CAA Record Policy Auditor
Pricing
Pay per usage
CAA Record Policy Auditor
Audit a public domain's CAA (Certificate Authority Authorization, RFC 8659) DNS policy in one API call. Validates issue and issuewild issuer authorization, iodef violation-reporting contacts, tag and flag validity, and blocked-issuance detection. Returns a score, grade, and recommendations.
Pricing
Pay per usage
Rating
0.0
(0)
Developer
Sanskar Jaiswal
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
2 days ago
Last modified
Categories
Share
Apify Actor that audits a public domain's CAA (Certificate Authority Authorization, RFC 8659) DNS policy in one cheap API call.
What it does
- Fetches the domain's CAA records via a public DNS-over-HTTPS resolver (Cloudflare 1.1.1.1 JSON API, no auth, no page fetching).
- Parses every record with full RFC 8659 semantics:
issue/issuewildissuer domains andname=valueparameters (duplicateaccounturi/validationmethodsdetection).iodefviolation-reporting contacts — validated as URI strings only (mailto / http / https schemes), never fetched.- Unknown tags, invalid flags, unknown flag bits, and the critical-bit (128) misuse that makes CAs ignore the property.
- Blocked issuance (
0 issue ";") and wildcard-only policies.
- Classifies issuer domains against a list of known certificate authorities.
- Returns a policy summary, weighted readiness score (0-100), letter grade, issues, and concrete recommendations.
Input
| Field | Type | Description |
|---|---|---|
startUrl | string (required) | Public domain or URL to audit |
timeoutSeconds | integer | DoH query timeout, default 10 |
Output (default dataset)
One JSON object: domain, caaFound, recordCount, records[] (flags, tag,
value, domain, parameters, iodef analysis, issues), tagCounts, policy
(issuers, issuersRecognized, wildcardPolicy, blockAllIssuance), hasIssueTag,
hasIssuewildTag, hasIodef, iodefValid, unknownTagCount,
unknownCaCount, hasDuplicateTags, recordIssues[], score, grade,
issues[], recommendations[], checkedAt.
Security
- DNS CAA lookups only, via a public DoH resolver; the target URL is never fetched over HTTP.
- SSRF protection: only HTTP/HTTPS input, credentials rejected, private IPv4 and IPv6 literals blocked, DNS resolution of the hostname checked against private ranges.
- iodef URLs are validated as strings and never requested, so the actor cannot be weaponized for report flooding.
Use cases
- Certificate-renewal and CA-migration QA (adding CAA for a new CA before switching issuers).
- Security posture monitoring for parked and production domains.
- Compliance audits (CAA is a low-cost control in frameworks like PCI DSS 4.0 as part of key/certificate management practices).
Pricing suggestion
$0.005 actor start + $0.01 per domain audited (~$0.015 per run).