Domain Inspector - DNS, WHOIS, TLS and Tech Stack avatar

Domain Inspector - DNS, WHOIS, TLS and Tech Stack

Pricing

from $1.44 / 1,000 domains

Go to Apify Store
Domain Inspector - DNS, WHOIS, TLS and Tech Stack

Domain Inspector - DNS, WHOIS, TLS and Tech Stack

Check up to 500 domains a run, one row each: DNS records, the registrar and expiry date from RDAP (the registry-run successor to WHOIS), SSL certificate dates, redirects, security headers, robots.txt, sitemap and the tech the site runs. No API key. $1.50 per 1,000 domains.

Pricing

from $1.44 / 1,000 domains

Rating

0.0

(0)

Developer

Dami's Studio

Dami's Studio

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

2 days ago

Last modified

Share

Check a list of domains and get one row each with the DNS records, the registrar and expiry date, the SSL certificate and what the site runs: plus the redirect chain, the security headers, robots.txt, sitemap.xml and a short list of technology signals.

Registration data comes from RDAP, the registry-run replacement for the old WHOIS service. Not every registry publishes it, so on some country domains the registrar and the expiry date come back empty while the rest of the row is filled in. And rows are written only once every domain in the run has finished.

InputDomains or URLs, up to 500 per run
OutputOne row per domain: DNS records, registrar and dates, certificate and expiry, redirects, security headers, robots.txt, sitemap, technology signals
Ceiling500 domains per run
Account neededNone, and no API key
Price$1.50 per 1,000 domains, flat on every plan. The free plan's $5 a month covers about 3,300

🔍 What Domain Inspector does

Each domain gets four independent checks, and you can switch any of them off.

DNS resolves six record types, reporting per-record errors rather than collapsing them into one failure. RDAP asks the registry for the registration record. Certificates connect on port 443 and read the certificate, including whether Node's trust store accepts the chain. Web requests both http:// and https://, follows the redirects, and reads the final status, the title, the canonical URL, the Open Graph block, the security headers and the technology signals.

If robots.txt and sitemap.xml checking is on, both are fetched from whichever origin answered best, and any sitemap URLs declared in robots.txt come back with them.

Anything that went wrong without killing the row lands in warnings, with warningsCount beside it, so you can sort by how messy a domain is.

📋 What data you get from each domain

What you getField
A, AAAA, MX, NS, TXT and CAA recordsdns, plus dnsA and dnsAAAA up top
Registrar, statuses, nameservers, registration, update and expiry datesrdap, plus registrationExpiresAt up top
The certificate: issuer, subject, alternative names, dates, days left, trust verdicttls, plus tlsExpiresAt up top
Status, redirect chain, final URL, title, metadata and headers, per schemehttp, https, plus httpStatus, httpsStatus and title up top
Security headershttps.securityHeaders, http.securityHeaders
Technology signalstechnologies
robots.txt and sitemap.xml, with any sitemaps robots.txt declaresrobots, sitemap
What went wrong without stopping the rowwarnings, warningsCount

▶️ How to check DNS, registration and SSL certificates for a list of domains

  1. Open Domain Inspector and click Try for free.
  2. Paste your domains into Domains or URLs, one per line.
  3. Leave the four check boxes on for a full row, or switch off the ones you do not need.
  4. Click Start. Rows land once every domain has finished, so a long list stays quiet for a while.
  5. Download the dataset as JSON, CSV or Excel, or read it from the Apify API.

Start it with an empty list and you get one labelled sample row. It is not charged.

💰 How much does it cost to inspect domains?

$1.50 per 1,000 domains. Flat on every Apify plan, no volume tiers. The free plan's $5 a month covers about 3,300 domains. Switching checks off does not change the price.

You pay per domain that came back with something. A parked domain counts, because it still has DNS and registration data. A domain where every check came back empty does not, and neither does the sample row or an invalid entry.

If you set a maximum charge for a run, it stops at the last domain that fits, and the run's status says so.

📥 What you give it

{
"domains": ["github.com", "example.org", "https://news.ycombinator.com/"],
"maxConcurrency": 5,
"requestTimeoutSecs": 8,
"checkRdap": true,
"checkTls": true
}
FieldDefaultWhat it is
domainsnone; the box starts at github.comDomains or full URLs, one per line. A URL is reduced to its hostname. Up to 500.
domainnoneA single domain, added to the list above. Handy for a task or an API call with one target.
maxConcurrency5How many domains are inspected at once, 1 to 20. Keep it modest or DNS and the sites themselves start limiting you.
requestTimeoutSecs8The limit on each individual lookup, 3 to 20. There is a deadline on the whole domain as well.
maxRedirects5How many hops to follow, up to 10. Every hop is safety checked.
checkRdaptrueRegistration data from the registry.
checkWebtrueThe HTTP and HTTPS requests, the redirect chain, headers and page metadata.
checkTlstrueThe certificate on port 443.
checkRobotsAndSitemaptruerobots.txt and sitemap.xml.
proxyConfigurationoffOptional network settings for the web requests only. DNS, RDAP and the certificate check always connect directly.

example.com and www.example.com are two different domains here. Both get inspected, both get a row, and both count against your total. Deduplication only catches exact repeats.

The 500 limit is applied before duplicates are removed, and the single domain field is added at the end of the list. So a list of 500 with repeats in it can push your single domain out.

Setting maxRedirects to 0 does not switch redirects off. It falls back to 5.

📤 What you get back

The flat summary fields from a real row of 14 September 2026, with the nested blocks left out here because a full row runs to several thousand characters:

{
"ok": true,
"domain": "github.com",
"inspectedAt": "2026-09-14T05:42:44.663Z",
"httpsStatus": 200,
"httpStatus": 200,
"title": "GitHub · Change is constant. GitHub keeps you ahead. · GitHub",
"dnsA": ["140.82.114.3"],
"dnsAAAA": [],
"tlsExpiresAt": "2026-11-29T23:59:59.000Z",
"registrationExpiresAt": "2028-10-09T18:20:50.000Z",
"technologies": ["React", "Server: github.com"],
"warningsCount": 0
}

Under those sit the full blocks. From the same row, the certificate one:

"tls": {
"available": true,
"authorized": true,
"authorizationError": null,
"protocol": "TLSv1.3",
"subject": { "CN": "github.com" },
"issuer": { "C": "GB", "O": "Sectigo Limited", "CN": "Sectigo Public Server Authentication CA DV E36" },
"subjectAlternativeNames": ["github.com", "www.github.com"],
"validFrom": "2026-09-01T00:00:00.000Z",
"expiresAt": "2026-11-29T23:59:59.000Z",
"daysUntilExpiry": 76,
"serialNumber": "A59EBDB596751DB7F5C095079613953C",
"fingerprint256": "46:B6:01:EE:08:B4:18:CF:8A:3A:1E:..."
}
BlockWhat is in it
dnsa, aaaa, mx, ns, txt, caa, plus errors keyed by record type and hasData.
rdapregistrar, statuses, nameservers, registeredAt, updatedAt, expiresAt, handle. available: false when the registry publishes nothing.
tlsThe certificate, as above. authorized is Node's own trust verdict, and authorizationError says why when it is false.
http, httpsSeparate blocks per scheme: status, finalUrl, redirects, redirectCount, metadata, responseHeaders, securityHeaders, technologies.
robots, sitemappresent, status, finalUrl, and any sitemaps declared in robots.txt.
warningsPlain sentences naming anything that went wrong but did not stop the row.

The overview table in the Console shows the flat summary only. Switch to JSON or All fields for the nested blocks.

🧾 Reading the output

Three kinds of row can land in your dataset.

RowHow to spot itCharged
An inspected domainok: true and a domainyes
The sample row_sample: trueno
A diagnosticok: false and an errorCodeno

Filter on _sample being absent, not on ok. The sample row also carries ok: true.

CodeWhat it means
BAD_INPUTThe entry was not a domain: a bare IP address, a single word with no dot, or something that would not parse. The input field on the row shows what you sent.
INSPECTION_FAILEDEvery check came back empty. Usually an unregistered or misspelled domain.

A BAD_INPUT row has no domain field, only input, so it shows in the overview table as a line with the domain column blank.

💡 What people use it for

  • Watching certificate and registration expiry across a portfolio, on a schedule, sorted by daysUntilExpiry.
  • Auditing security headers across every domain a company owns, in one pass.
  • Checking a list of suppliers or acquisition targets before a first email: is the site live, who registered it, what is it built with.
  • Confirming a migration actually landed, by reading the redirect chain and the final URL.

From a raw domain list to people you can write to, in three runs:

  1. Run this on the list and keep the rows whose httpsStatus is 200.
  2. Paste those domain values into Contact Details Scraper's websites.
  3. Put the emails it finds into Email Verifier and keep the ones marked valid.

🚧 What it does not do

  • No JavaScript. The title, metadata and technology signals come from the HTML the server sent, so a site that renders everything client side looks emptier than it is.
  • Technology detection is a short list of signals, not a full fingerprinting suite. Treat technologies as a hint.
  • RDAP only. There is no fallback to the old WHOIS service, so registries that publish no RDAP come back with available: false.
  • 500 domains per run, counted before duplicates are removed.
  • Nothing is delivered until every domain has finished. A run that is aborted partway through writes no rows at all, so split very large lists.
  • A domain pointing at a private address gets its web and certificate checks skipped, with a warning saying so. DNS and registration still come back.
  • One certificate, on port 443. No other ports, no chain download, no revocation check.
  • No subdomain discovery. It inspects exactly what you give it.
  • No traffic, ranking or backlink figures.

🧭 Which site checker do you need?

If you wantUse
DNS, registration, certificates and headers for a list of domainsThis one
To crawl a site and read what is on its pagesWebsite Intelligence Crawler
A picture of the page rather than its headersWebsite Screenshot Generator
The emails, phones and socials a site publishesContact Details Scraper
The company behind a domain: revenue, headcount, addressCompany Firmographics Scraper
Traffic estimates and audience data for a domainSimilarweb Traffic and Rank Scraper
To check whether an email address is deliverableEmail Verifier

❓ Questions people ask

Do I need an API key to look up DNS and WHOIS data?

No. DNS, RDAP and certificates are all public lookups.

Why is the registrar empty on some domains?

That registry does not publish RDAP. There is no second source here, so the field stays empty rather than being guessed.

Can I check subdomains?

Only ones you list yourself. It does not go looking for them.

How long do 500 domains take?

It depends on Concurrent domains and how fast the targets answer; each domain has its own deadline, so one slow site cannot stall the run. Raise concurrency carefully.

Why did I get nothing back from a run I stopped early?

Rows are written once every domain has been inspected. Stop it before then and nothing is written.

Can I call it from code or connect it to an AI assistant?

Yes. The API tab has ready-made code for Python, JavaScript and the command line. For Claude, ChatGPT or another MCP client, connect https://mcp.apify.com/?tools=fetch-actor-details,dami_studio/domain-inspector. Either way the run happens on your Apify account at the same price.

DNS, RDAP and certificates are published for public lookup, and robots.txt and sitemap.xml are files sites publish deliberately. Apify's write-up on the legality of web scraping is a good starting point, and we are not lawyers.

🆘 If something breaks

Open the Issues tab on the actor page. Send the run ID and the domain that behaved oddly. The warnings array on the row usually explains it, and errorCode names it when the whole row failed.