{"uid":"cap_VxRsEmhseCw1CvX1XegJH","slug":"delx-commerce-dns-caa-policy-check-d5a486a9","name":"Delx Commerce DNS CAA Policy Check","description":"Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.","url":"https://commerce.delx.ai/api/v1/x402/dns-caa-policy-check?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"issuer":{"type":"string","maxLength":8192,"description":"Issuer supplied to DNS Caa Policy Check; used only for this bounded calculation and processed in memory without retention."},"records":{"type":"array","items":{"type":"object","maxProperties":128,"additionalProperties":true},"maxItems":256,"description":"Records supplied to DNS Caa Policy Check; used only for this bounded calculation and processed in memory without retention."}}},"responseSchema":{"type":"json","example":{"result":{"issuer":"letsencrypt.org","permitted":true},"schema":"delx/util-dns-caa-policy-check/v1","status":"pass","evidence":{"retained":false,"input_sha256":"b0ce3b06dcfb1237aa32eef6c1398ecd3e5f4811ddf5558614373560166e3b1e","external_calls":0},"operation":"web_reliability:dns_caa_policy_check"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_CjyPPuvqVQgr26WvpMkwi","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks whether a given certificate issuer is permitted by a domain's DNS CAA (Certification Authority Authorization) records","exampleAgentPrompt":"Check whether letsencrypt.org is permitted to issue certificates under this domain's CAA policy — here are the CAA records: [{\"flags\":0,\"tag\":\"issue\",\"value\":\"letsencrypt.org\"}].","exampleUseCases":[{"title":"Pre-issuance CA authorization check","prompt":"Before I request an SSL cert from Sectigo, can you verify whether Sectigo is actually permitted by my domain's CAA records? Here are the records I pulled: [{\"flags\":0,\"tag\":\"issue\",\"value\":\"letsencrypt.org\"}]."},{"title":"Security audit of CAA policy","prompt":"I'm auditing our domain security — check if our CAA records correctly allow only Let's Encrypt to issue certificates. The issuer to check is letsencrypt.org and here are the records: [{\"flags\":0,\"tag\":\"issue\",\"value\":\"letsencrypt.org\"},{\"flags\":0,\"tag\":\"issuewild\",\"value\":\";\"}]."},{"title":"Troubleshooting cert issuance failure","prompt":"Our certificate renewal just failed and I suspect a CAA mismatch. Can you check if DigiCert is permitted under this CAA policy: [{\"flags\":0,\"tag\":\"issue\",\"value\":\"letsencrypt.org\"}] — the issuer we're trying to use is digicert.com."}],"resultDescription":"Returns a JSON object indicating whether the specified issuer is permitted (boolean) under the provided CAA records, along with the operation name, a pass/fail status, and tamper-evident evidence including an input SHA-256 hash, retained=false flag, and external_calls count — confirming in-memory-only processing with no data retention.","failureModes":["Invalid or malformed CAA record objects may cause unexpected validation results","Issuer string exceeding 8192 characters is rejected","Records array exceeding 256 items is rejected","Missing issuer or records fields may result in a validation error or incomplete result","Payment failure (x402 protocol) blocks request processing"],"whenToPreferThis":"Choose this endpoint when you need a lightweight, deterministic, in-memory check of whether a specific CA is authorized under a given set of DNS CAA records — without making live DNS lookups. It is ideal for pre-issuance validation, security audits, and automated certificate pipeline checks where you already have the CAA records on hand and want a verifiable, pay-per-call result with no data retention and cryptographic evidence of the input processed.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T00:54:07.187Z","isFirstParty":false,"canonicalSlug":"delx-commerce-dns-caa-policy-check-d5a486a9"}