https://www.grepular.com/Cert_Authorities_Check_for_DNSSEC_From_Today Skip to content repular.com [ ] Menu Website Home Search Blog Skills Privacy Security My Projects Gitlab (external) Docker (external) Email Privacy Tester (external) ParseMail (external) Support [ ] Bitcoin Bitcoin Address [1PQLtWnjUi1itHLG6QCQ] Copy Close PayPal (external) Patreon (external) [ ] [ ] [ ] Like Sends a private notification to Mike. No external services used. [ ] [ ] [ ] Cancel Send Feeds RSS Atom Mastodon (external) Bluesky (external) Cert Authorities Check for DNSSEC From Today Published 1 day ago March 15, 2026 1 min read * View Markdown * Other Articles Article written by a human: Mike Cardwell About 14 years ago I set up DNSSEC. I've been running it on all of my domains ever since, without issue. First using bind9 and then later using PowerDNS. From today, all Certificate Authorities (CAs) must validate DNSSEC when a domain has it enabled. So from today, when a CA looks up my CAA record to see if they are allowed to issue a cert for one of my domains, they must validate that the response they received is valid. And during the ACME dance, they have to validate those DNS records too. I assume that all CA's had implemented this requirement prior to today, if only so they could test it before the deadline was reached. But now it is mandatory, and I expect that any evidence that they are not doing it will be treated harshly. You might not want to learn about DNSSEC. You probably don't host your own DNS zone. There's a reasonable chance you own your own domain name though if you're here reading this. Why not go find out if your registrar supports DNSSEC for your domains? It might be a one click operation to turn it on... Support my work: [ ] [ ] [ ] Like Sends a private notification to Mike. No external services used. [ ] [ ] [ ] Cancel Send PayPal Patreon [ ] Bitcoin Bitcoin Address [1PQLtWnjUi1itHLG6QCQ] Copy Close Follow my work: RSS Atom Mastodon Bluesky Related Articles * Understanding DNSSEC 14 years ago * Publishing PGP Keys in the DNS 15 years ago * DNSCrypt Reduces Privacy 9 years ago - Read more [ ] Close JavaScript is disabled. These keyboard shortcuts require JavaScript to function. Keyboard Shortcuts ? Open this modal / or S Focus on search field L Like this page Esc Close popup / blur field Go to G H Home G B Blog G S Search Close