Domain security & deliverability audit (graded)
POST /v1/domain-auditHand over a domain and get one graded security & email-deliverability audit: SPF, DMARC, DKIM and MX (why your mail lands in spam), the web security headers, and the TLS certificate - every finding from a live probe, with an overall letter grade, a downloadable checks appendix, and a prioritized, specific list of fixes. Send POST /v1/domain-audit with the required field domain and pay $0.60 per call over x402 with USDC on an EVM chain. It returns a JSON object with report, domain, grade, composite, sources and 2 more.
USDC (x402/MPP) or card (Stripe). Not cached.
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
domain | string | yes | The domain to audit, e.g. example.com (also accepts a URL or host). Also accepted as host, hostname, site. |
format | string (one of: markdown, json) | no | Response shape (default markdown report). |
Example request
curl -i -X POST https://agent402.tools/v1/domain-audit \
-H "Content-Type: application/json" \
-d '{"domain":"example.com"}'
Without payment this returns HTTP 402 Payment Required with the exact price for domain-audit; any x402 v2 or MPP client pays it and retries.
Example response
{
"report": "# Domain Security Audit: example.com\n\n**Overall grade: B** (82/100)\n\n## Overall grade\n...",
"domain": "example.com",
"grade": "B",
"composite": 82,
"sources": [],
"tables": [
{
"name": "email-checks",
"label": "Email authentication checks",
"columns": [
"Check",
"Status",
"Detail"
],
"rows": [
[
"spf",
"pass",
"SPF record present, 1 DNS lookup, ~all qualifier"
]
]
}
],
"meta": {
"tier": "domain-audit",
"domain": "example.com",
"grade": "B",
"composite": 82,
"email_score": 90,
"header_score": 70,
"tls_days_remaining": 204,
"synthesis_model": "anthropic/claude-opus-5"
}
}
| Field | Type | Always present | In the example |
|---|---|---|---|
report | string | yes | # Domain Security Audit: example.com **Overall grade: B** (82/100) ## Overa... |
domain | string | yes | example.com |
grade | string | yes | B |
composite | number | yes | 82 |
sources | array | yes | 0 items in the example |
tables | array of objects | yes | 1 item in the example |
meta | object | yes | 8 fields: tier, domain, grade, composite, email_score, header_score |
From an MCP client
catalog.call {
"slug": "domain-audit",
"params": {
"domain": "example.com"
}
}
The hosted connector at https://agent402.tools/mcp needs a payment for domain-audit; the stdio package pays it from a wallet or from AGENT402_CREDITS_KEY. Local install: npx -y agent402-mcp.
Errors and behavior
domainis required. An input the tool rejects returns an HTTP 4xx whose body carrieserror,tool,expected,requiredandexample, so the caller can correct it.- A paid call that ends in any status of 400 or above is not charged over x402, MPP or a prepaid credits key: settlement is cancelled when the tool fails.
- Wallet-only: this tool runs a model, so it has no proof-of-work tier. A prepaid card-credits key (
Authorization: Bearer a402_...) also pays it. - Model-backed: the answer is generated by a model, so the same input can produce different wording.
- Long-running: payment settles after the work finishes, so only EVM exact payments are offered.
- A
GETorHEADto /v1/domain-audit returns the same 402 quote, so the price can be read without a body. - An
Idempotency-Keyheader makes a retried paid call replay the first 200 instead of charging again (an answer larger than 1 MB and a streamed response are not replayed).
Paid call (JavaScript agent)
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
const client = new x402Client();
client.setSpendControls?.(false); // keep your own spending ceiling in code
registerExactEvmScheme(client, { signer: privateKeyToAccount(KEY) });
const payFetch = wrapFetchWithPayment(fetch, client);
const res = await payFetch("https://agent402.tools/v1/domain-audit", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
"domain": "example.com"
}),
});
Related tools
Domain security audit - PRO (attack surface + stack)
POST /v1/domain-audit/proThe deeper tier: everything in the standard audit plus the attack surface from Certificate Transparency logs (subdomains…
Email deliverability check
POST /api/email-deliverabilityEnd-to-end email-auth report for a domain: SPF + DMARC + DKIM (probes common selectors automatically) + MX records + sco…
Company due-diligence dossier (grounded, cited)
POST /v1/dossierHand over a ticker and get one due-diligence dossier back. Pulls the company's SEC EDGAR filings (10-K / 10-Q / 8-K) and…
Company due-diligence dossier - MAX (exhaustive)
POST /v1/dossier/maxThe exhaustive due-diligence tier: more filings, a full year of Form 4 insider activity, wider web research (up to 8 ang…
Fund portfolio report (13F, grounded)
POST /v1/fundHand over an institutional manager (a fund name like "Berkshire Hathaway", a ticker, or a SEC CIK) and get one cited rep…
Fund portfolio report - MAX (deep)
POST /v1/fund/maxThe deep tier: the full holdings table, wider quarter-over-quarter change analysis, more grounded web research, and a lo…