CAA Record Policy Auditor avatar

CAA Record Policy Auditor

Pricing

Pay per usage

Go to Apify Store
CAA Record Policy Auditor

CAA Record Policy Auditor

Audit a public domain's CAA (Certificate Authority Authorization, RFC 8659) DNS policy in one API call. Validates issue and issuewild issuer authorization, iodef violation-reporting contacts, tag and flag validity, and blocked-issuance detection. Returns a score, grade, and recommendations.

Pricing

Pay per usage

Rating

0.0

(0)

Developer

Sanskar Jaiswal

Sanskar Jaiswal

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

2 days ago

Last modified

Share

Apify Actor that audits a public domain's CAA (Certificate Authority Authorization, RFC 8659) DNS policy in one cheap API call.

What it does

  • Fetches the domain's CAA records via a public DNS-over-HTTPS resolver (Cloudflare 1.1.1.1 JSON API, no auth, no page fetching).
  • Parses every record with full RFC 8659 semantics:
    • issue / issuewild issuer domains and name=value parameters (duplicate accounturi / validationmethods detection).
    • iodef violation-reporting contacts — validated as URI strings only (mailto / http / https schemes), never fetched.
    • Unknown tags, invalid flags, unknown flag bits, and the critical-bit (128) misuse that makes CAs ignore the property.
    • Blocked issuance (0 issue ";") and wildcard-only policies.
  • Classifies issuer domains against a list of known certificate authorities.
  • Returns a policy summary, weighted readiness score (0-100), letter grade, issues, and concrete recommendations.

Input

FieldTypeDescription
startUrlstring (required)Public domain or URL to audit
timeoutSecondsintegerDoH query timeout, default 10

Output (default dataset)

One JSON object: domain, caaFound, recordCount, records[] (flags, tag, value, domain, parameters, iodef analysis, issues), tagCounts, policy (issuers, issuersRecognized, wildcardPolicy, blockAllIssuance), hasIssueTag, hasIssuewildTag, hasIodef, iodefValid, unknownTagCount, unknownCaCount, hasDuplicateTags, recordIssues[], score, grade, issues[], recommendations[], checkedAt.

Security

  • DNS CAA lookups only, via a public DoH resolver; the target URL is never fetched over HTTP.
  • SSRF protection: only HTTP/HTTPS input, credentials rejected, private IPv4 and IPv6 literals blocked, DNS resolution of the hostname checked against private ranges.
  • iodef URLs are validated as strings and never requested, so the actor cannot be weaponized for report flooding.

Use cases

  • Certificate-renewal and CA-migration QA (adding CAA for a new CA before switching issuers).
  • Security posture monitoring for parked and production domains.
  • Compliance audits (CAA is a low-cost control in frameworks like PCI DSS 4.0 as part of key/certificate management practices).

Pricing suggestion

$0.005 actor start + $0.01 per domain audited (~$0.015 per run).