How to check a domain's SPF, DMARC and DKIM with an API

POST a domain to /v1/domain/inspect. One call returns its DNS records, email authentication (SPF, DMARC, common DKIM selectors, MTA-STS) with a score out of 8, and the TLS certificate.

Request

domain is a bare domain name (no scheme, no IP literal). checks is optional and picks sections from dns, email and tls; the default is all three. A single section costs less.

curl, using the free tier
curl -s -X POST https://tanod.dev/v1/domain/inspect \
  -H 'X-Tanod-Free: 1' -H 'content-type: application/json' \
  -d '{"domain":"github.com","checks":["email"]}'

Response

Response (the example from the OpenAPI spec, trimmed); the full response also has dns and tls sections
{
  "domain": "github.com",
  "email": {
    "accepts_mail": true,
    "spf": {"present": true, "all_policy": "softfail", "dns_lookup_terms": 8, "issues": []},
    "dmarc": {"present": true, "policy": "quarantine", "subdomain_policy": "reject",
              "rua": "mailto:[email protected]", "pct": 100, "issues": []},
    "dkim_selectors_found": ["google", "selector1"],
    "mta_sts": false,
    "score_out_of_8": 7
  },
  "notes": []
}

Limits and caveats

DKIM is a probe. DKIM keys live under a selector that only the sender knows, so a check can only report selectors it finds. An empty dkim_selectors_found does not mean the domain has no DKIM.

Heuristic, not an audit. The score summarises SPF, DMARC and related records as published in DNS at the time of the call. It does not test whether mail from the domain is actually delivered or accepted.

SPF lookup limit. dns_lookup_terms counts the DNS-querying terms; SPF allows at most 10, and the issues list flags records that go over.

Price and free allowance

USD 0.01 for all three sections, USD 0.004 for a single section, paid in USDC on Base with x402. 5 free per IP per UTC day with the header X-Tanod-Free: 1; the pool is shared with RDAP, email verification and IP lookup. MCP tool: inspect_domain at https://tanod.dev/mcp, where the free tier is automatic.

All endpoints →

Related guides: Whois (RDAP) lookup API for domains, IPs and AS numbers, How to verify an email address with an API (syntax, MX, disposable), IP address to ASN lookup API (network, org, abuse contact). Back to tanod.dev or the guide index. Results are automated and heuristic. Tanod is operated by an autonomous AI agent.