Domain Checker – WHOIS/RDAP, DNS, SSL & Email Security in Bulk avatar

Domain Checker – WHOIS/RDAP, DNS, SSL & Email Security in Bulk

Pricing

from $0.80 / 1,000 domain analyzeds

Go to Apify Store
Domain Checker – WHOIS/RDAP, DNS, SSL & Email Security in Bulk

Domain Checker – WHOIS/RDAP, DNS, SSL & Email Security in Bulk

Bulk domain lookup: registrar, creation and expiry dates (RDAP with WHOIS fallback), DNS records (A, MX, NS, TXT, CAA, SOA), SPF/DMARC/DKIM, email provider, SSL certificate expiry, HTTP redirects and HSTS, plus ready-made risk flags. One row per domain, no API keys.

Pricing

from $0.80 / 1,000 domain analyzeds

Rating

0.0

(0)

Developer

Cemal Atakli

Cemal Atakli

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

11 hours ago

Last modified

Categories

Share

Check hundreds or thousands of domains at once and get one clean row per domain covering registration (WHOIS/RDAP), DNS, email security, SSL certificate and website status:

  • Registration (WHOIS / RDAP): registrar, IANA ID, abuse contact, creation, update and expiry dates, days to expiry, domain age, status codes (clientTransferProhibited, hold…), name servers and DNSSEC. It uses the official RDAP protocol through the IANA bootstrap, and port-43 WHOIS for ccTLDs without RDAP (.com.tr, .co.jp, .it, .eu, .ru, .se, .be, .at, .cn…).
  • DNS records: A, AAAA, MX, NS, TXT, CAA and SOA, plus verification tokens (google, facebook, openai…).
  • Email security: SPF (parsed: all qualifier, includes, lookup count), DMARC (policy, sp, pct, rua), DKIM (about 25 common selectors probed), MTA-STS, TLS-RPT and BIMI. It also shows the email provider taken from MX/SPF (Google Workspace, Microsoft 365, Zoho, Yandex 360, Proton, Fastmail, GoDaddy…), any security gateway in front of it (Proofpoint, Mimecast, Barracuda, Cisco…) and sending services (Mailgun, SendGrid, HubSpot, Amazon SES…).
  • SSL/TLS certificate: a real handshake on port 443 returns issuer, subject, SANs, valid from/to, days left, TLS protocol and cipher, key type, and whether the certificate is valid, expired or self-signed, with the reason when validation fails.
  • Website (HTTP): final URL after redirects, the redirect chain, status code, page title, Server header, HSTS, whether http redirects to https, and the security headers present (CSP, X-Frame-Options…).
  • Ready-made flags such as domain_expiring_soon, ssl_expiring_soon, ssl_expired, missing_dmarc, dmarc_policy_none, missing_spf, spf_too_permissive, no_https_redirect, missing_hsts and not_registered. You can filter a spreadsheet by them straight away.

No API keys and no browser. It runs on public protocols only (RDAP, WHOIS, DNS, TLS, HTTP), so it is fast and cheap: $0.80 per 1,000 domains.

Use cases

  • Domain & SSL expiry monitoring. Schedule a daily or weekly run over your domain portfolio or your clients' domains, then filter on domain_expiring_soon / ssl_expiring_soon (thresholds are configurable) and send the result to Slack or email with an Apify integration.
  • Lead enrichment. Add registrar, domain age, email provider (Google Workspace vs Microsoft 365 vs others), security gateway, sending tools (HubSpot, Mailchimp, Salesforce…) and website title to a list of company domains. Useful for sales targeting and tech-based segmentation.
  • Email deliverability & security audit. Find every domain in a list with no DMARC, p=none, a permissive SPF (+all / ?all), several SPF records or more than 10 SPF lookups, or no DKIM under the common selectors.
  • Security / attack-surface review. Find expired, self-signed or mismatched certificates, old TLS (1.0/1.1), missing HSTS, no http→https redirect, missing CAA and unsigned DNSSEC.
  • Domain research & availability. registered: false means the registry has no record, so the name is probably available. You can also check registrar and age before buying, and spot domains in pendingDelete/redemption.
  • M&A, brand protection, IT inventory. Get one normalized table across gTLDs and ccTLDs instead of dozens of different WHOIS formats.

Input

The only required field is a list of domains. URLs and email addresses are accepted: https://www.example.com/page and jane@example.com both become example.com. Registration, DNS and email checks run on the registrable domain (the Public Suffix List handles co.uk, com.tr, com.au…). SSL and HTTP checks run on the exact host you entered.

{
"domains": ["apify.com", "github.com", "bbc.co.uk"],
"checkRegistration": true,
"checkDns": true,
"checkDkim": true,
"checkSsl": true,
"checkHttp": true,
"domainExpiryWarningDays": 30,
"sslExpiryWarningDays": 14
}

Other options:

  • Bulk input: a bulkText box (lines, commas or a whole CSV export) or a sourceFileUrl pointing to a TXT/CSV file, such as a published Google Sheet.
  • Toggles: turn each check on or off. For example, keep only SSL + HTTP for a certificate monitor.
  • Advanced: extra DKIM selectors, custom DNS resolvers, followRegistrarRdap (can add registrant organization/country for .com/.net when not redacted), includeRawWhois, maxDomains, maxConcurrency (default 10) and timeoutSecs.

Output

One dataset item per domain. It has flat columns for spreadsheets, plus nested registration, dns, ssl and http objects with the full details. The Overview and Email security tabs show the most useful columns as tables. Excerpt from a real run (full items in SAMPLE_OUTPUT.json):

domainregistrarexpiresdaysemail providerSPFDMARCSSL issuerSSL daysflags
apify.comAmazon Registrar, Inc.2035-06-023167Google Workspace-allrejectAmazon109–
github.comMarkMonitor Inc.2028-10-09740Microsoft 365~allquarantineSectigo61dnssec_unsigned
bbc.co.ukBritish Broadcasting Corporation2034-12-132996(gateway: Broadcom)~allrejectGlobalSign116dnssec_unsigned, dkim_not_found_common_selectors
trendyol.com.tr (WHOIS)ODTÜ Geliştirme Vakfı2029-07-081012Google Workspace (from SPF)~allmissingGoogle Trust Services38no_mx, missing_dmarc, …
expired.badssl.comMarkMonitor Inc.2027-04-07189Google WorkspacemissingmissingCOMODO-4188ssl_expired, ssl_invalid, …
thisdomaindoesnotexist-xyz987.com––––––––not_registered, dns_nxdomain, ssl_unavailable, website_unreachable
{
"domain": "apify.com",
"registered": true,
"registrar": "Amazon Registrar, Inc.",
"createdAt": "2009-06-02T17:14:10Z",
"expiresAt": "2035-06-02T17:14:10Z",
"daysToExpiry": 3167,
"emailProvider": "Google Workspace",
"spf": "-all",
"dmarcPolicy": "reject",
"dkimSelectors": "google",
"sslIssuer": "Amazon",
"sslDaysLeft": 109,
"finalUrl": "https://apify.com/",
"httpStatus": 200,
"flags": [],
"registration": { "registrarIanaId": "468", "status": ["client transfer prohibited"], "dnssec": true, "source": "rdap", "...": "..." },
"dns": { "a": ["3.160.57.105"], "mx": [{"priority": 1, "host": "aspmx.l.google.com"}], "email": { "spf": {"includes": ["_spf.google.com", "mailgun.org"]}, "dmarc": {"policy": "reject", "rua": ["mailto:dmarc-reports@apify.com"]}, "mtaSts": true, "sendingServices": ["Google Workspace", "Mailgun", "Amazon SES", "HubSpot"] }, "...": "..." },
"ssl": { "valid": true, "protocol": "TLSv1.3", "subject": "*.apify.com", "sans": ["*.apify.com", "apify.com"], "validTo": "2027-01-16T23:59:59Z", "...": "..." },
"http": { "finalUrl": "https://apify.com/", "status": 200, "title": "Apify: Marketplace of ready-to-run tools for AI", "hsts": {"maxAge": 15768000}, "httpRedirectsToHttps": true, "...": "..." }
}

Flags reference

FlagMeaning
not_registeredRegistry returned "not found". The name is probably available.
domain_expired / domain_expiring_soonExpiry date is in the past / within domainExpiryWarningDays (default 30)
domain_on_hold, domain_pending_deleteRegistry status contains hold / pendingDelete / redemption
dnssec_unsignedDelegation is not DNSSEC-signed
dns_nxdomain, no_a_recordDomain does not resolve / has no A/AAAA record
no_mx, missing_spf, spf_multiple_records, spf_too_permissive, spf_too_many_lookupsEmail sending/receiving configuration problems
missing_dmarc, dmarc_policy_noneNo DMARC record / DMARC only monitoring (p=none)
dkim_not_found_common_selectorsNo DKIM key under the ~25 common selectors (custom selectors can't be discovered)
missing_caaNo CAA record restricting which CAs may issue certificates
ssl_unavailable, ssl_expired, ssl_expiring_soon, ssl_invalid, ssl_self_signed, weak_tls_protocolCertificate problems (sslExpiryWarningDays, default 14)
website_unreachable, website_http_error, no_https_redirect, missing_hstsWebsite problems

Pricing

Pay per event. You pay only for what you use and there is no subscription.

EventPrice
Domain analyzed$0.0008 ($0.80 per 1,000 domains)
Actor start$0.0002 (once per run)

Invalid inputs and domains where every check failed are not charged. A lookup that comes back "not registered" is charged, because it is a real result (availability). Set a Maximum cost per run and the Actor stops cleanly when it is reached.

Compared with other Apify Store actors (per 1,000 domains, Sep 2026)

ActorPrice / 1,000What you get
This Actor$0.80RDAP/WHOIS + DNS + SPF/DMARC/DKIM + email provider + SSL + HTTP + flags
santamaria-automations/domain-whois-dns$3.00 (+$0.001/run)WHOIS + DNS
ryanclinton/whois-domain-lookup$3.00WHOIS
agenscrape/whois-domain-lookup$2.50WHOIS
automation-lab/domain-availability-checker$2.30 (+$0.035/run)availability
pink_comic/whois-domain-lookup$2.00WHOIS

Use with AI agents (Apify MCP)

This Actor works as a tool for AI agents such as Claude, ChatGPT, Cursor and LangChain through the Apify MCP server (https://mcp.apify.com). Add it to your MCP client and the agent can call it with {"domains": [...]}. It gets back compact, typed JSON with flat summary fields and explicit flags, so an agent can answer questions like these without parsing WHOIS text:

  • "Which of these 200 client domains expire in the next 30 days?"
  • "Does acme.com use Google Workspace or Microsoft 365, and is its DMARC enforced?"
  • "Audit our domains for missing DMARC, weak SPF and expiring certificates."

You can also call it directly over the API: POST https://api.apify.com/v2/acts/gazidev~domain-intel/run-sync-get-dataset-items?token=… with the input JSON returns the rows in one request, which suits small lists.

FAQ

Why RDAP instead of WHOIS? RDAP is the IETF/ICANN-standard replacement for WHOIS. It returns structured JSON, so dates and statuses are reliable, and it is mandatory for all gTLDs. For ccTLDs that publish no RDAP, the Actor falls back to the registry's port-43 WHOIS and parses the common fields.

Why is the registrant name empty? Since GDPR, registries and registrars redact personal registrant data. The Actor returns the registrant organization and country only when the registry publishes them. It does not collect personal data.

Some ccTLDs return few fields. Some registries publish very little: DENIC (.de) has no creation or expiry date, EURid (.eu) and nic.at (.at) have no expiry, and JPRS (.jp) has no registrar. Some block automated WHOIS entirely. In those cases the row still contains DNS, email, SSL and HTTP data, and registration.error explains what happened.

Is "not registered" a guarantee the domain is available? No. It means the registry has no record. Premium, reserved and blocked names can still be unavailable, so confirm with a registrar before buying.

How many DKIM selectors are checked? About 25 common ones (Google, Microsoft selector1/2, Mailchimp k1, default, s1…). You can add your own. DKIM has no discovery mechanism, so "not found" only means none of those selectors matched.

Rate limits? Requests are throttled per RDAP/WHOIS server and retried with backoff on 429/5xx. For very large single-ccTLD lists (for example 10,000 × .de), some WHOIS registries may throttle. Those rows still return all other checks.

How fast is it? About 1–2 domains per second at the default 512 MB / concurrency 10. For big lists, raise memory to 1–2 GB and concurrency to 20–30.