SPF check

$0.001 per call · USDC via x402 · POST /api/spf-check

Fetch and validate a domain's SPF record (RFC 7208). Send POST /api/spf-check with the required field domain and pay $0.001 per call over x402 or MPP (there is no free tier). It returns a JSON object with domain, hasRecord, raw, mechanisms, lookupCount and 3 more.

Parses mechanisms (ip4/ip6/include/a/mx/all), counts DNS lookups against the famous 10-lookup limit, and flags the qualifier on `all` (-/fail, ~/softfail, ?/neutral). The first stop when an email is hitting the spam folder.

Category: Network & domains · Tags: spf email email-auth deliverability dns rfc7208

TRY IN PLAYGROUND →

Parameters

NameTypeRequiredDescription
domainstringyesDomain name (also accepts email/url/host) Also accepted as host, hostname, site.

Example request

curl -i -X POST https://agent402.tools/api/spf-check \
  -H "Content-Type: application/json" \
  -d '{"domain":"google.com"}'

Without payment this returns HTTP 402 Payment Required with the exact price for spf-check; any x402 v2 or MPP client pays it and retries.

Example response

{
  "domain": "google.com",
  "hasRecord": true,
  "raw": "v=spf1 include:_spf.google.com ~all",
  "mechanisms": [
    {
      "type": "include",
      "qualifier": "pass",
      "value": "_spf.google.com"
    },
    {
      "type": "all",
      "qualifier": "softfail"
    }
  ],
  "lookupCount": 1,
  "all": "softfail",
  "valid": true,
  "warnings": []
}
FieldTypeAlways presentIn the example
domainstringyesgoogle.com
hasRecordbooleanyestrue
rawstringyesv=spf1 include:_spf.google.com ~all
mechanismsarray of objectsyes2 items in the example
lookupCountnumberyes1
allstringyessoftfail
validbooleanyestrue
warningsarrayyes0 items in the example

From an MCP client

catalog.call {
  "slug": "spf-check",
  "params": {
    "domain": "google.com"
  }
}

The hosted connector at https://agent402.tools/mcp needs a payment for spf-check; the stdio package pays it from a wallet or from AGENT402_CREDITS_KEY. Local install: npx -y agent402-mcp.

Errors and behavior

Paid call (JavaScript agent)

import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client();
client.setSpendControls?.(false); // keep your own spending ceiling in code
registerExactEvmScheme(client, { signer: privateKeyToAccount(KEY) });
const payFetch = wrapFetchWithPayment(fetch, client);

const res = await payFetch("https://agent402.tools/api/spf-check", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({
    "domain": "google.com"
  }),
});

Part of these workflows

SPF check is one step in these 4 skill packs, each sold as a single call:

Related tools

DKIM key lookup

$0.002 · POST /api/dkim-lookup

Fetch and parse a DKIM public-key record at <selector>._domainkey.<domain> (RFC 6376). Returns the parsed key params (al…

DMARC check

$0.001 · POST /api/dmarc-check

Fetch and validate a domain's DMARC policy at _dmarc.<domain> (RFC 7489). Surfaces the enforcement policy (none/quaranti…

Email deliverability check

$0.002 · POST /api/email-deliverability

End-to-end email-auth report for a domain: SPF + DMARC + DKIM (probes common selectors automatically) + MX records + sco…

Domain security & deliverability audit (graded)

$0.60 · POST /v1/domain-audit

Hand over a domain and get one graded security & email-deliverability audit: SPF, DMARC, DKIM and MX (why your mail land…

DNS lookup

$0.001 · GET /api/dns

Live DNS lookup for a domain: returns name, type and records[]. Supported record types: A, AAAA (addresses as strings), …

DNS lookup

$0.002 · POST /api/dns-lookup

Resolve any DNS record type for a host: A, AAAA, MX, TXT, CNAME, NS, SOA, CAA, SRV, PTR. Returns the records plus a coun…