# Certificate Authority Policy Lookup (CAA DNS Records)

> Certificate Authority Policy Lookup (CAA DNS Records) is a paid API for AI agents from market.datapackvibe.com, paid per call via x402, $0.01/call, status unknown (last checked 2026-10-02).

Returns CAA (Certification Authority Authorization) DNS records for a given domain, revealing which certificate authorities are permitted to issue SSL/TLS certificates for it.

## Facts

- Endpoint: POST https://market.datapackvibe.com/x402/demand-domain-certificate-authorities-sales-operations?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/certificate-authority-policy-lookup-caa-dns-records-b48aaa52
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_cVZsuKvyT1rnf42t7MbnM

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability certificate-authority-policy-lookup-caa-dns-records-b48aaa52 -d '<json body>'
```

Example prompt: Can you look up the CAA records for stripe.com and tell me which certificate authorities are authorized to issue SSL certificates for it?

## When to prefer this

Use this endpoint when you need to programmatically determine which certificate authorities are permitted to issue TLS/SSL certificates for a domain, as defined by its CAA DNS records. Ideal for security audits, pre-issuance CA eligibility checks, compliance verification, and third-party domain due diligence. It is a pure DNS lookup — choose it over general DNS tools when you specifically need CAA record data for PKI policy purposes.

## Known failure modes

- Domain has no CAA records (returns empty result, meaning any CA may issue)
- Invalid or malformed domain name input returns an error
- Domain does not exist in DNS (NXDOMAIN) may return empty or error
- Network timeout if DNS resolution is slow
- Private or internal domains not resolvable via public DNS will return no data

## How this service works

Certificate authority policy lookup for Sales operations: Return CAA records that constrain certificate issuance. DNS data only; does not send email or verify that an inbox exists.

## Output

Returns CAA DNS record data for the specified domain, including which certificate authorities (e.g. Let's Encrypt, DigiCert, Sectigo) are authorized to issue certificates. This is raw DNS policy data only — no email verification or inbox checking is performed.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "domain": {
   "type": "string",
   "default": "example.com",
   "description": "Public DNS domain, e.g. example.com."
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/certificate-authority-policy-lookup-caa-dns-records-b48aaa52/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from market.datapackvibe.com](https://www.zero.xyz/host/market.datapackvibe.com/llms.txt)
