The issue tag in a CAA record authorizes a certificate authority to issue non-wildcard certificates for a domain. It is the primary allowlist mechanism used when a domain owner wants to control which issuers may create certificates. If the CA is not listed, issuance should be denied.
What the issue tag does in DNS CAA
The issue tag in a CAA record tells a certificate authority whether it is permitted to issue a non-wildcard certificate for a domain. It functions as a domain-owner allowlist for issuance, so a CA not listed in the record should treat issuance as denied.
Because CAA is checked by certificate authorities before issuance, the issue tag is less about encrypting traffic and more about governing trust at the point a certificate request is evaluated. That makes it a narrow but important control for restricting which issuers can create publicly trusted certificates for a domain.
How issue tag authorization works
An issue tag can appear alongside other CAA parameters, but its central purpose is simple: express which CA names are allowed to issue certificates for the domain. The CA reads the record, compares itself to the allowlist, and decides whether it may proceed.
The tag applies to ordinary certificates for the labeled domain, not as a general statement about every certificate-related action. In practice, that means domain owners use it to reduce unwanted issuance paths, especially where multiple CAs, delegated teams, or third-party platforms might otherwise be able to request certificates.
The control is intentionally conservative. If no permitted CA is present, compliant issuers should refuse the request. That design helps make certificate issuance a policy decision owned by the domain holder rather than an open market behavior controlled only by whoever can reach a public CA.
Where issue tags fit in certificate governance
Issue tags are part of certificate governance, not certificate content. They do not replace domain validation, private key protection, or revocation processes, but they do add an upstream approval layer that reduces the set of acceptable issuers.
This matters when issuance is distributed across internal teams, managed service providers, or cloud platforms. A well-maintained CAA policy narrows the blast radius of misrouted requests and makes it easier to state which authorities are expected to issue for a domain.
Issue tags also work best when the domain owner treats them as living policy, not a one-time DNS setting. If the organization changes CAs, acquires a new platform, or transfers certificate operations, the record must be updated so the allowlist remains aligned with real operational intent.
Common failure modes and operational consequences
Issue tags fail when the policy is stale, incomplete, or inconsistent with the domain's real certificate workflow. A CA that is omitted may be blocked from issuance, while an outdated allowlist can create friction during renewals or migrations.
Another failure mode is assuming CAA alone prevents all certificate abuse. It helps constrain issuance, but it does not stop an already-issued certificate from being used, and it does not correct weak key handling, poor renewal automation, or compromised administrative access to DNS.
For that reason, the issue tag should be understood as a governance control over issuance authority, not a complete certificate-security program. Its value is highest when paired with accurate DNS ownership, trusted CA selection, and certificate inventory discipline.
Risk and Threat Considerations
Issue tags reduce the risk of unauthorized or mistaken certificate issuance, but they also create operational exposure if the allowlist is wrong or outdated. A missing permitted CA can interrupt renewals, while an overly broad allowlist can weaken the control's protective value.
Failure mechanism: Attackers or misconfigured automation may exploit gaps between certificate request paths and the DNS policy, especially when DNS control is weak or the CAA record is not maintained in step with certificate operations.
Impact: The result can be unwanted certificate issuance, renewal failure, service disruption, or reduced confidence that the domain's public certificates are being issued only by approved authorities.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST SP 800-57 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | SC-12 — Cryptographic Key Establishment and Management | CAA issuance policy supports control over trusted certificate use. |
| AC-3 — Access Enforcement | Issue tags enforce which CAs may issue for a domain. | |
| Recommendation — Align certificate issuance policy with approved trust and key management processes. Enforce domain issuance allowlists so only approved CAs can issue certificates. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | CAA issue tags are a policy control limiting authorized certificate issuance. |
| Recommendation — Define and maintain certificate issuance authorization as part of access control policy. | ||
| NIST SP 800-57 | Key management lifecycle | Certificate issuance policy is adjacent to certificate and trust lifecycle governance. |
| Recommendation — Manage certificate trust decisions alongside the certificate lifecycle and renewal process. | ||
Practitioner Guidance
Common misunderstanding: Issue tags are sometimes treated as a set-and-forget hardening setting, but they are really a governance control that must track actual certificate operations. If the record does not reflect the current CA landscape, it can block legitimate issuance or leave room for unintended issuance paths.
Practitioner note: Keep the allowlist tight, review it whenever issuance responsibilities change, and verify that DNS ownership and certificate operations are controlled by the same governance process. That is what makes the tag effective in practice rather than merely present in DNS.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org