{"slug":"dns","domain":"web","title":"What a domain says below the web page","summary":"Mail authentication, nameservers and registration.","help":"dns: what a domain says about itself below the web page.\n\nWHY IT IS NOT PART OF `browser`\n  None of this is reachable over HTTP. Whether a domain can authenticate its own\n  mail decides whether its invoices and its outreach land in a spam folder, and\n  how old the registration is, is the first thing a cautious buyer checks.\n  A browser — however capable — cannot answer either.\n\nREAD THE DMARC POLICY, NOT ITS PRESENCE\n  `p=none` means DMARC is published and asks receivers to do nothing about a\n  failure. That is a weaker thing than having it, and a report that says \"DMARC:\n  yes\" has told the reader nothing.\n\nDKIM CANNOT BE ENUMERATED\n  A key lives at `\u003cselector\u003e._domainkey.\u003cdomain\u003e` and the selector is chosen by\n  whoever set the mail up. This probes the ones the common providers use and\n  says which it tried. A miss is reported as inconclusive, because it is.\n\nStudies:\n  records \u003cdomain\u003e\n      addresses, nameservers, SPF, DKIM, DMARC and registration\n\nJSON to stdout, so it composes: pipe to `jq` to pick a field, or `\u003e /tmp/…` to keep it.\nRun a study with no arguments — `dns records` — to see what it takes.\n","example_command":"dns records hedwigai.com","example_output":"","cost_class":"upstream-fetch","tier":"free","price_per_1k_calls":0,"price_is_from":false,"status":"available","commands":["dns"],"studies":[{"call":"records","about":"addresses, nameservers, SPF, DKIM, DMARC and registration","args":[{"name":"domain","positional":true,"list":false,"hint":""},{"name":"registration","positional":false,"list":false,"hint":"true | false — also ask RDAP who registered it"},{"name":"dkim","positional":false,"list":false,"hint":"true | false — also probe the common DKIM selectors"}]}],"default_enabled":true,"first_seen":"2026-09-13T13:53:37.046827Z","enabled":false}
