# Delx Commerce DNS CAA Policy Check

> Delx Commerce DNS CAA Policy Check is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.001/call, status unknown (last checked 2026-10-01).

Checks whether a given certificate issuer is permitted by a domain's DNS CAA (Certification Authority Authorization) records

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/dns-caa-policy-check?utm_source=zero.xyz
- Price: $0.001/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-dns-caa-policy-check-d5a486a9
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_VxRsEmhseCw1CvX1XegJH

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-dns-caa-policy-check-d5a486a9 -d '<json body>'
```

Example prompt: Check whether letsencrypt.org is permitted to issue certificates under this domain's CAA policy — here are the CAA records: [{"flags":0,"tag":"issue","value":"letsencrypt.org"}].

## When to prefer this

Choose this endpoint when you need a lightweight, deterministic, in-memory check of whether a specific CA is authorized under a given set of DNS CAA records — without making live DNS lookups. It is ideal for pre-issuance validation, security audits, and automated certificate pipeline checks where you already have the CAA records on hand and want a verifiable, pay-per-call result with no data retention and cryptographic evidence of the input processed.

## Known failure modes

- Invalid or malformed CAA record objects may cause unexpected validation results
- Issuer string exceeding 8192 characters is rejected
- Records array exceeding 256 items is rejected
- Missing issuer or records fields may result in a validation error or incomplete result
- Payment failure (x402 protocol) blocks request processing

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a JSON object indicating whether the specified issuer is permitted (boolean) under the provided CAA records, along with the operation name, a pass/fail status, and tamper-evident evidence including an input SHA-256 hash, retained=false flag, and external_calls count — confirming in-memory-only processing with no data retention.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "issuer": {
   "type": "string",
   "maxLength": 8192,
   "description": "Issuer supplied to DNS Caa Policy Check; used only for this bounded calculation and processed in memory without retention."
  },
  "records": {
   "type": "array",
   "items": {
    "type": "object",
    "maxProperties": 128,
    "additionalProperties": true
   },
   "maxItems": 256,
   "description": "Records supplied to DNS Caa Policy Check; used only for this bounded calculation and processed in memory without retention."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "result": {
   "issuer": "letsencrypt.org",
   "permitted": true
  },
  "schema": "delx/util-dns-caa-policy-check/v1",
  "status": "pass",
  "evidence": {
   "retained": false,
   "input_sha256": "b0ce3b06dcfb1237aa32eef6c1398ecd3e5f4811ddf5558614373560166e3b1e",
   "external_calls": 0
  },
  "operation": "web_reliability:dns_caa_policy_check"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-dns-caa-policy-check-d5a486a9/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
