CAA Inspector
Walk the DNS tree the way a Certificate Authority does. See which CAs are authorised to issue certificates, where the effective policy lives, and whether parameters likeaccounturiand validationmethodsare set.
Implements the RFC 8659 tree-climbing algorithm. Recognises 30+ public CAs and flags common typos.
Tree walk
Climb labels per RFC 8659Show which level is effectiveDetect NXDOMAIN/SERVFAIL
Parse & validate
issue / issuewild / iodefaccounturi / validationmethods (RFC 8657)Critical flag handlingTypo detection
Cross-check
Multiple resolversConsistency comparison