Bulk Domain Intelligence avatar

Bulk Domain Intelligence

Pricing

$3.00 / 1,000 domain checkeds

Go to Apify Store
Bulk Domain Intelligence

Bulk Domain Intelligence

Check registration, expiry, DNS, SPF/DMARC and SSL for up to 10,000 domains per run. One clean record per domain, no personal data.

Pricing

$3.00 / 1,000 domain checkeds

Rating

0.0

(0)

Developer

Brost Digital

Brost Digital

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

2 days ago

Last modified

Categories

Share

Registration, DNS, email security and SSL data for thousands of domains in one run.

Paste a list of domains (or website addresses, or email addresses) and get one tidy row per domain that answers:

  • Who registered it through, and when does it expire? Registrar, registration date, expiry date, days left, status codes, DNSSEC, name servers.
  • Where is its email hosted, and is it protected? MX records and a best guess at the email provider (Google Workspace, Microsoft 365 and others), plus SPF and DMARC with the DMARC policy.
  • Is its SSL certificate healthy? Issuer, valid-from and valid-to dates, days until expiry, the names it covers, and a plain label when something is wrong (expired, wrong name, self-signed, no HTTPS, and so on).
  • Plus the raw DNS: A, AAAA, MX, NS, TXT, CAA and SOA records.

All data comes from open, public standards built for automated lookups: RDAP (the modern replacement for WHOIS, using the registries' own servers as listed by IANA), DNS (through Cloudflare's or Google's public resolver) and a normal TLS connection to the website.

Who it's for

  • Domain investors and portfolio owners: watch expiry dates and registrars across many domains.
  • IT and security teams: find SSL certificates about to expire, and domains missing SPF or DMARC or with a weak DMARC policy.
  • Sales and lead research: see how old a company's domain is and which email provider it uses.
  • SEO and website audits: check registration, DNS and HTTPS for a list of sites in one go.

Sample output

The Overview view, from a real run on 30 September 2026:

DomainRegistrarRegistered onExpires onDays until expiryEmail providerHas DMARCSSL days leftStatus
google.comMarkMonitor Inc.1997-09-152028-09-14714Google Workspacetrue63ok
apify.comAmazon Registrar, Inc.2009-06-022035-06-023166Google Workspacetrue108ok
wikipedia.orgMarkMonitor Inc.2001-01-132027-01-13104othertrue33ok
bbc.co.ukBritish Broadcasting Corporation1994-12-132034-12-132995Broadcom Email Securitytrue115ok
cira.caCIRA Default Registrar1998-02-052050-02-058528Microsoft 365true61ok
github.iononefalse31ok

github.io has no registration data because .io has no RDAP service (see What it doesn't do). The dataset also has Registration, DNS and email security, SSL certificate and Errors and warnings views, and every field is available in JSON, CSV and Excel exports.

How to use

  1. Open the Actor's Input tab.

  2. Paste your domains into Domains, one per line. You can mix formats:

    • plain domains: example.com
    • website addresses: https://www.example.com/pricing
    • email addresses: jane@example.com

    Each entry is reduced to its registrable domain using the Public Suffix List, so https://shop.example.co.uk/cart becomes example.co.uk. Duplicates are removed, and entries that aren't domains are reported as error records (free). Up to 10,000 entries per run.

  3. Optionally choose which checks to run (all three by default) and the other options below.

  4. Click Start. When the run finishes, open the Output tab or export the dataset.

Example input (the same thing you'd send through the API):

{
"domains": ["apify.com", "https://www.bbc.co.uk/news", "jane@example.org"],
"checks": ["rdap", "dns", "ssl"],
"followRegistrarRdap": true,
"dnsResolver": "cloudflare",
"maxConcurrency": 20
}
InputWhat it doesDefault
Domains (required)The domains, website addresses or email addresses to check.none
ChecksWhich data to collect: rdap (registration), dns (DNS and email security), ssl (certificate). Fields for checks you skip are left empty (null).all three
Follow registrar RDAPSome registries (for example .com and .net) keep only basic data and point to the registrar for more. When on, the registrar is asked too. If the two disagree, the registry's answer is used.on
DNS resolvercloudflare (1.1.1.1) or google (8.8.8.8). A fixed public resolver gives consistent results.cloudflare
Max concurrencyHow many domains are checked at the same time (1 to 100). Each registry's server also has its own, lower limit, so a large list from one registry is paced to what that registry allows.20

Understanding the output

Status: ok, partial or error

Every record has a status:

  • ok: every check you asked for returned an answer.
  • partial: at least one check returned an answer, but something failed. The record still has everything that worked, and errors says what didn't.
  • error: no check returned an answer, or the input wasn't a domain. Error records are free.

Errors versus warnings

  • errors list checks that failed, for example the registry didn't answer in time, or one DNS lookup timed out. Any error makes the record partial (or error if nothing worked).
  • warnings list extra data that couldn't be fetched while the main answer is fine. The usual one: the registry answered, but the registrar's server (asked for fuller data) didn't. A warning never changes the status.

Each entry has a check (rdap, dns, ssl or input), a short code and a plain-language message.

Empty (null) versus false or "none"

  • null means we couldn't find out. Either you didn't ask for that check, or the lookup it depends on failed (and errors says which). For example, if the DMARC lookup times out, hasDmarc and dmarcPolicy are null.
  • false, "none" or an empty list means we checked and it isn't there. For example, hasDmarc: false means the domain really has no DMARC record, and emailProvider: "none" means it has no mail servers (or explicitly says it accepts no email).

So hasDmarc: false is a finding you can act on, while hasDmarc: null means "try again".

A few more fields where the difference matters:

  • registered: false means the registry says the domain isn't registered. null means unknown: there's no RDAP service for that TLD, or the lookup failed.
  • rdapAvailable: false means the domain's TLD has no RDAP service, so there's no registration data (not an error).
  • emailProvider: a best guess from the mail servers. other means the servers are in use but aren't a provider we recognize (often a company's own mail servers).
  • daysUntilExpiry and sslDaysUntilExpiry: negative numbers mean it has already expired.

SSL problems (sslError)

The SSL check connects to the domain itself first and, only if that doesn't answer on the HTTPS port, to www. + the domain. sslHost tells you which one was checked. These are findings about the website, not failures of the check, so the record's status stays ok.

sslErrorWhat it means
(empty)The certificate is fine: in date, covers the host name, and is issued by a trusted authority.
expiredThe certificate's end date has passed.
not-yet-validThe certificate's start date is in the future.
hostname-mismatchThe certificate is for a different name than the host we connected to.
self-signedThe website signed its own certificate instead of getting one from a trusted authority.
untrustedThe certificate chain doesn't lead to an authority that browsers trust.
no-httpsNeither the domain nor its www. address accepts HTTPS connections (or has no address at all).
timeoutThe server didn't complete the connection within 8 seconds, so we couldn't read a certificate.
tls-errorThe server answered but the secure connection failed for another reason.
ipv6-only-not-checkedThe host only has an IPv6 address; this version checks SSL over IPv4 only, so the certificate wasn't checked. It does not mean there is no HTTPS.

Pricing

$3 per 1,000 domains checked ($0.003 per domain), charged per domain as its result is saved.

  • You pay only for domains where at least one check returned an answer (status ok or partial).
  • Free: entries that aren't valid domains, duplicates, and domains where every check failed (status error).
  • You're never charged twice for the same domain in a run, even if the platform restarts it.
  • If you set a spending limit for the run, the Actor stops cleanly when it's reached and the status message says how many domains weren't checked.

Personal data

This Actor never outputs personal data about domain owners. Registries sometimes return details of the registrant (the owner), and of administrative, technical or billing contacts, sometimes without redacting them. The Actor ignores all of them. The only contact data in the output is the registrar's (the company the domain was registered through): its name, IANA ID and abuse email address, which are published business contacts.

What it doesn't do

  • No owner or contact details. See Personal data.
  • Some country-code TLDs have no registration data. Registration data comes from RDAP, and not every registry offers RDAP yet. When a TLD isn't in IANA's list of RDAP services, the record has rdapAvailable: false and empty registration fields; the DNS and SSL checks still run. In our test this included .de, .io, .jp, .eu, .ch, .it, .se, .es, .us and .edu. The old WHOIS system isn't used.
  • Some registries limit how many lookups they answer. When a registry asks us to wait longer than a couple of minutes, the Actor respects that and stops asking it for the rest of the run; those domains come back partial with the error rdap-rate-limited (DNS and SSL data are still there). In our test, the .au registry answered about 20 lookups and then asked us to wait a day.
  • SSL over IPv6 isn't checked. Hosts with only an IPv6 address get ipv6-only-not-checked.
  • Subdomains are reduced to the registrable domain. blog.example.com is checked as example.com, for registration, DNS and SSL alike.
  • It doesn't watch domains by itself. Each run is a snapshot; for ongoing monitoring, schedule it (see below).

FAQ

How do I monitor domains over time? Save your input as a task and add a schedule (for example, weekly) in Apify Console. Each run produces a fresh dataset you can compare, export, or send to a spreadsheet or webhook through Apify integrations. Useful fields to watch: daysUntilExpiry, sslDaysUntilExpiry, sslError, hasDmarc and dmarcPolicy.

Can I use it from my own code or an AI agent? Yes. Like any Apify Actor it can be started through the Apify API or the official API clients, with the same JSON input as above. Apify's MCP server can also make it available to AI agents. Results come back as a dataset in JSON, CSV or Excel.

How fast is it? In our test of 1,000 mixed domains (about 40% .com, plus .org, .net and more than a dozen country codes), the run took about 2.5 minutes on Apify, roughly 390 domains per minute, with all three checks on. Registration lookups set the pace: to stay within what registry servers allow, the Actor sends at most two requests at a time to each registry and backs off when a registry asks it to, so a very large list from a single TLD runs slower than a mixed one. The 10,000-entry limit keeps a run comfortably inside Apify's default one-hour run timeout.

What happens if the run is restarted or migrated? Progress is saved as the run goes. If the Apify platform restarts or moves the run, it continues where it left off: domains that already have a result aren't checked again, don't appear twice in the dataset, and aren't charged twice.

Why is the registrar data sometimes missing for a registered domain? Either the TLD has no RDAP service (rdapAvailable: false), or the registry didn't answer or asked us to slow down (see errors). For .com and .net, basic data comes from the registry and fuller data from the registrar; if only the registrar fails, you still get the registry's data plus a warning.

Why does a domain show emailProvider: "other"? Its mail servers aren't operated by a provider we recognize, often because the organization runs its own. The raw MX records are in mx.

What does the final status message mean? At the end of each run you'll see a summary like "9,812 of 10,000 domains fully checked; 176 partial; 12 errors (see error records)". Filter the dataset by status, or open the Errors and warnings view, to see which domains need another look.