{"slug":"api-zfinia-com-x402-v1-mail-authentication-coherence-audit-5a75e9","title":"Read an SPF record, a DMARC record and a set of DKIM selectors together, and rep","host":"api.zfinia.com","method":"POST","resource":"https://api.zfinia.com/x402/v1/mail-authentication-coherence-audit","category":"code","description":"Read an SPF record, a DMARC record and a set of DKIM selectors together, and report the combinations that defeat themselves. Every finding needs two or three records at once, which is why a single-record checker finds none of them: a reject policy with no usable selector, an enforcing policy over an","price_listed":0.24,"price_asked":null,"state":"effects","state_label":"Not tested: has real-world effects","checks_7d":0,"answered_7d":0,"latency_ms_median":null,"reported_calls_30d":1,"reported_payers_30d":1,"networks":["eip155:8453"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"body":{"dkim_selectors":[{"record":"v=DKIM1; k=rsa; t=y; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1234QIDAQAB","selector":"rollout2026"},{"record":"v=DKIM1; k=rsa; p=","selector":"retired2024"}],"dmarc":"v=DMARC1; p=reject; aspf=s; adkim=s","domain":"example.test","sending_subdomains":["mail.example.test","notifications.example.test"],"spf":"v=spf1 include:_spf.vendor-a.test a mx +all"},"bodyType":"json","method":"POST","type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"body":{"additionalProperties":false,"properties":{"dkim_selectors":{"items":{"additionalProperties":false,"properties":{"record":{"maxLength":4096,"type":"string"},"selector":{"maxLength":128,"type":"string"}},"required":["selector","record"],"type":"object"},"maxItems":100,"minItems":1,"type":"array"},"dmarc":{"maxLength":4096,"type":"string"},"domain":{"maxLength":253,"type":"string"},"sending_subdomains":{"items":{"maxLength":253,"type":"string"},"maxItems":200,"minItems":1,"type":"array"},"spf":{"maxLength":4096,"type":"string"}},"required":["domain"],"type":"object"},"bodyType":{"enum":["json","form-data","text"],"type":"string"},"method":{"enum":["POST"],"type":"string"},"type":{"const":"http","type":"string"}},"required":["type","method","bodyType","body"],"type":"object"},"output":{"properties":{"example":{"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"},"history":[],"description_full":"Read an SPF record, a DMARC record and a set of DKIM selectors together, and report the combinations that defeat themselves. Every finding needs two or three records at once, which is why a single-record checker finds none of them: a reject policy with no usable selector, an enforcing policy over an SPF record ending in +all, strict alignment with subdomain senders, enforcement with no reporting address, and a subdomain policy that no sending path can satisfy.","last_updated":"2026-10-04T08:40:06.271Z","schemes":["exact"]}