{"uid":"cap_KBCb2qOtJ4NVFezFHQvfm","slug":"synthora-dns-caa-authorization-records-doh-cdaebe26","name":"SYNTHORA DNS CAA Authorization Records (DoH)","description":"Returns Certificate Authority Authorization (CAA) records showing which CAs are permitted to issue TLS certificates for a domain, via Cloudflare DoH JSON. A2A use: certificate-issuance and supply-chain-security agents verify CA policy and flag mis-issuance risk before trusting a host. First 3 calls FREE per wallet — send header X-WALLET: 0x<addr>. No charge on upstream failure.","url":"https://doh-caa-records.hergertsynthora.com/service","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"domain":{"type":"string","description":"domain"}}},"responseSchema":{"type":"json","example":{"ok":true,"niche":"doh-caa-records","result":{"domain":"google.com","status":"success","caa_records":[{"ttl":86400,"name":"google.com","value":"\\# 15 00 05 69 73 73 75 65 70 6b 69 2e 67 6f 6f 67"}]},"provenance":{"url":"https://cloudflare-dns.com/dns-query","source":"DNS CAA Authorization Records (DoH)"}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_CEd31J-cxMvAL70IKJdtX","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Retrieves DNS CAA records for a domain via Cloudflare DoH JSON, revealing which Certificate Authorities are authorized to issue TLS certificates for that domain.","exampleAgentPrompt":"Can you look up the CAA DNS records for example.com and tell me which Certificate Authorities are authorized to issue TLS certificates for it?","exampleUseCases":[{"title":"Pre-deployment TLS policy audit","prompt":"Before we deploy to api.mycompany.com, check the CAA records and confirm which CAs are actually authorized to issue certs for that domain — I want to make sure our Let's Encrypt setup won't be blocked."},{"title":"Supply chain security verification","prompt":"I'm reviewing the certificate issuance policy for payments.acmecorp.com — can you pull the CAA records and flag any mis-issuance risks or unexpected CA authorizations?"},{"title":"Incident investigation for rogue certificate","prompt":"We suspect a rogue certificate was issued for shop.retailbrand.com — can you fetch the current CAA records to see which CAs are permitted, so we can check if the issuing CA was even authorized?"}],"resultDescription":"A JSON object containing the domain name, a status field, and an array of CAA records each with TTL, name, and raw value (hex-encoded wire format). Also includes provenance metadata showing the Cloudflare DoH URL used as the source.","failureModes":["Domain does not exist (NXDOMAIN) — returns empty or error result","Domain has no CAA records — returns success with empty caa_records array","Invalid domain format input — may return error or unexpected behavior","Cloudflare DoH upstream unavailable — service may timeout or return error","Network timeout reaching Cloudflare endpoint — slow or failed response"],"whenToPreferThis":"Choose this endpoint when you need to programmatically verify DNS CAA policy for a domain as part of certificate issuance validation, supply-chain security checks, or PKI auditing workflows. It is particularly useful when you want privacy-preserving DNS resolution (DoH via Cloudflare rather than plaintext DNS) and need structured JSON output for agent pipelines. Prefer this over raw DNS queries when you need a reliable, pre-parsed, cloud-accessible CAA lookup that returns raw wire-format values alongside human-readable TTL and name fields.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:37:27.706Z","isFirstParty":false}