CDN Detector | Cloudflare, Fastly & Edge Signals
Pricing
$3.00 / 1,000 website checkeds
CDN Detector | Cloudflare, Fastly & Edge Signals
Detect exposed CDN and reverse-proxy signals from website HTML and response headers. Export provider matches for infrastructure research. Embedded assets can use a different CDN from the page origin.
Pricing
$3.00 / 1,000 website checkeds
Rating
0.0
(0)
Developer
Nick McNemar
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
6 days ago
Last modified
Categories
Share
Inspect visible CDN signals on websites
CDN Detector: Detect exposed CDN and reverse-proxy signals from website HTML and response headers. Export provider matches for infrastructure research. Embedded assets can use a different CDN from the page origin.
Start with a small example
- Open Input, switch to JSON and paste the example below. Replace the example startUrls with your own research targets when ready.
- Check the live Pricing tab and set a run spending limit.
- Run the Actor, then open the Workflow output view. Inspect
url,cdn,reverseProxy,matchedTechnologies,statusCode,error. - Export JSON for nested data or CSV for a spreadsheet. Review a small sample before increasing the scope.
{"startUrls": ["https://www.shopify.com","https://www.hp.com","https://pages.github.com"],"filterTechnologies": ["Cloudflare","Akamai","Fastly","Amazon CloudFront","Google Cloud CDN","Azure CDN","Bunny","KeyCDN","Imperva","Sucuri","CDN77","Cloudinary","imgix","jsDelivr","cdnjs","Google Hosted Libraries","Netlify","Vercel","StackPath","Limelight","Edgecast","Alibaba Cloud CDN","Tencent Cloud CDN"],"onlyMatching": false}
At the rate checked September 9, 2026, 3 saved rows cost $0.009 in Actor event fees ($3.00 per 1,000 rows). Actual returned rows determine the event fee. Taxes and other account services may be separate.
What can I use it for?
- CDN and edge-security sales. Find sites with no CDN at all, or on a competitor's network, and target them.
- Performance and reliability audits. Inventory which of a portfolio's sites are behind a CDN and which serve straight from origin.
- Crawl planning. Know which sites sit behind Cloudflare or Akamai before you schedule a large crawl, and set expectations accordingly.
- Market and competitive research. Measure the share of Cloudflare, Akamai, Fastly and CloudFront across an industry or region.
- Vendor due diligence. Confirm a prospective partner's or acquisition target's edge setup from the outside.
- Enriching your data. Add
cdnandwebServercolumns to a spreadsheet of domains in one run.
What data does it return?
One record per website:
| Field | Meaning |
|---|---|
url, finalUrl, statusCode, title | What you asked for, where it resolved to, and the page title |
cdn | The network(s) detected, e.g. Cloudflare, Akamai, Fastly, Amazon CloudFront, Google Cloud CDN |
matchesFilter | true when the site uses any of the networks you listed under CDNs to look for |
matchedTechnologies | Which listed networks were found |
webServer | Nginx, Apache HTTP Server, IIS, LiteSpeed and others where exposed |
reverseProxy | Proxy and edge layers where exposed |
hosting, paas | Origin hosting where it is visible behind the CDN |
security | Bot management and WAF services that ride on the CDN, e.g. Cloudflare Bot Management, Akamai Bot Manager |
technologyCount | Total technologies detected |
technologies | The complete list with categories, versions and confidence scores |
error | null on success, otherwise why the site could not be checked |
Sites that time out or refuse the connection are still returned with an error, so input and output line up one to one.
Illustrative output
Values explain the output shape; they are not a live result or guaranteed field coverage.
{"url": "https://www.hp.com","finalUrl": "https://www.hp.com/us-en/home.html","statusCode": 200,"title": "HP® Official Site | Laptop Computers, Desktops, Printers, and more","cdn": "Akamai","matchesFilter": true,"matchedTechnologies": ["Akamai"],"security": "Akamai Bot Manager","cms": "Adobe Experience Manager","technologyCount": 5,"technologies": [{ "name": "Akamai", "categories": ["CDN"], "version": null, "confidence": 100, "website": "https://www.akamai.com/" },{ "name": "Akamai Bot Manager", "categories": ["Security"], "version": null, "confidence": 100, "website": "https://www.akamai.com/products/bot-manager" }],"error": null}
How to use it
- Paste your domains under Websites to check, upload a file, or pass them through the API as
startUrls. Bare domains likeexample.comare fine. - Leave CDNs to look for at its defaults for a broad inventory, or narrow it to one network to build a targeted list.
- Switch on Store only matching websites to pay only for sites on the networks you listed and discard the rest.
- Click Start and download the results as JSON, CSV or Excel from the Output tab, or read them from the dataset via the API.
Input example
{"startUrls": ["https://www.shopify.com","hp.com","https://pages.github.com"],"filterTechnologies": ["Cloudflare", "Akamai", "Fastly"],"onlyMatching": false}
Raise Max concurrency for large lists. Turn on Proxy configuration only if some sites block the platform's IP range — most do not.
How detection works
CDNs identify themselves in response headers: cf-ray and server: cloudflare, x-akamai-transformed and Akamai's x-check-cacheable, Fastly's x-served-by: cache-… and x-cache: HIT, CloudFront's x-amz-cf-id and via: 1.1 … cloudfront.net, Google's via: 1.1 google, Bunny's server: BunnyCDN, and so on. The detector fetches each homepage once and checks the headers, cookies, HTML, script sources and meta tags against more than 7,600 technology fingerprints, then reports every match with a confidence score.
Because the page's JavaScript is never executed, signals that only appear after scripts run are not evaluated. For CDN detection that never matters — the evidence is in the headers of the first response — and the trade-off buys speed and a much lower cost per site.
The fingerprint database is the open-source webappanalyzer technology dataset, used under the GNU GPL v3. The matching engine in this actor is original code.
Pricing
You pay per website saved to the dataset. With Store only matching websites on, that means per matching site; with it off, per site checked. There are no subscriptions, seats or minimums, and you can cap the maximum spend of a run before it starts.
Scope and responsible use
The actor requests only the publicly served homepage of each URL you provide, exactly as a browser would. It requires no login, no cookies and no credentials, performs no DNS enumeration or IP-range lookups, does not crawl beyond the page you give it, and does not attempt to bypass any access control or bot-protection challenge. You are responsible for using the results in accordance with the laws that apply to you and the terms of the websites you check.
Limitations
- A CDN configured to strip its identifying headers is reported only when other signals remain.
- Multi-CDN setups can answer from different networks on different requests; the actor reports the one that served its request.
- Very large retail and media homepages that deliberately stall automated traffic can exceed the request timeout; they come back as rows with an
errorrather than being dropped. - Only the URL you supply is fetched; static assets served from a different CDN than the page are reported when they are referenced in the page.
Something not detected?
Open an issue on this actor's Issues tab with the URL and the network you expected. Include a reproducible input and the expected signal so the report can be investigated.
Interpret empty results and errors
A null technology field means no recognized signal was found in the inspected response; it does not prove absence. A returned error means that URL was not successfully analyzed. With onlyMatching: true, non-matches and errors are omitted from the dataset, so a zero-row result cannot distinguish an unavailable site from no matches. Start with onlyMatching: false when checking coverage.
Every saved row, including an error row, incurs the configured per-row event fee. Proxy selection and run duration can affect operating costs. Do not increase concurrency or enable a more expensive proxy merely to work around an unclear result.
For a reproducible problem, open this Actor’s Issues tab with a small public input, expected behavior and relevant error text. Remove tokens and confidential information. No response-time or uptime guarantee is offered.
Use the result in an automation
In Make or n8n, use the Apify integration to run this Actor with the same JSON input, wait for completion, then retrieve its default dataset. Route failed runs and error rows to a review step before sending valid results to your spreadsheet or CRM. Scheduling does not make these Actors emit only new records: deduplicate downstream using the source URL or record ID.
For Node.js, install the official apify-client package and set your own APIFY_TOKEN environment variable. The following example starts a paid run with a small spending limit.
import { ApifyClient } from 'apify-client';const client = new ApifyClient({ token: process.env.APIFY_TOKEN });const input = {"startUrls": ["https://www.shopify.com","https://www.hp.com","https://pages.github.com"],"filterTechnologies": ["Cloudflare","Akamai","Fastly","Amazon CloudFront","Google Cloud CDN","Azure CDN","Bunny","KeyCDN","Imperva","Sucuri","CDN77","Cloudinary","imgix","jsDelivr","cdnjs","Google Hosted Libraries","Netlify","Vercel","StackPath","Limelight","Edgecast","Alibaba Cloud CDN","Tencent Cloud CDN"],"onlyMatching": false};const run = await client.actor('keystonelabs/cdn-detector').call(input, {memory: 512, timeout: 180, maxTotalChargeUsd: 0.10});if (run.status !== 'SUCCEEDED') throw new Error('Run did not succeed: ' + run.id);const { items } = await client.dataset(run.defaultDatasetId).listItems({ limit: 100 });console.log(items);
The first 100 rows are retrieved in this example. Use the dataset API pagination for a larger result. Keep credentials out of shared inputs and source files.
A useful next step
- Website Tech Stack Detector | Bulk URL Lookup: qualify a website list by its technology. This is a separate Actor with its own input and price.
Understand the run at a glance
Open Run summary in Output for counts of unique URLs, analyzed responses, failures, matches and saved rows. It remains useful when onlyMatching produces an empty dataset. The summary is written at normal completion and does not add a billable dataset row. Failed or aborted runs may not have a final summary; check run status first. The summary contains counts only, not a second copy of scraped content.