Bulk Domain Intelligence
Pricing
$3.00 / 1,000 domain checkeds
Bulk Domain Intelligence
Check registration, expiry, DNS, SPF/DMARC and SSL for up to 10,000 domains per run. One clean record per domain, no personal data.
Pricing
$3.00 / 1,000 domain checkeds
Rating
0.0
(0)
Developer
Brost Digital
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
2 days ago
Last modified
Categories
Share
Registration, DNS, email security and SSL data for thousands of domains in one run.
Paste a list of domains (or website addresses, or email addresses) and get one tidy row per domain that answers:
- Who registered it through, and when does it expire? Registrar, registration date, expiry date, days left, status codes, DNSSEC, name servers.
- Where is its email hosted, and is it protected? MX records and a best guess at the email provider (Google Workspace, Microsoft 365 and others), plus SPF and DMARC with the DMARC policy.
- Is its SSL certificate healthy? Issuer, valid-from and valid-to dates, days until expiry, the names it covers, and a plain label when something is wrong (expired, wrong name, self-signed, no HTTPS, and so on).
- Plus the raw DNS: A, AAAA, MX, NS, TXT, CAA and SOA records.
All data comes from open, public standards built for automated lookups: RDAP (the modern replacement for WHOIS, using the registries' own servers as listed by IANA), DNS (through Cloudflare's or Google's public resolver) and a normal TLS connection to the website.
Who it's for
- Domain investors and portfolio owners: watch expiry dates and registrars across many domains.
- IT and security teams: find SSL certificates about to expire, and domains missing SPF or DMARC or with a weak DMARC policy.
- Sales and lead research: see how old a company's domain is and which email provider it uses.
- SEO and website audits: check registration, DNS and HTTPS for a list of sites in one go.
Sample output
The Overview view, from a real run on 30 September 2026:
| Domain | Registrar | Registered on | Expires on | Days until expiry | Email provider | Has DMARC | SSL days left | Status |
|---|---|---|---|---|---|---|---|---|
| google.com | MarkMonitor Inc. | 1997-09-15 | 2028-09-14 | 714 | Google Workspace | true | 63 | ok |
| apify.com | Amazon Registrar, Inc. | 2009-06-02 | 2035-06-02 | 3166 | Google Workspace | true | 108 | ok |
| wikipedia.org | MarkMonitor Inc. | 2001-01-13 | 2027-01-13 | 104 | other | true | 33 | ok |
| bbc.co.uk | British Broadcasting Corporation | 1994-12-13 | 2034-12-13 | 2995 | Broadcom Email Security | true | 115 | ok |
| cira.ca | CIRA Default Registrar | 1998-02-05 | 2050-02-05 | 8528 | Microsoft 365 | true | 61 | ok |
| github.io | none | false | 31 | ok |
github.io has no registration data because .io has no RDAP service (see What it doesn't do). The dataset also has Registration, DNS and email security, SSL certificate and Errors and warnings views, and every field is available in JSON, CSV and Excel exports.
How to use
-
Open the Actor's Input tab.
-
Paste your domains into Domains, one per line. You can mix formats:
- plain domains:
example.com - website addresses:
https://www.example.com/pricing - email addresses:
jane@example.com
Each entry is reduced to its registrable domain using the Public Suffix List, so
https://shop.example.co.uk/cartbecomesexample.co.uk. Duplicates are removed, and entries that aren't domains are reported as error records (free). Up to 10,000 entries per run. - plain domains:
-
Optionally choose which checks to run (all three by default) and the other options below.
-
Click Start. When the run finishes, open the Output tab or export the dataset.
Example input (the same thing you'd send through the API):
{"domains": ["apify.com", "https://www.bbc.co.uk/news", "jane@example.org"],"checks": ["rdap", "dns", "ssl"],"followRegistrarRdap": true,"dnsResolver": "cloudflare","maxConcurrency": 20}
| Input | What it does | Default |
|---|---|---|
| Domains (required) | The domains, website addresses or email addresses to check. | none |
| Checks | Which data to collect: rdap (registration), dns (DNS and email security), ssl (certificate). Fields for checks you skip are left empty (null). | all three |
| Follow registrar RDAP | Some registries (for example .com and .net) keep only basic data and point to the registrar for more. When on, the registrar is asked too. If the two disagree, the registry's answer is used. | on |
| DNS resolver | cloudflare (1.1.1.1) or google (8.8.8.8). A fixed public resolver gives consistent results. | cloudflare |
| Max concurrency | How many domains are checked at the same time (1 to 100). Each registry's server also has its own, lower limit, so a large list from one registry is paced to what that registry allows. | 20 |
Understanding the output
Status: ok, partial or error
Every record has a status:
- ok: every check you asked for returned an answer.
- partial: at least one check returned an answer, but something failed. The record still has everything that worked, and
errorssays what didn't. - error: no check returned an answer, or the input wasn't a domain. Error records are free.
Errors versus warnings
errorslist checks that failed, for example the registry didn't answer in time, or one DNS lookup timed out. Any error makes the recordpartial(orerrorif nothing worked).warningslist extra data that couldn't be fetched while the main answer is fine. The usual one: the registry answered, but the registrar's server (asked for fuller data) didn't. A warning never changes the status.
Each entry has a check (rdap, dns, ssl or input), a short code and a plain-language message.
Empty (null) versus false or "none"
nullmeans we couldn't find out. Either you didn't ask for that check, or the lookup it depends on failed (anderrorssays which). For example, if the DMARC lookup times out,hasDmarcanddmarcPolicyarenull.false,"none"or an empty list means we checked and it isn't there. For example,hasDmarc: falsemeans the domain really has no DMARC record, andemailProvider: "none"means it has no mail servers (or explicitly says it accepts no email).
So hasDmarc: false is a finding you can act on, while hasDmarc: null means "try again".
A few more fields where the difference matters:
registered:falsemeans the registry says the domain isn't registered.nullmeans unknown: there's no RDAP service for that TLD, or the lookup failed.rdapAvailable:falsemeans the domain's TLD has no RDAP service, so there's no registration data (not an error).emailProvider: a best guess from the mail servers.othermeans the servers are in use but aren't a provider we recognize (often a company's own mail servers).daysUntilExpiryandsslDaysUntilExpiry: negative numbers mean it has already expired.
SSL problems (sslError)
The SSL check connects to the domain itself first and, only if that doesn't answer on the HTTPS port, to www. + the domain. sslHost tells you which one was checked. These are findings about the website, not failures of the check, so the record's status stays ok.
sslError | What it means |
|---|---|
| (empty) | The certificate is fine: in date, covers the host name, and is issued by a trusted authority. |
expired | The certificate's end date has passed. |
not-yet-valid | The certificate's start date is in the future. |
hostname-mismatch | The certificate is for a different name than the host we connected to. |
self-signed | The website signed its own certificate instead of getting one from a trusted authority. |
untrusted | The certificate chain doesn't lead to an authority that browsers trust. |
no-https | Neither the domain nor its www. address accepts HTTPS connections (or has no address at all). |
timeout | The server didn't complete the connection within 8 seconds, so we couldn't read a certificate. |
tls-error | The server answered but the secure connection failed for another reason. |
ipv6-only-not-checked | The host only has an IPv6 address; this version checks SSL over IPv4 only, so the certificate wasn't checked. It does not mean there is no HTTPS. |
Pricing
$3 per 1,000 domains checked ($0.003 per domain), charged per domain as its result is saved.
- You pay only for domains where at least one check returned an answer (status
okorpartial). - Free: entries that aren't valid domains, duplicates, and domains where every check failed (status
error). - You're never charged twice for the same domain in a run, even if the platform restarts it.
- If you set a spending limit for the run, the Actor stops cleanly when it's reached and the status message says how many domains weren't checked.
Personal data
This Actor never outputs personal data about domain owners. Registries sometimes return details of the registrant (the owner), and of administrative, technical or billing contacts, sometimes without redacting them. The Actor ignores all of them. The only contact data in the output is the registrar's (the company the domain was registered through): its name, IANA ID and abuse email address, which are published business contacts.
What it doesn't do
- No owner or contact details. See Personal data.
- Some country-code TLDs have no registration data. Registration data comes from RDAP, and not every registry offers RDAP yet. When a TLD isn't in IANA's list of RDAP services, the record has
rdapAvailable: falseand empty registration fields; the DNS and SSL checks still run. In our test this included .de, .io, .jp, .eu, .ch, .it, .se, .es, .us and .edu. The old WHOIS system isn't used. - Some registries limit how many lookups they answer. When a registry asks us to wait longer than a couple of minutes, the Actor respects that and stops asking it for the rest of the run; those domains come back
partialwith the errorrdap-rate-limited(DNS and SSL data are still there). In our test, the .au registry answered about 20 lookups and then asked us to wait a day. - SSL over IPv6 isn't checked. Hosts with only an IPv6 address get
ipv6-only-not-checked. - Subdomains are reduced to the registrable domain.
blog.example.comis checked asexample.com, for registration, DNS and SSL alike. - It doesn't watch domains by itself. Each run is a snapshot; for ongoing monitoring, schedule it (see below).
FAQ
How do I monitor domains over time?
Save your input as a task and add a schedule (for example, weekly) in Apify Console. Each run produces a fresh dataset you can compare, export, or send to a spreadsheet or webhook through Apify integrations. Useful fields to watch: daysUntilExpiry, sslDaysUntilExpiry, sslError, hasDmarc and dmarcPolicy.
Can I use it from my own code or an AI agent? Yes. Like any Apify Actor it can be started through the Apify API or the official API clients, with the same JSON input as above. Apify's MCP server can also make it available to AI agents. Results come back as a dataset in JSON, CSV or Excel.
How fast is it? In our test of 1,000 mixed domains (about 40% .com, plus .org, .net and more than a dozen country codes), the run took about 2.5 minutes on Apify, roughly 390 domains per minute, with all three checks on. Registration lookups set the pace: to stay within what registry servers allow, the Actor sends at most two requests at a time to each registry and backs off when a registry asks it to, so a very large list from a single TLD runs slower than a mixed one. The 10,000-entry limit keeps a run comfortably inside Apify's default one-hour run timeout.
What happens if the run is restarted or migrated? Progress is saved as the run goes. If the Apify platform restarts or moves the run, it continues where it left off: domains that already have a result aren't checked again, don't appear twice in the dataset, and aren't charged twice.
Why is the registrar data sometimes missing for a registered domain?
Either the TLD has no RDAP service (rdapAvailable: false), or the registry didn't answer or asked us to slow down (see errors). For .com and .net, basic data comes from the registry and fuller data from the registrar; if only the registrar fails, you still get the registry's data plus a warning.
Why does a domain show emailProvider: "other"?
Its mail servers aren't operated by a provider we recognize, often because the organization runs its own. The raw MX records are in mx.
What does the final status message mean?
At the end of each run you'll see a summary like "9,812 of 10,000 domains fully checked; 176 partial; 12 errors (see error records)". Filter the dataset by status, or open the Errors and warnings view, to see which domains need another look.