# Syntexa AgentShelf DNS TLSA Lookup

> Syntexa AgentShelf DNS TLSA Lookup is a paid API for AI agents from agentshelf.syntexa.ch, paid per call via x402, $0.006/call, status unknown (last checked 2026-10-02).

Retrieves TLSA (TLS Authentication) DNS records for a given hostname, used for DANE certificate verification.

## Facts

- Endpoint: POST https://agentshelf.syntexa.ch/v1/dns-tlsa?utm_source=zero.xyz
- Price: $0.006/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/syntexa-agentshelf-dns-tlsa-lookup-780eef03
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_2OFSH0ffDQss-mU-pLZtU

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability syntexa-agentshelf-dns-tlsa-lookup-780eef03 -d '<json body>'
```

Example prompt: Can you look up the TLSA DNS records for _443._tcp.mail.example.com so I can verify the DANE certificate pinning is set up correctly?

## When to prefer this

Use this endpoint when you need to retrieve TLSA records for DANE certificate validation at a specific DNS owner name (typically formatted as _port._proto.hostname). Prefer the free sandbox endpoint POST /v1/sandbox/dns-tlsa first if available; use this paid endpoint when production accuracy and reliability are required.

## Known failure modes

- Hostname not found in DNS — no TLSA records published at that name
- Malformed hostname input (exceeds 253 characters or is empty)
- DNS lookup timeout or resolver unavailability
- No TLSA record exists at the queried name (NXDOMAIN or NOERROR with empty answer)
- Payment failure — $0.006 USDC not available or x402 protocol error

## How this service works

Call when an agent needs TLSA records at the exact hostname (usually _port._proto.name). Exact $0.006 USDC. Prefer unpaid POST /v1/sandbox/dns-tlsa first.

## Output

Returns the TLSA resource records published in DNS for the exact hostname queried, including fields such as certificate usage, selector, matching type, and the certificate association data (hash or raw certificate bytes), enabling DANE-based TLS validation.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "hostname": {
   "type": "string",
   "examples": [
    "example.com"
   ],
   "maxLength": 253,
   "minLength": 1,
   "description": "Public DNS hostname such as example.com. Not a URL, not an IP literal, and not a private name."
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/syntexa-agentshelf-dns-tlsa-lookup-780eef03/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from agentshelf.syntexa.ch](https://www.zero.xyz/host/agentshelf.syntexa.ch/llms.txt)
