# dns-tlsa-via-alidns

> dns-tlsa-via-alidns is a paid API for AI agents from dns.intel.rallylive.ca, paid per call via x402, $0.01/call, status unknown (last checked 2026-10-01).

Retrieves TLSA DNS records for a domain as answered by AliDNS (223.5.5.5) via DNS over HTTPS, including TTL, response code, DNSSEC validation status, and resolver answer time.

## Facts

- Endpoint: GET https://dns.intel.rallylive.ca/dns/tlsa/via/alidns?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/dns-tlsa-via-alidns-5ffef855
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_DqKdURpxg2DsV7Ik38757

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability dns-tlsa-via-alidns-5ffef855
```

Example prompt: Can you look up the TLSA records for example.com as seen by AliDNS (223.5.5.5) and tell me the TTL, response code, whether DNSSEC was validated, and how fast AliDNS answered?

## When to prefer this

Use this endpoint when you specifically need to know what TLSA records AliDNS (223.5.5.5) returns for a domain — particularly useful for comparing resolver behavior across geographic regions, detecting propagation lag to Chinese resolvers, identifying split-horizon or filtered answers, or auditing DNSSEC validation for certificate association records. Prefer this over generic DNS lookup tools when resolver-specific TLSA data is required.

## Known failure modes

- NXDOMAIN returned if domain or TLSA record does not exist
- SERVFAIL returned if AliDNS cannot resolve the domain
- Empty record set if domain has no TLSA records published
- Network timeout if AliDNS DoH endpoint is unreachable
- Invalid domain input may cause unexpected response or error

## How this service works

TLSA records for a domain as answered by AliDNS 223.5.5.5 (DNS over HTTPS): the records, TTL, response code (NOERROR/NXDOMAIN/SERVFAIL), whether the resolver validated DNSSEC, and the resolver's answer time. Compare resolvers to spot propagation lag, filtering or split-horizon answers. $0.01 per lookup.

## Output

Returns the TLSA records for the queried domain as answered by AliDNS (223.5.5.5) via DNS over HTTPS, including the record data, TTL, DNS response code (NOERROR, NXDOMAIN, or SERVFAIL), whether the resolver performed DNSSEC validation, and the resolver's answer latency.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "properties": {}
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object"
    }
   }
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/dns-tlsa-via-alidns-5ffef855/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from dns.intel.rallylive.ca](https://www.zero.xyz/host/dns.intel.rallylive.ca/llms.txt)
