iodef (Incident Object Description Exchange Format) is a CAA tag naming a mailto: or https: endpoint that CAs should report attempted violations to. If someone tries to get a rogue cert from a CA not in your issue list, the CA emails your iodef contact. Publish CAA without iodef and you’ll never learn about rogue-issuance attempts. Publish CAA with iodef and you get an early-warning signal.
All questions