Check · Domain & email identity · default severity low
Certificate authority authorization (CAA)
What Kavach checks
A CAA record names which certificate authorities may issue certs for your domain.
Why it matters
Without CAA, any CA in the world can be tricked into issuing a certificate for your domain to an attacker.
How an attacker uses it
- Attacker finds a CA with weak validation.
- With no CAA restriction, that CA issues them a cert for your domain.
How to fix it
Add a CAA record, e.g.: yourdomain. CAA 0 issue "letsencrypt.org"
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.