# Domain Lookup: Email Provider, SaaS Stack & DMARC (`digital_influx/domain-intel`) Actor

For any list of company domains: who hosts their email (Google Workspace, Microsoft 365...), which SaaS tools they verified in DNS (Atlassian, Zoom, HubSpot...), who sends their email (SPF), DMARC policy, DNS host and SSL expiry. Official DNS and TLS only.

- **URL**: https://apify.com/digital\_influx/domain-intel.md
- **Developed by:** [Bruno Petrelli](https://apify.com/digital_influx) (community)
- **Categories:** Lead generation, Developer tools, SEO tools
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $3.00 / 1,000 domain looked ups

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

## Domain Lookup: Email Provider, SaaS Stack & DMARC

Paste a list of company domains (or websites, or email addresses) and learn, for each one, **what the company runs on**, straight from its public DNS:

- **Email provider:** Google Workspace, Microsoft 365, Zoho, Proton, or a security gateway like Mimecast or Proofpoint.
- **SaaS tools verified in DNS:** companies publish a verification record for many tools they sign up for. We read them: Atlassian, Zoom, Slack, OpenAI, Anthropic, Figma, Miro, 1Password, DocuSign, HubSpot, Canva, Stripe and more.
- **Who sends email as the company (SPF):** Mailchimp, HubSpot, Salesforce Marketing Cloud, SendGrid, Amazon SES, Zendesk, Klaviyo...
- **Email security:** DMARC policy (none / quarantine / reject) and the SPF `all` rule.
- **DNS host:** Cloudflare, Amazon Route 53, Azure, GoDaddy...
- **SSL certificate:** issuer, organization (on OV/EV certificates), expiry date and days left.

**No scraping, no proxies, no browser.** Only standard DNS queries through the Actor's own resolver and the certificate every website presents on port 443. 5 domains took 6 seconds in our test.

### Use it for

- **Sales prospecting:** find companies on Microsoft 365 if you sell a Microsoft add-on, or HubSpot users if you sell a HubSpot integration. Combine with any list of domains.
- **Competitive and market research:** how many companies in a list use Zoom vs. another tool, or Google Workspace vs. Microsoft 365.
- **Email deliverability and security audits:** DMARC and SPF across all your clients' domains in one run; spot domains with no DMARC or with two SPF records.
- **SSL monitoring:** certificates expiring in the next 30 days across a portfolio of domains.
- **AI agents:** one plain JSON object per domain, callable through the Apify MCP server.

### Input

```json
{
  "domains": ["stripe.com", "https://www.userpilot.com", "jane@ottonova.de"],
  "includeSsl": true
}
```

### Output

One item per domain (real result for stripe.com on 2026-09-24, lists shortened):

```json
{
  "input": "stripe.com",
  "domain": "stripe.com",
  "status": "ok",
  "dnsResolves": true,
  "ipv4": ["198.137.150.111", "198.202.176.111"],
  "ipv6": false,
  "dnsProvider": "Amazon Route 53",
  "nameservers": ["ns-1087.awsdns-07.org", "ns-1882.awsdns-43.co.uk", "ns-423.awsdns-52.com", "ns-705.awsdns-24.net"],
  "mx": [{ "exchange": "aspmx.l.google.com", "priority": 10 }],
  "emailProvider": "Google Workspace",
  "acceptsEmail": true,
  "spfRecord": "v=spf1 ip4:198.2.180.60/32 ip4:13.111.2.227/32 include:spf1.stripe.com include:greenhouse-outbound-mail.stripe.com include:_spf.qualtrics.com ~all",
  "spfSenders": ["Qualtrics"],
  "spfAll": "softfail",
  "spfMultiple": false,
  "dmarcPolicy": "reject",
  "dmarcRecord": "v=DMARC1; p=reject; pct=100; fo=1; rua=mailto:dmarc-reports@stripe.com; ruf=mailto:dmarc-forensics@stripe.com;",
  "verifiedServices": ["Anthropic (Claude)", "Apple", "Atlassian", "Canva", "Cursor", "Docker", "DocuSign", "ElevenLabs", "Fastly", "Google Search Console", "HackerOne", "Linear", "LiveRamp", "Meta (Facebook) Business", "Microsoft 365", "OpenAI (ChatGPT)", "Postman", "Stripe", "Vercel", "Whimsical"],
  "txtRecords": 39,
  "sslIssuer": "DigiCert Inc",
  "sslSubject": "stripe.com",
  "sslOrganization": "Stripe, LLC",
  "sslValidFrom": "2026-08-17T00:00:00.000Z",
  "sslValidTo": "2026-11-12T23:59:59.000Z",
  "sslDaysLeft": 49,
  "checkedAt": "2026-09-24T00:00:00.000Z"
}
```

Field notes:

- `status` is `not_found` when the name does not exist in DNS.
- `verifiedServices` lists tools with a well-known verification record. A record shows the company verified the domain with that tool at some point; it may no longer be an active customer. Tokens that do not name their tool are ignored rather than guessed.
- `spfSenders` names the services behind `include:` entries; the company's own includes are not listed. `spfMultiple: true` means two SPF records, which breaks SPF.
- `acceptsEmail` is false when there is no MX record or a "null MX" (RFC 7505).
- `sslDaysLeft` can be negative: an expired certificate is still reported.

### Pricing

Pay per event: **one event per domain looked up**. Invalid inputs and duplicates are skipped for free. Set a maximum cost for the run and the Actor stops cleanly when it is reached.

### Good to know

- **No WHOIS / registration dates.** The registries' terms of use (Verisign for .com and .net, PIR for .org, Nominet for .uk, DENIC for .de and others) forbid high-volume automated queries, so this Actor does not query them.
- DNS answers are what the domain publishes at the moment of the run; TTLs and CDNs can make IP addresses vary between runs.
- Subdomains are looked up as given (`shop.example.com`), after removing `www.`.

### Support

A provider or a tool that should be recognized but isn't? Open an issue on the Actor's Issues tab with the domain. Issues get an answer within a few days.

# Actor input Schema

## `domains` (type: `array`):

One per line: stripe.com, a website URL (https://www.stripe.com/about) or an email address (jane@stripe.com). Duplicates are skipped.

## `includeSsl` (type: `boolean`):

Connects to port 443 of the domain to read its certificate issuer and expiry date.

## `maxConcurrency` (type: `integer`):

1 to 50.

## Actor input object example

```json
{
  "domains": [
    "stripe.com",
    "userpilot.com",
    "ottonova.de"
  ],
  "includeSsl": true,
  "maxConcurrency": 10
}
```

# Actor output Schema

## `results` (type: `string`):

No description

## `summary` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "domains": [
        "stripe.com",
        "userpilot.com",
        "ottonova.de"
    ]
};

// Run the Actor and wait for it to finish
const run = await client.actor("digital_influx/domain-intel").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "domains": [
        "stripe.com",
        "userpilot.com",
        "ottonova.de",
    ] }

# Run the Actor and wait for it to finish
run = client.actor("digital_influx/domain-intel").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "domains": [
    "stripe.com",
    "userpilot.com",
    "ottonova.de"
  ]
}' |
apify call digital_influx/domain-intel --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,digital_influx/domain-intel"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/n9uGeMhUl1mlF95Xo/builds/gh9SgrS5V3MiNxuPH/openapi.json
