Email Validator & Domain OSINT — WHOIS, DNS, SSL, Breach
Pricing
from $5.00 / 1,000 target checkeds
Email Validator & Domain OSINT — WHOIS, DNS, SSL, Breach
Check email syntax, disposable and role accounts, DNS/MX, WHOIS, SSL, SPF/DMARC/DKIM, public breach metadata, and company-name guesses. Supports bulk CSV, domain, email, and username inputs. No user API key. Active PPE: $0.001 start plus $0.005 per target after five free targets.
Pricing
from $5.00 / 1,000 target checkeds
Rating
0.0
(0)
Developer
Hojun Lee
Maintained by CommunityActor stats
0
Bookmarked
23
Total users
9
Monthly active users
10 hours ago
Last modified
Categories
Share
Email Validator & Domain OSINT
Check email syntax and public domain records for security and deliverability teams.
Quick start
Run this small input (observed under two minutes):
{"email":"hello@example.com","skipWhois":true,"skipSsl":true,"skipMxProbe":true}
One real email item from the 2026-10-05 run (a domain item also follows):
{"_type":"email","email":"hello@example.com","local_part":"hello","domain":"example.com","format_valid":true,"format_score":"valid","format_issues":[],"is_disposable":false,"disposable_email_check":false,"is_role_account":true,"is_free_email":false,"risk_score":20,"provider":null,"fetched_at":"2026-10-05T03:26:56.687243+00:00"}
_type distinguishes email and domain rows. format_valid and format_issues describe syntax; is_disposable, is_role_account, and is_free_email classify the address. risk_score is a heuristic, not proof of inbox delivery. The derived domain row has DNS and optional WHOIS, SSL, and breach fields.
Limits
Syntax and DNS cannot prove a mailbox exists. SMTP port 25, WHOIS, SSL, HIBP, and social sites may block or omit data. HIBP domain-breach metadata may be unavailable without upstream authorization; an empty breach list is not proof of no breach. Telegram alerts require your bot credentials. The password check is optional; do not submit a real password unintentionally.
Pricing
Active Apify contract verified 2026-10-05:
| Event | Price |
|---|---|
| Actor start (per GB memory, minimum one) | $0.001 |
| Email or domain target after first 5 targets | $0.005 per target |
The first five email/domain targets are exempt from target-checked (FREE_EVENTS = 5); an email and its derived domain are separate targets. The active contract has no username-scanned event. A future contract beginning 2026-10-09 schedules $0.01 per target and $0.01 per username; recheck the Store pricing tab then.
Use from AI agents (MCP)
Connect to Apify's official MCP server with an Apify token. Select gochujang/email-domain-osint, pass the Quick start JSON, and read the dataset items; no new gateway is needed.
More about Email & Domain OSINT
Email & Domain OSINT Toolkit is an all-in-one email domain OSINT and email intelligence actor that enriches any email address or domain with security, deliverability, and infrastructure data — all from free public APIs. Per email it returns RFC 5322 validation, disposable/role/free-email detection, MX reachability, a composite A–F risk score, and 20+ social platform presence checks. Per domain it returns full WHOIS, DNS records (A/AAAA/MX/TXT/SPF/DMARC/DKIM), SSL certificate status with days-to-expiry, and HIBP breach metadata.
This domain email lookup tool requires no user API key. The current event prices, five-target allowance, and start charge are listed in Pricing. It covers single targets, bulk CSV lists, and batch API inputs.
Why use Email & Domain OSINT Toolkit?
Cybersecurity reconnaissance, sales prospecting, and IT operations teams all run the same three lookups — WHOIS, DNS, SSL — plus a breach check. Commercial tools bundle these behind expensive monthly subscriptions. This actor provides the same email intelligence on-demand, billed only per target.
Key business use cases:
- Cybersecurity reconnaissance — Quick WHOIS + DNS + SSL triage on a suspicious domain during phishing or BEC investigations
- Pre-sales prospect verification — Confirm a lead's domain is real, active, and reputable before outreach; detect disposable and role accounts
- Email deliverability screening — Filter disposable, role-account, and catch-all domains before sending campaigns to protect sender reputation
- SSL certificate monitoring — Audit your domain portfolio for certs expiring within 30/60/90 days before they cause outages
- Security triage — Check whether your organization's domains appear in public breach datasets (HIBP)
- B2B lead qualification — Use
is_free_emailandis_role_accountflags to prioritize high-quality business email leads - Domain email lookup at scale — Bulk-enrich a list of 1,000 prospects for under $5
How to use Email & Domain OSINT Toolkit
- Open the actor on Apify Store and click Try for free
- Enter an
emailordomain, or use theemailsanddomainslists - For batch runs, use the
emailsanddomainsarrays to pass multiple targets at once - Toggle
skipWhoisorskipSslto speed up large batches where you only need DNS data - Optionally add a
samplePasswordto check it against HIBP Pwned Passwords (k-anonymity — only the first 5 chars of the SHA-1 hash are sent; plaintext never leaves the actor) - Click Start — results appear in the dataset within seconds
For a fast one-address run, use the Quick start input above. An email produces an email row and a derived domain row.
Input
| Parameter | Type | Default | Description |
|---|---|---|---|
emails | array | [] | Email addresses for email intelligence checks |
email | string | — | Single email (used when emails is empty) |
domains | array | [] | Domains for domain email lookup and OSINT enrichment |
domain | string | — | Single domain (used when domains is empty) |
samplePassword | string | — | Password to check against HIBP (k-anonymity, SHA-1 prefix only) |
skipWhois | boolean | false | Skip WHOIS (saves 1–3s per domain; use for speed in large cybersecurity reconnaissance batches) |
skipSsl | boolean | false | Skip SSL cert check (saves 0.5–2s per domain) |
Output
Email record
{"_type": "email","email": "jane@example.com","local_part": "jane","domain": "example.com","risk_score": 0,"risk_level": "low","format_valid": true,"format_score": "valid","is_disposable": false,"is_role_account": false,"is_free_email": false,"provider": null,"mx_reachable": true,"email_deliverability_score": 98,"catch_all_possible": false,"breach_count": 0,"fetched_at": "2026-06-10T03:30:00+00:00"}
Domain record
{"_type": "domain","domain": "example.com","company": "Internet Corporation for Assigned Names and Numbers","dns": {"a": ["93.184.216.34"],"mx": ["0 ."],"spf": ["v=spf1 -all"],"dmarc": ["v=DMARC1; p=reject;"],"dkim_probe": { "selector1": "v=DKIM1;k=rsa;p=MII..." }},"whois": {"registrar": "ICANN","creation_date": "1995-08-14T00:00:00","expiration_date": "2026-08-13T00:00:00","name_servers": ["a.iana-servers.net"]},"ssl": {"common_name": "*.example.com","issuer_cn": "DigiCert Global G3 TLS ECC SHA384 2020 CA1","not_after": "Mar 1 23:59:59 2026 GMT","days_until_expiry": 263},"hibp_breaches": [],"breach_count": 0}
Data fields
| Field | Type | Description |
|---|---|---|
risk_score | integer 0–100 | Composite email intelligence risk score (A–F grade) |
risk_level | string | low / medium / high based on risk score |
is_disposable | boolean | Matched against 250+ known disposable email provider domains |
is_role_account | boolean | admin@, noreply@, info@, etc. — not a real person |
is_free_email | boolean | Gmail, Yahoo, Outlook — useful for B2B email domain OSINT |
mx_reachable | boolean | MX record resolves and responds |
email_deliverability_score | integer | 0–100 deliverability confidence |
catch_all_possible | boolean | Domain accepts all addresses — bounce unpredictable |
domain_age_days | integer | Days since WHOIS creation_date — young domains = higher risk |
ssl.days_until_expiry | integer | Days before SSL cert expires — key for monitoring |
breach_count | integer | Number of HIBP breaches matching this domain |
breach_names | array | Names of known breaches |
latest_breach_date | string | ISO date of most recent breach |
Cost estimation
See the active-contract Pricing section above. The first five email/domain targets are exempt from the per-target event, but the Actor-start event still applies. Prices are scheduled to change on 2026-10-09.
FAQ
Is this legal for cybersecurity reconnaissance use? This actor queries only publicly available data: WHOIS records, public DNS, publicly visible SSL certificates, and HIBP's public breach database. All data sources are free-tier APIs with no authentication requirement. It does not attempt unauthorized access to any system. Users are responsible for ensuring their use complies with applicable laws (e.g. GDPR when processing personal data from emails).
How does the disposable email detection work? The actor checks the email's domain against a curated list of 250+ known disposable email providers (Mailinator, Guerrilla Mail, Temp-Mail, etc.) and applies pattern matching for subdomain variations. This is a static blocklist approach — newly created disposable domains may not yet be included.
Why is the HIBP per-account breach check not included?
The HIBP per-email lookup (/breachedaccount/) requires a paid API key ($3.95/month). This actor uses the free endpoints only: the k-anonymity Pwned Passwords API for password safety checks, and the public /breaches list for domain email lookup breach metadata. Per-account lookup is on the roadmap for a future version with optional API key input.
Disclaimer: This tool is intended for legitimate cybersecurity reconnaissance, IT security operations, and sales intelligence use cases. Do not use it to stalk, harass, or unlawfully surveil individuals. All data returned is publicly available through standard internet protocols. The author is not responsible for misuse.
Limitations
- WHOIS coverage varies by TLD. Some ccTLDs (
.cn,.jp) hide registrant info or require RDAP - DKIM probe tries 5 common selectors — custom selectors will not be detected
- HIBP per-email breach check (paid API) is not included; only domain-level breach metadata is returned
Related actors
- Crypto Address Sanctions Checker — On-chain equivalent for cybersecurity reconnaissance
- Wallet Label Lookup
- HTML Metadata Extractor
- Sitemap URL Discovery
A short review helps security and sales teams find this email domain OSINT tool: Leave a review on Apify Store
Keywords: email validation, domain OSINT, WHOIS lookup, DNS checker, SPF DMARC DKIM check, SSL certificate check, HIBP breach lookup, disposable email detector, email deliverability, MX record check, catch-all detection, bulk email verify, email risk score, domain intelligence