No restriction — any trusted CA can issue certs for your domain. That’s not necessarily bad (it’s the historical default) but it does mean an attacker who compromises your registrar account, DNS host, or exploits a validation flaw could get a rogue cert issued from any CA. CAA closes that vector by restricting issuance to CAs you’ve listed.
All questions