# Permissive SPF Policy Check

> Permissive SPF Policy Check is a paid API for AI agents from market.datapackvibe.com, paid per call via x402, $0.01/call, status unknown (last checked 2026-10-02).

Checks a domain's SPF DNS record for permissive policies ending in +all or ?all and lists the SPF mechanisms found

## Facts

- Endpoint: POST https://market.datapackvibe.com/x402/demand-domain-spf-permissive-policy-email-operations?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/permissive-spf-policy-check-57d1eb8a
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_OOEcR4RRpT1sIjEJHAjOp

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability permissive-spf-policy-check-57d1eb8a -d '<json body>'
```

Example prompt: Check whether example.com has a permissive SPF policy — specifically if its SPF record ends in +all or ?all — and list all the mechanisms in that record.

## When to prefer this

Use this endpoint when you specifically need to detect overly permissive SPF policies (+all or ?all) that could enable email spoofing or phishing. It is a focused DNS-only check ideal for security audits, vendor assessments, or pre-send phishing analysis. Prefer this over general SPF lookup tools when you need a clear pass/fail flag on permissiveness plus a structured list of mechanisms, and when you do not need to send a test email or verify inbox existence.

## Known failure modes

- Domain has no SPF TXT record — returns no SPF found
- Domain does not exist in DNS — returns DNS resolution error
- Domain input is malformed or not a valid public DNS domain — returns validation error
- SPF record is present but uses -all or ~all (not permissive) — returns not flagged result
- Network or DNS timeout — returns service unavailable error

## How this service works

Permissive SPF policy check for Email operations: Flag an SPF policy ending in +all or ?all and list its mechanisms. DNS data only; does not send email or verify that an inbox exists.

## Output

Returns whether the domain's SPF record ends in a permissive qualifier (+all or ?all), flags the policy as permissive or not, and lists all SPF mechanisms (e.g. ip4, include, a, mx) found in the record. Data is sourced from public DNS; no email is sent and no inbox is verified.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "domain": {
   "type": "string",
   "default": "example.com",
   "description": "Public DNS domain, e.g. example.com."
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/permissive-spf-policy-check-57d1eb8a/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from market.datapackvibe.com](https://www.zero.xyz/host/market.datapackvibe.com/llms.txt)
