{"uid":"cap_uFTwTeFQ7UMb0ytD9MsJS","slug":"tinstop-dmarc-check-244f78ff","name":"Tinstop DMARC Check","description":"Tinstop is a machine-payable Website Intelligence API for domain security and performance audits: DNS, SSL/TLS, HTTP security headers, SPF/DKIM/DMARC email authentication, and Google PageSpeed. Pay per call with x402 using USDC on Base. No accounts or API keys.","url":"https://tinstop.com/v1/dmarc-check","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"domain":{"type":"string","description":"The domain name to check (e.g. 'example.com'). Do not include http:// or https:// protocol prefixes."}}},"responseSchema":{"type":"object","title":"DmarcCheckResponse","required":["domain","dmarc_valid","policy","adkim","aspf","rua","ruf","issues","scan_id"],"properties":{"rua":{"type":"array","items":{"type":"string"},"title":"Rua","description":"Reporting aggregate email destinations"},"ruf":{"type":"array","items":{"type":"string"},"title":"Ruf","description":"Forensic incident reporting destinations"},"aspf":{"type":"string","title":"Aspf","description":"SPF alignment option: r (relaxed) or s (strict)"},"adkim":{"type":"string","title":"Adkim","description":"DKIM alignment option: r (relaxed) or s (strict)"},"cached":{"type":"boolean","title":"Cached","default":false},"domain":{"type":"string","title":"Domain"},"issues":{"type":"array","items":{"type":"object","additionalProperties":true},"title":"Issues"},"policy":{"type":"string","title":"Policy","description":"DMARC policy level: none, quarantine, or reject"},"scan_id":{"type":"string","title":"Scan Id"},"request_id":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Request Id","description":"Gateway request tracking ID"},"dmarc_valid":{"type":"boolean","title":"Dmarc Valid"}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"registry","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_ECPBWyu-wOV2lCnIou3Bk","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":null,"unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks a domain's DMARC record for validity, policy level, alignment options, and reporting destinations, flagging any configuration issues.","exampleAgentPrompt":"Can you check whether stripe.com has a valid DMARC record, what policy it's set to, and whether there are any configuration issues?","exampleUseCases":[{"title":"Pre-send email deliverability audit","prompt":"Before we launch this email campaign, can you verify that our domain sendgrid-campaigns.com has a proper DMARC record in place and tell me if the policy is set to quarantine or reject?"},{"title":"Vendor domain security vetting","prompt":"I'm evaluating a new supplier — can you check if their domain acmecorp.io has DMARC set up correctly and flag any issues with their email authentication configuration?"},{"title":"Phishing risk assessment","prompt":"Check the domain cheapbank-deals.net for DMARC validity — I want to know if it has a none, quarantine, or reject policy and whether there are any misconfigurations that could make it easy to spoof."}],"resultDescription":"Returns whether the domain's DMARC record is valid, the policy level (none/quarantine/reject), DKIM alignment mode (relaxed or strict), SPF alignment mode (relaxed or strict), aggregate and forensic reporting email destinations, a list of detected issues, a scan ID, and whether the response was cached.","failureModes":["Domain has no DMARC record — dmarc_valid returns false with issues populated","Malformed domain input (e.g. includes http://) — likely returns validation error","Domain does not exist or cannot be resolved — may return invalid with issues","Payment failure via x402 — request not processed, 402 response returned","Transient DNS lookup failure — may return error or empty result"],"whenToPreferThis":"Choose this endpoint when you need a focused, machine-payable DMARC-specific audit without requiring API keys or account setup. It is ideal for automated agent workflows that need to validate email authentication posture per domain on demand, especially when combined with sibling Tinstop endpoints for full DNS/SSL/header coverage. Prefer it over manual DNS lookups when you need structured issue detection, alignment settings, and reporting destinations parsed and returned in a consistent schema.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T18:39:44.640Z","isFirstParty":false}