Skip to content
puluno

Security & uptime

CAA and DNSSEC in DNS

Explorer reports missing CAA or DNSSEC — what it means and when to fix it at your registrar.

Typical symptom

Email & DNS panel shows caa_missing or dnssec_not_signed — external audits often mention the same.

Puluno modules

Guard

Undo change

No — info / hosting only

Issue codes

caa_missing, dnssec_not_signed

What you see

  • caa_missing — no CAA (Certification Authority Authorization) records on the domain.
  • dnssec_not_signed — no DNSKEY records visible (DNS answers are not signed).
  • Explorer SEO score is unchanged — informational DNS layer alongside SPF/DMARC.

Why it happens

Most shared hosts and registrars do not enable DNSSEC by default and do not add CAA. That is not a WordPress or Puluno Guard misconfiguration.

TopicRisk without itTypical priority for a WP shop
CAAAny CA could theoretically issue a cert for your name (CA compromise / process error)Medium — cheap hardening
DNSSECTheoretically easier DNS cache poisoningLow to medium — depends on registrar

Puluno does not cryptographically validate DNSSEC from the VPS — it only checks for DNSKEY presence.

What Puluno does

PhaseWhereAction
DiagnoseExplorerEmail & DNS panel after scan
FixDNS at registrar / hostoutside WordPress
Verifynew scanCAA / DNSSEC pass in panel

Guard headers (CSP, HSTS) cover HTTP, not CAA/DNSSEC — see Headers and XML-RPC.

CAA — step by step

  1. Identify who issues your TLS certificate (Let's Encrypt on host, Cloudflare, custom CA).
  2. Add CAA records in DNS — often issue "letsencrypt.org" per host docs.
  3. Add issuewild only if you use wildcard certificates.
  4. After DNS propagation, run a new scan — CAA row should pass.

Example (Let's Encrypt — adjust for your CA):

0 issue "letsencrypt.org"
0 issuewild "letsencrypt.org"

DNSSEC — step by step

  1. Enable DNSSEC at your DNS provider (registrar DNS, Cloudflare, etc.).
  2. Copy DS records into your domain registrar (.cz at CZ.NIC, gTLDs at your registrar).
  3. Wait for propagation (can take longer than normal A/TXT).
  4. Confirm “DNSSEC active” at the registrar and scan again in Explorer.

Rolling back DNSSEC = disable at DNS + remove DS at registrar — note the previous state.

When it is not Puluno

  • Renewing the server certificate — Downtime / SSL.
  • SPF / DMARC / MTA-STS — Forms and mail DNS.
  • Enterprise DNS with internal runbooks — out of scope for this guide.
CAA and DNSSEC in DNS | Puluno