SYNTHORA MTA-STS Audit
Verification PAYMENT-READY importedpayment-ready until 2026-08-20
imported from the x402 Bazaar, not submitted by the operator · own this service? claim it · or ask to be removed
Audits a domain's SMTP transport security: resolves MTA-STS (RFC 8461) and TLS-RPT (RFC 8460) DNS records, fetches and parses the policy file, cross-checks policy mx patterns against the real MX, and returns a score, grade and enforce/report verdict. Responses carry an Ed25519 receipt.
Pay from $0.05 per request in USDC on Base, settled onchain via the x402 protocol, no signup, no API key needed.
first settlement 2026-06-29 · $0.05 all-time · settled via coinbase, payAI
ASSESSMENT
updated 3h agoEvidence-backed signals, not a single score. Click any chip for the proof. Measured values stay read-only; unknown is honest.
reliability 84.8%
- uptime 24h
- 100%
- uptime 7d
- 100%
- uptime 30d
- 84.8%
- uptime 90d
- 84.8%
- response p95
- 1587ms
- avg response
- 1251ms
- total checks
- 2,088
Measured on the unpaid 402 handshake, not the paid call. A service can 402 correctly and still fail after payment.
compliance A (14/14)
14 of 14 x402 conformance checks pass. Full checklist below.
price $0.05 (p63 in Verification)
- price (min)
- $0.05
- category percentile (min)
- p63 in Verification
- endpoints / prices
- 1 / 1
- model
- flat
- stability
- 0%
risk clean
No deterministic risk flag. Risk fires only on an exact blocklist match, or a reserved-brand name with a mismatched verified payTo. Never from low uptime, a high price, or a model guess.
- domain age
- 68d
- registrar
- IONOS SE
- hosting
- custom
- domain created
- 2026-06-04
Identity facts, not a risk score.
traction $0.0225606061 30d · 11 buyers
- volume 30d
- $0.0225606061
- buyers 30d
- 11
- settlements 30d
- 103
- first settlement
- 2026-06-29
- last settlement
- 2026-08-13
- top buyer share
- 85% of 30d volume
- trend 7d vs 30d
- 3.93x the 30d daily rate
- networks
- eip155:8453
- volume all-time
- $0.05
- settlements all-time
- 232
- median settlement 30d
- $0.001
- max settlement 30d
- $0.10
- settled via
- coinbase ($1.44, 102 tx), payAI ($0.05, 1 tx)
Attributed pro-quota: this payout address is shared, so volume is the operator-level figure divided by the services sharing it, while buyer and transaction counts stay whole. A declared convention, not an individually observed measure, and still a conservative undercount.
Currently sharing this payout address with Agent Card Validator (A2A), Crypto 24h Trading Stats (Binance data), Crypto Fear & Greed Index, Crypto OHLCV Candles (Binance data), DEX Token Price (GeckoTerminal data), Email Deliverability Audit (SPF, DKIM, DMARC), FX Exchange Rates (ECB), German VAT Number Validator (SYNTHORA), Global Crypto Market Stats (CoinGecko data), Hyperliquid Perps Snapshot, iCalendar (.ics) Generator, LEI Lookup (GLEIF), Order Book Liquidity (Binance depth), Perp Funding Rates (Binance data), Polymarket Prediction Markets Feed, Public Holidays API (Nager.Date), SYNTHORA Address Risk Screen, SYNTHORA Agent Capability Attestation, SYNTHORA Agent Pre-Trade Safety, SYNTHORA AML Wallet Screen, SYNTHORA Base Block Metrics, SYNTHORA BIC/SWIFT Check, SYNTHORA Bridge Risk Evaluator, SYNTHORA Contract Code Check (eth_getCode), SYNTHORA Contract Guard, SYNTHORA Contract Watch, SYNTHORA Counterparty Risk Verdict, SYNTHORA Crypto News Sentiment, SYNTHORA DeFi Data (Hyperliquid perp feed), SYNTHORA DeFi Strategy Verdict, SYNTHORA Derivatives Intel Bundle, SYNTHORA DNS + WHOIS Domain Report, SYNTHORA ENS Resolver, SYNTHORA ERC-20 Token Balance, SYNTHORA Forex Rates (ECB), SYNTHORA FX Exchange Rates, SYNTHORA Gas & MEV Oracle, SYNTHORA IBAN Check, SYNTHORA Inference Router, SYNTHORA Keyless Web Search, SYNTHORA Liquidation Risk Signal (Aave v3), SYNTHORA Mailcheck, SYNTHORA MCP Server Security Scan, SYNTHORA MEV Exposure Detector, SYNTHORA Native Balance (eth_getBalance), SYNTHORA Open Interest Oracle, SYNTHORA Pre-Sign Transaction Verdict, SYNTHORA Routing Check, Synthora RPC Contract Metadata, SYNTHORA RPC Network Metadata, SYNTHORA RPC Proxy Detect, SYNTHORA RPC Receipt, SYNTHORA RPC Transaction by Hash, SYNTHORA Slippage Oracle, SYNTHORA Stablecoin Peg Monitor, SYNTHORA Stablecoin Supply, SYNTHORA Token Risk, SYNTHORA Translate, SYNTHORA Trending Coins, SYNTHORA Tx Intent Classifier, SYNTHORA Wallet Reputation Score, SYNTHORA x402 Endpoint Preflight, SYNTHORA x402 Registry Watch, VIN Decoder (NHTSA vPIC), Wikipedia Article Summary.
Top buyer share is a concentration signal, not part of the ranking score.
CHANGES
1 event, detecting since 2026-07-24Payout, price, and schema changes detected on this service's x402 wire. A payout rotation at an unchanged price shows up here even when nothing else moves. Full feed at /changes.
changes schema changed 9d ago (1 since 2026-07-24)
schema changed · 9d ago
schema removed POST /service exact eip155:8453 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 USDC 2 application/json 300 https://mtasts.hergertsynthora.com/service {"name":"USD Coin","version":"2"}
schema added POST /service exact eip155:8453 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 USDC 2 application/json 300 https://api.hergertsynthora.com/v1/mtasts {"name":"USD Coin","version":"2"}
WHAT IT DOES
ai-derivedPerforms MTA-STS and TLS-RPT audits for SMTP transport security
- category
- email-security-audit
- in
- body
AI-generated summary. The measured data is never altered by it.
ENDPOINTS
| METHOD | PATH | DESCRIPTION | PRICE | NETWORK | ASSET | 402 CHANNEL |
|---|---|---|---|---|---|---|
| POST | /service | SMTP transport-security audit: MTA-STS (RFC 8461) + TLS-RPT (RFC 8460). Resolves the policy DNS records, fetches and parses the well-known policy file, cross-validates the policy mx: patterns against the domain's real MX, and returns an enforce/report verdict. Complements SPF/DKIM/DMARC auditing with the TLS transport layer. Deterministic, Ed25519-signed. 0.003 USDC via x402 on Base. SYNTHORA. | $0.05 | Base | USDC | header |
REQUEST / RESPONSE EXAMPLE
An unpaid request to POST /service returns HTTP 402 with the payment terms. Settle onchain via your facilitator, then retry with the X-Payment header.
curl -i -X POST 'https://mtasts.hergertsynthora.com/service'
// 402 response (captured by monitor) · 1 payload · click to expand
[
{
"error": "Payment required",
"accepts": [
{
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"name": "USD Coin",
"version": "2"
},
"payTo": "0x10800a5a5B9d72251566EC651E862A8b4B427dE0",
"amount": "50000",
"scheme": "exact",
"network": "eip155:8453",
"mimeType": "application/json",
"resource": "https://api.hergertsynthora.com/v1/mtasts",
"description": "SYNTHORA mtasts: sMTP transport-security audit: MTA-STS (RFC 8461) + TLS-RPT (RFC 8460). Resolves the policy DNS records, fetches and parses the well-known policy file, cross-validates the policy mx: patterns against the domain's real MX, and returns an enforce/report verdict. Complements SPF/DKIM/DMARC auditing with the TLS transport layer. Deterministic, Ed25519-signed. 0.003 USDC via x402 on Base. SYNTHORA.",
"maxAmountRequired": "50000",
"maxTimeoutSeconds": 300
}
],
"resource": {
"url": "https://api.hergertsynthora.com/v1/mtasts",
"mimeType": "application/json",
"description": "SYNTHORA mtasts: sMTP transport-security audit: MTA-STS (RFC 8461) + TLS-RPT (RFC 8460). Resolves the policy DNS records, fetches and parses the well-known policy file, cross-validates the policy mx: patterns against the domain's real MX, and returns an enforce/report verdict. Complements SPF/DKIM/DMARC auditing with the TLS transport layer. Deterministic, Ed25519-signed. 0.003 USDC via x402 on Base. SYNTHORA."
},
"extensions": {
"bazaar": {
"info": {
"input": {
"body": {
"op": "check",
"domain": "example.com"
},
"type": "http",
"method": "POST",
"bodyType": "json"
},
"output": {
"type": "json",
"example": {
"ok": true,
"niche": "mtasts",
"result": {
"score": 100,
"domain": "example.com",
"issues": [],
"mta_sts": {
"mx": [
"*.mail.example.com"
],
"mode": "enforce",
"max_age": 604800,
"dns_present": true,
"mx_matches_dns": true,
"policy_reachable": true
},
"tls_rpt": {
"present": true
},
"verdict": "enforced+reporting"
}
}
}
},
"schema": {
"type": "object",
"$schema": "https://json-schema.org/draft/2020-12/schema",
"required": [
"input"
],
"properties": {
"input": {
"type": "object",
"required": [
"type",
"method",
"bodyType",
"body"
],
"properties": {
"body": {
"type": "object",
"required": [
"domain"
],
"properties": {
"op": {
"enum": [
"check",
"mtasts",
"tlsrpt"
],
"type": "string",
"description": "Audit scope (default check = full)"
},
"domain": {
"type": "string",
"description": "Domain or email address to audit"
}
}
},
"type": {
"type": "string",
"const": "http"
},
"method": {
"enum": [
"POST",
"PUT",
"PATCH"
],
"type": "string"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
}
},
"additionalProperties": false
},
"output": {
"type": "object",
"required": [
"type"
],
"properties": {
"type": {
"type": "string"
},
"example": {
"ok": {
"type": "boolean"
},
"type": "object",
"niche": {
"type": "string"
}
}
}
}
}
}
}
},
"x402Version": 2
}
] OVER TIME
All charts use the 90d selector; each series spans only the dates it has data for. Every series is also served as JSON at /api/v1/services/synthora-mta-sts-audit/price, /scores, /volume and /buyers. On-chain volume and distinct buyers are measured over the service's settlement address and are a conservative undercount (only settlements that reach a measured facilitator are counted). The on-chain series roll up hourly, so the latest day can be up to about an hour behind; distinct buyers are counted per payout address, so a service that settles to more than one address is an upper bound.
checklist grew 11->14 on 2026-07-28; a step here is a metric change, not a regression
Measured site and economics pillars from the assessment history, so the latest value shown elsewhere on this page reads as a point on a trend rather than a permanent state.
Shared payout address (65 other services). These bars are the full shared address (operator-level), so do not sum them across the services that share it. Where a per-service figure is attributed, the assessment block and the ranking, it is the address total divided pro-quota by the 66 services sharing it: a declared convention, not an individually observed measure.
Shared payout address (65 other services). These bars are the full shared address (operator-level), so do not sum them across the services that share it. Per-service buyer and transaction counts are shown whole (integers), not divided; only volume is attributed pro-quota. A declared convention, not an individually observed measure.
COMPLIANCE
14/14 checks pass · grade Alast 402 captured 2026-08-04 · last up 2026-08-13
- 402 payload captured
- accepts[] array present
- payTo address recoverable
- payTo at accepts[0].payTo (conformant shape)
- payTo is a valid on-chain address
- atomic price declared
- atomic price in a sane range
- asset (token) address declared
- network resolves to CAIP-2
- payment scheme declared
- served over HTTPS
- declares the current x402 version (2)
- EIP-712 domain parameters present on every EVM entry
- x402 v2 envelope delivered in the payment-required header
SITE PILLARS
- homepage reachable
- openapi doc
- pricing page
- llms.txt
- robots.txt
- terms page
recent checks (18) live · click to expand
EMBED THIS BADGE
<a href="https://x402-list.com/services/synthora-mta-sts-audit?utm_source=badge&utm_medium=referral&utm_campaign=embed"> <img src="https://x402-list.com/badge/synthora-mta-sts-audit.svg" alt="SYNTHORA MTA-STS Audit listed on x402-list" height="28"> </a>
[](https://x402-list.com/services/synthora-mta-sts-audit?utm_source=badge&utm_medium=referral&utm_campaign=embed)
<a href="https://x402-list.com/services/synthora-mta-sts-audit?utm_source=badge&utm_medium=referral&utm_campaign=embed"> <img src="https://x402-list.com/badge/synthora-mta-sts-audit.svg?data=uptime" alt="SYNTHORA MTA-STS Audit uptime on x402-list" height="28"> </a>