# InboxGuards Email Test > Send a real email to a one-time address and get a deliverability and security report: SPF, DKIM, DMARC, ARC, sending IP reverse DNS, SpamCop, MTA-STS/TLS-RPT, BIMI, List-Unsubscribe, header and content checks. Free to create a test; pay only to read a finished report. Payments: x402 v2, scheme "exact", USDC on Base mainnet (eip155:8453), asset 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913, payTo 0x2dAF658B01e257206375798a15832E9f547D65dD. No accounts or API keys. Flow: call the paid URL -> HTTP 402 with a base64 JSON PAYMENT-REQUIRED header -> sign an EIP-3009 USDC authorization for one of `accepts` -> retry with PAYMENT-SIGNATURE -> 200 + PAYMENT-RESPONSE (settlement receipt). Invalid input returns 400 and is never charged; upstream failures return 5xx and are not settled. Client libraries: @x402/fetch (wrapFetchWithPayment), @x402/axios, or any x402 v2 client. ## Paid endpoints - [GET /v1/report](https://api.inboxguardstest.com/v1/report) $0.05: Email deliverability and security report for a real email you sent. 1) POST /v1/tests (free) for a one-time address + read token. 2) Send one real email to it. 3) GET this with ?test_id= and X-Read-Token. Report: SPF, DKIM (key size, alignment), DMARC, ARC, BIMI, sending IP rDNS + SpamCop, MTA-STS/TLS-RPT, one-click unsubscribe, headers, content, 0-100 score, top fixes. Not-ready/unknown tests: 4xx, never charged. Query: `test_id`. Example: https://api.inboxguardstest.com/v1/report?test_id=abcdefgh2345 ## Free endpoints - POST https://api.inboxguardstest.com/v1/tests: create a one-time test address (returns test_id, address, read_token) - GET https://api.inboxguardstest.com/v1/tests/{test_id}/status: waiting | processing | ready | rejected_or_not_received | analysis_failed ## Discovery - OpenAPI: https://api.inboxguardstest.com/openapi.json - x402 manifest: https://api.inboxguardstest.com/.well-known/x402 - API catalog (RFC 9727): https://api.inboxguardstest.com/.well-known/api-catalog - Sitemap: https://api.inboxguardstest.com/sitemap.xml ## Flow 1. POST /v1/tests (free) -> {test_id, address, read_token}. Keep read_token secret; it is shown once. 2. Send ONE real email to `address` within 60 minutes, from the system you want tested. 3. Poll GET /v1/tests/{test_id}/status (free) until `ready` (usually seconds). 4. GET /v1/report?test_id=... with header `X-Read-Token: ` -> 402 -> pay -> 200 report JSON. Re-reads after payment are free. ## Never charged Unknown test (404), wrong token (403), malformed input (400), report not ready / mail never arrived / analysis failed (409). If Cloudflare's mail servers refused the email (fails both SPF and DKIM, fails the sender's DMARC policy, or IP on a blocklist), no report exists and status becomes rejected_or_not_received after 15 minutes. ## Privacy The raw email is analyzed in memory and never stored. Links are never opened. Reports are deleted 24 hours after the email arrives; unused tests 24 hours after creation.