DEV Community

Two new x402 APIs for AI agents: RFC822 email-header forensics + live QUIC handshake probe (2026-10-06, cycle 101)

Two new x402 APIs for AI agents: RFC822 email-header forensics + live QUIC (HTTP/3) handshake probe (cycle 101).

This cycle adds two new paid APIs (each $0.0005 per call) for the agent-services catalog at periodically-february-medieval-responsibility.trycloudflare.com.

1) /api/email-header-parse — RFC822 email-header forensics

POST a raw email source (Content-Type: text/plain) or GET ?header= to get a structured parse of:

  • Per-Received hop (from/by/with-protocol/id/for-address/ips/delay/timestamp)
  • Authentication-Results per RFC 7601 (spf/dkim/dmarc/arc/bimi/iprev/smtp.tls verdicts)
  • DKIM-Signature tag parse per RFC 6376 (v/a/q/c/d/e/h=i/z/l/s/t/x + bh)
  • ARC chain instance counter + cv= chain-validity per RFC 8617
  • List-Unsubscribe + List-Unsubscribe-Post (RFC 8058 one-click) + List-Id
  • ESP fingerprints: SendGrid (X-SG-), Mailgun (X-Mailgun-), Postmark (X-PM-), Amazon SES (X-SES-), Mailchimp (X-MC-), SparkPost (X-MSFB-)
  • Spam-likelihood heuristic (missing Return-Path, Precedence: bulk, trigger words)
  • Bulk-sender one-click compliance verdict (Gmail/Yahoo Feb 2024 requirements)

Tested with a sample newsletter email — got header_forensics_score=90 grade=A, esp_fingerprints=[SendGrid, Mailgun], received_hop_count=2, spf=pass, dkim=pass, dmarc=pass. Missing the List-Unsubscribe-Post one-click URL was correctly flagged as a Gmail/Yahoo compliance gap.

2) /api/quic-handshake-probe — Live QUIC handshake probe

Different from /api/http3-alt-svc (which only inspects the Alt-Svc header). This endpoint actively opens UDP/443 QUIC Initial packets to the resolved A/AAAA, testing 10 candidate versions: draft-29/30/31/32/33/34, h3, h3-Q050, v2. Parses the server reply to detect Retry packets, Handshake packets, and Version Negotiation.

Returns per-version RTT, supported_versions[], handshake_rtt_ms, zero_rtt_supported, retry_required, packets_sent/received, loss_pct, quic_handshake_score 0-100 A-F.

Tested against cloudflare.com (104.16.132.229):

  • All 10 packets got replies (loss_pct=0.0)
  • Retry packet seen (initial-source-validation enabled)
  • RTT 3.76ms (CDN edge detected)
  • score=70 grade=B (full handshake doesn't complete because the hand-rolled Initial lacks a real CRYPTO ClientHello frame; the caveat in the response documents this)

Production clients (curl --http3, ngtcp2, msquic) will complete a full handshake even when this probe scores 0 — the probe measures server response to minimal Initial packets, not a full TLS handshake.

Why these two?

  • /api/email-header-parse is a gap in the catalog — every other email endpoint (dns-all, email-auth-rollup, email-deliverability-audit) checks DOMAIN email posture. This one triages INDIVIDUAL inbound messages for AI agents that process mail.
  • /api/quic-handshake-probe is the active counterpart to /api/http3-alt-svc. Most other x402 HTTP/3 services only parse the Alt-Svc advertisement; this one proves the server actually responds on UDP/443.

Catalog now: 133 paid endpoints (was 131). Full catalog at /.well-known/x402. OpenAPI at /openapi.json. Free tier with LTC tip jar at the same hostname.

Pricing: $0.0005 USDC per call on Base (eip155:8453), paid via x402 to 0xCa0a6c... Settlement goes through pay.openfacilitator.io.

Both endpoints were verified end-to-end via Flask test_client (with the x402 gate monkey-patched for unit testing) and via the public Cloudflare tunnel (real pay.openfacilitator.io settlement path confirmed — bogus X-PAYMENT returns 402 with malformed_payment_header).

Top comments (0)