# CAA Record Lookup for Vendor Screening

> CAA Record Lookup for Vendor Screening is a paid API for AI agents from market.datapackvibe.com, paid per call via x402, $0.01/call, status unknown (last checked 2026-10-02).

Looks up DNS CAA (Certification Authority Authorization) records for a domain to identify which certificate authorities are permitted to issue SSL/TLS certificates for it.

## Facts

- Endpoint: POST https://market.datapackvibe.com/x402/demand-domain-certificate-authorities-vendor-screening?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/caa-record-lookup-for-vendor-screening-260d96fd
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_08PNrWUf3u115Ul9osZz7

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability caa-record-lookup-for-vendor-screening-260d96fd -d '<json body>'
```

Example prompt: Can you look up the CAA DNS records for acmecorp.com so I can see which certificate authorities are authorized to issue certs for them as part of our vendor screening?

## When to prefer this

Use this endpoint when you need to inspect a domain's CAA DNS records specifically for vendor due diligence, security policy auditing, or PKI compliance checks. Prefer this over generic DNS tools when the use case is vendor screening and you want a focused, paid API that returns only CAA data. Not suitable if you need to verify email deliverability, check domain ownership, or perform full DNS enumeration.

## Known failure modes

- Domain has no CAA records (empty result, not an error — many domains do not set CAA records)
- Invalid or malformed domain input returns an error
- Non-existent domain (NXDOMAIN) returns no records
- DNS resolution timeout causes request failure
- Private/internal domains not resolvable via public DNS return no results

## How this service works

Certificate authority policy lookup for Vendor screening: Return CAA records that constrain certificate issuance. DNS data only; does not send email or verify that an inbox exists.

## Output

Returns the CAA (Certification Authority Authorization) DNS records for the queried domain, listing which certificate authorities are permitted to issue SSL/TLS certificates for it. This is pure DNS data — no email verification or inbox checking is performed.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "domain": {
   "type": "string",
   "default": "example.com",
   "description": "Public DNS domain, e.g. example.com."
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/caa-record-lookup-for-vendor-screening-260d96fd/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from market.datapackvibe.com](https://www.zero.xyz/host/market.datapackvibe.com/llms.txt)
