Every CA that participates in the CA/Browser Forum — which is every CA whose certs are trusted by mainstream browsers. Let’s Encrypt, DigiCert, Sectigo, GlobalSign, Entrust, GoDaddy, Amazon, Google Trust Services all check CAA. This has been mandatory since 2017. A CA that ignores CAA loses its browser trust.
All questions