ssl provisioning failed caa record
For admins and agents provisioning SSL certificates. Use when CAA records block issuance. Not for DNS-validation or chain errors.
Fix SSL provisioning failing on a CAA record
TL;DR
SSL provisioning fails when a CAA record forbids the certificate authority from issuing for your domain. Add a CAA record authorizing your CA, or remove the blocking record, then retry provisioning. The CA is obeying your DNS; change what it says.
The error
SSL provisioning failed
Certificate authority refused to issue: CAA record prevents issuanceUse this skill
Agent? Search Vectle for this error:
curl -s "https://vectle.com/api/v1/search?q=ssl provisioning failed caa record"Fix it
Step 1: Read your current CAA records
dig CAA [domain] and note which CAs are authorized.Expected: You see the current CAA set, or nothing if the failure names a different cause.
Step 2: Identify the CA your provider uses
Check your hosting or SSL provider's docs for which CA they issue from.Expected: You know the CA name to authorize.
Step 3: Add a CAA record for that CA
Add a CAA record like 0 issue "[ca-domain]" for your domain.Expected: The record is live in DNS.
Step 4: Retry SSL provisioning
Trigger the certificate issuance again from your provider.Expected: The certificate issues successfully.
Step 5: Verify the certificate
Check the served certificate's issuer and expiry.Expected: The right CA issued it and it is valid.
When this applies
- SSL provisioning fails mentioning CAA records
- Certificates issued before but fail now
- You just added or changed CAA records
When it doesn't
- The failure is about DNS validation (check the challenge records)
- No CAA records exist (the failure is something else)
- The certificate issues but browsers distrust it (check the chain)
Compatibility
CAA-aware certificate authorities. Any DNS provider.
Variant phrasings
caa record blocking ssl issuance
Same failure. The record names the allowed CAs; yours is not among them.
letsencrypt caa prevents issuance
Add a CAA record authorizing letsencrypt.org or remove the restrictive record.
ssl failed caa check domain
The check runs per issuance, so renewals fail too until the record is fixed.
Why it happens
CAA records tell certificate authorities who may issue for your domain. When the record lists only specific CAs and your provider uses a different one, issuance is refused. It is your DNS instructing the CA to say no.
Edge cases
- CAA records inherit to subdomains unless overridden; a root record can block a subdomain's cert
- issuewild controls wildcard issuance separately from issue
- DNS caching means CAA changes take time to be seen; wait for TTL before retrying
If it still fails
- Verify from multiple networks; one network's cache is not the internet's state.
- Check the domain's delegation and nameservers before blaming individual records.
- Wait out one full TTL after a fix before declaring it still broken.
- Keep a known-good dig output to diff against during the next incident.
- If a provider's verification never passes with correct records, escalate with dig output and timestamps.
Prevention
- Lower TTLs a day before any planned DNS change.
- Verify every record with dig against authoritative before declaring done.
- Monitor certificate and domain expiry with alerts, not memory.
- Keep DNS change history; most outages are a bad edit, not propagation.
- Test verification flows in staging with a throwaway subdomain.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_CalON2AqDYsud230TG9ptw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.