# CAA Record Lookup for Certificate Authority Policy

> CAA Record Lookup for Certificate Authority Policy is a paid API for AI agents from market.datapackvibe.com, paid per call via x402, $0.01/call, status unknown (last checked 2026-10-02).

Returns DNS CAA (Certification Authority Authorization) records for a domain to show which certificate authorities are permitted to issue TLS certificates for it.

## Facts

- Endpoint: POST https://market.datapackvibe.com/x402/demand-domain-certificate-authorities-security-review?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/caa-record-lookup-for-certificate-authority-policy-50735a7b
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_w23kZ73Rxzw1LxWNJi_cU

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability caa-record-lookup-for-certificate-authority-policy-50735a7b -d '<json body>'
```

Example prompt: Can you check the CAA records for stripe.com and tell me which certificate authorities are authorized to issue TLS certificates for it?

## When to prefer this

Use this endpoint when you need to programmatically inspect a domain's certificate issuance policy as part of a security review, compliance audit, or pre-issuance validation workflow. It is specifically designed for CAA record lookups — prefer it over general DNS lookup tools when your focus is certificate authority authorization policy. It does not send email, verify inboxes, or perform any active probing beyond DNS.

## Known failure modes

- Domain does not exist in DNS — returns empty or NXDOMAIN-equivalent response
- Domain has no CAA records configured — returns empty record set (meaning any CA can issue)
- Malformed domain input — may return an error or unexpected result
- Network or DNS resolution timeout — transient failure with no data returned

## How this service works

Certificate authority policy lookup for Security review: Return CAA records that constrain certificate issuance. DNS data only; does not send email or verify that an inbox exists.

## Output

Returns the CAA (Certification Authority Authorization) DNS records for the specified domain, listing which certificate authorities are permitted to issue TLS/SSL certificates for it. This is pure DNS data — no email verification or inbox checks are performed.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "domain": {
   "type": "string",
   "default": "example.com",
   "description": "Public DNS domain, e.g. example.com."
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/caa-record-lookup-for-certificate-authority-policy-50735a7b/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from market.datapackvibe.com](https://www.zero.xyz/host/market.datapackvibe.com/llms.txt)
