Outbound Stack Detector Cold Email Sending Domains Clay avatar

Outbound Stack Detector Cold Email Sending Domains Clay

Pricing

from $3.40 / 1,000 domain analyzeds

Go to Apify Store
Outbound Stack Detector Cold Email Sending Domains Clay

Outbound Stack Detector Cold Email Sending Domains Clay

Detects whether a company runs cold email outbound and on what stack. Finds the lookalike sending domains behind the program, the inbox provider, the sequencer, warmup and infrastructure vendors, plus SPF, DKIM and DMARC posture. One flat Clay ready row per domain.

Pricing

from $3.40 / 1,000 domain analyzeds

Rating

0.0

(0)

Developer

Mamba Labs

Mamba Labs

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

7 hours ago

Last modified

Share

๐Ÿ“ฎ What can Outbound Stack Detector do?

Give it a company domain and it tells you whether that company runs cold outbound, and on what stack. One flat row per domain, ready to drop into a Clay column or a CRM field.

The core of it is finding a company's lookalike sending domains: the getcompany.com and company-mail.co addresses a real outbound program buys so it never burns the domain the business runs on.

๐Ÿ“ฆ What you getโš™๏ธ Features and integrations
๐ŸŽฏ A four-level runs_outbound verdict with the rule that fired
๐Ÿ“ง Lookalike sending domains, attributed by redirect
๐Ÿท๏ธ Inbox provider and sequencer, read from DNS
๐Ÿงพ 40 flat fields, snake_case, one row per domain
๐Ÿ—“๏ธ Registration clustering, bought-together domains
๐Ÿญ Cold email infrastructure vendor detection
๐Ÿ›ก๏ธ SPF, DKIM and DMARC posture at no extra cost
โฌ‡๏ธ Export to JSON, CSV, Excel, HTML or XML

Bought by vendors selling into outbound teams, who read program as "these people buy tools like mine", and by prospectors, who read the same row as "their inbox is crowded, expect a hard landing".

๐Ÿšซ This does not read anyone's mailbox and does not send anything. Every field comes from public DNS and a public HTTP redirect. Nothing here touches a message, an inbox, or any private system.

๐Ÿ’ก Why use Outbound Stack Detector?

If you want to knowRead these fields
Do they run outbound at allruns_outbound, verdict_reason, confidence
How big the program issending_domain_count, sending_domain_names, registration_clusters
What they send withsending_platforms, sequencer_detected, tracking_domains
Who hosts their mailinbox_provider, mx_records
Whether they buy pre-warmed inboxesinfrastructure_vendors
Their deliverability posturespf_policy, dkim_status, dmarc_policy
Whether to trust the verdictbrand_is_common_word, signals_missing, evidence

๐Ÿ” The lookalike domain trick, which is the whole product

A real outbound program does not send from the domain the business runs on, because one spam complaint would burn it. It buys lookalikes instead.

This actor generates those patterns, checks which ones carry mail, and keeps only the ones whose web root redirects back to the primary domain. That redirect is the attribution. It is what separates a company's own sending domain from an unrelated business that happens to own mycompany.com.

Measured 2026-08-06 on nine live domains across three bands: sending domain detection 6 of 6 on companies that demonstrably run outbound (smartlead.ai, instantly.ai, apollo.io, lemlist.com, clay.com, rippling.com), and 0 false positives of 3 on controls (irs.gov, wikipedia.org, redcross.org).

An earlier sixteen-domain feasibility probe scored 6 of 8, missing gong.io and outreach.io. Both misses have the same cause: when the brand token is an ordinary English word, the lookalike patterns collide with unrelated businesses that own them legitimately. getgong.com and outreachone.com are real companies that owe nothing to Gong or Outreach.

๐Ÿ“‹ What data can Outbound Stack Detector extract?

40 fields per domain. The ones buyers use:

FieldWhat it holds
runs_outboundprogram, light, none or unknown
verdict_reasonThe rule that produced the verdict, in words
confidenceCapped automatically when attribution is ambiguous
sending_domains, sending_domain_count, sending_domain_namesThe lookalikes, attributed
registration_clustersSending domains bought on the same day
sending_platforms, sending_platform_names, sequencer_detectedThe tooling layer
inbox_provider, inbox_provider_label, mx_recordsMail hosting, primary and per sending domain
infrastructure_vendorsSellers of pre-warmed inboxes
tracking_domainsCustom tracking CNAMEs
warmup_detected, warmup_vendorsPublic warmup traces, when any exist
spf_status, spf_record, spf_policy, dkim_status, dkim_selectors_found, dmarc_policy, dmarc_recordDeliverability posture
deliverability_score, deliverability_risk, blacklistedOnly when check_deliverability is on
brand_is_common_wordThe ambiguity flag, read it before a none
candidates_tested, candidates_with_mailHow much work the scan actually did
evidence, signals_fired, signals_missingQuotable strings and coverage

โš ๏ธ An empty sending_platform_names tells you very little. Instantly, Smartlead, Lemlist, Apollo and Salesloft connect to a customer's own mailbox over OAuth or SMTP and publish no SPF include host at all. All fourteen documented SPF hostnames for those vendors returned NXDOMAIN when checked. A platform being present is solid; a platform being absent is not evidence.

๐Ÿ› ๏ธ How to detect a company's cold outbound stack

  1. Open the Input tab and put a domain in domain, or a list in domains.
  2. Leave scan_sending_domains on true. It is the differentiator, and turning it off makes the verdict much weaker.
  3. Leave sending_domain_depth on deep. It costs no measurable wall-clock because the lookups run in parallel.
  4. Click Start.
  5. Read runs_outbound with verdict_reason, and check confidence before acting on a none.

๐Ÿงช Using it in Clay

Add an Apify enrichment column and map your domain column to domain. Every field lands as its own column.

If you sell to outbound teams, filter runs_outbound = "program". If you are prospecting into them, treat the same value as a warning about how crowded that inbox is.

๐Ÿฉบ About check_deliverability

It is off by default, and not because the integration is missing. As of 2026-08-06, Domain Deliverability Checker returns an empty audit for every domain when called as a sub-actor: an unhandled DNS rejection while probing DKIM selectors fails the whole audit, and the empty record it falls back to carries deliverability_score: 0 and risk_level: high. That reads as "this domain has terrible deliverability" when it actually means "the audit did not happen".

This actor detects that shape and discards it rather than republishing a confident wrong number, but you would still pay that actor's per-domain rate for nothing. SPF, DKIM and DMARC are read directly from DNS either way, at no extra cost.

๐Ÿ’ต How much does it cost to fingerprint outbound infrastructure?

You are charged once per domain analyzed.

PlanPer domainPer 1,000 domains
Free$0.004$4.00
Bronze$0.0038$3.80
Silver$0.0036$3.60
Gold$0.0034$3.40

There is also an Actor start event at $0.00005, charged once per run per GB of memory.

๐Ÿ’ณ One charge per domain, however many lookups it takes. A single domain costs a few hundred DNS lookups plus an HTTP probe for each lookalike that carries mail, and it still bills once. Free Apify plans get 15 results per calendar month; paid plans are unlimited. Repeat lookups inside 7 days are served from cache.

โŒจ๏ธ Input

Everything is on the Input tab. The options worth explaining:

FieldTypeDefaultWhat it does
domainstringsmartlead.aiOne domain.
domainsarray[]Batch. Takes precedence over domain.
scan_sending_domainsbooleantrueThe differentiator. Off makes runs fast and the verdict much weaker.
sending_domain_depthstringdeepdeep covers .com .co .io .net .org. standard drops the last two.
check_deliverabilitybooleanfalseAdds the blacklist check and score. See the note above.
batchSizeinteger3Concurrent domains, 1 to 10.
max_sending_domain_probesinteger80Per-domain cap on HTTP attribution probes.
request_timeout_msinteger9000Per-request timeout.
dns_timeout_msinteger4000Per-lookup DNS timeout.
skipCachebooleanfalseIgnore the 7 day result cache.

Anything skipped by max_sending_domain_probes is named in evidence, never dropped silently.

๐Ÿ“ค Output

One flat row per domain, exportable as JSON, CSV, Excel, HTML or XML.

{
"domain": "smartlead.ai",
"runs_outbound": "program",
"verdict_reason": "20 attributed sending domains and a registration cluster",
"confidence": 0.85,
"sending_domain_count": 20,
"sending_domain_names": "get-smartlead.co, getsmartlead.co, gosmartlead.co",
"registration_clusters": [{"date": "2024-08-29", "count": 4}],
"inbox_provider": "google_workspace",
"sending_platform_names": null,
"sequencer_detected": false,
"spf_policy": "~all",
"dmarc_policy": "none",
"brand_is_common_word": false,
"evidence": [
"Sending domain trysmartlead.com redirects to smartlead.ai, registered 2024-08-29",
"4 sending domains registered together on 2024-08-29"
],
"is_summary_row": false
}

evidence is the quotable part. Every run emits at least one row; rows with is_summary_row: true are notices (empty input, free tier reached, QA run), not data.

๐Ÿ’ก Tips

  • Read confidence and brand_is_common_word before you trust a none. On brands like "Gong", "Clay" or "Ramp", the pattern generator collides with unrelated businesses and the actor caps confidence rather than reporting a confident negative.
  • registration_clusters is the strongest single tell. Four sending domains bought on the same day is a program. One domain bought two years ago is not.
  • An infrastructure_vendors hit is close to proof. Nothing but a cold email program buys pre-warmed inboxes.
  • Compare inbox_provider on the primary domain against the sending domains. A deliberate split means the outbound tenant is being kept away from the corporate one.

โš ๏ธ Known limits

Sending platform recall is structurally partial, and this is the honest limit of the product. The major sequencers publish no SPF include host. The only DNS-visible trace they leave is a custom tracking domain, and only when the customer configured one. Smartlead itself, a cold email company with twenty of its own sending domains, returns no platform at all.

Warmup detection is weaker still. No major warmup vendor publishes a usable public DNS fingerprint, so warmup_detected: false means "no public trace", never "not warming up".

Common-word brands are ambiguous by nature. When the brand token is an ordinary English word, lookalike patterns collide with legitimate unrelated businesses. brand_is_common_word flags it and confidence is capped.

unknown is not none. It means the domain did not resolve, or the sending domain scan was turned off. Those are different from a clean scan that found nothing.

Speed is 6 to 24 seconds per domain, dominated by DNS fan-out. No headless browser, no proxy, no LLM.

Two discovery channels were measured and dropped. Certificate transparency search: 10 of 16 crt.sh queries timed out at 25 seconds, and the ones that returned added nothing the pattern generator had not already found. DMARC rua attribution added one domain across sixteen. Both are documented in the source rather than silently omitted.

โ“ FAQ

What is the difference between program and light?

program is a deliberate cold outbound setup: multiple sending domains, a registration cluster, a sending domain plus a sequencer, or an infrastructure vendor. light is one sending domain, or a sequencer with no sending domains. Real but small, or a marketing tool rather than a program.

Why is sending_platform_names empty for a company I know uses Instantly?

Because Instantly leaves no public DNS trace unless the customer configured a custom tracking domain. See the callout above. Absence of a platform is not evidence of absence.

Does it read email or send anything?

No. Public DNS and a public HTTP redirect, nothing else.

Can I disagree with the verdict?

Yes, and the actor is built for it. verdict_reason names the rule that fired and every raw field is on the row, so you can rebuild the reading yourself.

Why is deliverability scoring off by default?

Because the sub-actor it calls currently returns an empty audit that looks like a terrible score. See the note in the How to section. SPF, DKIM and DMARC come from DNS regardless.

๐Ÿงฉ Want other GTM data?

Mamba Labs builds custom actors for B2B go-to-market teams. The public versions of that work live here on the Store, so our users get the same tooling we build under contract.

๐Ÿง‘โ€๐Ÿ’ผ GTM Hiring Signal Scraper๐Ÿงฑ Tech Stack Detector
๐Ÿ“ก B2B Buying Signals Aggregator๐Ÿ”‘ Job Board Keyword Scanner
๐Ÿ”— Domain to LinkedIn URL Resolver๐ŸŽฏ ICP Fit Scorer
๐Ÿ“‹ Job Posting Monitor๐Ÿ“ฌ Domain Deliverability Checker
๐Ÿข Company Firmographic Enricher๐ŸŒ Company Social Presence Mapper
๐Ÿชช Company Identity Resolver๐Ÿ’ฐ Funding and Press Signal Scanner
๐Ÿ”„ Company Change-Event Feed๐Ÿ‘ค People Finder and Email Verifier
๐Ÿš€ Prospect Engine๐Ÿค– AI Tooling Detector
๐Ÿ“ Publishing Frequency Trackerโœ‰๏ธ Work Email Waterfall Finder
โฉ Sequencer Lead Push๐Ÿ… Workplace Program Detector
๐Ÿ‘ฅ Team Page People Extractor๐Ÿงญ Company Discovery List Builder

Every actor in the suite takes a domain or a company and returns one flat row, so they stack in the same Clay table without reshaping anything.

๐Ÿ› ๏ธ Need something custom built for you or your team? Tell us what you are trying to find and we will build it. Talk to Mamba Labs.

๐Ÿ†˜ Support

Something wrong, or a sending domain the actor missed? Open an issue on the Issues tab with the domain and the row, and we will look at it.

โ„น๏ธ Sourcing and legal. Everything on the row comes from public DNS records and public HTTP redirects. Nothing reads a mailbox, sends a message, or touches anything that is not published. Domain registration dates come from public registration data. You are responsible for how you use the output.

Built by Mamba Labs.