Outbound Stack Detector Cold Email Sending Domains Clay
Pricing
from $3.40 / 1,000 domain analyzeds
Outbound Stack Detector Cold Email Sending Domains Clay
Detects whether a company runs cold email outbound and on what stack. Finds the lookalike sending domains behind the program, the inbox provider, the sequencer, warmup and infrastructure vendors, plus SPF, DKIM and DMARC posture. One flat Clay ready row per domain.
Pricing
from $3.40 / 1,000 domain analyzeds
Rating
0.0
(0)
Developer
Mamba Labs
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
7 hours ago
Last modified
Categories
Share
๐ฎ What can Outbound Stack Detector do?
Give it a company domain and it tells you whether that company runs cold outbound, and on what stack. One flat row per domain, ready to drop into a Clay column or a CRM field.
The core of it is finding a company's lookalike sending domains: the getcompany.com and
company-mail.co addresses a real outbound program buys so it never burns the domain the business
runs on.
| ๐ฆ What you get | โ๏ธ Features and integrations |
|---|---|
๐ฏ A four-level runs_outbound verdict with the rule that fired๐ง Lookalike sending domains, attributed by redirect ๐ท๏ธ Inbox provider and sequencer, read from DNS ๐งพ 40 flat fields, snake_case, one row per domain | ๐๏ธ Registration clustering, bought-together domains ๐ญ Cold email infrastructure vendor detection ๐ก๏ธ SPF, DKIM and DMARC posture at no extra cost โฌ๏ธ Export to JSON, CSV, Excel, HTML or XML |
Bought by vendors selling into outbound teams, who read program as "these people buy tools like
mine", and by prospectors, who read the same row as "their inbox is crowded, expect a hard landing".
๐ซ This does not read anyone's mailbox and does not send anything. Every field comes from public DNS and a public HTTP redirect. Nothing here touches a message, an inbox, or any private system.
๐ก Why use Outbound Stack Detector?
| If you want to know | Read these fields |
|---|---|
| Do they run outbound at all | runs_outbound, verdict_reason, confidence |
| How big the program is | sending_domain_count, sending_domain_names, registration_clusters |
| What they send with | sending_platforms, sequencer_detected, tracking_domains |
| Who hosts their mail | inbox_provider, mx_records |
| Whether they buy pre-warmed inboxes | infrastructure_vendors |
| Their deliverability posture | spf_policy, dkim_status, dmarc_policy |
| Whether to trust the verdict | brand_is_common_word, signals_missing, evidence |
๐ The lookalike domain trick, which is the whole product
A real outbound program does not send from the domain the business runs on, because one spam complaint would burn it. It buys lookalikes instead.
This actor generates those patterns, checks which ones carry mail, and keeps only the ones whose
web root redirects back to the primary domain. That redirect is the attribution. It is what
separates a company's own sending domain from an unrelated business that happens to own
mycompany.com.
Measured 2026-08-06 on nine live domains across three bands: sending domain detection 6 of 6 on companies that demonstrably run outbound (smartlead.ai, instantly.ai, apollo.io, lemlist.com, clay.com, rippling.com), and 0 false positives of 3 on controls (irs.gov, wikipedia.org, redcross.org).
An earlier sixteen-domain feasibility probe scored 6 of 8, missing gong.io and outreach.io. Both
misses have the same cause: when the brand token is an ordinary English word, the lookalike
patterns collide with unrelated businesses that own them legitimately. getgong.com and
outreachone.com are real companies that owe nothing to Gong or Outreach.
๐ What data can Outbound Stack Detector extract?
40 fields per domain. The ones buyers use:
| Field | What it holds |
|---|---|
runs_outbound | program, light, none or unknown |
verdict_reason | The rule that produced the verdict, in words |
confidence | Capped automatically when attribution is ambiguous |
sending_domains, sending_domain_count, sending_domain_names | The lookalikes, attributed |
registration_clusters | Sending domains bought on the same day |
sending_platforms, sending_platform_names, sequencer_detected | The tooling layer |
inbox_provider, inbox_provider_label, mx_records | Mail hosting, primary and per sending domain |
infrastructure_vendors | Sellers of pre-warmed inboxes |
tracking_domains | Custom tracking CNAMEs |
warmup_detected, warmup_vendors | Public warmup traces, when any exist |
spf_status, spf_record, spf_policy, dkim_status, dkim_selectors_found, dmarc_policy, dmarc_record | Deliverability posture |
deliverability_score, deliverability_risk, blacklisted | Only when check_deliverability is on |
brand_is_common_word | The ambiguity flag, read it before a none |
candidates_tested, candidates_with_mail | How much work the scan actually did |
evidence, signals_fired, signals_missing | Quotable strings and coverage |
โ ๏ธ An empty
sending_platform_namestells you very little. Instantly, Smartlead, Lemlist, Apollo and Salesloft connect to a customer's own mailbox over OAuth or SMTP and publish no SPF include host at all. All fourteen documented SPF hostnames for those vendors returned NXDOMAIN when checked. A platform being present is solid; a platform being absent is not evidence.
๐ ๏ธ How to detect a company's cold outbound stack
- Open the Input tab and put a domain in
domain, or a list indomains. - Leave
scan_sending_domainsontrue. It is the differentiator, and turning it off makes the verdict much weaker. - Leave
sending_domain_depthondeep. It costs no measurable wall-clock because the lookups run in parallel. - Click Start.
- Read
runs_outboundwithverdict_reason, and checkconfidencebefore acting on anone.
๐งช Using it in Clay
Add an Apify enrichment column and map your domain column to domain. Every field lands as its own
column.
If you sell to outbound teams, filter runs_outbound = "program". If you are prospecting into
them, treat the same value as a warning about how crowded that inbox is.
๐ฉบ About check_deliverability
It is off by default, and not because the integration is missing. As of 2026-08-06,
Domain Deliverability Checker returns
an empty audit for every domain when called as a sub-actor: an unhandled DNS rejection while
probing DKIM selectors fails the whole audit, and the empty record it falls back to carries
deliverability_score: 0 and risk_level: high. That reads as "this domain has terrible
deliverability" when it actually means "the audit did not happen".
This actor detects that shape and discards it rather than republishing a confident wrong number, but you would still pay that actor's per-domain rate for nothing. SPF, DKIM and DMARC are read directly from DNS either way, at no extra cost.
๐ต How much does it cost to fingerprint outbound infrastructure?
You are charged once per domain analyzed.
| Plan | Per domain | Per 1,000 domains |
|---|---|---|
| Free | $0.004 | $4.00 |
| Bronze | $0.0038 | $3.80 |
| Silver | $0.0036 | $3.60 |
| Gold | $0.0034 | $3.40 |
There is also an Actor start event at $0.00005, charged once per run per GB of memory.
๐ณ One charge per domain, however many lookups it takes. A single domain costs a few hundred DNS lookups plus an HTTP probe for each lookalike that carries mail, and it still bills once. Free Apify plans get 15 results per calendar month; paid plans are unlimited. Repeat lookups inside 7 days are served from cache.
โจ๏ธ Input
Everything is on the Input tab. The options worth explaining:
| Field | Type | Default | What it does |
|---|---|---|---|
domain | string | smartlead.ai | One domain. |
domains | array | [] | Batch. Takes precedence over domain. |
scan_sending_domains | boolean | true | The differentiator. Off makes runs fast and the verdict much weaker. |
sending_domain_depth | string | deep | deep covers .com .co .io .net .org. standard drops the last two. |
check_deliverability | boolean | false | Adds the blacklist check and score. See the note above. |
batchSize | integer | 3 | Concurrent domains, 1 to 10. |
max_sending_domain_probes | integer | 80 | Per-domain cap on HTTP attribution probes. |
request_timeout_ms | integer | 9000 | Per-request timeout. |
dns_timeout_ms | integer | 4000 | Per-lookup DNS timeout. |
skipCache | boolean | false | Ignore the 7 day result cache. |
Anything skipped by max_sending_domain_probes is named in evidence, never dropped silently.
๐ค Output
One flat row per domain, exportable as JSON, CSV, Excel, HTML or XML.
{"domain": "smartlead.ai","runs_outbound": "program","verdict_reason": "20 attributed sending domains and a registration cluster","confidence": 0.85,"sending_domain_count": 20,"sending_domain_names": "get-smartlead.co, getsmartlead.co, gosmartlead.co","registration_clusters": [{"date": "2024-08-29", "count": 4}],"inbox_provider": "google_workspace","sending_platform_names": null,"sequencer_detected": false,"spf_policy": "~all","dmarc_policy": "none","brand_is_common_word": false,"evidence": ["Sending domain trysmartlead.com redirects to smartlead.ai, registered 2024-08-29","4 sending domains registered together on 2024-08-29"],"is_summary_row": false}
evidence is the quotable part. Every run emits at least one row; rows with is_summary_row: true
are notices (empty input, free tier reached, QA run), not data.
๐ก Tips
- Read
confidenceandbrand_is_common_wordbefore you trust anone. On brands like "Gong", "Clay" or "Ramp", the pattern generator collides with unrelated businesses and the actor caps confidence rather than reporting a confident negative. registration_clustersis the strongest single tell. Four sending domains bought on the same day is a program. One domain bought two years ago is not.- An
infrastructure_vendorshit is close to proof. Nothing but a cold email program buys pre-warmed inboxes. - Compare
inbox_provideron the primary domain against the sending domains. A deliberate split means the outbound tenant is being kept away from the corporate one.
โ ๏ธ Known limits
Sending platform recall is structurally partial, and this is the honest limit of the product. The major sequencers publish no SPF include host. The only DNS-visible trace they leave is a custom tracking domain, and only when the customer configured one. Smartlead itself, a cold email company with twenty of its own sending domains, returns no platform at all.
Warmup detection is weaker still. No major warmup vendor publishes a usable public DNS
fingerprint, so warmup_detected: false means "no public trace", never "not warming up".
Common-word brands are ambiguous by nature. When the brand token is an ordinary English word,
lookalike patterns collide with legitimate unrelated businesses. brand_is_common_word flags it
and confidence is capped.
unknown is not none. It means the domain did not resolve, or the sending domain scan was
turned off. Those are different from a clean scan that found nothing.
Speed is 6 to 24 seconds per domain, dominated by DNS fan-out. No headless browser, no proxy, no LLM.
Two discovery channels were measured and dropped. Certificate transparency search: 10 of 16
crt.sh queries timed out at 25 seconds, and the ones that returned added nothing the pattern
generator had not already found. DMARC rua attribution added one domain across sixteen. Both are
documented in the source rather than silently omitted.
โ FAQ
What is the difference between program and light?
program is a deliberate cold outbound setup: multiple sending domains, a registration cluster, a
sending domain plus a sequencer, or an infrastructure vendor. light is one sending domain, or a
sequencer with no sending domains. Real but small, or a marketing tool rather than a program.
Why is sending_platform_names empty for a company I know uses Instantly?
Because Instantly leaves no public DNS trace unless the customer configured a custom tracking domain. See the callout above. Absence of a platform is not evidence of absence.
Does it read email or send anything?
No. Public DNS and a public HTTP redirect, nothing else.
Can I disagree with the verdict?
Yes, and the actor is built for it. verdict_reason names the rule that fired and every raw field
is on the row, so you can rebuild the reading yourself.
Why is deliverability scoring off by default?
Because the sub-actor it calls currently returns an empty audit that looks like a terrible score. See the note in the How to section. SPF, DKIM and DMARC come from DNS regardless.
๐งฉ Want other GTM data?
Mamba Labs builds custom actors for B2B go-to-market teams. The public versions of that work live here on the Store, so our users get the same tooling we build under contract.
Every actor in the suite takes a domain or a company and returns one flat row, so they stack in the same Clay table without reshaping anything.
๐ ๏ธ Need something custom built for you or your team? Tell us what you are trying to find and we will build it. Talk to Mamba Labs.
๐ Support
Something wrong, or a sending domain the actor missed? Open an issue on the Issues tab with the domain and the row, and we will look at it.
โน๏ธ Sourcing and legal. Everything on the row comes from public DNS records and public HTTP redirects. Nothing reads a mailbox, sends a message, or touches anything that is not published. Domain registration dates come from public registration data. You are responsible for how you use the output.
Built by Mamba Labs.

