# Domain Intelligence: Tech Stack, SaaS & Email Security (`jfaro19/domain-intel`) Actor

Analyze company domains in bulk. Input: domains, URLs or emails. Returns the website tech stack (CMS, analytics, ads, chat, payments), SaaS tools found in DNS (Microsoft 365, Google Workspace, HubSpot, Salesforce, Zendesk...), email provider, SPF/DKIM/DMARC grade, SSL expiry and site-health signals.

- **URL**: https://apify.com/jfaro19/domain-intel.md
- **Developed by:** [Jason Faro](https://apify.com/jfaro19) (community)
- **Categories:** Lead generation, Developer tools, SEO tools
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $3.00 / 1,000 domain analyzeds

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

### What does Domain Intelligence do?

**Domain Intelligence** analyzes a list of company domains in bulk and returns, for each one:

- the **website tech stack**: CMS, site builder, analytics, ad pixels, live chat, scheduling, payments, frameworks, CDN and hosting
- the **SaaS tools revealed by DNS**, which HTML-only detectors can't see: Microsoft 365, Google Workspace, HubSpot, Salesforce, Zendesk, DocuSign, Atlassian, Stripe, SendGrid, Mailchimp, Proofpoint, Mimecast and 100+ more
- the **email provider and email security grade**: SPF, DKIM and DMARC status, DMARC policy, SPF lookup count, and an A–F grade with a list of issues
- **website health**: HTTPS, days until the SSL certificate expires, mobile-friendliness, copyright year, contact form
- public **contact details** on the homepage: emails, phone links and social profiles

Paste domains, URLs or email addresses, click **Start**, and download the results as JSON, CSV or Excel, or get them through the Apify API. You can schedule runs, connect them to Make, Zapier, n8n or Google Sheets, and call the Actor from AI agents over MCP.

### Why use Domain Intelligence?

Most tech-stack tools only read the homepage HTML. That misses most of what a company actually pays for. Back-office tools rarely leave traces in the HTML, but they do leave them in **DNS**:

- **MX records** show the mailbox provider and any email security gateway.
- **SPF includes** show which services send email for the domain (CRM, help desk, marketing and transactional email).
- **Domain verification TXT records** show which SaaS accounts the company has verified (Atlassian, DocuSign, Zoom, Slack, Stripe, Adobe, OpenAI and others).
- **DKIM selectors** confirm which platforms are set up to send email for the domain.

**Use cases**

- **Sales prospecting and lead scoring.** Find companies that use (or don't use) Microsoft 365, HubSpot, Salesforce, Shopify or WordPress, and personalize outreach to their stack.
- **Agency prospecting.** Spot local businesses with outdated websites, no analytics, missing DMARC, expiring SSL certificates or pages that aren't mobile-friendly. Each of these is a service you can offer.
- **Enriching Google Maps lead lists.** Run the website column from a Google Maps scrape through this Actor to add tech stack and contact data.
- **Email deliverability and security audits.** Grade SPF/DKIM/DMARC across a portfolio of domains, a client list or vendors.
- **Market research.** Measure the market share of CMSs, email providers or SaaS tools in a niche.

### How to use Domain Intelligence

1. Click **Try for free**.
2. Paste your domains into the **Domains** field, one per line. `example.com`, `https://www.example.com/contact` and `jane@example.com` all work.
3. Optionally, turn off **Analyze website** for a faster DNS-only run.
4. Click **Start**. About 1,000 domains take a few minutes.
5. Download the dataset or connect it to your tools.

### Input

| Field | Type | Description |
|---|---|---|
| `domains` | array of strings | Domains, URLs or email addresses. They are normalized and de-duplicated. |
| `includeWebsite` | boolean (default `true`) | Fetch the homepage for website technologies, contacts and site health. |
| `maxConcurrency` | integer (default `20`) | Number of domains processed in parallel. |

```json
{
  "domains": ["hubspot.com", "https://www.shopify.com", "info@example-plumbing.com"],
  "includeWebsite": true
}
```

### Output

Each domain produces one item. This example is shortened from a real run on `hubspot.com`:

```json
{
  "domain": "hubspot.com",
  "status": "ok",
  "mailboxProvider": "Google Workspace",
  "emailAuthGrade": "A",
  "websitePlatform": "HubSpot CMS",
  "technologyCount": 21,
  "technologyNames": ["HubSpot CMS", "Atlassian", "Atlassian Statuspage", "Cloudflare", "Adobe", "Jamf", "DocuSign",
    "Google Workspace", "Mandrill", "SendGrid", "HubSpot", "Stripe", "OneTrust", "Smartsheet", "Google Tag Manager"],
  "technologiesByCategory": {
    "CMS": ["HubSpot CMS"],
    "E-signature": ["DocuSign"],
    "Device management": ["Jamf"],
    "Email sending": ["Google Workspace", "Mandrill", "SendGrid", "HubSpot"],
    "Payments": ["Stripe"]
  },
  "technologies": [
    {"name": "DocuSign", "categories": ["E-signature"], "sources": ["dns-txt"]},
    {"name": "HubSpot CMS", "categories": ["CMS"], "sources": ["html"]}
  ],
  "email": {
    "mxHosts": ["smtp.google.com"],
    "spfStatus": "valid",
    "spfDnsLookups": 4,
    "dmarcPolicy": "reject",
    "dmarcReporting": true,
    "dkimSelectorsFound": ["google", "s1", "s2", "mandrill", "hs1", "hs2"],
    "authGrade": "A",
    "issues": []
  },
  "dns": {"dnsHost": "Cloudflare", "nameservers": ["jerry.ns.cloudflare.com", "yolanda.ns.cloudflare.com"]},
  "website": {
    "finalUrl": "https://www.hubspot.com/",
    "httpStatus": 200,
    "https": true,
    "title": "HubSpot | Software & Tools for your Business - Homepage",
    "mobileViewport": true,
    "copyrightYear": 2026,
    "sslDaysLeft": 74,
    "sslIssuer": "Google Trust Services"
  },
  "contacts": {"emails": [], "phones": [], "socialProfiles": {"linkedin": "https://www.linkedin.com/company/hubspot"}},
  "signals": [],
  "checkedAt": "2026-09-27T19:40:12+00:00"
}
```

Each technology lists its `sources`, so you can see how it was detected: `html`, `header`, `cookie`, `html-meta`, `dns-mx`, `dns-spf`, `dns-txt`, `dns-dkim` or `dns-ns`.

#### Main fields

| Field | Description |
|---|---|
| `websitePlatform` | CMS, site builder or ecommerce platform (WordPress, Shopify, Wix, Squarespace, Webflow, Duda, …) |
| `mailboxProvider` | Google Workspace, Microsoft 365, Zoho, GoDaddy, Proton, … (inferred even behind Proofpoint or Mimecast) |
| `emailAuthGrade` | **A** DMARC reject · **B** quarantine · **C** DMARC p=none · **D** SPF or DMARC missing/broken · **F** both missing/broken · `null` if the domain doesn't use email |
| `technologyNames` | Flat list of every detected product, which is easy to filter in CSV or Excel |
| `technologiesByCategory` | Products grouped by category |
| `signals` | Ready-made flags: `dmarc_missing`, `spf_missing`, `spf_multiple_records`, `spf_too_many_lookups`, `dmarc_policy_none`, `ssl_expiring_soon`, `ssl_invalid`, `no_https`, `not_mobile_friendly`, `outdated_copyright`, `no_analytics`, `website_unreachable`, `no_mx_records`, … |

### How much does it cost to analyze domains?

The Actor uses **pay-per-event** pricing: you pay only for domains that were analyzed successfully. Domains that don't exist and domains that error out are **free**. Check the **Pricing** tab for the current price per 1,000 domains. The Actor uses lightweight HTTP and DNS requests (no browser), so runs are fast and cheap. To cap spending, set a maximum cost per run: the Actor stops as soon as it reaches that limit.

### Tips

- **DNS-only mode** (`includeWebsite: false`) is the fastest option. It still returns the email provider, SaaS stack from DNS, email security grade and DNS host.
- To enrich a **Google Maps scrape**, pass its `website` column straight into `domains`.
- Filter the dataset on `signals` to build prospect lists, for example every business with `dmarc_missing` and `outdated_copyright`.

### Works well with

- [Contact Details Scraper](https://apify.com/jfaro19/website-contact-finder): get the emails, phone numbers and social profiles for the same list of domains. Pay only when contacts are found.
- [Website Screenshot & PDF](https://apify.com/jfaro19/website-screenshot): attach a screenshot of each prospect's homepage to your audit or outreach, with cookie banners hidden.

### FAQ, disclaimers and support

**Is this legal?** The Actor reads only public information: DNS records that anyone can query, one TLS handshake, and one normal request for each domain's homepage. It doesn't log in, submit forms or crawl beyond the homepage. If you process personal data from the `contacts` field (such as named email addresses), you're responsible for complying with GDPR, CAN-SPAM and similar laws.

**How accurate is it?** DNS verification tokens show that a domain was verified with a service at some point, which is a strong signal but not proof of current use. DKIM is checked at the most common selectors only, so `dkim_not_found_at_common_selectors` means "not found at the usual places" rather than "definitely missing". Sites that build all their content with JavaScript may show fewer HTML-detected technologies.

**Missing a technology or found a bug?** Open an issue on the **Issues** tab. New signatures are added regularly.

# Actor input Schema

## `domains` (type: `array`):

Domains to analyze. You can paste bare domains (example.com), full URLs (https://www.example.com/about) or email addresses (jane@example.com); they are normalized and de-duplicated.

## `includeWebsite` (type: `boolean`):

Fetch the homepage to detect website technologies, contacts, SSL expiry and site-health signals. Turn off for a faster DNS-only run (email provider, SaaS stack from DNS, SPF/DKIM/DMARC).

## `maxConcurrency` (type: `integer`):

How many domains to analyze in parallel.

## Actor input object example

```json
{
  "domains": [
    "apify.com",
    "hubspot.com",
    "shopify.com"
  ],
  "includeWebsite": true,
  "maxConcurrency": 20
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "domains": [
        "apify.com",
        "hubspot.com",
        "shopify.com"
    ]
};

// Run the Actor and wait for it to finish
const run = await client.actor("jfaro19/domain-intel").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "domains": [
        "apify.com",
        "hubspot.com",
        "shopify.com",
    ] }

# Run the Actor and wait for it to finish
run = client.actor("jfaro19/domain-intel").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "domains": [
    "apify.com",
    "hubspot.com",
    "shopify.com"
  ]
}' |
apify call jfaro19/domain-intel --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,jfaro19/domain-intel"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/suf9GGPrUhkK1oIg0/builds/ww8p02ggc1fXbx1rG/openapi.json
