A CAA value is made of a flag, a tag and data — for example, example.com CAA 0 issue "letsencrypt.org" allows only Let's Encrypt to issue. The main tags are:
Previously any public certificate authority could issue a certificate for any domain — a single mistake or breach risked producing a fraudulent one. CAA narrows the set of trusted authorities, and they must check the record on every issuance. Unlike free-form TXT text, CAA has a strict machine-readable format and directly affects whether a certificate can be obtained.