Certificate-Transparency Newly-Launched Startup Lead Extractor avatar

Certificate-Transparency Newly-Launched Startup Lead Extractor

Pricing

from $8.00 / 1,000 newly-launched startup lead with contacts

Go to Apify Store
Certificate-Transparency Newly-Launched Startup Lead Extractor

Certificate-Transparency Newly-Launched Startup Lead Extractor

Day-zero startup leads from Certificate Transparency: crt.sh finds domains whose FIRST TLS cert was just issued, we enrich each new site's OWN website with MX/DNS-verified emails + phones + socials + tech stack + A-D launch-readiness. Be first to a newly-launched business. Per-result, no keys.

Pricing

from $8.00 / 1,000 newly-launched startup lead with contacts

Rating

0.0

(0)

Developer

Virtual Footprint LLC

Virtual Footprint LLC

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

3 days ago

Last modified

Share

Turn the Certificate-Transparency log firehose into verified day-zero startup sales leads. Every time a new business stands up a website it secures a TLS certificate — that issuance is recorded publicly in the CT log before the site even has a homepage. This Actor finds domains whose first TLS certificate was just issued, then enriches each newly-launched site's OWN website with MX/DNS-verified decision-maker emails, phones, socials, tech stack, and an A-D launch-readiness grade.

Be first to a newly-launched business. "New businesses spend the most in their first 30 days — be there when vendor decisions are made" is the thesis behind a whole SaaS tier (New Business Radar, FeedLead, Letrics) that sells day-zero newly-launched-business leads monthly. This Actor delivers the same signal per-result, with verified contacts, at a fraction of the cost.

What makes it different

The existing CT/cert actors on the store (ryanclinton/crt-sh-search, parseforge/crtsh-certificate-transparency-scraper, perryay/subdomain-enumeration-ct-logs, scrapemint/newly-registered-domain-leads) all hand you raw certificate rows or a raw cert dump. None of them hand you a lead. This Actor is the only one that:

  • computes the earliest-cert date per registrable domain (the real "first seen in CT" day-zero signal — not just the latest cert);
  • rolls subdomains up under the apex (wildcards stripped) — one lead per business, not a row per cert;
  • enriches the newly-launched site's OWN website for MX/DNS-verified decision-maker emails, phones, socials, and tech stack;
  • grades each lead A-D for launch-readiness (earliest-cert recency + contactability + subdomain traction);
  • charges per verified-contact lead (you don't pay for domains with no live site or no contact — honestly dropped, not billed).

How it works

  1. Discovery — queries the public keyless crt.sh CT-log search:
    • Explicit domains list → one cert-history fetch per apex (score + enrich a known domain list).
    • searchQuery (keyword or SQL-LIKE pattern such as ai, openai, %.dev, %.ai) → discover newly-secured apices across the whole CT log, apex-deduped, known-big infrastructure domains dropped.
  2. Day-zero signal — for each apex, computes earliestCertDate (first TLS cert = when the business stood up the domain), latestCertDate, certCount, top issuer, and the discovered subdomains.
  3. Enrichment — fetches https://<apex> (and a www. fallback) and runs the proven enrichment layer: MX/DNS-verified emails, NANP phones, social profiles, tech-stack fingerprint, A-D lead score.
  4. Launch-readiness grade — A-D from earliest-cert recency + contactability + subdomain traction, plus a newlyLaunched boolean when the first cert falls within your window.

No third-party API keys, no residential proxy, no compose cost. CT logs are public-by-design (that is their purpose) — the lowest-ToS-risk discovery surface in the lead-gen portfolio. Contact always comes from the newly-launched site's own public pages (same posture as the website-contact actor); the CT log carries only domain names, never personal data.

Input

FieldTypeDefaultDescription
domainsstring[][]Explicit domains/URLs to score + enrich (one lead per registrable apex).
searchQuerystring""crt.sh keyword or SQL-LIKE pattern (openai, %.dev, %.ai) to discover apices across the CT log.
newlyLaunchedWithinDaysint30Flag apices whose first cert was issued within the trailing N days. In search mode, also pre-filters to only day-zero apices. 0 disables.
maxDomainsint25Cap on apices enriched (after dedupe + filters). Max 100.
dropKnownBigbooltrueIn search mode, drop known-big infrastructure domains (google.com, shopify.com, cloudflare.com, …).
verifyEmailsbooltrueMX/DNS-validate the best contact email's domain.
concurrencyint3Apices/sites processed in parallel (1-6).
proxyConfigurationobject{}Optional; only if you hit IP rate limits.

Provide domains and/or searchQuery (at least one).

Output schema

One record per registrable apex that has a live, contactable website:

FieldTypeDescription
domainstringRegistrable apex (the newly-launched business domain).
companyWebsitestringhttps://<apex> (or www. variant if that's what served).
earliestCertDatestring|nullFirst TLS cert issuance date (YYYY-MM-DD) — the day-zero signal. null if crt.sh could not be reached.
latestCertDatestring|nullMost recent cert issuance date.
certCountintNumber of cert rows observed for this apex.
issuerTopstring|nullMost common certificate issuer (CA), short label.
subdomainsstring[]Discovered subdomains (api., docs., app., …) — a traction/infrastructure signal.
subdomainCountintCount of discovered subdomains.
newlyLaunchedboolTrue if earliestCertDate is within the window.
emailsstring[]MX/DNS-cleaned contact emails (host-domain emails ranked first).
emailVerifiedboolTrue if the best email's domain has live MX/DNS.
phonesstring[]NANP phones found on the site.
socialsobject{facebook, instagram, twitter, linkedin, youtube, tiktok, pinterest} profile URLs.
techStackstring[]Detected technologies (Stripe, Cloudflare, React, Klaviyo, …).
launchReadinessstringA-D launch-readiness grade.
launchLabelstringPlain-English explanation of the grade.
leadScorestringA-D signal-richness lead score.
hasContactboolTrue if any email/phone/social was found (the billing gate).

Apices with no live website or no contact are honestly dropped (not billed, not emitted).

Launch-readiness grades

  • A — Peak day-zero: first TLS cert within the window + verified website contact + subdomain traction. Newly launched and reachable.
  • B — Fresh launch: first cert within the wider recent band + contactable. Good newly-launched prospect.
  • C — Established but contactable: older apex (not newly launched) with a verified contact.
  • D — Weak: no website contact found; CT data only, not billed as a verified lead.

Pricing (pay-per-event)

EventPriceWhen charged
Startup Lead with Contact (primary)$0.008Once per apex that returns a real contact signal (email/phone/social).
Verified Startup Email$0.003When the lead yields an MX/DNS-validated email.
Newly-Launched Signal$0.001When the apex's first cert falls within your window.
Actor Start$0.0001One-time per run.

You only pay for leads with a real contact. Domains with no live site or no contact are dropped, not billed. Zero upstream compose cost (keyless crt.sh + each site's own public pages) → margin-positive from day one.

Real-run sample

All three records below are copied verbatim from actual live Apify runs on 2026-08-04 (subdomains truncated to the first few for readability). Nothing is fabricated.

1. Day-zero lead (the wedge) — searchQuery: "openai", newlyLaunchedWithinDays: 30

droplive.io — a domain whose first TLS certificate was issued 2026-07-08 (27 days ago), with an MX-verified contact email. This is the day-zero signal: a business that just stood up its domain.

{
"domain": "droplive.io",
"companyWebsite": "https://droplive.io",
"earliestCertDate": "2026-07-08",
"latestCertDate": "2026-07-08",
"certCount": 2,
"issuerTop": "Let's Encrypt",
"subdomains": ["corpus-openai-assistants-quickst--ben.eu1.dev.droplive.io"],
"subdomainCount": 1,
"newlyLaunched": true,
"emails": ["hi@droplive.io"],
"emailVerified": true,
"phones": [],
"socials": {},
"techStack": [],
"launchReadiness": "B",
"launchLabel": "Fresh launch — first cert within the wider recent band + contactable; good newly-launched prospect.",
"leadScore": "B",
"hasContact": true
}

2. Established domain, rich cert stats — domains: ["anthropic.com"]

anthropic.com — an older apex (first cert 2021) surfaced via explicit mode, showing the full cert-history rollup: 3,915 certs, 130 subdomains, top issuer, socials, tech stack. newlyLaunched: false (honest — it's not a day-zero lead).

{
"domain": "anthropic.com",
"companyWebsite": "https://anthropic.com",
"earliestCertDate": "2021-01-27",
"latestCertDate": "2026-08-03",
"certCount": 3915,
"issuerTop": "Let's Encrypt",
"subdomains": ["a-api.anthropic.com", "a-cdn.anthropic.com", "alignment.anthropic.com", "api.anthropic.com", "console.anthropic.com", "docs.anthropic.com"],
"subdomainCount": 130,
"newlyLaunched": false,
"emails": [],
"emailVerified": false,
"phones": [],
"socials": {
"linkedin": "https://www.linkedin.com/company/anthropicresearch",
"twitter": "https://x.com/AnthropicAI",
"youtube": "https://www.youtube.com/@anthropic-ai"
},
"techStack": ["Cloudflare", "HubSpot", "Webflow"],
"launchReadiness": "C",
"launchLabel": "Established but contactable — older apex (not newly launched) with a verified website contact.",
"leadScore": "C",
"hasContact": true
}

3. Verified decision-maker email + clean enrichment — domains: ["clerk.com"]

clerk.com — first cert 2022, 1,220 certs, 41 subdomains, MX-verified privacy@clerk.com, real socials (twitter resolved to the company profile x.com/clerk, not a tweet URL), leadScore A. (Note: Clerk's auth docs emit example emails like cameron@work.com / example@gmail.com — those are filtered out as doc placeholders, not billed.)

{
"domain": "clerk.com",
"companyWebsite": "https://clerk.com",
"earliestCertDate": "2022-11-30",
"latestCertDate": "2026-08-01",
"certCount": 1220,
"issuerTop": "Let's Encrypt",
"subdomains": ["accounts.clerk.com", "api.clerk.com", "beta.clerk.com", "cdn.discord.clerk.com", "dashboard.clerk.com", "docs.clerk.com"],
"subdomainCount": 41,
"newlyLaunched": false,
"emails": ["privacy@clerk.com", "cameron.walker@gmail.com"],
"emailVerified": true,
"phones": [],
"socials": {
"twitter": "https://x.com/clerk",
"linkedin": "https://www.linkedin.com/company/clerkinc",
"youtube": "https://www.youtube.com/@clerkdev"
},
"techStack": ["React"],
"launchReadiness": "C",
"launchLabel": "Established but contactable — older apex (not newly launched) with a verified website contact.",
"leadScore": "A",
"hasContact": true
}

Run cost for sample #1 (1 day-zero lead, 1 verified email, 1 newly-launched signal): $0.008 + $0.003 + $0.001 = $0.012. Domains with no live site or no contact are dropped, not billed.

Performance & cost

  • Latency: dominated by crt.sh (a free, per-IP-rate-limited service; ~5-15s per query, retried with backoff on 502/404) + the per-apex website fetch. A 25-apex run typically completes in 1-3 minutes.
  • Cost: at $0.008/lead + $0.003/verified-email, a run returning 10 contactable day-zero leads costs ~$0.11. No proxy, no compose cost.
  • Honest caps: crt.sh intermittently returns 502/404 under load → the Actor retries up to 5× with exponential backoff and, if a query still cannot be satisfied, degrades that apex's cert stats to null (the core verified-website-contact value still ships and is billed; only the CT launch signal is honestly missing). CT-log coverage begins ~2018 → earliestCertDate is trustworthy for apices first seen since then. Batch ≤100 apices (default 25) to stay well under crt.sh's per-IP capacity.

Troubleshooting

  • "No apices matched" / empty result — crt.sh is rate-limiting (502/404). Re-run in a few minutes, lower concurrency, or reduce maxDomains. The Actor retries automatically but a sustained rate-limit can still zero a run.
  • earliestCertDate: null on some leads — crt.sh could not be reached for that apex within the retry budget; the verified contact is still delivered. Re-run later to recover the launch signal.
  • No contact on a real domain — the apex's site has no discoverable email/phone/social on its public pages, or it's a parking/holding page. Dropped, not billed.
  • newlyLaunched: false on an old domain — expected; the apex's first cert is years old. Set newlyLaunchedWithinDays and use searchQuery (not explicit domains) to surface only day-zero apices.
  • Search query returns huge / times out — broad patterns like %.com are too large for crt.sh. Use narrower patterns (%.ai, %.dev, a keyword like saas).

Use cases

  • Vendor outreach on day zero: sell hosting, payments, analytics, dev-tools, agencies to businesses the week they incorporate online.
  • Newly-launched monitoring: run a searchQuery + newlyLaunchedWithinDays on a schedule to catch every new business in your niche as it stands up a site.
  • Investor / VC sourcing: a fresh cert + a verified contact + tech stack = a just-started company worth a look.
  • Competitor watch: pass an explicit domains list to freshness-score + enrich a known market.

MCP-ready

Designed as an agent tool: "find newly launched SaaS sites with a verified contact and Stripe detected" maps directly to searchQuery + newlyLaunchedWithinDays + the techStack field. Clean, normalized, deduped JSON output.