Security & uptime
CAA and DNSSEC in DNS
Explorer reports missing CAA or DNSSEC — what it means and when to fix it at your registrar.
Typical symptom
Email & DNS panel shows caa_missing or dnssec_not_signed — external audits often mention the same.
Puluno modules
Guard
Undo change
No — info / hosting only
Issue codes
caa_missing, dnssec_not_signed
What you see
caa_missing— no CAA (Certification Authority Authorization) records on the domain.dnssec_not_signed— no DNSKEY records visible (DNS answers are not signed).- Explorer SEO score is unchanged — informational DNS layer alongside SPF/DMARC.
Why it happens
Most shared hosts and registrars do not enable DNSSEC by default and do not add CAA. That is not a WordPress or Puluno Guard misconfiguration.
| Topic | Risk without it | Typical priority for a WP shop |
|---|---|---|
| CAA | Any CA could theoretically issue a cert for your name (CA compromise / process error) | Medium — cheap hardening |
| DNSSEC | Theoretically easier DNS cache poisoning | Low to medium — depends on registrar |
Puluno does not cryptographically validate DNSSEC from the VPS — it only checks for DNSKEY presence.
What Puluno does
| Phase | Where | Action |
|---|---|---|
| Diagnose | Explorer | Email & DNS panel after scan |
| Fix | DNS at registrar / host | outside WordPress |
| Verify | new scan | CAA / DNSSEC pass in panel |
Guard headers (CSP, HSTS) cover HTTP, not CAA/DNSSEC — see Headers and XML-RPC.
CAA — step by step
- Identify who issues your TLS certificate (Let's Encrypt on host, Cloudflare, custom CA).
- Add CAA records in DNS — often
issue "letsencrypt.org"per host docs. - Add
issuewildonly if you use wildcard certificates. - After DNS propagation, run a new scan — CAA row should pass.
Example (Let's Encrypt — adjust for your CA):
0 issue "letsencrypt.org"
0 issuewild "letsencrypt.org"
DNSSEC — step by step
- Enable DNSSEC at your DNS provider (registrar DNS, Cloudflare, etc.).
- Copy DS records into your domain registrar (.cz at CZ.NIC, gTLDs at your registrar).
- Wait for propagation (can take longer than normal A/TXT).
- Confirm “DNSSEC active” at the registrar and scan again in Explorer.
Rolling back DNSSEC = disable at DNS + remove DS at registrar — note the previous state.
When it is not Puluno
- Renewing the server certificate — Downtime / SSL.
- SPF / DMARC / MTA-STS — Forms and mail DNS.
- Enterprise DNS with internal runbooks — out of scope for this guide.
Module manual