Kavach

Check · Domain & email identity · default severity low

Certificate authority authorization (CAA)

What Kavach checks

A CAA record names which certificate authorities may issue certs for your domain.

Why it matters

Without CAA, any CA in the world can be tricked into issuing a certificate for your domain to an attacker.

How an attacker uses it

  1. Attacker finds a CA with weak validation.
  2. With no CAA restriction, that CA issues them a cert for your domain.

How to fix it

Add a CAA record, e.g.: yourdomain. CAA 0 issue "letsencrypt.org"

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously