{"uid":"cap_5fYzH5XcFbLXml2GygzpT","slug":"foundry-dns-dkim-selector-txt-record-comparison-7434b578","name":"Foundry DNS DKIM Selector TXT Record Comparison","description":"Pay-per-request evidence and data tools: CSV validation and reconciliation, DNS/email configuration evidence, and bounded official weather, earthquake, vehicle, company and study records. Exact USDC prices, explicit JSON contracts and source provenance. No mailbox, ownership, medical or safety guarantees.","url":"https://foundry-par007-machine-revenue-mainnet.inference-chip-index.workers.dev/v2/domain/dns-mail-auth-selector-compare","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"domain":{"type":"string","maxLength":253,"minLength":3},"selectors":{"type":"array","items":{"type":"object","required":["selector","expected_txt"],"properties":{"selector":{"type":"string","pattern":"^[a-zA-Z0-9_-]{1,63}$"},"expected_txt":{"type":"string","maxLength":4096,"minLength":1}},"additionalProperties":false},"maxItems":2,"minItems":1}}},"responseSchema":{"type":"json","example":{"route":"dns-mail-auth-selector-compare","result":{"domain":"example.com","comparisons":[{"status":"ABSENT","evidence":{"name":"s1._domainkey.example.com","type":"TXT","rcode":3,"dnssec":"UNKNOWN","source":"https://cloudflare-dns.com/dns-query?name=s1._domainkey.example.com&type=TXT","status":"NXDOMAIN","records":[],"observedAt":"2026-09-07T00:00:00Z","attribution":"Cloudflare 1.1.1.1 public resolver; authoritative DNS records; no endorsement"},"selector":"s1","query_name":"s1._domainkey.example.com","expected_txt":"v=DKIM1; p=EXAMPLE_PUBLIC_KEY","observed_txt":[],"authentication_record":{"tags":{},"status":"ABSENT","records":[],"limitations":["Synthetic example only."]}}],"limitations":["Queries only the one or two selectors explicitly supplied by the caller. No guessing, enumeration, email sending or private-key access.","Matches decoded TXT content exactly, including tag order, case and whitespace; lexical differences do not establish different cryptographic keys.","A MATCH establishes published text equality only, not message signature validity, successful rotation, delivery or ownership. Truncated/failed resolver answers remain UNKNOWN."],"observed_at":"2026-09-07T00:00:00Z"},"observed_at":"2026-09-06T00:00:00Z"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_B1l51m2yguRLIwAtNsYyo","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Looks up DKIM selector TXT records in DNS for a domain and compares the observed values against caller-supplied expected strings, returning match/absent/unknown evidence with source provenance.","exampleAgentPrompt":"Check whether the DKIM selector 's1' for 'acme.com' is published in DNS and matches this expected TXT value: 'v=DKIM1; k=rsa; p=MIGfMA0G...'","exampleUseCases":[{"title":"Post-rotation DKIM key verification","prompt":"We just rotated our DKIM key for 'mailgun._domainkey.mycompany.com' — can you look up the TXT record live in DNS and confirm it now matches the new value 'v=DKIM1; k=rsa; p=NEWKEY123abc'?"},{"title":"Email deliverability audit","prompt":"I'm troubleshooting bounced emails for 'newsletter.example.org'. Check if the DKIM selector 'k1' is actually present in DNS and whether it matches the value 'v=DKIM1; p=PUBKEYABC' that our ESP says we set."},{"title":"Multi-selector DKIM deployment check","prompt":"Confirm that both of our DKIM selectors for 'beta.startup.io' are live: selector 'selector1' should have TXT 'v=DKIM1; p=AAABBBCCC' and selector 'selector2' should have 'v=DKIM1; p=DDDEEEFFF'."}],"resultDescription":"A JSON object containing per-selector comparison results: each entry includes the selector name, query name used, status (MATCH, ABSENT, or UNKNOWN), the expected TXT string, observed TXT records retrieved from DNS, DNSSEC status, the resolver source URL, timestamp, and textual limitations disclaiming that a MATCH confirms published text equality only — not cryptographic validity, message signing success, or delivery guarantees.","failureModes":["Selector not found in DNS returns status ABSENT with NXDOMAIN rcode","DNS resolution failure or timeout returns status UNKNOWN","TXT record present but differs in whitespace, case, or tag order returns no match even if semantically equivalent","Invalid selector name format (non-alphanumeric) rejected with input validation error","Domain too short or too long rejected at input validation","More than 2 selectors in request rejected due to maxItems constraint","Truncated DNS responses leave status UNKNOWN with no records"],"whenToPreferThis":"Choose this endpoint when you need cryptographically-neutral, sourced evidence that a specific DKIM selector TXT record is live in DNS and matches an exact expected string — for example after key rotation, during email configuration audits, or as a compliance artifact. It is not a mail-sending test, ownership proof, or full email deliverability audit; it is a precise, pay-per-call DNS lookup-and-compare with source attribution and explicit limitations.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T00:50:47.826Z","isFirstParty":false}