Email DNS Change Monitor — MX, SPF & DMARC
Pricing
from $4.00 / 1,000 domain checkeds
Email DNS Change Monitor — MX, SPF & DMARC
Check domain lists for email DNS changes, missing MX, multiple SPF records and published DMARC policies. Get before/after evidence and CSV. No emails sent or mailbox probing.
Pricing
from $4.00 / 1,000 domain checkeds
Rating
0.0
(0)
Developer
Tender Delta
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
3 days ago
Last modified
Categories
Share
See exactly what changed in your domains' email settings after a migration or DNS edit.
Check a domain list in one run and export published MX, SPF and direct DMARC records with DNS evidence. Compare against a previous run to identify changed mail routing or policy records without manually checking each domain.
Who this helps
- IT teams verifying public DNS after an email-provider migration.
- Agencies maintaining several client domains and reviewing DNS changes.
- Operations teams that want source-backed records in a spreadsheet or automation workflow.
This is a published-record check, not an inbox-delivery guarantee or a full authentication evaluation. It sends no email and never contacts a mailbox over SMTP.
Try two domains
{"domains":["apify.com","example.com"],"maxDomains":2}
Two delivered domain checks cost $0.008, plus the displayed Actor start charge. No source account, paid resolver key or proxy subscription is needed. The example.com domain intentionally publishes a null MX; the tool reports this explicit no-mail configuration rather than treating it as a timeout.
Read the findings correctly
| Finding | Meaning |
|---|---|
| explicit_null_mx | The domain explicitly advertises that it accepts no email |
| mx_not_published | No MX observed; SMTP's possible A/AAAA fallback is not evaluated |
| multiple_spf_records | More than one SPF policy observed at the queried domain |
| spf_allows_every_sender | An explicit unqualified all or +all mechanism was observed |
| no_direct_dmarc_record_inheritance_not_checked | No policy at _dmarc of the supplied domain; a parent policy may still apply |
| dmarc_monitoring_only | Direct p=none observed; this can be intentional |
| domain_nxdomain | The resolver returned NXDOMAIN for the supplied name |
No arbitrary 0–100 security score is invented. TTL changes and DNS answer reordering do not create false configuration-change events. An SPF ~all policy is reported as a note, not automatically labeled broken.
Compare before and after
Run once to save SNAPSHOT. On the next run select the previous run's key-value store in previousSnapshotStoreId, keep the domain list the same and optionally enable changesOnly. The changes array includes each changed field's before and after values. Your workflow must pass the preceding run's store ID each time; no automatic persistent global history or email alert is created.
The dataset contains one row per delivered domain: domain, mxRecords, spfRecords, dmarcRecords, dmarcPolicy, findings, notes, evidence, checkedAt and optional change fields. Evidence includes resolver URLs, DNS statuses and relevant answer records. Other unrelated domain-verification TXT values are excluded.
OUTPUT-CSV is UTF-8 and spreadsheet-formula-safe; JSON preserves original text. SUMMARY reports coverage and failures, DELIVERY records export completion, DIAGNOSTICS lists unchecked targets, and SNAPSHOT supports the next comparison. Source absence is distinct from network failure.
Pricing and limits
$4 per 1,000 delivered domain checks ($0.004 each) plus the displayed Actor start charge. Platform usage is included; no monthly rental. Completed checks with missing records or NXDOMAIN are useful diagnostic results and are charged. Resolver HTTP failures, SERVFAIL, truncation or incomplete checks are unchecked diagnostics and are not charged as domain checks. Suppressed unchanged rows are not charged. The start charge may apply even when no result is delivered.
Up to 50 domains per input, 10 checked by default, three DNS queries per domain, an 8-second request timeout and an approximately 90-second work budget. Set Apify's maximum charge before starting. Snapshots retain up to 10,000 recent records. No parallel batch flood: three record queries per domain, then a short pause before the next domain.
Scope and source
Uses Google's public DNS-over-HTTPS JSON API with client-subnet disclosure disabled. Results reflect the resolver's cache at check time, not a guarantee that DNS propagation has completed worldwide. Only the supplied name and its direct _dmarc name are queried. No recursive SPF include evaluation, sender IP evaluation, DMARC organizational-domain fallback, alignment evaluation, DKIM signature/selector discovery, blocklist, WHOIS or mailbox verification. Findings are practical observations, not standards certification.
Google DNS API documentation, SPF specification, Null MX specification. Public resolver policies and availability apply. You control reuse of the public records.
Independent tool by Tender Delta. Use this Actor's Issues tab for a reproducible problem with your input and a redacted run link. Do not include credentials or private domain inventories.