{"uid":"cap_q-Z36aWX8hdaW6uj_58gk","slug":"apiacre-com-email-authentication-posture-check-489b208c","name":"apiacre.com Email Authentication Posture Check","description":"Check a public domain's email authentication and anti-spoofing posture using MX, SPF, DMARC, caller-selected DKIM, MTA-STS, TLS-RPT, and BIMI DNS evidence.","url":"https://apiacre.com/v1/web/email-auth","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"domain":{"type":"string"},"dkim_selectors":{"type":"array","items":{"type":"string"}}}},"responseSchema":{"type":"json","example":{"data":{"spf":{"records":["v=spf1 include:_spf.protonmail.ch ~all"],"configured":true,"recordCount":1,"allQualifier":"softfail","multipleRecords":false},"dkim":{"reason":null,"checked":true,"selectors":[{"revoked":false,"selector":"protonmail","configured":true,"recordCount":1,"multipleRecords":false}],"checkedSelectors":["protonmail"]},"dmarc":{"policy":"quarantine","records":["v=DMARC1; p=quarantine"],"configured":true,"recordCount":1,"multipleRecords":false},"domain":"apiacre.com","posture":{"basis":"published DNS records only","status":"enforcing"},"findings":[],"checkedAt":"2026-08-12T18:03:16+00:00","provenance":{"source":"recursive DNS","queries":["apiacre.com A","apiacre.com AAAA","apiacre.com MX","apiacre.com TXT","_dmarc.apiacre.com TXT","protonmail._domainkey.apiacre.com TXT","_mta-sts.apiacre.com TXT","_smtp._tls.apiacre.com TXT","default._bimi.apiacre.com TXT"],"queryCount":9},"limitations":["DNS answers are a time-specific recursive-resolver snapshot and may be cached.","DKIM is checked only for selectors explicitly supplied by the caller.","Published records do not prove delivery, domain ownership, sender identity, o..."],"mailRouting":{"mode":"explicit_mx","nullMx":false,"mxRecords":["10 mail.protonmail.ch.","20 mailsec.protonmail.ch."],"addressFallbackObserved":true},"collectionMs":19,"optionalPolicies":{"bimi":{"records":[],"configured":false,"recordCount":0},"mtaSts":{"records":[],"configured":false,"recordCount":0},"tlsReporting":{"records":[],"configured":false,"recordCount":0}}},"meta":{"cached":false,"sources":[],"warnings":[],"duration_ms":42,"next_actions":[]},"service":"web.email-auth","version":"1","request_id":"018f1f54-7f38-7ba2-8dc3-5f90272d9f1a"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_s6TEFyRBCAHcYq1ndChCz","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks a public domain's email authentication and anti-spoofing configuration by inspecting MX, SPF, DMARC, DKIM, MTA-STS, TLS-RPT, and BIMI DNS records.","exampleAgentPrompt":"Can you check the email authentication posture of example.com — I want to see its SPF, DMARC, DKIM (selector 'google'), MTA-STS, TLS-RPT, and BIMI DNS records to find out if it's protected against spoofing?","exampleUseCases":[{"title":"Pre-send domain security audit","prompt":"Before we start emailing customers from our new domain acmecorp.io, can you check its SPF, DMARC, MTA-STS, and TLS-RPT records to make sure everything is set up correctly to prevent spoofing?"},{"title":"Vendor phishing risk assessment","prompt":"We're about to onboard payments.supplierco.com as a vendor — can you pull their full email authentication posture including DMARC policy, SPF, and DKIM with selector 'selector1' to see if they're vulnerable to phishing?"},{"title":"BIMI brand display verification","prompt":"We set up BIMI for ourbrand.com last week — can you verify our BIMI DNS record is present and check that our SPF and DMARC are in enforcement mode so our logo should appear in email clients?"}],"resultDescription":"Returns structured DNS evidence for the queried domain covering MX, SPF, DMARC (including policy enforcement level), caller-specified DKIM selector record, MTA-STS policy, TLS-RPT reporting address, and BIMI record — giving a complete picture of the domain's email authentication and anti-spoofing posture.","failureModes":["Domain does not exist or has no DNS records — empty or error result per record type","Invalid DKIM selector provided — DKIM check returns not-found or NXDOMAIN","Domain is private or behind split-horizon DNS — records may be inaccessible","Rate limiting or DNS resolver timeouts — transient failure with error response","Malformed domain input — validation error returned"],"whenToPreferThis":"Choose this endpoint when you need a comprehensive, multi-record email authentication audit in a single call covering SPF, DMARC, DKIM, MTA-STS, TLS-RPT, and BIMI together. Prefer it over manual dig/nslookup lookups or single-record checkers when you need structured, normalized JSON output suitable for automated agent workflows or compliance reporting.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:41:05.058Z","isFirstParty":false}