CAA record uses an unknown property
ATTENTIONWhat it means
The property the offending value is not one a certificate authority acts on. A CAA set that a CA cannot interpret gives you neither the restriction you intended nor a warning that it is absent.
How to fix it
Use issue, issuewild or iodef. Anything else is ignored.
Check your own domain
This page describes the condition. To find out whether your domain has it, run the CAA test or the full checkup, which examines every record at once.
Understand it properly
This page covers one condition. For the whole picture, DNSSEC and certificate authority records, or start at the Health Library.
Where this comes from
We judge this against RFC 8659 section 4. Every finding on this site cites the specification behind it so you can check the work rather than take our word for it.
Other CAA conditions
CAA_SYNTAX
Every fix on this site is yours to implement. If you would rather someone did it, I take this work directly.