methodology / Security & Infrastructure / #23
CAA records
live factor #23 · Security & Infrastructure · scoring impl: implemented · weight 0.7%
What we measure
CAA records tell Certificate Authorities which ones are allowed to issue SSL certs for your domain. Without CAA, any CA can issue a cert — including a malicious one.
How to improve your score
Add a TXT-style CAA record listing your trusted issuer, e.g. `0 issue "letsencrypt.org"`.
Data source
Data source for this factor is not yet documented.
Scoring
Scoring formulas are versioned with the methodology. The current method (v1.1.0) maps raw measurements to pass, warn, fail. Factor weights determine how much each contributes to the composite — see the methodology index for the full table.
Version history
| Version | Change | Date |
|---|---|---|
| v1.1.0 | Factor introduced. Status: live. Scoring impl: implemented. | 2026-04-25 |