Email DNS Change Monitor — MX, SPF & DMARC avatar

Email DNS Change Monitor — MX, SPF & DMARC

Pricing

from $4.00 / 1,000 domain checkeds

Go to Apify Store
Email DNS Change Monitor — MX, SPF & DMARC

Email DNS Change Monitor — MX, SPF & DMARC

Check domain lists for email DNS changes, missing MX, multiple SPF records and published DMARC policies. Get before/after evidence and CSV. No emails sent or mailbox probing.

Pricing

from $4.00 / 1,000 domain checkeds

Rating

0.0

(0)

Developer

Tender Delta

Tender Delta

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

3 days ago

Last modified

Categories

Share

See exactly what changed in your domains' email settings after a migration or DNS edit.

Check a domain list in one run and export published MX, SPF and direct DMARC records with DNS evidence. Compare against a previous run to identify changed mail routing or policy records without manually checking each domain.

Who this helps

  • IT teams verifying public DNS after an email-provider migration.
  • Agencies maintaining several client domains and reviewing DNS changes.
  • Operations teams that want source-backed records in a spreadsheet or automation workflow.

This is a published-record check, not an inbox-delivery guarantee or a full authentication evaluation. It sends no email and never contacts a mailbox over SMTP.

Try two domains

{"domains":["apify.com","example.com"],"maxDomains":2}

Two delivered domain checks cost $0.008, plus the displayed Actor start charge. No source account, paid resolver key or proxy subscription is needed. The example.com domain intentionally publishes a null MX; the tool reports this explicit no-mail configuration rather than treating it as a timeout.

Read the findings correctly

FindingMeaning
explicit_null_mxThe domain explicitly advertises that it accepts no email
mx_not_publishedNo MX observed; SMTP's possible A/AAAA fallback is not evaluated
multiple_spf_recordsMore than one SPF policy observed at the queried domain
spf_allows_every_senderAn explicit unqualified all or +all mechanism was observed
no_direct_dmarc_record_inheritance_not_checkedNo policy at _dmarc of the supplied domain; a parent policy may still apply
dmarc_monitoring_onlyDirect p=none observed; this can be intentional
domain_nxdomainThe resolver returned NXDOMAIN for the supplied name

No arbitrary 0–100 security score is invented. TTL changes and DNS answer reordering do not create false configuration-change events. An SPF ~all policy is reported as a note, not automatically labeled broken.

Compare before and after

Run once to save SNAPSHOT. On the next run select the previous run's key-value store in previousSnapshotStoreId, keep the domain list the same and optionally enable changesOnly. The changes array includes each changed field's before and after values. Your workflow must pass the preceding run's store ID each time; no automatic persistent global history or email alert is created.

The dataset contains one row per delivered domain: domain, mxRecords, spfRecords, dmarcRecords, dmarcPolicy, findings, notes, evidence, checkedAt and optional change fields. Evidence includes resolver URLs, DNS statuses and relevant answer records. Other unrelated domain-verification TXT values are excluded.

OUTPUT-CSV is UTF-8 and spreadsheet-formula-safe; JSON preserves original text. SUMMARY reports coverage and failures, DELIVERY records export completion, DIAGNOSTICS lists unchecked targets, and SNAPSHOT supports the next comparison. Source absence is distinct from network failure.

Pricing and limits

$4 per 1,000 delivered domain checks ($0.004 each) plus the displayed Actor start charge. Platform usage is included; no monthly rental. Completed checks with missing records or NXDOMAIN are useful diagnostic results and are charged. Resolver HTTP failures, SERVFAIL, truncation or incomplete checks are unchecked diagnostics and are not charged as domain checks. Suppressed unchanged rows are not charged. The start charge may apply even when no result is delivered.

Up to 50 domains per input, 10 checked by default, three DNS queries per domain, an 8-second request timeout and an approximately 90-second work budget. Set Apify's maximum charge before starting. Snapshots retain up to 10,000 recent records. No parallel batch flood: three record queries per domain, then a short pause before the next domain.

Scope and source

Uses Google's public DNS-over-HTTPS JSON API with client-subnet disclosure disabled. Results reflect the resolver's cache at check time, not a guarantee that DNS propagation has completed worldwide. Only the supplied name and its direct _dmarc name are queried. No recursive SPF include evaluation, sender IP evaluation, DMARC organizational-domain fallback, alignment evaluation, DKIM signature/selector discovery, blocklist, WHOIS or mailbox verification. Findings are practical observations, not standards certification.

Google DNS API documentation, SPF specification, Null MX specification. Public resolver policies and availability apply. You control reuse of the public records.

Independent tool by Tender Delta. Use this Actor's Issues tab for a reproducible problem with your input and a redacted run link. Do not include credentials or private domain inventories.