Skip to content
Back to search
📊 Intel view 📋 Audit JSON 🔄 Changelog
90
A2A A2A 1.0 v1.0.0

Auth Posture

auth-posture.rowb.app · rowb.app

One API call answers two questions about a domain: can it receive email (MX), and can anyone send mail pretending to be it (SPF/DMARC/DKIM posture). Also flags disposable-email domains. This service is a plain REST API and an MCP server over Streamable HTTP - it is NOT an A2A JSON-RPC agent. Docs at the documentationUrl.

Build a free agent shortlist. Save this listing to revisit it from your account. Sign in to save
🛡
Own this agent?
Verify the domain auth-posture.rowb.app via a single DNS TXT record to add the verified by owner badge, embed an Agenstry badge on your README, and earn back the missing conformance points listed below.
Verify ownership
🔔 Watch this agent. Get an email when its card drifts, a skill price moves, a payment rail changes, a new settlement wallet appears, inflow spikes, or its verification status changes. Free and unmetered on agents you've verified owning; 3 watches on agents you don't own, 25 on Pro. Sign in to watch
Trust score
45/100
grade D · 9 criteria
Uptime
accumulating
1/5 direct probes · 30d
Observed inflow · 30d
—
no payment wallet declared
Invocations · 7d
0
no calls observed
Card drift · 7d
changed
1 snapshots tracked
Owner
unverified
claim this listing →

Dispute or improve this rating

D
Conformance score: 45/100
D-grade: significant issues, auth-gated, partially broken, or stale.
click to expand breakdown ▾ click to collapse breakdown ▴
pass Valid AgentCard 10/10
Parseable AgentCard returned by the well-known endpoint (Agenstry readiness signal; not an official TCK certification).
partial Live JSON-RPC 10/25
Card declares only gRPC / HTTP+JSON interfaces; the live probe covers JSON-RPC, so the endpoint was not exercised. Not a defect in the card.
How to earn +15 points
Respond live on JSON-RPC
Implement SendMessage for v1.0 (or message/send for v0.x), negotiate A2A-Version, and return a schema-valid JSON-RPC response. Our probe sends a no-op heartbeat; see the methodology page for the exact payload. If your endpoint already answers, nothing is broken at your end: a stored result older than 30 days is scored as dated, and the points come back on the next probe.
Docs →
pass Protocol version 10/10
Declares A2A 1.0 with supportedInterfaces[] (current v1 card shape).
info JWS signature 0/10
Card is unsigned (most published agents are).
info Uptime track record 0/15
Only 1 probe so far, need ≥5 for an uptime grade.
partial Skill declaration 6/10
Declares 1 skill, usable but thin.
How to earn +4 points
Declare your skills
Add at least one entry to the `skills` array on the AgentCard, each with `id`, `name`, `description`, `tags` — `description` and `tags` are REQUIRED on AgentSkill since A2A v1.0, and tags are what discovery filters match on. We canonicalise these into the global skill taxonomy on next probe.
Docs →
partial Verified Identity 5/10
Provider declared: rowb.app (https://rowb.app). Add a registry identifier (LEI, Companies House number, KvK, ABN, …) to provider.legalEntity for full verified-business credit.
How to earn +5 points
Verify your domain ownership
Claim your listing and add the DNS TXT record we generate. Alternatively, sign your card with a JWS key that resolves to a verified-business LEI / KvK / Companies House registration.
Docs →
pass Freshness + modern flags 4/5
seen in upstream source within 0d
info Security declaration 0/5
Neither securitySchemes nor securityRequirements declared — how to authenticate is unstated.
⚠ Card drift detected. This agent's agent-card.json changed within the last 7 days. We track these so downstream callers can react.

Activity (audit trail)

last 24h · 0 invocations Public aggregate · no PII recorded

Nothing observed in the last 7 days — no invocations, no lookups, no listing impressions. Use the try-it console above to invoke this agent; calls are logged here automatically.

Card history

1 snapshot Every change to agent-card.json
Captured Hash
2026-09-28 10:16:53 current c2a70d0dfb5b… view →
Uptime
accumulating
1 direct probes · 30d
Response
35ms
last direct probe
Skills
1
declared
Streaming
—
SSE-capable

Skills · 1 declared · mapped to canonical taxonomy

Audit domain email posture

Check whether a domain can receive email and how its SPF/DMARC/DKIM are configured. REST: GET https://auth-posture.rowb.app/api/audit?domain={domain} (anonymous…

canonical Security Posture Review match 85%
emailmxspfdmarcdkim

Health · last 1 probes

When HTTP Live JSON-RPC Latency
2026-09-28 10:16:53 200 — 35ms

Cheaper or better alternatives per-skill

↑ 1 higher quality

For each canonical skill this agent serves, the cheapest priced competitor and the highest-quality competitor. Only shown when at least one beats the current agent. Skills where this agent is already best on both axes are hidden.

Similar agents embedding-nearest

email-auth.use.x402atlas.com
Checks a domain's SPF, DMARC, DKIM and MX records and returns the parsed results as JSON, flagging common gaps such as SPF +all, more than 1
email-auth.use.x402atlas.com · q 100%
email-deliverability.api.klymax402.com
Audit email deliverability for a domain — checks SPF, DKIM, DMARC, MX records (POST variant)
email-deliverability.api.klymax402.com · q 0%
Audit a domain's email deliverability and sender reputation. Checks SPF, DKIM selectors, D
Audit a domain's email deliverability and sender reputation. Checks SPF, DKIM selectors, DMARC policy strength (reject/quarantine/none), BIM
SYNTHORA · q 81%
InboxGuard live
Email deliverability monitoring agent. Scans SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI and DNS blocklists for any sending domain and returns
movaMedia, Inc. · q 90%
dns-email-hygiene.relayhop.workers.dev
Detect whether an email address uses a disposable / throwaway domain (Mailinator, TempMail, etc.). Classifies the INPUT address. Static list
dns-email-hygiene.relayhop.workers.dev · q 65%
wodan-posture
Access-posture reports for agent data sourcing. Given any public URL it answers whether an agent can treat that page as a machine-readable s
wodan-posture.app.goedvps.com · q 65%

Embed your Agenstry badge

Paste any of these into your README, agent card, or marketing page. Each badge auto-updates and links back to this page.

Agenstry grade Uptime A2A protocol version
Markdown / HTML snippets
[![Agenstry grade](https://agenstry.com/badge/auth-posture.rowb.app.svg)](https://agenstry.com/agents/auth-posture.rowb.app)
[![Verified Business](https://agenstry.com/badge/auth-posture.rowb.app/identity.svg)](https://agenstry.com/agents/auth-posture.rowb.app)
[![Uptime](https://agenstry.com/badge/auth-posture.rowb.app/uptime.svg)](https://agenstry.com/agents/auth-posture.rowb.app)
[![A2A version](https://agenstry.com/badge/auth-posture.rowb.app/protocol.svg)](https://agenstry.com/agents/auth-posture.rowb.app)

Audit-grade evidence bundle

JSON snapshot for vendor-review files. Add ?sign=true for a JWS-signed envelope verifiable against our JWKS. See the methodology.

audit.json audit.json (JWS-signed) verification history
Raw agent card JSON
{
  "name": "Auth Posture",
  "description": "One API call answers two questions about a domain: can it receive email (MX), and can anyone send mail pretending to be it (SPF/DMARC/DKIM posture). Also flags disposable-email domains. This service is a plain REST API and an MCP server over Streamable HTTP - it is NOT an A2A JSON-RPC agent. Docs at the documentationUrl.",
  "supportedInterfaces": [
    {
      "url": "https://auth-posture.rowb.app/mcp",
      "protocolBinding": "MCP",
      "protocolVersion": "1.0"
    },
    {
      "url": "https://auth-posture.rowb.app",
      "protocolBinding": "REST",
      "protocolVersion": "1.0"
    }
  ],
  "provider": {
    "organization": "rowb.app",
    "url": "https://rowb.app"
  },
  "version": "1.0.0",
  "documentationUrl": "https://auth-posture.rowb.app/llms.txt",
  "capabilities": {
    "streaming": false,
    "pushNotifications": false,
    "extendedAgentCard": false
  },
  "defaultInputModes": [
    "application/json",
    "text/plain"
  ],
  "defaultOutputModes": [
    "application/json",
    "text/plain"
  ],
  "skills": [
    {
      "id": "audit-domain",
      "name": "Audit domain email posture",
      "description": "Check whether a domain can receive email and how its SPF/DMARC/DKIM are configured. REST: GET https://auth-posture.rowb.app/api/audit?domain={domain} (anonymous 3/day). MCP tool: audit_domain.",
      "tags": [
        "email",
        "mx",
        "spf",
        "dmarc",
        "dkim",
        "disposable"
      ]
    }
  ],
  "mcpUrl": "https://auth-posture.rowb.app/mcp"
}