Domain Intelligence Enricher - DNS, Email, WHOIS, TLS & Tech avatar

Domain Intelligence Enricher - DNS, Email, WHOIS, TLS & Tech

Pricing

from $4.00 / 1,000 results

Go to Apify Store
Domain Intelligence Enricher - DNS, Email, WHOIS, TLS & Tech

Domain Intelligence Enricher - DNS, Email, WHOIS, TLS & Tech

Bulk-enrich domains with DNS records, email provider, SPF/DKIM/DMARC grade, registrar and domain age (RDAP), TLS certificate expiry, security headers and CMS/framework hints. No proxies, no API keys. Pay per domain.

Pricing

from $4.00 / 1,000 results

Rating

0.0

(0)

Developer

HerbCode LLC

HerbCode LLC

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

3 days ago

Last modified

Categories

Share

Domain Intelligence Enricher - DNS, Email Security, WHOIS/RDAP, TLS and Tech Stack

Paste a list of domains (or URLs, or email addresses) and get back a complete technical profile of each one in a single row: who hosts their email, whether their SPF/DKIM/DMARC are set up properly (with an A-F grade), when the domain was registered and when it expires, whether the TLS certificate is valid and how long it has left, what the website runs on, and whether the domain is parked or dead.

Everything comes from authoritative, public sources only - DNS, the registries' RDAP services (the modern WHOIS), the TLS handshake and the site's own homepage. No proxies, no API keys, no rate-limited third-party services, so it is fast (about 50 domains per minute per run at default concurrency) and cheap.

What you can do with it

  • Lead qualification / CRM enrichment - email provider (Google Workspace vs Microsoft 365 vs self-hosted) and tech stack (Shopify, WordPress, HubSpot, Next.js...) are strong firmographic signals. Feed a list of prospect domains, get back segments.
  • Cold-email list hygiene - drop domains that do not accept mail (email.acceptsMail = false), are parked, or do not resolve, before you send.
  • Email deliverability and security audits - SPF -all vs ~all, DMARC policy and reporting addresses, DKIM selectors present, MTA-STS, BIMI, DNSSEC. Sell or embed the A-F grade.
  • Domain portfolio monitoring - expiry dates, registrar changes, EPP status locks, certificate expiry (tls.daysToExpiry) across hundreds of domains on a schedule.
  • Security research / attack surface - nameservers, hosting provider hints, security headers (HSTS, CSP, X-Frame-Options...), certificate SANs.
  • Domain investing - rdap.registered = false plus no DNS means the name is probably available; domainAgeDays and registrar for the rest.

Input

FieldTypeDefaultNotes
domainsarray of stringsrequiredDomains, URLs or email addresses. https://www.example.com/x and jane@example.com both become example.com. Duplicates removed.
checkDnsbooleantrueA, AAAA, CNAME, MX, NS, TXT.
checkEmailbooleantrueProvider, SPF, DMARC, DKIM, MTA-STS, BIMI, grade.
checkRdapbooleantrueRegistrar, dates, status, nameservers, DNSSEC via RDAP.
checkTlsbooleantrueCertificate on port 443.
checkHttpbooleantrueHomepage fetch: redirects, headers, title, technologies.
dkimSelectorsarray20 common selectorsSelectors probed at <selector>._domainkey.<domain>.
dnsResolvercloudflare / google / systemcloudflareDNS-over-HTTPS resolver.
concurrencyinteger8Domains in parallel (max 25).
timeoutSecsinteger12Per-request timeout.
maxDomainsinteger0 (all)Hard cap on rows = hard cap on cost.

Example input:

{
"domains": ["apify.com", "https://www.github.com/apify", "jane@stripe.com", "example.org"],
"checkHttp": true
}

Output

One dataset item per domain. Sections you turned off are null; individual check failures are listed in errors instead of failing the row.

{
"domain": "apify.com",
"input": "apify.com",
"resolves": true,
"dns": {
"a": ["13.32.99.86", "13.32.99.116"],
"aaaa": [],
"cname": [],
"mx": [{ "priority": 1, "exchange": "aspmx.l.google.com" }, { "priority": 5, "exchange": "alt1.aspmx.l.google.com" }],
"ns": ["ns-1099.awsdns-09.org", "ns-1745.awsdns-26.co.uk"],
"txt": ["v=spf1 include:_spf.google.com include:servers.mcsv.net -all", "google-site-verification=..."]
},
"email": {
"acceptsMail": true,
"provider": "Google Workspace",
"mxHosts": ["aspmx.l.google.com", "alt1.aspmx.l.google.com"],
"spf": { "present": true, "record": "v=spf1 include:_spf.google.com include:servers.mcsv.net -all", "allMechanism": "-all", "includes": ["_spf.google.com", "servers.mcsv.net"], "lookups": 2 },
"dmarc": { "present": true, "record": "v=DMARC1; p=reject; rua=mailto:dmarc@apify.com", "policy": "reject", "subdomainPolicy": "reject", "pct": 100, "rua": ["mailto:dmarc@apify.com"], "ruf": [] },
"dkim": { "selectorsChecked": 20, "selectorsFound": ["google"], "wildcard": false },
"mtaSts": true,
"bimi": true,
"security": { "score": 100, "grade": "A" }
},
"rdap": {
"registered": true,
"registrar": "Amazon Registrar, Inc.",
"registrarIanaId": "468",
"registrantOrg": null,
"registrantCountry": null,
"createdAt": "2009-06-02T14:52:47Z",
"updatedAt": "2025-05-03T01:18:23Z",
"expiresAt": "2035-06-02T14:52:47Z",
"status": ["client transfer prohibited"],
"nameservers": ["ns-1099.awsdns-09.org", "ns-1745.awsdns-26.co.uk"],
"dnssec": true,
"source": "https://rdap.verisign.com/com/v1/domain/apify.com"
},
"domainAgeDays": 6320,
"tls": {
"reachable": true,
"valid": true,
"error": null,
"protocol": "TLSv1.3",
"subject": "apify.com",
"issuer": "Amazon",
"validFrom": "2026-01-16T00:00:00.000Z",
"validTo": "2027-01-16T23:59:59.000Z",
"daysToExpiry": 117,
"sans": ["apify.com", "*.apify.com"],
"fingerprint256": "AB:CD:..."
},
"http": {
"reachable": true,
"status": 200,
"finalUrl": "https://apify.com/",
"redirected": false,
"finalHost": "apify.com",
"responseMs": 412,
"server": "AmazonS3",
"poweredBy": null,
"contentType": "text/html; charset=utf-8",
"title": "Apify: Full-stack web scraping and data extraction platform",
"metaDescription": "Cloud platform for web scraping, browser automation, and data for AI...",
"generator": null,
"language": "en",
"technologies": ["AWS CloudFront", "HubSpot", "Next.js", "Google Tag Manager", "Intercom"],
"securityHeaders": { "strictTransportSecurity": "max-age=63072000", "contentSecurityPolicy": null, "xFrameOptions": "SAMEORIGIN", "xContentTypeOptions": "nosniff", "referrerPolicy": null, "permissionsPolicy": null },
"parked": false
},
"errors": [],
"checkedAt": "2026-09-21T17:02:11.104Z"
}

The Overview tab shows the most useful columns (provider, email grade, DMARC policy, registrar, registered/expiry dates, TLS days left, HTTP status, title, technologies); the full nested record is available as JSON, CSV (flattened), Excel or via the API.

Email security grade

SignalPoints
SPF record present20 (+10 for -all, +5 for ~all)
DMARC record present20 (+20 for p=reject, +12 for p=quarantine)
At least one DKIM selector found15
MTA-STS policy record10
DNSSEC signed (from RDAP)5

A = 85+, B = 65+, C = 45+, D = 25+, F below.

Pricing

Pay per event:

EventPriceWhat it means
Actor start$0.005Once per run.
domain-result$0.004 (= $4 per 1,000 domains)One per domain written to the dataset, regardless of how many checks you enable.

1,000 domains with every check enabled cost about $4.01. Comparable single-purpose Actors charge $3 per 1,000 for DNS + WHOIS only; this one adds email security grading, TLS, HTTP and technology detection in the same row.

Limits and notes

  • RDAP coverage: all gTLDs (.com, .net, .org, .io, .ai, .app, ...) and most ccTLDs publish RDAP. A few ccTLDs (for example .de, .es, .au use RDAP; .ch, .ru, .jp currently do not) return errors: ["rdap: ..."] and rdap: null. Registrant name/org/country is usually redacted for privacy.
  • DKIM can only be detected for selectors you probe; the default list covers Google, Microsoft, Mailchimp/Mandrill, Postmark, Proton, Fastmail, Zendesk and common custom names. Add your own in dkimSelectors.
  • Technology detection is fingerprint-based (script URLs, markup, headers) - it identifies common CMSs, frameworks, analytics and hosting, not every library on the page.
  • email.acceptsMail means MX records exist; it does not perform SMTP mailbox verification.
  • Uses DNS-over-HTTPS (Cloudflare or Google) with a fallback to the system resolver, so results are consistent regardless of where the Actor runs.

FAQ

Is this allowed? Yes. DNS, RDAP and TLS are public protocols designed to be queried; the HTTP check fetches only the homepage with a normal browser-like request. No personal data is collected beyond what registries publish (and they redact most of it).

How fast is it? Each domain needs ~30 small requests, run in parallel. Expect roughly 50-100 domains per minute at concurrency 8-16.

Can I run it from an AI agent? Yes - use it through the Apify MCP server or the API; the flat top-level fields (resolves, email.provider, email.security.grade, rdap.expiresAt, tls.daysToExpiry, http.technologies) are designed to be easy to reason over.