{"uid":"cap_bLA-boGQNYNZfCpalppE_","slug":"dns-caa-record-lookup-0bda2d55","name":"DNS CAA Record Lookup","description":"DNS CAA record lookup: which certificate authorities are allowed to issue TLS certificates for a domain (issue, issuewild, iodef), parsed. Certificate policy audits and issuance troubleshooting. $0.01 per lookup.","url":"https://intel.rallylive.ca/dns/caa","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_qkjPXZ5QPyIrYiHRnw4Uu","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Looks up DNS CAA records for a domain to identify which certificate authorities are authorized to issue TLS certificates, including issue, issuewild, and iodef directives.","exampleAgentPrompt":"Can you look up the CAA DNS records for example.com and tell me which certificate authorities are authorized to issue TLS certificates for it, including any wildcard or iodef directives?","exampleUseCases":[{"title":"Diagnose failed certificate issuance","prompt":"My Let's Encrypt certificate renewal for mybusiness.com just failed — can you check the CAA records on mybusiness.com to see if Let's Encrypt is even authorized to issue certs for it?"},{"title":"Pre-deployment certificate policy audit","prompt":"Before we go live, can you pull the CAA records for newproduct.io and confirm which CAs are allowed to issue TLS certs, and whether wildcard certificates are permitted?"},{"title":"Detect misconfigured iodef reporting","prompt":"Can you check the CAA records for api.example.com and tell me if there's an iodef directive set up to receive certificate misissuance reports, and what address it points to?"}],"resultDescription":"Returns parsed CAA record data for the queried domain, including all issue directives (which CAs may issue standard certificates), issuewild directives (which CAs may issue wildcard certificates), iodef directives (where to report policy violations), TTL values, record count, and any DNSSEC validation status.","failureModes":["Domain has no CAA records (returns empty set, not an error — many domains have none)","Invalid or non-existent domain name returns DNS resolution failure","Network timeout if DNS resolver is unreachable","Payment not received results in 402 response blocking the lookup"],"whenToPreferThis":"Use this endpoint when you specifically need to audit or troubleshoot TLS certificate authority authorization policies for a domain. It is the right choice when diagnosing certificate issuance failures, verifying CAA policy compliance, or checking wildcard cert permissions — distinct from general DNS lookups (A, TXT records) which are served by sibling endpoints on the same provider.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T13:10:36.326Z","isFirstParty":false}