{"uid":"cap_XzfxhmY6RiIaOoJ__kU4K","slug":"dns-caa-policy-check-06741952","name":"DNS CAA Policy Check","description":"DNS Caa Policy Check: DNS Caa Policy Check checks whether a certificate authority identifier is allowed by CAA records from bounded caller-supplied values without an external provider. Call DNS Caa Policy Check before accepting, caching, redirecting, or retrying a caller-supplied web response. Returns normalized web evidence, the computed finding, and an explicit pass or advisory status for DNS Caa Policy Check as versioned deterministic JSON. Price: $0.001 USDC via x402 on Base. First-party, s…","url":"https://api.delx.ai/api/v1/x402/dns-caa-policy-check","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"issuer":{"type":"string","maxLength":8192,"description":"Issuer supplied to DNS Caa Policy Check; used only for this bounded calculation and processed in memory without retention."},"records":{"type":"array","items":{"type":"object","maxProperties":128,"additionalProperties":true},"maxItems":256,"description":"Records supplied to DNS Caa Policy Check; used only for this bounded calculation and processed in memory without retention."}}},"responseSchema":{"type":"json","example":{"result":{"issuer":"letsencrypt.org","permitted":true},"schema":"delx/util-dns-caa-policy-check/v1","status":"pass","evidence":{"retained":false,"input_sha256":"b0ce3b06dcfb1237aa32eef6c1398ecd3e5f4811ddf5558614373560166e3b1e","external_calls":0},"operation":"web_reliability:dns_caa_policy_check"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_oacYPabvWEbTW9OWTgjbB","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks whether a certificate authority identifier is permitted by DNS CAA records, returning a deterministic pass/advisory verdict as structured JSON.","exampleAgentPrompt":"Check whether the certificate authority 'letsencrypt.org' is permitted by these CAA records before we accept this TLS certificate — run a DNS CAA policy check and tell me if it passes or gets an advisory flag.","exampleUseCases":[{"title":"Pre-issuance CA authorization check","prompt":"Before we proceed with issuing a TLS certificate, check whether 'digicert.com' is authorized as an issuer by these CAA records I've collected from the DNS zone — give me a pass or advisory verdict."},{"title":"Automated TLS pipeline validation","prompt":"We're about to cache a web response that came with a certificate from 'sectigo.com' — run a CAA policy check against these DNS CAA records first and tell me if the issuer is explicitly allowed."},{"title":"Security audit of CAA record compliance","prompt":"I need to audit whether our current CAA records actually permit 'letsencrypt.org' as a certificate authority — run a policy check and return the full finding with evidence so I can review it."}],"resultDescription":"Returns versioned deterministic JSON containing: normalized CAA record evidence, the computed policy finding, and an explicit pass or advisory status indicating whether the supplied issuer identifier is authorized by the provided CAA records.","failureModes":["Malformed issuer string causes validation error","Records array exceeds 256-item limit returns error","Individual record objects exceeding 128-property limit rejected","Missing required fields returns 400-level error","Ambiguous or empty issuer may produce advisory rather than pass"],"whenToPreferThis":"Prefer this endpoint when you need a fast, deterministic, serverless CAA policy check without relying on live DNS resolution — it evaluates caller-supplied records and issuer in-memory, making it ideal for pre-issuance validation pipelines, caching decisions, or security audits where you already have the CAA records and want a structured, versioned verdict without external DNS dependencies.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T19:05:41.864Z","isFirstParty":false}