Domain Intelligence & Enrichment — WHOIS, DNS, Email Provider avatar

Domain Intelligence & Enrichment — WHOIS, DNS, Email Provider

Pricing

from $2.10 / 1,000 domain enricheds

Go to Apify Store
Domain Intelligence & Enrichment — WHOIS, DNS, Email Provider

Domain Intelligence & Enrichment — WHOIS, DNS, Email Provider

Bulk domain enrichment and DNS check, one row per domain or email: email provider (Google Workspace, M365, Proofpoint), DMARC/SPF/DKIM, WHOIS/RDAP domain age and registrar, SSL type (EV/OV/DV), hosting ASN (AWS, Cloudflare), CDN, tech stack and a maturity score.

Pricing

from $2.10 / 1,000 domain enricheds

Rating

0.0

(0)

Developer

Brenton Keller

Brenton Keller

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

an hour ago

Last modified

Share

Domain Intelligence Check

What does a company run, and how seriously does it run it?

Bulk domain enrichment: a WHOIS lookup, a DNS check and an email-provider check in one row. Input domains, URLs or email addresses and get one row for each:

  • who handles the company's mail (Google Workspace, Microsoft 365, or a security gateway such as Proofpoint)
  • whether its domain is protected against spoofing (SPF, DMARC, DKIM)
  • how old the domain is and who registered it
  • what kind of TLS certificate it serves
  • what sits in front of its website, and which network hosts it (AWS, Google Cloud, Cloudflare, or the company's own network)
  • which SaaS tools it has verified ownership with

A maturity score adds those up, and maturity_signals gives the reasons for the score.

stripe.com 92 registered 31 years ago · Google Workspace · DMARC p=reject · EV certificate
accenture.com 100 registered 26 years ago · mail behind Proofpoint · DMARC p=reject · OV cert · CloudFront
notion.so 70 registered 11.5 years ago · DMARC p=quarantine · behind Cloudflare · no MX on this domain

Everything comes from public infrastructure: DNS (including an IP-to-ASN lookup), RDAP/WHOIS, a TLS handshake and one request to the homepage. That is why it is fast. 14 inputs took 1.5 s and there's no proxy to pay for.

Paste a column of emails

A lead list is usually a column of email addresses, so the actor accepts them directly:

  • jane@figma.com → figma.com
  • https://shop.acme.co.uk/x → acme.co.uk

Each line you submit gets its own row, with your original text in query, so the results join straight back onto your sheet.

Free mailbox domains (gmail.com, outlook.com, yahoo.com …) say nothing about a person's employer. They are returned with a note and not charged.

Output

FieldExampleNotes
maturity_score920–100. The weights are below.
maturity_signals["domain registered 31.1 years ago", "uses google workspace", "DMARC p=reject enforced", "EV certificate (organisation validated)"]
email_providergoogle_workspace, microsoft_365, proofpoint, self_hosted, no_mx …Read from MX records.
email_provider_kindmailbox · gateway · forwarder · self_hosted · none · unknown
email_securityenforced · partial · monitoring · spf_only · noneThe DMARC/SPF posture in one word.
dmarc_policy / dmarc_pctreject / 100
spf_allfail (-all), softfail (~all) …
spf_senders["google", "hubspot", "zendesk", "postmark"]Services allowed to send mail as the domain.
dkim_selectors_found["google", "s1", "s2"]
mta_stsenforce · testing · none · policy_unreachable · policy_invalid · absentWhether inbound mail must use TLS. Read from the published policy file, not just the DNS record, and checked against RFC 8461: the version, a mode, max_age, and at least one mx unless the mode is none. When the DNS record exists but the policy can't be used, mail servers ignore it. policy_unreachable means the policy file couldn't be fetched; policy_invalid means it was fetched but is incomplete.
tls_rpttruePublishes TLS failure reporting.
bimi / bimi_vmctrue / trueBrand logo in the inbox. bimi_vmc means a Verified Mark Certificate, a paid trademark check (paypal.com, cnn.com).
txt_verified_services["atlassian", "docusign", "microsoft_365", "slack", "stripe"]SaaS tools whose domain-verification record is published.
registered_on / domain_age_years1995-09-12 / 31.1The age of the domain, not the company. A bought domain carries its original date: cal.com reads 1997 and vercel.com 1999.
registrar / registrant_orgMarkMonitor Inc. / British Broadcasting CorporationThe organisation only, and only when it is published.
tls_valid / tls_cert_typetrue / EVThe type comes from the certificate's CA/Browser Forum policy ID, not a guess from the issuer name.
tls_issuer / tls_subject_org / tls_days_to_expiryDigiCert, Inc. / Stripe, LLC / 64
cdn / cdn_source / hosting_platformfastly / asn / shopifyThe CDN is read from response headers. If the headers name none, it falls back to the hosting network when that network is a CDN (nytimes.com sends no Fastly header but sits on Fastly). cdn_source says which. AWS addresses are never assumed to be CloudFront, because the same network also carries plain servers.
web_hostwww.toyota.co.jpThe host the website checks ran on. It falls back to www. when the bare domain has no address.
redirects_to_https / hsts_max_age / security_headers_presenttrue / 63072000 / [...]
hosting_provider / hosting_asn / hosting_asn_orgaws / 16509 / Amazon.com, Inc.The network serving the domain's IP address. own_network means the company announces its own address space (accenture.com on AS3573), which few companies do.
dns_provider / dnssec / has_ipv6 / caa_issuersaws_route53 / true / true / ["digicert.com"]
hintSet whenever an answer needs a caveat. Read it.
chargedtrueWhether this row was billed.

Raw records (mx_hosts, spf_record, dmarc_record, nameservers) are included, so you can check any classification yourself.

Read these before trusting a column

email_provider comes from MX, never from SPF. SPF lists who may send mail as the domain, which includes every marketing and transactional tool, not who receives it. A test version that read SPF reported Amazon SES as Pfizer's mail provider. SPF goes into spf_senders instead, where it's accurate and useful.

A security gateway is reported as the gateway. When MX points at Proofpoint, Mimecast or Cisco, the mailbox behind it is hidden. We return proofpoint / gateway rather than a guess. "Uses Proofpoint" is a strong signal in its own right: it implies an enterprise security budget.

no_mx is an answer, not an error. About 28% of a real prospect list has no MX record, and most of those domains still serve a website. Companies often split their web and mail domains: notion.so has no MX, and Notion's mail runs on makenotion.com.

No DKIM found isn't proof there's no DKIM. DKIM keys sit under selector names that can't be listed from DNS. The actor tries 12 common selectors and reports how many it checked. Add your own in extraDkimSelectors.

hosting_provider is whoever serves the address, not the origin behind it. With a CDN in front, it's the CDN: paypal.com shows fastly. It's read from the IPv4 address of the bare domain, so a site that serves only from www. may show a different network there. When the address has no BGP origin, or the ASN service returns something unexpected, the hosting columns are left empty and hint says which happened.

txt_verified_services means "verified at some point". A verification token can outlive the subscription.

Maturity score

ComponentPoints
Domain age ≥10 years / ≥5 / ≥220 / 15 / 8
Mail behind a security gateway / on Google Workspace or M365 / any other real mailbox15 / 12 / 6
DMARC enforced (quarantine or reject at 100%) / partial / monitoring only15 / 10 / 5
SPF ends in -all or ~all5
DKIM key found5
Valid TLS certificate10
… that is OV or EV (organisation validated)+10
HTTP redirects to HTTPS with HSTS / without HSTS10 / 5
Behind a CDN (by headers or hosting network)5
3 or more security headers5

MTA-STS and BIMI appear in maturity_signals but carry no points, so scores stay comparable with earlier runs.

If a component couldn't be measured (website down, registry publishes no dates), it scores 0 and is listed in maturity_unmeasured. A low score caused by missing data is visible as such.

Pricing

EventPriceWhen
domain-intel$0.003One domain enriched.

Not charged:

  • invalid input: a company name, a public suffix such as co.uk, an IP address, or a malformed domain such as stripe..com. Typos are rejected with the reason, never "corrected" into someone else's domain.
  • free mailbox domains
  • domains that don't resolve
  • any row that ends in an error, including a DNS lookup that every resolver refused or failed. That is reported as an error, never as "no MX" or "no DMARC"

Every row says whether it was charged in charged.

Coverage

  • Registration data comes from RDAP (the IANA bootstrap list) and falls back to WHOIS for TLDs without RDAP. In testing that included .io, .co, .so and .jp. Older .co.jp names publish the registrant organisation but no creation date.
  • Some registries publish no creation date at all (DENIC for .de, for example). Those rows have a null age and say so.
  • The registrant organisation is often redacted under GDPR. It is shown only when a real organisation is published. Privacy-service placeholders and personal names, emails and phone numbers are never returned.

Limitations

  • Email-provider detection matches known MX hostnames. A provider that doesn't appear in the list is reported as other, with the raw mx_hosts alongside so you can classify it yourself.