# Certificate Authority Policy Lookup (CAA DNS Records)

> Certificate Authority Policy Lookup (CAA DNS Records) is a paid API for AI agents from market.datapackvibe.com, paid per call via x402, $0.01/call, status unknown (last checked 2026-10-02).

Returns CAA DNS records for a domain, indicating which certificate authorities are authorized to issue TLS certificates for it.

## Facts

- Endpoint: POST https://market.datapackvibe.com/x402/demand-domain-certificate-authorities-it-administration?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/certificate-authority-policy-lookup-caa-dns-records-5588c06a
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_6p-A2eHmD9E8F_7qdyBl5

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability certificate-authority-policy-lookup-caa-dns-records-5588c06a -d '<json body>'
```

Example prompt: Can you look up the CAA DNS records for example.com so I can see which certificate authorities are allowed to issue TLS certificates for it?

## When to prefer this

Use this endpoint when you need to programmatically query CAA DNS records for IT administration, security auditing, or pre-issuance checks. Prefer this over manual DNS tools when automating certificate lifecycle management, running compliance audits across multiple domains, or when an AI agent needs structured CAA data for decision-making. Not suitable for email verification or certificate issuance itself.

## Known failure modes

- Domain has no CAA records (returns empty result, meaning any CA is implicitly allowed)
- Invalid or non-existent domain name returns a DNS lookup error
- Malformed domain input triggers a validation error
- Transient DNS resolution failures may occur for newly registered or propagating domains

## How this service works

Certificate authority policy lookup for IT administration: Return CAA records that constrain certificate issuance. DNS data only; does not send email or verify that an inbox exists.

## Output

Returns the CAA (Certification Authority Authorization) DNS records for the queried domain, showing which certificate authorities are explicitly permitted to issue TLS/SSL certificates. The response contains DNS record data only — no email verification or inbox checks are performed.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "domain": {
   "type": "string",
   "default": "example.com",
   "description": "Public DNS domain, e.g. example.com."
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/certificate-authority-policy-lookup-caa-dns-records-5588c06a/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from market.datapackvibe.com](https://www.zero.xyz/host/market.datapackvibe.com/llms.txt)
