# Permissive SPF Policy Security Check

> Permissive SPF Policy Security Check is a paid API for AI agents from market.datapackvibe.com, paid per call via x402, $0.01/call, status unknown (last checked 2026-10-02).

Checks a domain's SPF DNS record for permissive policies ending in +all or ?all and lists the mechanisms found

## Facts

- Endpoint: POST https://market.datapackvibe.com/x402/demand-domain-spf-permissive-policy-security-review?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/permissive-spf-policy-security-check-68adde8b
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_R0mFnSewoMNGfQWoi2MTr

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability permissive-spf-policy-security-check-68adde8b -d '<json body>'
```

Example prompt: Can you check if acme.com has a dangerously permissive SPF policy — specifically if it ends in +all or ?all — and list all the mechanisms in its SPF record?

## When to prefer this

Choose this endpoint when you need a lightweight, DNS-only check specifically to detect permissive SPF policies (+all or ?all) for security audits, compliance reviews, or red team assessments. It is ideal when you only need to flag email spoofing risk at the SPF level without doing full email deliverability testing or DMARC/DKIM analysis.

## Known failure modes

- Domain has no SPF TXT record — returns no-policy or not-found result
- Domain does not exist in DNS — returns DNS resolution error
- Malformed SPF record that cannot be parsed — may return parse error
- Network or DNS timeout — returns timeout or service error
- Invalid domain format provided — returns input validation error

## How this service works

Permissive SPF policy check for Security review: Flag an SPF policy ending in +all or ?all and list its mechanisms. DNS data only; does not send email or verify that an inbox exists.

## Output

Returns whether the domain's SPF TXT DNS record ends in a permissive qualifier (+all or ?all), flags the policy as permissive or not, and lists all the individual SPF mechanisms found in the record. Data is DNS-only; no email is sent and no inbox is verified.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "domain": {
   "type": "string",
   "default": "example.com",
   "description": "Public DNS domain, e.g. example.com."
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/permissive-spf-policy-security-check-68adde8b/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from market.datapackvibe.com](https://www.zero.xyz/host/market.datapackvibe.com/llms.txt)
