Domain Intelligence: Tech Stack, SaaS & Email Security avatar

Domain Intelligence: Tech Stack, SaaS & Email Security

Pricing

from $3.00 / 1,000 domain analyzeds

Go to Apify Store
Domain Intelligence: Tech Stack, SaaS & Email Security

Domain Intelligence: Tech Stack, SaaS & Email Security

Analyze company domains in bulk. Input: domains, URLs or emails. Returns the website tech stack (CMS, analytics, ads, chat, payments), SaaS tools found in DNS (Microsoft 365, Google Workspace, HubSpot, Salesforce, Zendesk...), email provider, SPF/DKIM/DMARC grade, SSL expiry and site-health signals.

Pricing

from $3.00 / 1,000 domain analyzeds

Rating

0.0

(0)

Developer

Jason Faro

Jason Faro

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

2 days ago

Last modified

Share

What does Domain Intelligence do?

Domain Intelligence analyzes a list of company domains in bulk and returns, for each one:

  • the website tech stack: CMS, site builder, analytics, ad pixels, live chat, scheduling, payments, frameworks, CDN and hosting
  • the SaaS tools revealed by DNS, which HTML-only detectors can't see: Microsoft 365, Google Workspace, HubSpot, Salesforce, Zendesk, DocuSign, Atlassian, Stripe, SendGrid, Mailchimp, Proofpoint, Mimecast and 100+ more
  • the email provider and email security grade: SPF, DKIM and DMARC status, DMARC policy, SPF lookup count, and an A–F grade with a list of issues
  • website health: HTTPS, days until the SSL certificate expires, mobile-friendliness, copyright year, contact form
  • public contact details on the homepage: emails, phone links and social profiles

Paste domains, URLs or email addresses, click Start, and download the results as JSON, CSV or Excel, or get them through the Apify API. You can schedule runs, connect them to Make, Zapier, n8n or Google Sheets, and call the Actor from AI agents over MCP.

Why use Domain Intelligence?

Most tech-stack tools only read the homepage HTML. That misses most of what a company actually pays for. Back-office tools rarely leave traces in the HTML, but they do leave them in DNS:

  • MX records show the mailbox provider and any email security gateway.
  • SPF includes show which services send email for the domain (CRM, help desk, marketing and transactional email).
  • Domain verification TXT records show which SaaS accounts the company has verified (Atlassian, DocuSign, Zoom, Slack, Stripe, Adobe, OpenAI and others).
  • DKIM selectors confirm which platforms are set up to send email for the domain.

Use cases

  • Sales prospecting and lead scoring. Find companies that use (or don't use) Microsoft 365, HubSpot, Salesforce, Shopify or WordPress, and personalize outreach to their stack.
  • Agency prospecting. Spot local businesses with outdated websites, no analytics, missing DMARC, expiring SSL certificates or pages that aren't mobile-friendly. Each of these is a service you can offer.
  • Enriching Google Maps lead lists. Run the website column from a Google Maps scrape through this Actor to add tech stack and contact data.
  • Email deliverability and security audits. Grade SPF/DKIM/DMARC across a portfolio of domains, a client list or vendors.
  • Market research. Measure the market share of CMSs, email providers or SaaS tools in a niche.

How to use Domain Intelligence

  1. Click Try for free.
  2. Paste your domains into the Domains field, one per line. example.com, https://www.example.com/contact and jane@example.com all work.
  3. Optionally, turn off Analyze website for a faster DNS-only run.
  4. Click Start. About 1,000 domains take a few minutes.
  5. Download the dataset or connect it to your tools.

Input

FieldTypeDescription
domainsarray of stringsDomains, URLs or email addresses. They are normalized and de-duplicated.
includeWebsiteboolean (default true)Fetch the homepage for website technologies, contacts and site health.
maxConcurrencyinteger (default 20)Number of domains processed in parallel.
{
"domains": ["hubspot.com", "https://www.shopify.com", "info@example-plumbing.com"],
"includeWebsite": true
}

Output

Each domain produces one item. This example is shortened from a real run on hubspot.com:

{
"domain": "hubspot.com",
"status": "ok",
"mailboxProvider": "Google Workspace",
"emailAuthGrade": "A",
"websitePlatform": "HubSpot CMS",
"technologyCount": 21,
"technologyNames": ["HubSpot CMS", "Atlassian", "Atlassian Statuspage", "Cloudflare", "Adobe", "Jamf", "DocuSign",
"Google Workspace", "Mandrill", "SendGrid", "HubSpot", "Stripe", "OneTrust", "Smartsheet", "Google Tag Manager"],
"technologiesByCategory": {
"CMS": ["HubSpot CMS"],
"E-signature": ["DocuSign"],
"Device management": ["Jamf"],
"Email sending": ["Google Workspace", "Mandrill", "SendGrid", "HubSpot"],
"Payments": ["Stripe"]
},
"technologies": [
{"name": "DocuSign", "categories": ["E-signature"], "sources": ["dns-txt"]},
{"name": "HubSpot CMS", "categories": ["CMS"], "sources": ["html"]}
],
"email": {
"mxHosts": ["smtp.google.com"],
"spfStatus": "valid",
"spfDnsLookups": 4,
"dmarcPolicy": "reject",
"dmarcReporting": true,
"dkimSelectorsFound": ["google", "s1", "s2", "mandrill", "hs1", "hs2"],
"authGrade": "A",
"issues": []
},
"dns": {"dnsHost": "Cloudflare", "nameservers": ["jerry.ns.cloudflare.com", "yolanda.ns.cloudflare.com"]},
"website": {
"finalUrl": "https://www.hubspot.com/",
"httpStatus": 200,
"https": true,
"title": "HubSpot | Software & Tools for your Business - Homepage",
"mobileViewport": true,
"copyrightYear": 2026,
"sslDaysLeft": 74,
"sslIssuer": "Google Trust Services"
},
"contacts": {"emails": [], "phones": [], "socialProfiles": {"linkedin": "https://www.linkedin.com/company/hubspot"}},
"signals": [],
"checkedAt": "2026-09-27T19:40:12+00:00"
}

Each technology lists its sources, so you can see how it was detected: html, header, cookie, html-meta, dns-mx, dns-spf, dns-txt, dns-dkim or dns-ns.

Main fields

FieldDescription
websitePlatformCMS, site builder or ecommerce platform (WordPress, Shopify, Wix, Squarespace, Webflow, Duda, …)
mailboxProviderGoogle Workspace, Microsoft 365, Zoho, GoDaddy, Proton, … (inferred even behind Proofpoint or Mimecast)
emailAuthGradeA DMARC reject · B quarantine · C DMARC p=none · D SPF or DMARC missing/broken · F both missing/broken · null if the domain doesn't use email
technologyNamesFlat list of every detected product, which is easy to filter in CSV or Excel
technologiesByCategoryProducts grouped by category
signalsReady-made flags: dmarc_missing, spf_missing, spf_multiple_records, spf_too_many_lookups, dmarc_policy_none, ssl_expiring_soon, ssl_invalid, no_https, not_mobile_friendly, outdated_copyright, no_analytics, website_unreachable, no_mx_records, …

How much does it cost to analyze domains?

The Actor uses pay-per-event pricing: you pay only for domains that were analyzed successfully. Domains that don't exist and domains that error out are free. Check the Pricing tab for the current price per 1,000 domains. The Actor uses lightweight HTTP and DNS requests (no browser), so runs are fast and cheap. To cap spending, set a maximum cost per run: the Actor stops as soon as it reaches that limit.

Tips

  • DNS-only mode (includeWebsite: false) is the fastest option. It still returns the email provider, SaaS stack from DNS, email security grade and DNS host.
  • To enrich a Google Maps scrape, pass its website column straight into domains.
  • Filter the dataset on signals to build prospect lists, for example every business with dmarc_missing and outdated_copyright.

Works well with

  • Contact Details Scraper: get the emails, phone numbers and social profiles for the same list of domains. Pay only when contacts are found.
  • Website Screenshot & PDF: attach a screenshot of each prospect's homepage to your audit or outreach, with cookie banners hidden.

FAQ, disclaimers and support

Is this legal? The Actor reads only public information: DNS records that anyone can query, one TLS handshake, and one normal request for each domain's homepage. It doesn't log in, submit forms or crawl beyond the homepage. If you process personal data from the contacts field (such as named email addresses), you're responsible for complying with GDPR, CAN-SPAM and similar laws.

How accurate is it? DNS verification tokens show that a domain was verified with a service at some point, which is a strong signal but not proof of current use. DKIM is checked at the most common selectors only, so dkim_not_found_at_common_selectors means "not found at the usual places" rather than "definitely missing". Sites that build all their content with JavaScript may show fewer HTML-detected technologies.

Missing a technology or found a bug? Open an issue on the Issues tab. New signatures are added regularly.