Email Security Audit (SPF, DMARC, DKIM, MX) avatar

Email Security Audit (SPF, DMARC, DKIM, MX)

Pricing

from $6.00 / 1,000 results

Go to Apify Store
Email Security Audit (SPF, DMARC, DKIM, MX)

Email Security Audit (SPF, DMARC, DKIM, MX)

Audit any domain's email security in bulk: SPF, DMARC, DKIM, MX, MTA-STS and BIMI, with a 0-100 score, spoofing risk and plain-English fixes.

Pricing

from $6.00 / 1,000 results

Rating

0.0

(0)

Developer

Maged

Maged

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

a day ago

Last modified

Categories

Share

Email Security Audit checks any list of domains for SPF, DMARC, DKIM, MX, MTA-STS, TLS-RPT and BIMI in one run. Each domain gets a 0–100 score, an A–F grade, a spoofing-risk verdict and a plain-English list of fixes. Find out in seconds whether someone could send email pretending to be you, your clients, or your prospects.

What does Email Security Audit do?

For every domain you provide, the Actor reads its public DNS email configuration and grades it:

  • MX & mail provider: where the domain receives email (Google Workspace, Microsoft 365, Zoho, Proofpoint, Mimecast and more).
  • SPF: the record, its policy (-all, ~all…), duplicate records, and the DNS lookup count against the hard limit of 10, a common silent failure.
  • DMARC: policy, subdomain policy, pct, and where reports are sent.
  • DKIM: signing keys found on the most common selectors (plus any selectors you add).
  • MTA-STS, TLS-RPT and BIMI: transport encryption policy and brand-logo readiness.

On the Apify platform you also get API access, scheduling, integrations (Google Sheets, Zapier, Make, Slack, webhooks) and run monitoring, so you can re-audit a portfolio every week automatically.

Why audit email security?

  • MSPs & security consultants: audit every client domain in one run and hand over a prioritized fix list.
  • Cold email & deliverability: find the SPF/DMARC/DKIM gaps that send your mail to spam, before you launch a campaign.
  • Sales prospecting: find companies with spoofable domains (spoofingRisk: high), a strong opener for security, email or IT services.
  • Vendor & M&A due diligence: check the email hygiene of partners and acquisition targets.
  • Compliance with Google and Yahoo sender rules: bulk senders need SPF, DKIM and DMARC; see who's compliant.

How to audit SPF, DMARC and DKIM in bulk

  1. Open the Actor and go to the Input tab.
  2. Paste domains into Domains, one per line. Website URLs and email addresses work too.
  3. Optionally add your own DKIM selectors.
  4. Click Start.
  5. Open the Output tab: the Scorecard view shows grades and fixes, and the DNS records view shows the raw records.

Input

FieldTypeDescription
domainsarrayDomains, website URLs or email addresses. Required.
dkimSelectorsarrayOptional extra DKIM selectors to check, on top of the built-in common ones.
{
"domains": ["apify.com", "github.com", "someone@example.com"],
"dkimSelectors": ["mycompany2024"]
}

Output

One row per domain. You can download the dataset in various formats such as JSON, HTML, CSV, or Excel.

{
"domain": "github.com",
"score": 85,
"grade": "B",
"spoofingRisk": "medium",
"issues": [
"SPF ends in ~all (softfail): unauthorized mail is only marked, not rejected. Consider -all.",
"DMARC policy is quarantine: spoofed mail goes to spam. p=reject blocks it entirely."
],
"hasMx": true,
"mxRecords": [
{
"priority": 0,
"host": "github-com.mail.protection.outlook.com"
}
],
"mailProvider": "Microsoft 365",
"spfRecord": "v=spf1 ip4:192.30.252.0/22 include:spf.protection.outlook.com include:_netblocks.google.com include:_netblocks2.google.com include:mail.zendesk.com include:_spf.salesforce.com include:servers.mcsv.net include:mktomail.com include:sendgrid.net ip4:62.253.227.114 ip4:166.78.69.169 ip4:166.78.69.170 ip4:166.78.71.131 ~all",
"spfPolicy": "softfail",
"spfLookupCount": 10,
"spfRecordCount": 1,
"dmarcRecord": "v=DMARC1; p=quarantine; sp=reject; pct=100; rua=mailto:dmarc@github.com; ruf=mailto:dmarc@github.com; fo=1",
"dmarcPolicy": "quarantine",
"dmarcSubdomainPolicy": "reject",
"dmarcPct": 100,
"dmarcReportingEmails": [
"dmarc@github.com"
],
"dkimSelectorsFound": [
"google",
"selector1",
"k1",
"k2",
"k3",
"s1",
"s2",
"smtpapi"
],
"mtaStsEnabled": false,
"mtaStsMode": null,
"tlsRptEnabled": false,
"bimiEnabled": false,
"error": null,
"checkedAt": "2026-09-25T17:23:46+00:00"
}

Output data fields

FieldDescription
score / grade0–100 score and A–F grade (A ≥ 90, B ≥ 75, C ≥ 60, D ≥ 40).
spoofingRiskhigh = spoofed mail gets delivered, medium = it goes to spam, low = it's rejected.
issuesWhat's wrong and how to fix it, most important first.
mailProvider / mxRecordsDetected email provider and the MX hosts.
spfRecord / spfPolicy / spfLookupCount / spfRecordCountSPF record, its enforcement, DNS lookups used (limit 10), and number of SPF records (must be 1).
dmarcRecord / dmarcPolicy / dmarcSubdomainPolicy / dmarcPct / dmarcReportingEmailsDMARC configuration.
dkimSelectorsFoundDKIM selectors with a published key.
mtaStsEnabled / mtaStsMode / tlsRptEnabled / bimiEnabledTransport security and brand-indicator records.
errorWhy a domain couldn't be audited (e.g. it doesn't exist), otherwise null.

How is the score calculated?

AreaPoints
MX records present10
SPF present, single record, strict policy, within 10 lookups35
DMARC present, enforcing policy (reject > quarantine), reporting enabled35
DKIM key found15
MTA-STS, TLS-RPT, BIMI5

Domains that don't handle email but are correctly locked down (v=spf1 -all plus DMARC p=reject) aren't penalized for missing MX or DKIM.

How many results will I get?

Exactly one row per domain. 500 domains produce 500 rows. Duplicates are removed automatically.

Tips

  • Paste email lists directly: addresses are reduced to their domain and deduplicated, so a 10,000-contact list audits only its unique domains.
  • Filter by spoofingRisk to build a prospect list or a client remediation queue.
  • Schedule it weekly to catch changes, such as an SPF record that silently grew past 10 lookups.
  • Add your DKIM selector if you know it (e.g. from your email provider's setup page) to confirm DKIM exactly.

FAQ

Why does it say no DKIM was found when I have DKIM? DKIM keys can only be looked up by selector name, and there's no way to list them. The most common selectors are checked automatically. If yours has a custom name, add it under Extra DKIM selectors.

Does it send any email? No. It only reads public DNS records and the public MTA-STS policy file.

Is this legal? Yes. Email DNS records are public by design, so that every mail server in the world can read them.

Found a bug or need a custom feature? Open an issue in the Issues tab. Custom solutions are available on request.