Skip to content

Restrict HTTPS certificates to Let’s Encrypt

Only allow Let’s Encrypt — used by most hosts including Vercel, Netlify and GitHub Pages — to issue HTTPS certificates for your domain.

About 5 minutesLet’s Encrypt documentation

1

Tell us about your setup

We fill in your details so you can copy each value exactly.

Your details

Certificate authorities can report problems here.

We’ll check your work

Enter your domain above. After adding the records, click “Check my records” and we’ll look them up live and point out any mistakes.

2

Add these records where your DNS is hosted

Pick your provider to see exactly what to type in each .
How to add records in Other provider
  1. Log in where you manage your domain’s DNS (see “DNS hosted at” above if we detected it).
  2. Find the DNS, Zone editor or “Advanced DNS” page.
  3. Add each record below. In the name field, type only what’s shown — most providers add your domain automatically.
  4. Save, then come back here and check again.
  • 💡 If your provider asks for a full name, add your domain after the name shown, followed by a dot.
Other provider help article ↗
CAA

Allows Let’s Encrypt to issue certificates for your domain.

Name / Host
@
Value / Points to
0 issue "letsencrypt.org"

Some optional records are hidden until you fill in the matching field above.

3

Check your setup

Changes usually show up within a few minutes. Click “Check again” or turn on “Keep checking” and leave this page open — we’ll tell you when everything is in place.
  • Check which certificate authority your host uses before adding this. Cloudflare, for example, also needs pki.goog and others.