---
title: "Implementation of Multi-Perspective Issuance Corroboration (MPIC) and Mandatory CAA Checks for Mailbox Addresses – HARICA"
description: "Multi-Perspective Issuance Corroboration (MPIC) Starting on March 15, 2025, HARICA will implement Multi-Perspective Issuance Corroboration (MPIC) for Domain Authorization, Control, and Certification Authority Authorization (CAA) Record checks before issuing any TLS Server Authentication Certificates, in accordance with CA/B Forum Baseline Requirements for TLS Server Certificates.  With MPIC, DNS queries for Domain Validation and CAA checks must be verified from multiple, randomly distributed and distant locations across"
author: "Alkisti Vasilika Patsarasli"
date: "2025-03-14T08:14:14+00:00"
language: "en-US"
canonical_url: "https://demo.harica.gr/en/posts/post-5630"
source_url: "https://demo.harica.gr/en/posts/post-5630/"
content_type: "text/markdown"
---

#### Multi-Perspective Issuance Corroboration (MPIC)

Starting on **March 15, 2025**, HARICA will implement **Multi-Perspective Issuance Corroboration (MPIC)** for Domain Authorization, Control, and Certification Authority Authorization (CAA) Record checks before issuing any **TLS Server Authentication Certificates**, in accordance with CA/B Forum [Baseline Requirements for TLS Server Certificates](https://cabforum.org/working-groups/server/baseline-requirements/documents/).

With MPIC, DNS queries for **Domain Validation** and **CAA checks** must be verified from **multiple, randomly distributed and distant locations** across the Internet. If the information corroboration fails (up to a certain level), the certificate issuance will be blocked. Domain Owners **must ensure** that their **Authoritative DNS servers are accessible from the global Internet**, allowing the corroboration to be completed without failures that would prevent certificate issuance.

We remind our Subscribers that Publicly-Trusted TLS Server Authentication Certificates are “intended to be used for authenticating servers accessible through the Internet”, as described in the CA/Browser Forum TLS Baseline Requirements.

#### Mandatory CAA Checks for Mailbox Addresses

Effective **March 15, 2025**, HARICA will also be required to perform **CAA checks for Mailbox Addresses**, as mandated by the CA/Browser Forum S/MIME Baseline Requirements.

What You Need to Know:

- Before issuing an S/MIME certificate that includes a Mailbox Address, HARICA will retrieve and process CAA records, similar to the process used for TLS Certificates.

- If your DNS CAA record contains the **issuemail** tag, it must explicitly include the value “harica.gr”, authorizing HARICA for S/MIME certificate issuance.

- If no issuemail tag is present, no action is required.

**TAGS:**

[CAA](https://demo.harica.gr/en/posts/post-tag/caa), [Domain Validation](https://demo.harica.gr/en/posts/post-tag/domain-validation), [MPIC](https://demo.harica.gr/en/posts/post-tag/mpic), [S/MIME](https://demo.harica.gr/en/posts/post-tag/s-mime), [TLS](https://demo.harica.gr/en/posts/post-tag/tls)

## Latest News

- May 21, 2023[HARICA](https://demo.harica.gr/en/posts/post-category/harica-en)

#### [Implementation of a new policy in the protection of the private key in Code Signing certificates](https://demo.harica.gr/en/posts/post-3128)

- May 16, 2023[HARICA](https://demo.harica.gr/en/posts/post-category/harica-en), [Support](https://demo.harica.gr/en/posts/post-category/support)

#### [HARICA announcement on Kiwifarms](https://demo.harica.gr/en/posts/post-3174)
