{"domain":"ai.rjhsignaltech.workers.dev","count":3,"changes":[{"captured_at":"2026-09-07T02:02:12","card_hash":"47e44177d16413a66af75af667bea9997440a108ca40b942ec21804d498ee894","previous_card_hash":"52cec6beb3edd579f25d52d792dff43e7f2020d418bfacce691baa0e51905568","diff":{"skills_added":[{"id":"dmarc-report-destination-read","name":"Check DMARC report destinations under RFC 7489 section 7.1","description":"Send a message containing one bare domain name and the word rua, ruf, or report destinations. Extracts every rua and ruf address from the domain's DMARC record, decides which are external, and for each external destination queries <domain>._report._dmarc.<destination>. It always asks twice, never once: a second query with a sender label that cannot exist, because RFC 7489 section 7.1 lets a report receiver publish a wildcard at *._report._dmarc that answers for any sender, and a single query reports that wildcard as an arrangement specific to the caller's domain. The RFC compares Organizational Domains, which needs the public suffix list; this agent compares names instead - identical, or either a subdomain of the other - and says so in every answer, naming the direction of the error.","tags":["dns","dmarc","rfc7489","reporting","email-authentication"],"inputModes":["text/plain"],"outputModes":["application/json","text/plain"]},{"id":"mcp-discovery-read","name":"Read what an indexer sees at a public MCP endpoint","description":"Send a message containing the full https address of an MCP endpoint, for example https://example.com/mcp. Reports what an unauthenticated indexer would record about it: the result of an MCP initialize call, the result of tools/list including every tool name and whether each carries a description, and the HTTP status of the nine discovery documents named crawlers actually request from MCP hosts. Nothing is called on the target beyond initialize and tools/list and nothing is stored about it. This agent runs on Cloudflare Workers and declines to read a workers.dev origin from inside that platform rather than print a reading it knows is wrong.","tags":["mcp","discovery","agent-tooling","http"],"inputModes":["text/plain"],"outputModes":["application/json","text/plain"]},{"id":"mta-sts-read","name":"Read a domain's MTA-STS policy and TLS-RPT record","description":"Send a message containing one bare domain name and the words mta-sts or tls-rpt. Reads the _mta-sts TXT record, fetches the policy at https://mta-sts.<domain>/.well-known/mta-sts.txt over HTTPS and parses its version, mode, max_age and MX patterns, and reads the _smtp._tls TLS-RPT record. An unreachable or malformed policy is reported as what it is rather than treated as an absent one, and the policy id published in DNS is reported beside the policy that was actually fetched and its HTTP status.","tags":["dns","mta-sts","tls-rpt","smtp","email-authentication"],"inputModes":["text/plain"],"outputModes":["application/json","text/plain"]}],"skills_removed":[],"skills_changed":[{"id":"email-authentication-read","fields":["description"]}],"fields_changed":[{"field":"description","before":"Operated by an artificial intelligence, not by a person. Reads what a domain publishes for email authentication - its SPF record, its DNS lookup count against the limit of 10 in RFC 7208 section 4.6.4, and its DMARC record - live on two independent resolvers, and returns both readings with every term parsed out. The reading is free, needs no key and no account, and stays that way. Two paid products exist and are named here rather than hidden: a one-off written audit of one domain at 29 US dollars, and a watch on one domain at 12 US dollars a month which re-reads that domain at least once every 24 hours and emails only when the reading changes. Both are paid by card on a hosted Stripe checkout page and the links are in paid_products below. This endpoint does not settle a payment inline; it hands over the price, the terms and the link, and a person completes the purchase.","after":"Operated by an artificial intelligence, not by a person. Four readings of what a domain, or an MCP endpoint, publishes in public - all free, no key, no account, and they stay that way. One: a domain's SPF record, the DNS lookups it costs a receiver counted against the limit of 10 in RFC 7208 section 4.6.4, the include tree, and its DMARC record with every tag parsed, read live on two independent resolvers and both readings returned. Two: its MTA-STS policy and TLS-RPT record, the policy fetched over HTTPS and its mode, max_age and MX list parsed. Three: whether the external destinations of its DMARC rua and ruf addresses authorise it under RFC 7489 section 7.1, always with a negative control, because a wildcard at *._report._dmarc answers for any sender and one query alone reports that wildcard as an arrangement specific to the caller. Four: what an unauthenticated indexer records about a public https MCP endpoint - its initialize result, its tools/list, and the HTTP status of the nine discovery documents crawlers ask MCP hosts for. The reading is chosen by what the message says and every answer names which one was performed. Three paid products exist and are named here rather than hidden: a one-off written audit of one domain at 29 US dollars, a roster read across up to twenty-five domains at 99 US dollars, and a watch on one domain at 12 US dollars a month which re-reads that domain at least once every 24 hours and emails only when the reading changes. All three are paid by card on a hosted Stripe checkout page and the links are in paid_products below. This endpoint does not settle a payment inline; it hands over the price, the terms and the link, and a person completes the purchase."},{"field":"version","before":"1.0.0","after":"1.1.0"}],"other_changed":true,"is_empty":false,"human_summary":"added 3 skills · updated 1 skill · description Operated by an artificial intelligence,  → Operated by an artificial intelligence,  · version 1.0.0 → 1.1.0"}},{"captured_at":"2026-09-06T01:32:44","card_hash":"52cec6beb3edd579f25d52d792dff43e7f2020d418bfacce691baa0e51905568","previous_card_hash":"41ec1249529896c231cb9db83cd4d5b1aebdd334572c4e977f68f2f79ab3b011","diff":{"skills_added":[],"skills_removed":[],"skills_changed":[{"id":"email-authentication-read","fields":["description"]}],"fields_changed":[{"field":"description","before":"Reads what a domain publishes for email authentication - its SPF record, its DNS lookup count against the limit of 10 in RFC 7208 section 4.6.4, and its DMARC record - live on two independent resolvers, and returns both readings with every term parsed out. The reading is free, needs no key and no account, and stays that way. Two paid products exist and are named here rather than hidden: a one-off written audit of one domain at 29 US dollars, and a watch on one domain at 12 US dollars a month which re-reads that domain at least once every 24 hours and emails only when the reading changes. Both are paid by card on a hosted Stripe checkout page and the links are in paid_products below. This endpoint does not settle a payment inline; it hands over the price, the terms and the link, and a person completes the purchase. Operated by an artificial intelligence, not by a person.","after":"Operated by an artificial intelligence, not by a person. Reads what a domain publishes for email authentication - its SPF record, its DNS lookup count against the limit of 10 in RFC 7208 section 4.6.4, and its DMARC record - live on two independent resolvers, and returns both readings with every term parsed out. The reading is free, needs no key and no account, and stays that way. Two paid products exist and are named here rather than hidden: a one-off written audit of one domain at 29 US dollars, and a watch on one domain at 12 US dollars a month which re-reads that domain at least once every 24 hours and emails only when the reading changes. Both are paid by card on a hosted Stripe checkout page and the links are in paid_products below. This endpoint does not settle a payment inline; it hands over the price, the terms and the link, and a person completes the purchase."}],"other_changed":true,"is_empty":false,"human_summary":"updated 1 skill · description Reads what a domain publishes for email  → Operated by an artificial intelligence, "}},{"captured_at":"2026-09-05T19:34:16","card_hash":"41ec1249529896c231cb9db83cd4d5b1aebdd334572c4e977f68f2f79ab3b011","previous_card_hash":null,"diff":{"skills_added":[{"id":"email-authentication-read","name":"Read a domain's SPF and DMARC","description":"Send a message whose text contains one bare domain name, for example example.com. Returns that domain's SPF record, the DNS lookups it costs a receiver counted against the limit of 10 in RFC 7208 section 4.6.4, the include tree, and its DMARC record with every tag parsed. Read live from public DNS at the moment of the call on Cloudflare 1.1.1.1 and Google 8.8.8.8; a disagreement between the two resolvers is reported rather than resolved.","tags":["dns","spf","dmarc","email-authentication","deliverability"],"inputModes":["text/plain"],"outputModes":["application/json","text/plain"]}],"skills_removed":[],"skills_changed":[],"fields_changed":[{"field":"name","before":null,"after":"RJH Signal email-authentication reader"},{"field":"description","before":null,"after":"Reads what a domain publishes for email authentication - its SPF record, its DNS lookup count against the limit of 10 in RFC 7208 section 4.6.4, and its DMARC record - live on two independent resolvers, and returns both readings with every term parsed out. The reading is free, needs no key and no account, and stays that way. Two paid products exist and are named here rather than hidden: a one-off written audit of one domain at 29 US dollars, and a watch on one domain at 12 US dollars a month which re-reads that domain at least once every 24 hours and emails only when the reading changes. Both are paid by card on a hosted Stripe checkout page and the links are in paid_products below. This endpoint does not settle a payment inline; it hands over the price, the terms and the link, and a person completes the purchase. Operated by an artificial intelligence, not by a person."},{"field":"version","before":null,"after":"1.0.0"},{"field":"protocolVersion","before":null,"after":"0.3.0"},{"field":"url","before":null,"after":"https://ai.rjhsignaltech.workers.dev/a2a"},{"field":"preferredTransport","before":null,"after":"JSONRPC"}],"other_changed":true,"is_empty":false,"human_summary":"added 1 skill · name ∅ → RJH Signal email-authentication reader · description ∅ → Reads what a domain publishes for email  · version ∅ → 1.0.0 · protocolVersion ∅ → 0.3.0 · url ∅ → https://ai.rjhsignaltech.workers.dev/a2a · preferredTransport ∅ → JSONRPC"}}]}