# Domain DNS & Email Policy Monitor - SPF, DMARC, MX (`maydit/domain-dns-email-monitor`) Actor

Read public DNS records and SPF, DMARC, MX and supplied DKIM selectors. Compare complete observations over time with per-query errors. No API key or mailbox access required.

- **URL**: https://apify.com/maydit/domain-dns-email-monitor.md
- **Developed by:** [Brandt May](https://apify.com/maydit) (community)
- **Categories:** Developer tools, Automation
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $1.80 / 1,000 domain observations

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.
Since this Actor supports Apify Store discounts, the price gets lower the higher subscription plan you have.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

## Domain DNS & Email Policy Monitor

Read public DNS records and inspect the published SPF, DMARC and MX information for a list of domains. Optionally query known DKIM selectors and compare each complete observation with its previous snapshot.

Use this to document DNS changes, inspect an email migration, or maintain a structured domain inventory. Each finding includes the public evidence and any query errors. The Actor does not invent a security grade or claim to verify mailbox delivery.

### Quick start

Empty input checks `wordpress.org` and `apify.com`:

```json
{}
```

For your own domain list:

```json
{
  "domains": ["wordpress.org", "apify.com"],
  "comparePrevious": false,
  "maxRunSeconds": 240
}
```

No account credentials or API key are required. Queries use the [Cloudflare public DNS-over-HTTPS JSON endpoint](https://developers.cloudflare.com/1.1.1.1/encryption/dns-over-https/make-api-requests/dns-json/). The Actor reads DNS; it does not connect to mailboxes or change domain settings.

### Inputs

| Field | Default | Meaning |
|---|---|---|
| `domains` | `wordpress.org`, `apify.com` | Up to 100 distinct domains. Empty or omitted uses these samples. |
| `dkimSelectors` | none | Up to five known selectors, queried for every domain. |
| `comparePrevious` | false | Opt in to storing and comparing observations. |
| `snapshotName` | `default` | Independent monitor namespace, up to 100 characters. |
| `maxRunSeconds` | 240 | 30–3,600 seconds, also bounded by the platform deadline. |

Use domain names, or origin URLs without paths, ports, credentials or query strings. IP addresses are not accepted. A DKIM selector is the prefix in `selector._domainkey.example.com`, not the entire DNS name. Selectors are never guessed. Each selector must begin with a letter or digit and contain at most 63 letters, digits, dots, underscores or hyphens.

### What each observation contains

One dataset row represents one domain. A row is `complete` when every requested query produced a usable response; otherwise it is `partial`. A legitimate no-data response or NXDOMAIN is a DNS observation, not a service failure.

| Field | Contents |
|---|---|
| `domain`, `observedAt`, `status` | Domain, observation time and complete/partial status. |
| `records` | A, AAAA, MX, NS, TXT and exact-domain DMARC results; additional `DKIM:selector` keys for supplied selectors. |
| `records.*.status` | `answer`, `no_data` or `nxdomain`. A query failure is recorded separately. |
| `records.*.answers` | Answer owner, resolver TTL and record value. TXT chunks are joined. |
| `records.*.authenticatedData` | The resolver's AD flag; this is not a general domain security rating. |
| `spf` | Observed SPF records, count, first all mechanism, simple include/redirect fields and a direct lookup-term count. |
| `dmarc` | Observed exact-domain records, count, `p`, `sp`, and `pct` summary. |
| `mxProviders` | Provider hints derived from recognized MX hostnames, each with the hostname as evidence. Empty means no recognized hint. |
| `dkim` | Supplied selector names, DNS status and returned TXT values. |
| `issues` | Specific informational findings or warnings, each with a code, severity and explanation. |
| `queryErrors` | Resolver, shape, response-size or time-budget errors by query type. |
| `comparisonStatus`, `previousObservedAt`, `changes`, `baselineEligible` | Optional snapshot comparison and whether this observation can update the baseline. |
| `limitations` | The explicit boundaries of the policy checks. |

SPF findings include missing or multiple records, the first permissive `all`, multiple `all` terms and excessive direct lookup terms. DMARC checks summarize policy tags and flag selected invalid/duplicate policy cases. This is a policy inspection, not a full SPF or DMARC evaluator. A sole Null MX record is distinguished from an invalid Null MX mixed with other MX records.

### Compare changes over time

```json
{
  "domains": ["wordpress.org"],
  "comparePrevious": true,
  "snapshotName": "dns-observations"
}
```

The first complete run emits a full observation with `comparisonStatus: "first_observation"` and an empty changes list. Later complete runs compare statuses and sorted record values. TTL countdowns and answer ordering are excluded from the comparison. Unchanged observations are still emitted.

The named key-value store `maydit-dns-email-baselines` holds snapshots by domain, sorted selector list and snapshot namespace. Changing selectors or namespace starts a separate comparison scope. A partial observation has `comparisonStatus: "skipped_partial"` and never replaces previous history. `baselineEligible` describes eligibility; confirmed updates are listed in `SUMMARY.baselinesUpdated` after persistence.

Use a separate `snapshotName` for independent monitors. Avoid overlapping runs with the same name and scope, because key-value storage does not provide an atomic monitor lock. Schedule future runs through Apify only when you want recurring execution; this Actor does not create schedules itself.

### Run summary and failures

`SUMMARY` contains requested/emitted/complete/partial counts, failed domains, query errors, unprocessed domains, deadline status and confirmed baseline updates. If one domain fails completely, usable results from others are retained. If no domain yields any usable query response, the run fails with a diagnostic.

Resolver errors and malformed/truncated responses are not silently converted into missing DNS records. A partial observation can still contain useful DNS evidence; inspect `status` and `queryErrors` before making a decision from it.

### Billing

Launch price: **$3 per 1,000 emitted domain observations** ($0.003 each) on Free/Bronze, plus an Actor Start event of $0.00005. Silver is 20% lower and Gold/Platinum/Diamond 40% lower. The live Pricing tab is authoritative.

**Partial observations are billable**, as are unchanged observations, first snapshots and valid no-data/NXDOMAIN results. A domain whose every query fails produces no dataset row and no result event. Each domain observation is one result; individual DNS answers and DKIM selectors are not separate result events. Consult the published pricing tab for any platform resource charges.

### Limits

- No RDAP/WHOIS, ownership, expiry or registrant lookup is performed.
- No mailbox verification, SMTP probing, email sending or inbox-deliverability test is performed.
- SPF include chains are not expanded. The direct term count is not a complete SPF lookup-budget evaluation.
- DMARC is checked at `_dmarc.<exact-domain>` only. Organizational-domain fallback and policy inheritance are not evaluated.
- DKIM is queried only for supplied selectors. Returned keys do not prove that outbound mail is correctly signed.
- MX provider labels are hostname hints and can miss custom gateways or other providers.
- DNS caches, propagation and geography can affect observations. A public resolver's answer is a point-in-time observation, not proof that every resolver sees the same result.
- `authenticatedData: false` is not, by itself, proof of an insecure domain.

### Development

Run `npm test` for the fixture suite. Use isolated `CRAWLEE_STORAGE_DIR` directories when running locally. The three inputs in `examples/` are drafts for verification; the comparison example explicitly opts into state storage and does not create an external schedule.

# Actor input Schema

## `domains` (type: `array`):

Up to 100 distinct public DNS domains, such as wordpress.org. Omitted or empty uses wordpress.org and apify.com. Do not include paths, ports, credentials or IP addresses.

## `dkimSelectors` (type: `array`):

Optional known selectors to query for every domain, up to five. Supply selector names only, not full DNS names. A selector may contain letters, digits, dots, underscores and hyphens, begins with a letter or digit, and is at most 63 characters. No selectors are guessed.

## `comparePrevious` (type: `boolean`):

Opt in to named snapshot storage. First use returns a full observation with no previous comparison. Later complete observations report changes. Partial results never replace the baseline. Every emitted observation is billable, including unchanged and partial results.

## `snapshotName` (type: `string`):

Optional namespace, up to 100 characters, for independent monitors. Domain and sorted DKIM selector list also identify the scope. Avoid overlapping runs with the same namespace and scope.

## `maxRunSeconds` (type: `integer`):

Own wall-clock budget, shared by requests and bounded by the platform deadline with a safety margin. Work unfinished at the deadline is reported in SUMMARY.

## Actor input object example

```json
{
  "domains": [
    "wordpress.org",
    "apify.com"
  ],
  "comparePrevious": false,
  "snapshotName": "default",
  "maxRunSeconds": 240
}
```

# Actor output Schema

## `results` (type: `string`):

One complete or partial public DNS observation per domain, with record answers, email-policy evidence, query errors and optional comparison.

## `summary` (type: `string`):

Requested and emitted counts, failures, skipped work and budget status. Use this to assess source coverage.

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "domains": [
        "wordpress.org",
        "apify.com"
    ]
};

// Run the Actor and wait for it to finish
const run = await client.actor("maydit/domain-dns-email-monitor").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "domains": [
        "wordpress.org",
        "apify.com",
    ] }

# Run the Actor and wait for it to finish
run = client.actor("maydit/domain-dns-email-monitor").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "domains": [
    "wordpress.org",
    "apify.com"
  ]
}' |
apify call maydit/domain-dns-email-monitor --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,maydit/domain-dns-email-monitor"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/scigxgTNPBdhOd1I5/builds/oeucHyW1oHEryju6l/openapi.json
