Email DNS Change Audit — SPF, DMARC, DKIM & MX
Pricing
$2.00 / 1,000 domain audits
Email DNS Change Audit — SPF, DMARC, DKIM & MX
Bulk-check public email DNS and compare it with a supplied baseline. See exact SPF, DMARC, MX and known DKIM selector changes. Ignore TTL noise; keep failed lookups unknown. Read-only DNS evidence, without inbox scores or mail sending.
Pricing
$2.00 / 1,000 domain audits
Rating
0.0
(0)
Developer
Ahmed Firas
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
2 days ago
Last modified
Categories
Share
Email DNS Change Audit
Check email-related DNS across a domain portfolio and see what changed from a reviewed baseline. Built for admins and agencies maintaining several brands, especially after a DNS migration or a new sending-service setup.
The Actor reads MX, SPF, direct DMARC and the DKIM selectors you specify. It returns source-linked observations and exact added/removed values. It does not send mail, probe mailboxes, change DNS, assign a deliverability score or promise inbox placement.
Quick start
{"domains":["google.com","example.com"],"dkimSelectors":[],"previousSnapshots":{}}
- Enter 1–50 bare domains. Internationalized domains are converted to ASCII; duplicates are checked once. Email addresses, URLs and private DNS names are rejected.
- Optionally provide up to five known DKIM selectors. The same selectors are checked on every domain. If you do not know them, leave the list empty: the result says DKIM was not checked. A missing supplied selector does not prove there is no DKIM.
- Start and open Completed domain audits. Export JSON, CSV or Excel through Apify.
- In Reports and candidate snapshots, open
REPORTfor unknowns and counts, orCANDIDATE_SNAPSHOTSfor reusable snapshots.CHECK-001, etc. preserve individual evidence.
Public example domains demonstrate behavior; they are not customers. example.com intentionally publishes null MX, meaning it does not accept mail. That is a valid configuration for a non-mail domain, not automatically a problem.
Compare with a baseline
After reviewing a successful run, copy its CANDIDATE_SNAPSHOTS JSON object into previousSnapshots for the next run. Supply only domains included in that run's input. Keep the same DKIM selector set.
| Comparison | Meaning |
|---|---|
first_run | No baseline supplied for this domain. |
unchanged | Normalized records and alias chains match the baseline. |
changed | Added or removed values are listed in changes. |
not_comparable | The selector context changed; no change verdict is issued. |
unknown | A required DNS lookup failed or was inconclusive; no change verdict is issued. |
You can keep a fixed approved baseline in an Apify Task and schedule repeated comparisons. For rolling comparisons, your workflow must explicitly fetch and pass reviewed snapshots into the next run. There is no hidden persistent monitor, automatic baseline acceptance, email alert or Slack message.
Candidate snapshots contain fresh completed observations plus unchanged copies of supplied baselines for failed or unattempted domains. REPORT.retainedBaselineDomains identifies these older copies. Do not treat them as fresh results. Review changes before replacing your approved baseline.
DNS record order and TTL countdowns do not create differences. Split quoted TXT chunks are joined without extra spaces. SPF whitespace is normalized but mechanism order is preserved. Well-formed DMARC/DKIM tag order is normalized; malformed or duplicate tags remain visible. Some cosmetic case changes can still be reported. CNAME changes are tracked separately from record values.
Observations
- Missing direct SPF or DMARC records, multiple SPF/DMARC records, a pass-qualified SPF
all, and DMARC tag issues. - Direct DMARC
psummary,t=ytesting notice and legacypctnotice. RFC 9989 (May 2026) removedpct; the Actor does not calculate an enforcement percentage. Omittedpis summarized asnoneonly at the tag level, with an explicit note. - Null MX, no explicit MX, and null MX mixed with other MX records.
- Known DKIM selector presence, multiple TXT records or an empty/revoked
pvalue. Public-key cryptography and actual message signatures are not verified.
These are review observations, not a pass/fail security certification. p=none may be an intentional monitoring stage. Missing direct DMARC can coexist with an inherited policy. Missing MX does not rule out SMTP A/AAAA fallback.
Pricing
USD 0.002 per completed domain audit — $2 per 1,000, including platform usage and selected DKIM queries. A complete audit with missing records still counts as completed. unknown audits are stored in REPORT and do not produce charged dataset items. No startup fee, paid model API or proxy is required.
Examples: 10 completed domains cost $0.02; 50 cost $0.10. Set maximum run cost to at least $0.002. Once the number of completed results reaches the budget, remaining domains are unattempted. Each new run is a new audit and may charge again; unchanged results are still audits and are billed.
Evidence is saved before each billed row. Dataset writes are never retried after an uncertain response. Runs with existing dataset rows refuse resurrection to prevent duplicate charges. If interrupted, inspect CHECK records and dataset; final REPORT and candidate snapshots may not exist yet. Owner tests are not paying-customer invoice verification.
Scope, DNS privacy and limits
- Uses Google's public DNS-over-HTTPS JSON API. Domain names and selector queries are sent to Google; EDNS client subnet is set to
0.0.0.0/0. No email list, SMTP session, private resolver or domain account is used. Only check public domains you are authorized to process. - A single recursive resolver is one observation point. Caches and DNS propagation can differ elsewhere; this does not compare authoritative nameservers or prove global consistency.
- DNS SERVFAIL, refused/truncated answers, malformed data and HTTP failures stay unknown. HTTP 200 alone is not treated as DNS success. DNSSEC validation is not disabled; the resolver's AD flag is recorded, not independently verified.
- Checks only
_dmarcat the exact supplied name. It does not perform organizational-domain discovery, RFC 9989 tree walks, inherited-policy resolution or DMARC alignment tests. - SPF includes, redirects, macros and their recursive DNS lookup costs are not evaluated. No sender IP is tested. An observed SPF record is not proof of valid SPF or delivery.
- DKIM selectors are not discoverable from these checks. A visible public key is not proof that a sender uses it correctly.
- No A/AAAA fallback, blocklists, reputation, inbox placement, DMARC aggregate report parsing, TLS or message-content testing.
- 64 KiB decoded DNS response limit, 12-second request deadline, one bounded retry for selected transient HTTP/network failures. At least 250 ms between sequential query starts; Retry-After over ten seconds stops that lookup. Provider limits can still apply.
- Input limit 1 MiB. Each domain uses three DNS queries plus one per supplied selector. CNAME chains are limited to eight links. No external production dependencies.
Documentation and support
Primary references: Google DNS JSON API, SPF RFC 7208, DMARC RFC 9989, DKIM RFC 6376 and Null MX RFC 7505. This tool is independent and not endorsed by these organizations.
Open an issue with the error code and a public or fictional reproduction. Do not post secrets, private DNS zones, personal email lists or private customer baselines.