# CAA Setup for Let's Encrypt

**URL:** <https://community.letsencrypt.org/t/caa-setup-for-lets-encrypt/9893>\
**Category:** Uncategorized\
**Created:** [January 31, 2016, 6:25pm UTC](https://community.letsencrypt.org/t/caa-setup-for-lets-encrypt/9893 "2016-01-31T18:25:02Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [February 1, 2016, 12:45am UTC](https://community.letsencrypt.org/t/caa-setup-for-lets-encrypt/9893/3 "2016-02-01T00:45:57Z")

</div>

> [@sca\_le](#):
>
> [example.org](http://example.org). CAA 1 issue "[letsencrypt.org](http://letsencrypt.org)"

This is correct and should be all you need.

> [@sca\_le](#):
>
> [example.org](http://example.org). CAA 1 iodef "[mailto:caa@example.org](mailto:caa@example.org)"

FYI, iodef is not (yet) supported by Let's Encrypt.

> [@Jason](#):
>
> I would also like to specify the critical flag in my DNS CAA Records.

The critical flag in CAA, like the critical flag in x509 extensions, means only "error out if you don't understand this." Adding the critical flag to CAA types that are part of the base RFC (like `issue`) has no effect.

Also keep in mind: ~~I'm not aware of any other CA that implements CAA yet. So, while adding the entries is nice, keep in mind that most other CAs will be willing to issue for your domain regardless.~~ Edit: As of September 2017, all public CAs are required by the Baseline Requirements to implement CAA.

---

_[View the full topic](https://community.letsencrypt.org/t/caa-setup-for-lets-encrypt/9893)._
