{"uid":"cap_2OFSH0ffDQss-mU-pLZtU","slug":"syntexa-agentshelf-dns-tlsa-lookup-780eef03","name":"Syntexa AgentShelf DNS TLSA Lookup","description":"Call when an agent needs TLSA records at the exact hostname (usually _port._proto.name). Exact $0.006 USDC. Prefer unpaid POST /v1/sandbox/dns-tlsa first.","url":"https://agentshelf.syntexa.ch/v1/dns-tlsa?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"hostname":{"type":"string","examples":["example.com"],"maxLength":253,"minLength":1,"description":"Public DNS hostname such as example.com. Not a URL, not an IP literal, and not a private name."}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.006","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.006/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.006","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.006","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_qhneX1TiZwsozqQ19Aral","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.006","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Retrieves TLSA (TLS Authentication) DNS records for a given hostname, used for DANE certificate verification.","exampleAgentPrompt":"Can you look up the TLSA DNS records for _443._tcp.mail.example.com so I can verify the DANE certificate pinning is set up correctly?","exampleUseCases":[{"title":"SMTP DANE certificate verification","prompt":"Fetch the TLSA records for _25._tcp.mail.protonmail.com — I need to confirm that DANE is properly configured for their mail server before setting up email delivery."},{"title":"HTTPS DANE pin validation","prompt":"Look up the TLSA records at _443._tcp.www.example.com to check if the website has certificate pinning via DANE in DNS."},{"title":"Debugging TLS handshake failures","prompt":"Can you pull the TLSA DNS record for _443._tcp.api.myservice.io? I'm troubleshooting a DANE validation failure and need to see what's published in DNS."}],"resultDescription":"Returns the TLSA resource records published in DNS for the exact hostname queried, including fields such as certificate usage, selector, matching type, and the certificate association data (hash or raw certificate bytes), enabling DANE-based TLS validation.","failureModes":["Hostname not found in DNS — no TLSA records published at that name","Malformed hostname input (exceeds 253 characters or is empty)","DNS lookup timeout or resolver unavailability","No TLSA record exists at the queried name (NXDOMAIN or NOERROR with empty answer)","Payment failure — $0.006 USDC not available or x402 protocol error"],"whenToPreferThis":"Use this endpoint when you need to retrieve TLSA records for DANE certificate validation at a specific DNS owner name (typically formatted as _port._proto.hostname). Prefer the free sandbox endpoint POST /v1/sandbox/dns-tlsa first if available; use this paid endpoint when production accuracy and reliability are required.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T02:20:21.967Z","isFirstParty":false,"canonicalSlug":"syntexa-agentshelf-dns-tlsa-lookup-780eef03"}