CAA Record Parser API

POST

See which certificate authorities are authorized to issue for any domain.

CAA Record Parser analyzes DNS CAA records that specify which Certificate Authorities are authorized to issue certificates for a domain.

Try it — live request, no key required

Request
POSTapi.apiverve.com/v1/caaparser
Body
Verification
Format

No key required to try it. Get a key to use it in your app.

Example
{
  "status": "ok",
  "error": null,
  "data": {
    "raw_record": "example.com. 3600 IN CAA 0 issue \"letsencrypt.org\"",
    "parsed": {
      "domain": "example.com",
      "ttl": 3600,
      "class": "IN",
      "flags": 0,
      "tag": "issue",
      "value": "letsencrypt.org"
    },
    "ca_info": {
      "name": "Let's Encrypt",
      "type": "Free",
      "wildcard_support": true
    },
    "interpretation": {
      "meaning": "Only letsencrypt.org is authorized to issue certificates",
      "restriction": "Restricted to specific CA",
      "critical": false,
      "critical_explanation": "Non-critical - CA may proceed if not understood"
    },
    "tag_description": "Authorizes a CA to issue certificates (any type)",
    "is_valid": true
  }
}

About the CAA Record Parser API

Includes a database of known Certificate Authorities like Let's Encrypt, DigiCert, and others, with automatic identification and policy interpretation.

What people use it for

Security Analysis
Parse CAA records for security analysis and threat detection to identify unauthorized certificate authorities
Policy Validation
Validate certificate issuance policies by parsing CAA records to ensure only authorized CAs can issue certificates
DNS Security Tools
Build DNS security tools that monitor and analyze CAA records for compliance and security posture assessment
Certificate Auditing
Audit domain certificate authorization settings to maintain control over which CAs can issue certificates for your domains

Ways to call it

One endpoint, many ways in — REST with JSON, XML, YAML and CSV, plus GraphQL and an MCP interface for AI agents.

JSON
Default REST response
XML
Markup format
YAML
Human-readable
CSV
Tabular export
Beta
GraphQL
Query language
New
MCP
For AI agents

Other ways to use CAA Record Parser

Same data, same APIVerve account, same credit balance — one key works on all of them.

Questions.

Common questions about the CAA Record Parser API.

Read the docs →
Which CAA record tags and Certificate Authorities does it recognize?
It parses standard CAA tags including issue, issuewild, and iodef. The parser includes a database of recognized Certificate Authorities such as Let's Encrypt and DigiCert, providing their classification and wildcard support details.
Do I get CA details and policy interpretations on the Free plan?
No, detailed CA information, policy interpretations, and tag descriptions are premium fields reserved for paid plans. The Free plan provides structural parsing like domain, TTL, flags, tag, and value, while Starter and higher plans unlock the recognized CA name, policy restrictions, and criticality analysis.
How does the parser handle malformed or invalid CAA strings?
The response returns an is_valid boolean flag that marks whether the provided CAA record string is properly formatted according to DNS standards. If a record contains invalid syntax or unrecognized formatting, this flag reflects the failure so your pipeline can flag bad records without crashing.
Which plan fits 25,000 CAA record audits a month?
The Starter plan easily covers this volume. Each parse costs 2 credits, so 25,000 lookups require 50,000 credits, using one-quarter of Starter's monthly 200,000 credits. On Starter, usage works out to about $0.30 per 1,000 calls ($0.0003 per call), while the Free plan includes 100 calls each month.
Can I use this data inside a commercial DNS security tool?
Yes, commercial use is permitted on all paid plans, starting with Starter. You can display parsed CAA policies and CA authorization data directly inside your security audit software, provided you do not resell or redistribute the raw data feed as-is.

Ready to build with CAA Record Parser? Start with 200 free credits — one key unlocks all 300+ APIs.

Explore the catalog

300+ APIs on the same key and the same response shape.

Browse all APIs