsencrypt.org` in the record. For how it issues and renews them, refer to [Issuance and renewal](/en/documentation/platform/workloads/certificate-manager/issuance-and-renewal/).

**Console**

To add the record in Azion Console:

1. **Open the Edge DNS page**

   Access [Azion Console](https://console.azion.com/) > **Edge DNS**.

2. **Open the zone's Records tab**

   On the **Zones** page, select the row of the zone, then select the **Records** tab.

3. **Select + Record**

   The **Create Record** drawer opens.

4. **Enter the apex name**

   In **Name**, enter `@`. The Console adds the domain for you, so never type the domain.

5. **Select the CAA type**

   In **Record Type**, select *CAA - Certification Authority Authorization*.

6. **Keep the TTL**

   Keep **TTL (seconds)** at `3600`.

7. **Enter the value**

   In **Value**, enter `0 issue "letsencrypt.org"`. To allow another CA, add its value on a new line.

8. **Select Save**

The Console shows `Edge DNS Record has been created`, and the CAA record appears in the **Records** table.

**CLI**

To add the record with the Azion CLI, save the record as `caa.json`:

```json
{"name":"@","type":"CAA","rdata":["0 issue \"letsencrypt.org\""],"ttl":3600}
```

Then create the record from the file. Replace `<zone-id>` with the ID of your zone:

```bash
azion create dns-record --zone-id <zone-id> --file caa.json
```

The command prints the ID of the record:

```text
Created DNS record with ID 100782
```

The zone holds the CAA record. Pass the value through `--file`: `--rdata` refuses a value that contains double quotes.

**API**

To add the record with the Azion API, send a `POST` request to the zone's records endpoint. Replace `<zone-id>` with the `id` of your zone:

```bash
curl -X POST https://api.azion.com/v4/workspace/dns/zones/<zone-id>/records \
  -H "Authorization: Token [TOKEN VALUE]" \
  -H "Content-Type: application/json" \
  -d '{"name":"@","type":"CAA","rdata":["0 issue \"letsencrypt.org\""],"ttl":3600}'
```

A `201` returns the record:

```json
{
  "state": "executed",
  "data": {
    "id": 100180,
    "description": "",
    "name": "@",
    "ttl": 3600,
    "type": "CAA",
    "rdata": ["0 issue \"letsencrypt.org\""],
    "policy": "simple",
    "weight": 255
  }
}
```

The zone holds the CAA record. Each CA you allow is one string in `rdata`, and the double quotes around the CA's name are escaped inside the JSON string.

A CAA record on a name that holds a CNAME is refused with `19018` `CNAME Record Already Exists For Domain`. A CNAME on another name of the zone does not block it. Like any change, the record can take a few minutes to reach every nameserver. For how answers are cached, refer to [How it works](/en/documentation/platform/edge-dns/how-it-works/#caching-and-propagation).

---

## Check the record

To ask Azion's nameserver for the record directly, without your resolver's cache, replace `example.com` with your domain:

```bash
dig +short @ns1.aziondns.net example.com CAA
```

The answer lists the values of the CAA record. If it lists nothing, refer to [Troubleshooting](/en/documentation/platform/edge-dns/troubleshooting/).

---

## Next steps

- [Issuance and renewal](/en/documentation/platform/workloads/certificate-manager/issuance-and-renewal.md): How Azion requests a Let's Encrypt certificate for a workload's domains.
- [Add the Let's Encrypt TXT record](/en/documentation/guides/application-security/tls-and-certificates/lets-encrypt-record.md): Add the TXT record a DNS-01 challenge checks.
- [Record types](/en/documentation/platform/edge-dns/record-types.md#caa): The issue, issuewild, and iodef tags, and more CAA values.
- [Add, edit, or delete a record](/en/documentation/guides/application-security/dns/add-records.md): Change or remove the CAA record later.
