# Fix SSL provisioning failing on a CAA record

## TL;DR
SSL provisioning fails when a CAA record forbids the certificate authority from issuing for your domain. Add a CAA record authorizing your CA, or remove the blocking record, then retry provisioning. The CA is obeying your DNS; change what it says.

## The error
```text
SSL provisioning failed
Certificate authority refused to issue: CAA record prevents issuance
```

## Use this skill
Agent? Search Vectle for this error:
```bash
curl -s "https://vectle.com/api/v1/search?q=ssl provisioning failed caa record"
```

## Fix it

### Step 1: Read your current CAA records

```bash
dig CAA [domain] and note which CAs are authorized.
```

Expected: You see the current CAA set, or nothing if the failure names a different cause.

### Step 2: Identify the CA your provider uses

```bash
Check your hosting or SSL provider's docs for which CA they issue from.
```

Expected: You know the CA name to authorize.

### Step 3: Add a CAA record for that CA

```bash
Add a CAA record like 0 issue "[ca-domain]" for your domain.
```

Expected: The record is live in DNS.

### Step 4: Retry SSL provisioning

```bash
Trigger the certificate issuance again from your provider.
```

Expected: The certificate issues successfully.

### Step 5: Verify the certificate

```bash
Check the served certificate's issuer and expiry.
```

Expected: The right CA issued it and it is valid.

## When this applies

- SSL provisioning fails mentioning CAA records
- Certificates issued before but fail now
- You just added or changed CAA records

## When it doesn't

- The failure is about DNS validation (check the challenge records)
- No CAA records exist (the failure is something else)
- The certificate issues but browsers distrust it (check the chain)

## Compatibility

CAA-aware certificate authorities. Any DNS provider.

## Variant phrasings

### caa record blocking ssl issuance

Same failure. The record names the allowed CAs; yours is not among them.

### letsencrypt caa prevents issuance

Add a CAA record authorizing letsencrypt.org or remove the restrictive record.

### ssl failed caa check domain

The check runs per issuance, so renewals fail too until the record is fixed.

## Why it happens

CAA records tell certificate authorities who may issue for your domain. When the record lists only specific CAs and your provider uses a different one, issuance is refused. It is your DNS instructing the CA to say no.

## Edge cases

- CAA records inherit to subdomains unless overridden; a root record can block a subdomain's cert
- issuewild controls wildcard issuance separately from issue
- DNS caching means CAA changes take time to be seen; wait for TTL before retrying

## If it still fails

- Verify from multiple networks; one network's cache is not the internet's state.
- Check the domain's delegation and nameservers before blaming individual records.
- Wait out one full TTL after a fix before declaring it still broken.
- Keep a known-good dig output to diff against during the next incident.
- If a provider's verification never passes with correct records, escalate with dig output and timestamps.

## Prevention

- Lower TTLs a day before any planned DNS change.
- Verify every record with dig against authoritative before declaring done.
- Monitor certificate and domain expiry with alerts, not memory.
- Keep DNS change history; most outages are a bad edit, not propagation.
- Test verification flows in staging with a throwaway subdomain.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_CalON2AqDYsud230TG9ptw
