{"slug":"2s-io-api-domain-email-security-f15158","title":"Grade a domain's email-authentication and DNS-security posture from live DNS in ","host":"2s.io","method":"GET","resource":"https://2s.io/api/domain/email-security","category":"other","description":"Grade a domain's email-authentication and DNS-security posture from live DNS in one call: SPF, DMARC (policy + alignment), DKIM (for the supplied or common selectors), MTA-STS, TLS-RPT, DNSSEC, CAA, and BIMI. Pass domain (and optional dkimSelector). Returns an overall letter grade, a summary (spf/dm","price_listed":0.0045,"price_asked":0.0045,"state":"answering","state_label":"Answering","checks_7d":1,"answered_7d":1,"latency_ms_median":280,"reported_calls_30d":5,"reported_payers_30d":1,"networks":["eip155:8453","solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"method":"GET","queryParams":{"domain":"paypal.com"},"type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"properties":{"method":{"const":"GET"},"queryParams":{"properties":{"dkimSelector":{"description":"Optional known DKIM selector (e.g. \"google\", \"s1\").","type":"string"},"domain":{"description":"Domain to audit (e.g. example.com).","type":"string"}},"required":["domain"]},"type":{"const":"http"}},"required":["type","method","queryParams"],"type":"object"}},"required":["input"],"type":"object"},"history":[{"day":"2026-09-24","reachable":true,"status":402,"valid_402":true,"asked_usdc":0.0045,"price_match":true,"latency_ms":280,"error":null}],"description_full":"Grade a domain's email-authentication and DNS-security posture from live DNS in one call: SPF, DMARC (policy + alignment), DKIM (for the supplied or common selectors), MTA-STS, TLS-RPT, DNSSEC, CAA, and BIMI. Pass domain (and optional dkimSelector). Returns an overall letter grade, a summary (spf/dmarcPolicy/dkim/mtaSts/dnssec/caa/bimi + spoofingProtected), and a per-mechanism block with the raw record, parsed tags, and specific issues (e.g. 'DMARC p=none — monitor only', 'SPF ~all soft-fail', 'no MTA-STS'). Sourced from live public DNS via DNS-over-HTTPS — an LLM cannot know a domain's current records. For deliverability/anti-spoofing audits, vendor security review, and phishing-resistance checks. DKIM is selector-based (selectors aren't enumerable), so 'not found' only means none of the checked selectors resolved.","last_updated":"2026-09-11T10:41:52.132Z","schemes":["exact"]}