# Bulk WHOIS DNS SSL Lookup — Domain Enrichment (`ingenious_quip_bxq/whois-dns-ssl-lookup`) Actor

Batch WHOIS, DNS (A/AAAA/MX/NS/TXT) and TLS cert lookup for domain lists — 256 MB default; failed domains free by default. One row per domain: registrar/dates + DNS + SSL days-left; no paid WHOIS API keys.

- **URL**: https://apify.com/ingenious\_quip\_bxq/whois-dns-ssl-lookup.md
- **Developed by:** [新世紀書僮](https://apify.com/ingenious_quip_bxq) (community)
- **Categories:** SEO tools, Developer tools, Automation
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $2.00 / 1,000 domain looked ups

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

## WHOIS DNS SSL Lookup — Batch Domain Enrichment

**Look up WHOIS, DNS records and SSL certificates for a list of domains — structured enrichment for knowledge-base hygiene, low memory, failed domains free by default.**
Paste domains (or URLs). For each host the Actor can query public WHOIS, resolve A/AAAA/MX/NS/TXT, and read the TLS leaf certificate (issuer, validity, days left). Default memory: **256 MB**. No browser, no paid WHOIS API keys.

### What you get

- 📇 **WHOIS** — registrar, created, expires (when the public server returns them)
- 🌐 **DNS** — A, AAAA, MX, NS, TXT (selectable)
- 🔒 **SSL / TLS** — issuer, subject, validFrom / validTo, daysLeft, SAN
- 📦 **Structured output** — one dataset row per domain + flat overview columns
- 🧾 **SUMMARY** — ok / partial / error counts, duration, peak memory
- 💸 **Failed domains free by default** — only `ok` / `partial` rows are charged unless you turn on `chargeFailedDomains`
- 🪶 **Light** — no browser; WHOIS + DNS + stdlib SSL; **256 MB** default

### Measured results

Local + private cloud benches (2026-09-30 Asia/Taipei). PPE locked from measured cost — see `docs/PRICING.md`.

| Test | Result |
|---|---|
| Local smoke: example.com + google.com | **2/2 ok** in 0.7 s, peak **80 MB**; charged 2 |
| Local: example.com + nonexistent `.test` | ok 1 charged, **error 1 free** (NXDOMAIN) |
| Cloud smoke `f9qom9UMGniuQOtwr` (2 domains, 512 MB, build 0.1.1) | **SUCCEEDED**; peak **90 MB**; settled **$0.000280** |
| Cloud bench `LsndNzP5DyvhbHi4b` (50 domains) | **SUCCEEDED**; 46 ok / 4 partial; peak **94 MB**; settled **$0.001584** (~$0.000032 / domain) |
| Cloud bench `8fCgMF187IGXYhbhV` (100 domains) | **SUCCEEDED**; 92 ok / 8 partial; peak **95 MB**; settled **$0.002725** (~$0.000027 / domain) |

### Use cases

- **Domain enrichment for knowledge bases** — registrar, age, expiry, nameservers as structured fields
- **SSL / DNS hygiene** — certificate days-left and record snapshots before crawl or index jobs
- **Inventory & migration checks** — bulk WHOIS + DNS for domains you already operate or archive
- **Dataset cleanup** — validate hosts in an existing URL/domain list (broken or expired names surface as errors)

### How to use

1. Paste domains in **Domains** (or URLs — the host is used).
2. Choose WHOIS / DNS / SSL modules and optional concurrency / WHOIS delay.
3. Click **Start**. Results are in the **Dataset**; `SUMMARY` / `OUTPUT` in the **Key-value store**.

#### Input example

```json
{
  "domains": ["example.com", "google.com"],
  "maxDomains": 100,
  "lookupWhois": true,
  "lookupDns": true,
  "lookupSsl": true,
  "maxConcurrency": 4,
  "whoisDelayMs": 200,
  "chargeFailedDomains": false
}
```

#### Output example (one dataset item)

```json
{
  "domain": "example.com",
  "status": "ok",
  "whois": {
    "registrar": "RESERVED-Internet Assigned Numbers Authority",
    "created": "1995-08-14T04:00:00+00:00",
    "expires": "2027-08-13T04:00:00+00:00"
  },
  "whoisRegistrar": "RESERVED-Internet Assigned Numbers Authority",
  "whoisCreated": "1995-08-14T04:00:00+00:00",
  "whoisExpires": "2027-08-13T04:00:00+00:00",
  "dns": {
    "A": ["93.184.216.34"],
    "AAAA": [],
    "MX": [],
    "NS": ["a.iana-servers.net", "b.iana-servers.net"],
    "TXT": ["v=spf1 -all"]
  },
  "dnsA": "93.184.216.34",
  "ssl": {
    "issuer": "Example CA",
    "validFrom": "2025-01-01T00:00:00+00:00",
    "validTo": "2026-12-25T22:56:35+00:00",
    "daysLeft": 86
  },
  "sslIssuer": "Example CA",
  "sslValidTo": "2026-12-25T22:56:35+00:00",
  "sslDaysLeft": 86,
  "errors": [],
  "durationMs": 1200
}
```

#### Key-value store records

| Key | Content |
|---|---|
| `SUMMARY` | Counts: totalLookedUp, charged, freeErrors, ok/partial/error, duration, peak memory |
| `OUTPUT` | Same summary (sibling Actors consistency) |

### Pricing

Pay per event (locked from measured cloud cost — see `docs/PRICING.md`):

| Event | Price |
|---|---|
| Domain looked up (primary) | **$0.002** per domain (= $2.00 per 1,000) |
| Actor start (Apify synthetic) | $0.00005 per GB (platform default) |

**Worked example:** 1,000 successful/partial domains ≈ **$2.00** + one start event. Platform cost on a 100-domain public bench was about **$0.0027** (own run; not PPE revenue).

By default, complete failures (`status: error`) are **not** charged. Invalid inputs never become a lookup row and are not charged. Details: `docs/PRICING.md`.

### Integrations

Call from the Apify API or another Actor. Chain domain lists from spreadsheets / crawlers into `domains`.

```python
from apify_client import ApifyClient
client = ApifyClient("<token>")
run = client.actor("ingenious_quip_bxq/whois-dns-ssl-lookup").call(run_input={
    "domains": ["example.com", "google.com"],
    "maxDomains": 100,
})
for item in client.dataset(run["defaultDatasetId"]).iterate_items():
    print(item["domain"], item["whoisExpires"], item.get("sslDaysLeft"))
```

### Known limits

- Public WHOIS servers rate-limit and often privacy-redact contact fields; some TLDs return thin or empty parses.
- WHOIS is best-effort via `python-whois` (no paid WHOIS API in this Actor).
- SSL check uses TCP + TLS to the given port (default 443); it does not crawl HTTP.
- IP addresses are rejected as input (hostnames only).
- Be polite: keep concurrency low and use `whoisDelayMs` on large batches.

### FAQ

**Are failed domains charged?** Not by default. Turn on `chargeFailedDomains` to charge every attempted domain.

**Why is a row `partial`?** At least one module returned data and another failed (or DNS NXDOMAIN with other modules on).

**Do you copy closed Actors?** No. MIT/ISC/stdlib libraries only; AGPL-3.0 for this Actor’s source.

### License & source code

Actor source is **AGPL-3.0** (see `LICENSE`). Dependency licenses: `docs/LICENSE_REVIEW.md`. Public GitHub link will be added when the coordinator approves publishing.

### Changelog

See `CHANGELOG.md`.

# Changelog

This Actor's version history is a separate document: https://apify.com/ingenious\_quip\_bxq/whois-dns-ssl-lookup/changelog.md

# Actor input Schema

## `domains` (type: `array`):

One or more domains. Accepts plain strings (`example.com`), `{"domain": "..."}` objects, or `{"url": "https://..."}` (host is used). Deduplicated, order preserved.

## `maxDomains` (type: `integer`):

Stop after looking up this many unique domains (0 = no limit). Also caps cost.

## `lookupWhois` (type: `boolean`):

Query public WHOIS for registrar, creation and expiry dates. Some TLDs rate-limit or return privacy-redacted data.

## `lookupDns` (type: `boolean`):

Resolve DNS records (types selected below) via public resolvers.

## `lookupSsl` (type: `boolean`):

Connect to the domain on the SSL port and read the leaf certificate (issuer, validity, days left).

## `dnsRecordTypes` (type: `array`):

Which DNS record types to resolve when DNS lookup is on.

## `sslPort` (type: `integer`):

TCP port for the TLS handshake (usually 443).

## `maxConcurrency` (type: `integer`):

Parallel domain lookups. Keep low (2–6) to be polite to WHOIS servers.

## `whoisDelayMs` (type: `integer`):

Minimum milliseconds between starting WHOIS queries (global). 0 = no extra delay.

## `requestTimeoutSecs` (type: `integer`):

Timeout for each WHOIS, DNS, or SSL attempt on a domain.

## `chargeFailedDomains` (type: `boolean`):

When off (default), only domains with status ok or partial are charged. Complete failures (status error) are saved free. When on, every attempted domain is charged once.

## Actor input object example

```json
{
  "domains": [
    "example.com",
    "google.com"
  ],
  "maxDomains": 50,
  "lookupWhois": true,
  "lookupDns": true,
  "lookupSsl": true,
  "dnsRecordTypes": [
    "A",
    "AAAA",
    "MX",
    "NS",
    "TXT"
  ],
  "sslPort": 443,
  "maxConcurrency": 4,
  "whoisDelayMs": 200,
  "requestTimeoutSecs": 15,
  "chargeFailedDomains": false
}
```

# Actor output Schema

## `results` (type: `string`):

Default dataset items, one per domain: domain, status, whois (registrar/created/expires), dns (A/AAAA/MX/NS/TXT), ssl (issuer/validFrom/validTo/daysLeft), errors, durationMs. Views: overview, detail.

## `summary` (type: `string`):

Key-value store record SUMMARY (JSON): totalLookedUp, charged, ok/partial/error counts, durationSecs, peakMemoryMb.

## `output` (type: `string`):

Key-value store record OUTPUT (JSON): same run summary as SUMMARY plus charged event counts. Kept for consistency with sibling Actors.

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "domains": [
        "example.com",
        "google.com"
    ],
    "maxDomains": 50
};

// Run the Actor and wait for it to finish
const run = await client.actor("ingenious_quip_bxq/whois-dns-ssl-lookup").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {
    "domains": [
        "example.com",
        "google.com",
    ],
    "maxDomains": 50,
}

# Run the Actor and wait for it to finish
run = client.actor("ingenious_quip_bxq/whois-dns-ssl-lookup").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "domains": [
    "example.com",
    "google.com"
  ],
  "maxDomains": 50
}' |
apify call ingenious_quip_bxq/whois-dns-ssl-lookup --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,ingenious_quip_bxq/whois-dns-ssl-lookup"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/uGujgwmc7ermByFTT/builds/DuLWwrm3VTeaf40Fy/openapi.json
