If you want to use CAA-Records, you can use my backport: https://blog.schaal-24.de/ispconfig/caa-records-mit-ispconfig/?lang=en RFC6844 has some options that are currently not used by the CAs so you can not see this in the interface (until you change the templates). Read more about CAA: https://sslmate.com/labs/caa/ https://www.dawnbringer.net/blog/1029/More certificate control with CAA-records in your DNS https://tools.ietf.org/html/rfc6844