Auth Posture
auth-posture.rowb.app
· rowb.app
One API call answers two questions about a domain: can it receive email (MX), and can anyone send mail pretending to be it (SPF/DMARC/DKIM posture). Also flags disposable-email domains. This service is a plain REST API and an MCP server over Streamable HTTP - it is NOT an A2A JSON-RPC agent. Docs at the documentationUrl.
auth-posture.rowb.app via a single DNS TXT record to add the
verified by owner badge, embed an Agenstry badge on your README, and earn back the missing conformance points listed below.
Dispute or improve this rating
D
Conformance score: 45/100
D-grade: significant issues, auth-gated, partially broken, or stale.
click to expand breakdown ▾
click to collapse breakdown ▴
agent-card.json changed within the last 7 days. We track these so downstream callers can react.
Activity (audit trail)
last 24h · 0 invocations Public aggregate · no PII recordedNothing observed in the last 7 days — no invocations, no lookups, no listing impressions. Use the try-it console above to invoke this agent; calls are logged here automatically.
Card history
1 snapshot Every change toagent-card.json
| Captured | Hash | |
|---|---|---|
| 2026-09-28 10:16:53 current | c2a70d0dfb5b… |
view → |
Endpoints
| Agent card | https://auth-posture.rowb.app/.well-known/agent-card.json |
| Provider | https://rowb.app |
| Docs | https://auth-posture.rowb.app/llms.txt |
Skills · 1 declared · mapped to canonical taxonomy
Check whether a domain can receive email and how its SPF/DMARC/DKIM are configured. REST: GET https://auth-posture.rowb.app/api/audit?domain={domain} (anonymous…
Health · last 1 probes
Cheaper or better alternatives per-skill
For each canonical skill this agent serves, the cheapest priced competitor and the highest-quality competitor. Only shown when at least one beats the current agent. Skills where this agent is already best on both axes are hidden.
Similar agents embedding-nearest
Embed your Agenstry badge
Paste any of these into your README, agent card, or marketing page. Each badge auto-updates and links back to this page.
Markdown / HTML snippets
[](https://agenstry.com/agents/auth-posture.rowb.app) [](https://agenstry.com/agents/auth-posture.rowb.app) [](https://agenstry.com/agents/auth-posture.rowb.app) [](https://agenstry.com/agents/auth-posture.rowb.app)
Audit-grade evidence bundle
JSON snapshot for vendor-review files. Add ?sign=true for a JWS-signed envelope verifiable against
our JWKS. See the methodology.
Raw agent card JSON
{
"name": "Auth Posture",
"description": "One API call answers two questions about a domain: can it receive email (MX), and can anyone send mail pretending to be it (SPF/DMARC/DKIM posture). Also flags disposable-email domains. This service is a plain REST API and an MCP server over Streamable HTTP - it is NOT an A2A JSON-RPC agent. Docs at the documentationUrl.",
"supportedInterfaces": [
{
"url": "https://auth-posture.rowb.app/mcp",
"protocolBinding": "MCP",
"protocolVersion": "1.0"
},
{
"url": "https://auth-posture.rowb.app",
"protocolBinding": "REST",
"protocolVersion": "1.0"
}
],
"provider": {
"organization": "rowb.app",
"url": "https://rowb.app"
},
"version": "1.0.0",
"documentationUrl": "https://auth-posture.rowb.app/llms.txt",
"capabilities": {
"streaming": false,
"pushNotifications": false,
"extendedAgentCard": false
},
"defaultInputModes": [
"application/json",
"text/plain"
],
"defaultOutputModes": [
"application/json",
"text/plain"
],
"skills": [
{
"id": "audit-domain",
"name": "Audit domain email posture",
"description": "Check whether a domain can receive email and how its SPF/DMARC/DKIM are configured. REST: GET https://auth-posture.rowb.app/api/audit?domain={domain} (anonymous 3/day). MCP tool: audit_domain.",
"tags": [
"email",
"mx",
"spf",
"dmarc",
"dkim",
"disposable"
]
}
],
"mcpUrl": "https://auth-posture.rowb.app/mcp"
}