• Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to X
  • Link to Instagram
  • English English English en
  • Deutsch Deutsch German de
Sales: +49 5251 304-800 | Support: +49 5251 304-636
NoSpamProxy
  • PRODUCT
    • NoSpamProxy Cloud
    • NoSpamProxy Protection
    • NoSpamProxy Encryption
    • NoSpamProxy Large Files
    • NoSpamProxy Disclaimer
  • SOLUTIONS
    • M365 Mail Security
    • Managed Certificates
    • 32Guards
    • AS4
  • RESOURCES
    • Documentation
    • Forum
    • Webcast Training
    • Training Courses
    • Support
    • Software Download
  • PARTNERS
    • Finding Resellers
    • Becoming Reseller
    • Partner Portal
    • NFR Licenses
  • COMPANY
    • Contact
    • Testimonials
    • Team
    • Career
    • Events
    • Awards
  • PRICES
  • BLOG
    • Blog
    • Newsletter Subscription
  • FREE TRIAL VERSION
    • Price Request
    • Free Trial Version
  • English
    • Deutsch
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Information

CAA records for S/MIME certificates will be verified from September 2024

26.08.2024|Last edited:15.11.2024

From September 2024, CAA records in the Domain Name System (DNS) will also be verified when issuing S/MIME certificates. Previously, this was only done when issuing SSL/TLS certificates.

What does CAA mean?

DNS Certification Authority Authorisation (CAA) is a security mechanism in the Domain Name System (DNS) that controls the issuing of SSL/TLS and S/MIME certificates. CAA records allow domain owners to specify which certification authorities (CAs) are authorised to issue certificates for their domain. This reduces the risk of an unauthorised CA issuing a certificate for the domain, which could lead to security problems. The check of CAA records is based on the specifications of RFC 9495.

How does the CAA verification work?

First, the domain owner creates one or more CAA records in the DNS zone of his domain. Once this has been done, the domain owner can apply to a CA for an SSL/TLS or S/MIME certificate for their domain. Before the CA issues a certificate, it must query the CAA record of the domain. This is done by a DNS query of the CAA record for the domain. If the CA is listed as authorised in the CAA record, it will proceed with issuing the certificates. If this is not the case, it rejects the issue and reports an incident if necessary.

A typical CAA record has the following format:

example.com CAA 0 issuemail "ca.example"
  • example.com: The domain to which the CAA record applies.
  • 0: Flags (usually 0, but can be different in special cases).
  • issuemail: Specifies which CA is authorised to issue a certificate.
  • “ca.example”: The name of the CA that is authorised.

What does the CAA verification mean for me?

This change planned for September 2024 has no impact on existing S/MIME certificates. However, if a domain has one or more CAA records with the property tag ‘issuemail’, but none of these records list the CA you are using as an authorised issuer, no new S/MIME certificates can be issued for this domain (or subdomain).

If you have created a CAA record in the DNS, this CAA record must contain the CA you are using as an authorised issuer.

Are you using the latest version of NoSpamProxy?

You can always find the latest versions of NoSpamProxy Server on our download page. Update now and benefit from maximum email security and the latest functions.

Download now

  • share 
  • share 
  • share 
  • email 

SEARCH

PRODUCT

  • All Topics
  • NoSpamProxy Cloud
  • NoSpamProxy Protection
  • NoSpamProxy Encryption
  • NospamProxy Large Files

You need support?

You can find more information about NoSpamProxy in our documentation and forum.

CATEGORY

  • All Topics
  • News
  • Product
  • Tech & Support
  • Events

NoSpamProxy Newsletter

Subscribe to Newsletter
RSS Feed Logo RSS Feed Logo Subscribeto RSS Feed

NoSpamProxy

  • NoSpamProxy Cloud
  • NoSpamProxy Encryption
  • NoSpamProxy Large Files
  • NoSpamProxy Disclaimer
  • Price request
  • Team
  • Career
  • General terms and conditions
  • Data Protection Information for Business Partners and Applicants
  • Cybersecurity (PSIRT)

Partners

  • Becoming a reseller
  • Partners
  • Order Certificates
  • Newsletter

Categories

  • All topics
  • News
  • Support
  • Updates
  • Order certificates

Latest News

  • Advanced Threat Protection ATP Preview
    Advanced Threat Protection: NoSpamProxy offers numerous ATP features at no extra charge13.06.2025 - 13:32
  • NoSpamProxy Update
    NoSpamProxy Server 15.5 now available03.06.2025 - 13:00
  • Customer Success Management Tim Kaleja Preview
    Interview: How NoSpamProxy ensures customer satisfaction with strong customer success management26.05.2025 - 10:00
IMPRINT • EULA • Privacy Policy • • © 2025 Net at Work GmbH
  • Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to X
  • Link to Instagram
Link to: What is Typosquatting? Link to: What is Typosquatting? What is Typosquatting?Was ist Typosquatting Preview Link to: How to spot phishing mails Link to: How to spot phishing mails Merkmale von Phishing Mails PreviewHow to spot phishing mails
Scroll to top Scroll to top Scroll to top