{"openapi":"3.1.0","info":{"title":"Email Auth SPF/DMARC/DKIM Check","version":"1.0.0","description":"![x402 Atlas](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI0OCIgaGVpZ2h0PSI0OCIgdmlld0JveD0iMCAwIDQ4IDQ4IiBmaWxsPSJub25lIj48ZyBzdHJva2U9IiMxRTQwQUYiIHN0cm9rZS1saW5lY2FwPSJyb3VuZCI+PHBhdGggZD0iTTI0IDdWMjhNMjQgMjhMOCA0Mk0yNCAyOEw0MCA0MiIgc3Ryb2tlLXdpZHRoPSIyLjEiLz48cGF0aCBkPSJNMjQgN0w4IDQyTTI0IDdMNDAgNDJNMTUgMjhIMzMiIHN0cm9rZS13aWR0aD0iMi43Ii8+PC9nPjxnIGZpbGw9IiMxRTQwQUYiPjxjaXJjbGUgY3g9IjgiIGN5PSI0MiIgcj0iMy4yIi8+PGNpcmNsZSBjeD0iNDAiIGN5PSI0MiIgcj0iMy4yIi8+PGNpcmNsZSBjeD0iMTUiIGN5PSIyOCIgcj0iMy4yIi8+PGNpcmNsZSBjeD0iMzMiIGN5PSIyOCIgcj0iMy4yIi8+PGNpcmNsZSBjeD0iMjQiIGN5PSIyOCIgcj0iMi45Ii8+PC9nPjxjaXJjbGUgY3g9IjI0IiBjeT0iNyIgcj0iNC4yIiBmaWxsPSIjMTRCOEE2Ii8+PC9zdmc+)\n\n**Email Auth SPF/DMARC/DKIM Check** is an independently documented x402 Atlas bridge at https://email-auth.use.x402atlas.com.\nThis document describes only this bridge; it does not aggregate routes, schemas,\nor content from any other bridge.\n\n## How payment works\n\nPaid operations use the [x402 payment protocol](https://x402.org) and settle in\nUSDC. Atlas supports deployments on Base, Polygon, and Arbitrum, plus configured\nSolana networks. This bridge currently advertises Arbitrum One (`eip155:42161`), Base (`eip155:8453`), Polygon (`eip155:137`), Solana mainnet (`solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp`).\n\n1. Send the HTTP request without a payment signature.\n2. Read the `402 Payment Required` response. Its `accepts` entries are the\n   authoritative network, asset, amount, and recipient options for that call.\n3. Select an option, sign it with an x402-compatible wallet or SDK, and repeat\n   the request with the `PAYMENT-SIGNATURE` header. The successful response is\n   returned after verification and settlement.\n\nTypeScript clients can automate the challenge, signing, and retry flow with\n[`x402-fetch`](https://www.npmjs.com/package/x402-fetch) or\n[`x402-axios`](https://www.npmjs.com/package/x402-axios). Fund a dedicated\nwallet only with the working USDC balance it needs and keep that key separate\nfrom treasury accounts.\n\n## Pricing\n\nAtlas route prices start at $0.005 per successful call. This bridge's fallback\nprice is $0.005; operations below state their exact configured price in\n`x-x402` and `x-payment-info`. The live `402` challenge remains authoritative.\n\n## Worked payment example\n\nRequest one documented operation without a signature to inspect its live terms:\n\n```bash\ncurl -i 'https://email-auth.use.x402atlas.com/check?domain=example.com\u0026selector=google'\n# HTTP/1.1 402 Payment Required\n# Read accepts[].network, asset, amount, and payTo from this response.\n```\n\nSign one accepted option and repeat the identical request with the\n`PAYMENT-SIGNATURE` header. Do not invent or cache payment terms; read them from\nthe current challenge.\n\n## Use this API\n\n- Interactive reference: https://email-auth.use.x402atlas.com/docs\n- OpenAPI 3.1 specification: https://email-auth.use.x402atlas.com/openapi.json\n- Agent-readable route corpus: https://email-auth.use.x402atlas.com/llms.txt\n- Endpoint index: https://email-auth.use.x402atlas.com/index.json\n\nUse the operation schemas and examples below to construct requests. Copy the\nserver URL, path, method, parameters, and request body from the operation you\nwant to call. Path and query examples are concrete and can be used directly.\n\n## Atlas response metadata\n\nSuccessful JSON responses include an additive top-level `_atlas` block, kept\nseparate from the bridge's data fields. `_atlas.docs` links this bridge's\n`/llms.txt` corpus. `_atlas.related` suggests adjacent APIs, each with a callable\n`url`, its own `docs` link, and a short `summary`. Suppress this block by sending\n`X-Atlas-Meta: none` or by adding `?_atlas=0` to the request.\n\n## Errors and compatibility\n\nValidation failures use HTTP `400`. Paid operations may return `402` before\ndispatch. Upstream and internal failures use the documented `5xx` responses.\nClients should rely on documented fields and tolerate additive response fields,\nincluding `_atlas` unless they explicitly opt out.\n\n## Protocol reference\n\n- x402 protocol and SDKs: https://x402.org","x-guidance":"Use the operation schemas and examples to construct requests. Paid operations return an HTTP 402 challenge with the authoritative payment terms."},"servers":[{"url":"https://email-auth.use.x402atlas.com"}],"tags":[{"name":"Email Auth SPF/DMARC/DKIM Check"}],"paths":{"/check":{"get":{"description":"Resolves MX, SPF, DMARC and DKIM for `domain` (required) and grades the deliverability/anti-spoofing posture into a `warnings[]` verdict — parsed `spf` (mechanisms, `all` qualifier, DNS-lookup count), parsed `dmarc` (policy, pct, rua/ruf, adkim/aspf), the `mx` servers, and resolved DKIM selectors are all included for transparency, but the grade is the product (SPF `+all`, SPF over 10 lookups, DMARC `p=none`, missing DKIM, and more). A domain that exists but has weak or missing auth is a `200` with warnings — only a true NXDOMAIN is a `404` — and `spf`/`dmarc` are `null` when absent, distinct from present-but-weak. Gotcha: a DKIM selector is not discoverable from the domain, so without `\u0026selector=\u003cs\u003e` only a best-effort common-selector list is probed and a \"no DKIM selector found\" warning means we did not guess it, not that none exists — pass `\u0026selector=` to check authoritatively. Use the DNS API's TXT lookup when you need the raw records instead.\n\n**Price:** $0.01 per call.","operationId":"email-auth_GET_check","parameters":[{"name":"domain","in":"query","required":true,"description":"Domain to check — hostname only, no scheme/IP literal, no trailing dot, no localhost, no local/internal/reserved suffix (.local, .internal, .localdomain, .lan, .test)","schema":{"description":"Domain to check — hostname only, no scheme/IP literal, no trailing dot, no localhost, no local/internal/reserved suffix (.local, .internal, .localdomain, .lan, .test)","maxLength":253,"pattern":"^[A-Za-z0-9-]{1,63}(\\.[A-Za-z0-9-]{1,63})*$","type":"string"},"example":"example.com"},{"name":"selector","in":"query","description":"Optional DKIM selector to check authoritatively; if omitted, a common-selector list is probed","schema":{"description":"Optional DKIM selector to check authoritatively; if omitted, a common-selector list is probed","type":"string"},"example":"google"}],"responses":{"200":{"description":"Success.","content":{"application/json":{"schema":{"properties":{"accepts_mail":{"description":"true when the domain has at least one MX record","type":"boolean"},"dkim":{"properties":{"checked_selectors":{"description":"exact selectors probed","items":{"type":"string"},"type":"array"},"found":{"items":{"properties":{"record":{"type":"string"},"selector":{"type":"string"}},"type":"object"},"type":"array"}},"type":"object"},"dmarc":{"description":"null when no DMARC record is present","properties":{"adkim":{"default":"r","enum":["r","s"],"type":"string"},"aspf":{"default":"r","enum":["r","s"],"type":"string"},"pct":{"default":100,"maximum":100,"minimum":0,"type":"integer"},"policy":{"description":"p= tag; empty when missing/invalid","enum":["none","quarantine","reject",""],"type":"string"},"record":{"type":"string"},"rua":{"description":"aggregate report addresses","items":{"type":"string"},"type":"array"},"ruf":{"description":"forensic report addresses","items":{"type":"string"},"type":"array"},"subdomain_policy":{"description":"sp= tag; empty when absent (inherits policy)","type":"string"}},"type":["object","null"]},"domain":{"type":"string"},"mx":{"items":{"properties":{"host":{"type":"string"},"pref":{"maximum":65535,"minimum":0,"type":"integer"}},"type":"object"},"type":"array"},"queried_at":{"format":"date-time","type":"string"},"spf":{"description":"null when no SPF record is present","properties":{"all_qualifier":{"description":"qualifier on the all mechanism; empty when absent","enum":["-all","~all","?all","+all",""],"type":"string"},"dns_lookups":{"description":"count of lookup-causing terms; RFC 7208 limit is 10","minimum":0,"type":"integer"},"mechanisms":{"items":{"properties":{"causes_dns":{"type":"boolean"},"kind":{"enum":["include","a","mx","ip4","ip6","all","exists","ptr","redirect","exp","unknown"],"type":"string"},"qualifier":{"enum":["+","-","~","?"],"type":"string"},"value":{"type":"string"}},"type":"object"},"type":"array"},"record":{"type":"string"}},"type":["object","null"]},"warnings":{"description":"human-readable posture advisories; never null","items":{"type":"string"},"type":"array"}},"required":["domain","queried_at","accepts_mail","mx","spf","dmarc","dkim","warnings"],"type":"object"},"example":{"accepts_mail":true,"dkim":{"checked_selectors":["default","google","selector1","selector2","k1","dkim","mail"],"found":[{"record":"v=DKIM1; k=rsa; p=MIGfMA0GCSq...","selector":"google"}]},"dmarc":{"adkim":"s","aspf":"s","pct":100,"policy":"reject","record":"v=DMARC1; p=reject; pct=100; rua=mailto:dmarc@example.com; adkim=s; aspf=s","rua":["mailto:dmarc@example.com"],"ruf":[],"subdomain_policy":""},"domain":"example.com","mx":[{"host":"aspmx.l.google.com.","pref":1}],"queried_at":"2026-07-02T12:00:00Z","spf":{"all_qualifier":"~all","dns_lookups":1,"mechanisms":[{"causes_dns":true,"kind":"include","qualifier":"+","value":"_spf.google.com"},{"causes_dns":false,"kind":"all","qualifier":"~","value":""}],"record":"v=spf1 include:_spf.google.com ~all"},"warnings":[]}}}},"400":{"description":"Validation error — the request was rejected before the handler ran.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"402":{"description":"Payment required. The response carries an x402 payment challenge.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/PaymentRequired"}}}},"500":{"description":"Unexpected internal error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}}},"security":[{"x402Payment":[]}],"summary":"Email authentication posture check: parses SPF, DMARC and DKIM plus MX for any domain and grades deliverability/anti-spoofing gaps (SPF +all, SPF \u003e10 lookups, DMARC p=none, missing DKIM). Clean JSON for deliverability and security-ops automation.","tags":["Email Auth SPF/DMARC/DKIM Check"],"x-payment-info":{"price":{"amount":"0.01","currency":"USD","mode":"fixed"},"protocols":[{"x402":{}}]},"x-x402":{"discoverable":true,"enabled":true,"paid":true,"price":"$0.01","service_name":"Email Auth SPF/DMARC/DKIM Check"}}}},"components":{"schemas":{"Error":{"properties":{"error":{"properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"type":"object"}},"required":["error"],"type":"object"},"PaymentRequired":{"description":"x402 payment-required envelope. The exact shape comes from the x402 SDK and includes per-network accepted payment options. See https://x402.org for the canonical schema.","type":"object"}},"securitySchemes":{"x402Payment":{"description":"Pay the route via x402 (https://x402.org). The 402 response carries the payment challenge; resubmit with a PAYMENT-SIGNATURE header.","scheme":"x402","type":"http"}}}}
