Email Provider & DMARC Checker - SPF, DKIM, DMARC Audit
Pricing
from $2.00 / 1,000 domain auditeds
Email Provider & DMARC Checker - SPF, DKIM, DMARC Audit
Bulk-check which email provider a domain uses (Google Workspace, Microsoft 365, Zoho, Proofpoint, Mimecast...) and grade its email security: SPF, DKIM, DMARC policy, MTA-STS, BIMI. Finds spoofable domains and sending tools (HubSpot, SendGrid, Mailchimp...). $2 per 1,000 domains.
Pricing
from $2.00 / 1,000 domain auditeds
Rating
0.0
(0)
Developer
kaleb ashton
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
2 days ago
Last modified
Categories
Share
Email Provider & DMARC Checker: bulk SPF, DKIM, DMARC audit
For any list of domains (or email addresses), find out who hosts their email (Google Workspace, Microsoft 365, Zoho, Proton, GoDaddy and 60+ more, including security gateways like Proofpoint, Mimecast and Barracuda) and how well the domain is protected against spoofing: SPF, DKIM, DMARC, MTA-STS, TLS-RPT and BIMI, summarised as an A-F grade with plain-English issues.
- 📮 Email provider detection with security-gateway awareness (a domain behind Proofpoint is still identified as Microsoft 365 or Google Workspace when the records show it)
- 🛡️ Full authentication audit: SPF syntax,
allqualifier and recursive 10-DNS-lookup limit check; DMARC policy, pct, reporting addresses and reporting vendor; 35 common DKIM selectors with key size; MTA-STS, TLS-RPT, BIMI - 🚩 Flags spoofable domains (no DMARC or
p=none) and Google/Yahoo/Microsoft bulk-sender compliance - 📤 Lists the services a domain sends email through (HubSpot, Salesforce, SendGrid, Mailchimp, Zendesk, Klaviyo...)
- ⚡ DNS-only, so it's fast and cheap: $2 per 1,000 domains
What can you use it for?
| You are... | Use it to... |
|---|---|
| Cold email / lead gen agency | Segment prospects by mailbox provider (send to Outlook leads from Outlook inboxes, Google leads from Google), and drop domains with no MX. |
| MSP / security consultant | Find prospects with no DMARC, p=none or broken SPF. Every row comes with a ready-made list of issues to pitch. |
| DMARC / email security vendor | Build target lists by provider, gateway, current DMARC vendor and policy maturity. |
| IT / security team | Audit all of your own brands' domains, including parked ones, in one run. |
| Deliverability specialist | Check clients' SPF lookup counts, DKIM keys and alignment basics before a migration. |
What data do you get?
emailProvider,emailSecurityGateway,mxRecords(each MX host classified)grade(A-F),score(0-100),spoofable,bulkSenderCompliantspf: record, validity,allQualifier,lookupCount, includes, senders, issuesdmarc: record,policy,subdomainPolicy,pct,rua/ruf,reportingVendor(dmarcian, Valimail, EasyDMARC, Red Sift, Proofpoint, Mimecast, Cloudflare...), issuesdkim: selectors found, key size, revoked keysmtaSts,tlsRpt,bimi(logo and VMC URLs)emailSendingServices: services authorised to send for the domainissues: human-readable list of problems, e.g. "DMARC policy is p=none (monitoring only): spoofed mail is still delivered."- Flat columns (
dmarcPolicy,spfValid,dkimFound,mxHosts,sendingServices) for easy spreadsheet filtering
Sample output (trimmed)
Real output for basecamp.com (trimmed):
{"domain": "basecamp.com","emailProvider": "Google Workspace","emailSecurityGateway": null,"grade": "B","score": 77,"spoofable": false,"dmarcPolicy": "quarantine","spfValid": true,"spfLookupCount": 3,"dkimFound": true,"sendingServices": "Google Workspace, Mailchimp","issues": ["DMARC has no rua= reporting address, so abuse goes unnoticed.","No MTA-STS policy: inbound mail can be downgraded to unencrypted delivery."]}
A domain behind a security gateway, e.g. gymshark.com, comes back as "emailProvider": "Microsoft 365" with "emailSecurityGateway": "Proofpoint" and "dmarcReportingVendor": "Proofpoint EFD".
How to use it
- Paste domains or email addresses (one per line). Emails are converted to their domain and duplicates removed.
- Click Start.
- Filter the Overview table by provider or grade, or export to CSV/Excel/JSON or your CRM.
curl -X POST "https://api.apify.com/v2/acts/plainsight~email-security-audit/run-sync-get-dataset-items?token=YOUR_API_TOKEN" \-H "Content-Type: application/json" \-d '{"domains": ["stripe.com", "jane@basecamp.com"]}'
Pricing
$0.002 per domain audited ($2 per 1,000). Domains that don't exist (NXDOMAIN) are free.
Try it free: start a run with an empty input and it analyses 3 sample websites at no charge, so you can see the exact output format first.
FAQ
How accurate is DKIM detection? DKIM keys live under selector names that aren't published anywhere, so no tool can list them all. This Actor checks 35 selectors used by the most common providers (Google, Microsoft 365, Mailchimp, SendGrid, Proton, Fastmail, Zoho, Klaviyo and more). If none match, the report says "not found on common selectors" rather than claiming DKIM is missing.
Does it send any email? No. It only performs public DNS lookups. Nothing is sent to the domains being checked.
What counts as "spoofable"?
A domain with no DMARC record, or with p=none, gives receivers no instruction to reject forged mail, so attackers can send email that appears to come from it.
Related tools by the same developer
- Company Enrichment: email provider plus company profile, contacts, tech stack and domain age.
- Tech Stack Detector: 7,600+ website technologies plus internal SaaS tools from DNS.
- Website Contact Extractor: emails, phones and social profiles from websites.
- SEO & AI Visibility Audit: security headers, TLS, robots.txt and AI-crawler access per page.