Domain Lookup: Tech Stack, Email Provider, DNS, WHOIS & SSL
Pricing
from $2.20 / 1,000 domain analyseds
Domain Lookup: Tech Stack, Email Provider, DNS, WHOIS & SSL
One row per domain: email provider (Google Workspace, Microsoft 365…), SPF/DMARC/BIMI, DNS provider, hosting & CDN, CMS and tech stack (Shopify, WordPress, HubSpot…), SSL expiry and registrar dates. Paste up to 5,000 domains or URLs. Public DNS, RDAP and TLS data only, no personal data.
Pricing
from $2.20 / 1,000 domain analyseds
Rating
0.0
(0)
Developer
locaihost data
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
10 minutes ago
Last modified
Categories
Share
Domain Intelligence: DNS, Email Security, Hosting, Tech Stack & SSL
Paste a list of company domains and get one row per domain with everything a sales, marketing or security team wants to know about it:
- Email: who hosts it (Google Workspace, Microsoft 365, Zoho, Proton…), any security gateway in front of it (Proofpoint, Mimecast…), and whether SPF, DMARC, BIMI and MTA-STS are set up.
- Website: HTTP status, redirects, HTTPS and HSTS, response time, page title, and the hosting and CDN behind it (Shopify, Vercel, Netlify, WP Engine, Cloudflare, CloudFront, Akamai, Fastly…).
- Tech stack: CMS (WordPress, Shopify, Wix, Squarespace, Webflow, Ghost, Drupal, HubSpot CMS…), e-commerce, analytics (GA4, GTM, Segment, Hotjar, Plausible…), JavaScript frameworks (Next.js, Nuxt, React, Vue, Angular…), chat widgets (Intercom, Drift, Zendesk, Crisp…), payments (Stripe, PayPal, Klarna…) and marketing tools (HubSpot, Marketo, Klaviyo, Meta Pixel…).
- SSL: certificate issuer, validity dates and days until expiry.
- Registration: registrar, creation date, expiry date and status, straight from the official registry (RDAP).
Everything comes back in one run, as one flat row per domain, ready for a spreadsheet or CRM.
Who is it for?
- Lead generation & sales ops. Segment accounts by technology: every Shopify store in your list, every company on Microsoft 365, everyone still on Universal Analytics. Technographic filters make outbound far more relevant.
- Agencies & freelancers. Find prospects running WordPress without HSTS, sites with SSL expiring this month, or companies with no DMARC policy. Each one is a concrete reason to get in touch.
- Security & IT audits. Check email authentication (SPF
-allvs~all, DMARCp=nonevsreject), certificate expiry and domain expiry across a whole portfolio of brands or suppliers in minutes. - Market research. Measure hosting, CMS and email-provider market share across any list of companies.
Why this one
- One row per domain, everything in one run. No juggling separate DNS, WHOIS, SSL and tech-lookup tools and joining the results.
- Accuracy over a long list. Technology detection uses product-specific signals only (the vendor's own script host, a global it defines, a header it sets). A blog that writes about Shopify won't be tagged as a Shopify store.
- Honest results. If a lookup fails, the field is
nullanderrorssays why. You never get a silent "no DMARC" just because a DNS server timed out. - Sees through email gateways. If MX points at Proofpoint or Mimecast, SPF tells us whether the mailboxes are on Microsoft 365 or Google Workspace.
- Paste anything.
stripe.com,https://www.shopify.com/pricing,info@acme.comandwww.bbc.co.ukall work. Duplicates are merged, and junk lines are skipped and listed in the run summary. - No personal data. No registrant names, emails or phone numbers. The local part of DMARC report addresses is redacted (
mailto:***@vendor.com).
How to use
- Click Try for free and paste your domains (one per line, up to 5,000).
- Optionally turn off sections you don't need. DNS only runs are the fastest.
- Run it and open the Overview, Email security or Tech stack table, or export everything as CSV, Excel or JSON.
- Re-check a portfolio regularly by saving the input as a task and adding a schedule, for example a monthly SSL and domain-expiry check.
Example input
{"domains": ["stripe.com", "https://www.allbirds.com/", "hubspot.com", "bbc.co.uk", "info@nextjs.org"],"checkWebsite": true,"checkSsl": true,"checkRegistration": true}
Example output (one row)
{"domain": "allbirds.com","registered": true,"resolves": true,"ipv4": ["23.227.38.32"],"nameservers": ["ns2.markmonitor.com", "ns3.markmonitor.com", "…"],"dnsProvider": "MarkMonitor","mxRecords": ["allbirds-com.mail.protection.outlook.com"],"emailProvider": "Microsoft 365","emailSecurityGateway": null,"hasSpf": true,"spfRecord": "v=spf1 include:allbirds_com._es.easydmarc.com include:spf.protection.outlook.com ~all","spfAll": "~all","hasDmarc": true,"dmarcRecord": "v=DMARC1;p=quarantine;pct=100;rua=mailto:***@allbirds.com;ruf=mailto:***@allbirds.com;fo=1","dmarcPolicy": "quarantine","dmarcPct": 100,"hasBimi": true,"hasMtaSts": false,"caaIssuers": [],"httpStatus": 200,"finalUrl": "https://www.allbirds.com/","redirectCount": 1,"https": true,"hsts": true,"server": "cloudflare","title": "Allbirds: Comfortable, Sustainable Shoes & Apparel","responseTimeMs": 230,"cdn": "Cloudflare","hosting": "Shopify","cms": null,"ecommerce": ["Shopify"],"analytics": ["Google Tag Manager", "Microsoft Clarity"],"frameworks": [],"chatWidgets": [],"payments": [],"marketing": [],"technologies": ["Shopify", "Google Tag Manager", "Microsoft Clarity"],"sslIssuer": "Let's Encrypt","sslValidTo": "2027-01-07T03:10:03.000Z","sslDaysToExpiry": 88,"sslValid": true,"tlsVersion": "TLSv1.3","registrar": "MarkMonitor Inc.","registeredAt": "2002-01-09T15:24:37Z","expiresAt": "2028-01-09T15:24:37Z","daysToDomainExpiry": 456,"domainStatus": ["client delete prohibited", "client transfer prohibited", "…"],"dnssec": false,"errors": {},"checkedAt": "2026-10-10T09:00:00.000Z"}
Fields
| Field | Meaning |
|---|---|
domain / input | The registrable domain we checked, and what you typed |
registered / resolves | Found in the registry / has an IP address. A typo'd or dead domain shows false |
dnsProvider | Inferred from name servers: Cloudflare, AWS Route 53, Azure DNS, Google Cloud DNS, GoDaddy, Namecheap, NS1, Akamai… or Self-hosted |
emailProvider | Where the mailboxes live, from MX (and SPF when a gateway hides it) |
emailSecurityGateway | Inbound filter in front of the mailboxes: Proofpoint, Mimecast, Cisco, Barracuda, Broadcom… |
spfAll | How strict SPF is: -all (fail), ~all (softfail), ?all, +all |
dmarcPolicy | none, quarantine or reject. hasDmarc: false = no DMARC record at all |
dmarcReportDomains | Where aggregate reports go, which often reveals the DMARC vendor |
hasBimi / hasMtaSts / caaIssuers | Brand logo in inboxes / enforced TLS for inbound mail / which CAs may issue certificates |
httpStatus, finalUrl, redirectCount | Result of one GET of the homepage, following redirects |
https / hsts | Final page served over HTTPS / with Strict-Transport-Security |
responseTimeMs | Time to the final response's headers, including redirects |
cdn / hosting | Edge network and hosting platform, from response headers, CNAME, reverse DNS and published IP ranges |
cms, ecommerce, analytics, frameworks, chatWidgets, payments, marketing | Technologies grouped for filtering. technologies lists them all |
sslDaysToExpiry | Days until the certificate on port 443 expires (negative = already expired). sslValid = trusted chain and matches the name |
registrar, registeredAt, expiresAt, daysToDomainExpiry, domainStatus, dnssec | From the registry's RDAP service |
errors | Per-section explanation when something couldn't be checked: dns, website, tech, ssl, registration |
Pricing
Pay per domain: you're charged once for each domain row returned, however much was found for it. Invalid lines and duplicates you pasted are skipped for free.
Free Apify plan: each run returns up to 100 domains. Any paid Apify plan removes the cap.
Good to know
- Polite by design. Each website gets one
robots.txtrequest, one homepage GET and one TLS handshake, one after another, never in parallel. About 10 domains are checked at a time. Ifrobots.txtdisallows the homepage for our crawler (locaihost-domain-intel), we skip the website and tech sections and say so inerrors.website. - Tech detection reads the homepage HTML and headers. Tools loaded only later by JavaScript (some chat widgets, tag-manager-injected pixels) can't be seen, so an empty list means "nothing visible on the homepage", not "definitely not used".
- Bot walls. Some sites (often government or banking) answer automated requests with
403. You still get DNS, email, SSL, registration and usually CDN/hosting.errors.techexplains the gap. - Hosting behind a CDN. When a site sits behind Cloudflare or another proxy and the origin sends no identifying headers,
hostingisnull. We don't guess. - Registration data. Comes from each registry's RDAP service. A few country domains (e.g.
.io,.de,.co,.so,.me) don't offer RDAP, so those rows explain that inerrors.registration. Registrant and contact details are never collected. - Subdomains are checked at the registrable domain (
shop.acme.co.uk→acme.co.uk). Customer sites on platforms such as*.myshopify.comor*.github.ioare kept as they are. - Speed. Roughly 30–60 domains per minute, so 1,000 domains take about 15–30 minutes. A DNS-only run (website, SSL and registration off) is much faster.
- Run summary. The
SUMMARYrecord has counts by email provider, site platform and hosting, how many domains lack DMARC or have SSL expiring within 30 days, and any inputs that weren't domains.
Feedback
Missing a technology, provider or field you need? Open an issue on the Issues tab. Replies usually within a day.