# Spoofability Check Watch

> Spoofability Check Watch is a paid API for AI agents from intel.rallylive.ca, paid per call via x402, $0.02/call, status unknown (last checked 2026-09-14).

Monitors a domain's email spoofability (SPF + DMARC) over time and returns whether the result has changed since the last call, with before/after field diffs.

## Facts

- Endpoint: GET https://intel.rallylive.ca/watch/email/spoofable
- Price: $0.02/call
- Payment: x402
- Status: unknown
- Last checked: 2026-09-14
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/spoofability-check-watch-a0295be7
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_DHd1gQxYhOHTxGZpmZwul

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability spoofability-check-watch-a0295be7
```

Example prompt: Keep an eye on whether example.com can be spoofed — run the spoofability watch check and tell me if anything has changed since the last time you checked, including exactly which SPF or DMARC fields changed and what the values were before and after.

## When to prefer this

Choose this endpoint when you need to detect changes in email spoofability over time rather than just a one-off check. It is ideal for scheduled monitoring workflows where you want to be alerted only when the spoofability status or underlying SPF/DMARC configuration actually changes, avoiding noise from repeated identical results. Prefer it over a simple spoofability check when diff tracking and change history matter.

## Known failure modes

- Domain not previously checked — no prior result to compare against, diff will be empty
- Domain does not exist or has no DNS records — check may return error or inconclusive
- SPF/DMARC records temporarily unavailable due to DNS propagation delays
- Previous result expired (older than 90 days) — treated as first call with no diff
- Rate limiting or payment failure via x402 protocol

## How this service works

Change watch for spoofability check: runs the check and compares it with the result from your previous call for the same domain (kept 90 days), returning the current answer, changed true/false, exactly which fields changed with before/after values, and when it was last seen. Call it on a schedule to be told when can this domain be spoofed? checks whether spf and dmarc together actually block forged mail changes. $0.01 per check.

## Output

Returns the current spoofability answer (can the domain be spoofed: yes/no), a boolean 'changed' flag indicating if the result differs from the previous call, a detailed diff of exactly which fields changed with their before and after values, and a timestamp of when the previous result was last seen. Previous results are retained for 90 days.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "properties": {}
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object"
    }
   }
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/spoofability-check-watch-a0295be7/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from intel.rallylive.ca](https://www.zero.xyz/host/intel.rallylive.ca/llms.txt)
