# CAA Records: Allowed Certificate Authorities

The CAA record of google.com: which certificate authority may issue certificates for the domain.

Source: https://docs.deepinfo.com/reference/lookup/dns/examples/type-caa/

Last updated: 2026-09-24

---
`GET https://api.deepinfo.com/v1/lookup/dns?domain=google.com&type=CAA`

The CAA record of google.com: which certificate authority may issue certificates for the domain.

Example 8 of 13 in **Record Types** · [DNS Lookup Examples](/reference/lookup/dns/examples/) · endpoint: [DNS](/reference/lookup/dns/)

Tags: `param` `domain` · `param` `type` · `value` `google.com` · `value` `CAA`

Asks for the `CAA` records of `google.com`.

A `CAA` record says which certificate authorities may issue SSL/TLS certificates for a domain. The single value `0 issue "pki.goog"` allows only Google's own CA.

## Request

| Parameter | In | Value |
|---|---|---|
| `domain` | query | `google.com` |
| `type` | query | `CAA` |

```bash
curl 'https://api.deepinfo.com/v1/lookup/dns?domain=google.com&type=CAA' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

## Response

### 200 · OK

`Content-Type: application/json` · `ratelimit-limit: 100000` · `ratelimit-remaining: 99992` · `ratelimit-reset: 36` · `x-ratelimit-limit-minute: 100000` · `x-ratelimit-remaining-minute: 99992` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "fqdn": "google.com",
  "requested_types": [
    "CAA"
  ],
  "responses": [
    {
      "type": "CAA",
      "conn_status": "success",
      "rcode": "NOERROR",
      "raw": "google.com. 3190 IN CAA 0 issue \"pki.goog\"",
      "values": [
        "0 issue \"pki.goog\""
      ],
      "server": "8.8.8.8"
    }
  ],
  "servers": [
    "8.8.8.8"
  ],
  "check_date": "2026-09-24T07:48:24Z"
}
```

## Related Examples

- [SOA Record: Zone Authority](/reference/lookup/dns/examples/type-soa/)
- [SRV Record of a Service](/reference/lookup/dns/examples/type-srv/)
- [CNAME Record of a Host Name](/reference/lookup/dns/examples/type-cname/)
- [PTR Record: Reverse DNS](/reference/lookup/dns/examples/type-ptr/)
- [TXT Records](/reference/lookup/dns/examples/type-txt/)
- [DMARC Policy in a TXT Record](/reference/lookup/dns/examples/dmarc-txt/)
