Docs/Sources/Parse CAA Records

Parse CAA Records

Parse DNS CAA records

OperationalCredits 2 per callp50 253msReference Data

Overview

Includes a database of known Certificate Authorities like Let's Encrypt, DigiCert, and others, with automatic identification and policy interpretation.

Formula

One function covers the whole catalog: the first argument names the source, the rest are its inputs, and the "field" pair says which single value lands in the cell. Formulas covers the grammar that applies to all of them.

=VERVE("caaparser", A2, "field", "raw_record")

A2 holds the record you are looking up. Drag the formula down and each row resolves on its own.

With literal values

Nothing has to come from a cell — typed values work the same way.

=VERVE("caaparser", "example.com. 3600 IN CAA 0 issue ""letsencrypt.org""", "field", "raw_record")

Inputs

Required inputs are positional, in the order below. Everything else is passed as a "name", value pair after them — the same shape as SUMIFS. Premium inputs are accepted on every plan but only take effect on plans that include them.

InputTypeWhere it goesDescription
recordRequiredstringargument 2 (A2)The CAA record string to parse

What lands in your sheet

The "field" pair is what makes the formula resolve to one cell. Its value is a dot-path from the table below, so swapping it is how you pull a different value — one formula per column.

Seeing everything at once

Drop the "field" pair and the formula returns the whole response instead: two columns, field name on the left and value on the right, spilling from the cell you typed in.

=VERVE("caaparser", A2)
Good for exploring, not for filling down

The second row's table would land on top of the first's, and every cell after the first reads #REF! (#SPILL! in Excel). Keep one per sheet, or name a field, and leave the cells below and to the right empty.

Response fields

Paths are relative to data. Each one is exactly what the "field" pair accepts, so swapping it is how you pull a different value into a cell. On a plan without a Premium field the cell reads #PREMIUM(field) rather than a value, so a locked field never looks like a real answer.

Use as "field"TypeExample cell valueDescription
raw_recordstringexample.com. 3600 IN CAA 0 issue "letsencrypt.org"The original CAA record string provided for parsing
parsedobject{…}
parsed.domainstringexample.comDomain name extracted from the CAA record
parsed.ttlnumber3600Time-to-live value in seconds for the CAA record
parsed.classstringINDNS class designation, typically IN for internet
parsed.flagsnumber0CAA record flags value indicating record criticality
parsed.tagstringissueCAA tag type such as issue, issuewild, or iodef
parsed.valuestringletsencrypt.orgValue associated with the CAA tag
ca_infoPremiumobject{…}Information about the recognized Certificate Authority
ca_info.namePremiumstringLet's EncryptRecognized Certificate Authority name if identified
ca_info.typePremiumstringFreeCertificate Authority type classification such as Free or Commercial
ca_info.wildcard_supportPremiumbooleantrueIndicates if the CA supports wildcard certificate issuance
interpretationPremiumobject{…}Detailed interpretation and security analysis of CAA record
interpretation.meaningPremiumstringOnly letsencrypt.org is authorized to issue certificatesHuman-readable explanation of what the CAA record authorizes
interpretation.restrictionPremiumstringRestricted to specific CADescription of access restrictions imposed by this CAA record
interpretation.criticalPremiumbooleanfalseIndicates if the critical flag is set on the CAA record
interpretation.critical_explanationPremiumstringNon-critical - CA may proceed if not understoodExplanation of critical flag behavior and implications
tag_descriptionPremiumstringAuthorizes a CA to issue certificates (any type)Description of the CAA tag purpose and behavior
is_validbooleantrueValidation status indicating if the CAA record is properly formatted

Filling a whole column

Both platforms make one batched call for a column rather than one request per cell, and both cost the same — 2 credits per row looked up. How you write it differs, because the two runtimes batch at different points.

Rows 2–100 in one call
=VERVE("caaparser", A2:A100, "field", "raw_record")

In Google Sheets, give the arguments ranges and the answers spill down from the cell you typed in. Custom functions there run synchronously and in isolation, so dragged cells cannot be coalesced — the range form is how a column becomes one call. The "field" pair is required here: a per-row two-column table has nowhere to spill. Use a full column per input (A2:A100, not A2) — a single-cell reference is read as row 1 only and the rest of the column comes back blank.

In Excel, type the formula once and fill down — no range form and none needed, because its runtime is asynchronous and the add-in coalesces the calls a fill produces into a single batched request. Do not hand VERVE.CALL a range: Excel flattens it into positional arguments, so A2:A100 arrives as a hundred separate arguments and the cell reads #ERR rather than filling.

Either way, column A holds your record values and the answers land beside them, one row each, blank rows skipped.

When a cell doesn't fill

A failed lookup returns readable text starting with #ERR rather than a spreadsheet error, because Excel cannot show a custom message on a real error — you would get a bare #VALUE! with no reason. The trade-off is that IFERROR() will not catch it; test with LEFT(cell, 4) = "#ERR" instead. Error handling covers the rest.

Cell readsWhat happened
#ERR Not connectedNo API key saved. Open the side panel and connect your account.
#ERR Replace <name> with a cell or valueA preview formula was copied as-is. Swap the placeholder for a cell reference.
#ERR No "x" in caaparserAn option name this source does not take. The message lists the ones it does.
#ERR No data point "…"The "field" path is not in the response. Check it against the table above.
#PREMIUM(field)The field exists but your plan does not include it.
#ERR Out of creditsThe cycle's credits are spent. Usage resets on your billing date.

Before the formula works

The add-in reads the API key you saved once in the side panel — the key never goes in the formula, so a shared sheet does not leak it and a collaborator without access simply sees the last calculated values.

  1. Install the add-in for Google Sheets or Excel.
  2. Open the side panel and sign in, or paste a key from your dashboard.
  3. Type the formula above into any cell.

Use cases

Security Analysis
Parse CAA records for security analysis and threat detection to identify unauthorized certificate authorities
Policy Validation
Validate certificate issuance policies by parsing CAA records to ensure only authorized CAs can issue certificates
DNS Security Tools
Build DNS security tools that monitor and analyze CAA records for compliance and security posture assessment
Certificate Auditing
Audit domain certificate authorization settings to maintain control over which CAs can issue certificates for your domains

Other ways to use Parse CAA Records

Set up Parse CAA Records on VerveSheets, or reach the same source a different way. Your VerveSheets account and credits work on all of them — one key, one balance.

Call it as a REST APIOne HTTPS endpoint and an x-api-key header, with SDKs for Node, Python and .NET.APIVerveReference →
Give it to an AI agentConnect over MCP and your agent calls it as a native tool — Claude, Cursor, ChatGPT.VerveKitReference →
Ground an agent on itA cited, machine-checkable fact your model can't produce on its own.VerveContextReference →

More in Reference Data:

Was this page helpful?