Email Provider & DMARC Checker - SPF, DKIM, DMARC Audit avatar

Email Provider & DMARC Checker - SPF, DKIM, DMARC Audit

Pricing

from $2.00 / 1,000 domain auditeds

Go to Apify Store
Email Provider & DMARC Checker - SPF, DKIM, DMARC Audit

Email Provider & DMARC Checker - SPF, DKIM, DMARC Audit

Bulk-check which email provider a domain uses (Google Workspace, Microsoft 365, Zoho, Proofpoint, Mimecast...) and grade its email security: SPF, DKIM, DMARC policy, MTA-STS, BIMI. Finds spoofable domains and sending tools (HubSpot, SendGrid, Mailchimp...). $2 per 1,000 domains.

Pricing

from $2.00 / 1,000 domain auditeds

Rating

0.0

(0)

Developer

kaleb ashton

kaleb ashton

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

2 days ago

Last modified

Share

Email Provider & DMARC Checker: bulk SPF, DKIM, DMARC audit

For any list of domains (or email addresses), find out who hosts their email (Google Workspace, Microsoft 365, Zoho, Proton, GoDaddy and 60+ more, including security gateways like Proofpoint, Mimecast and Barracuda) and how well the domain is protected against spoofing: SPF, DKIM, DMARC, MTA-STS, TLS-RPT and BIMI, summarised as an A-F grade with plain-English issues.

  • 📮 Email provider detection with security-gateway awareness (a domain behind Proofpoint is still identified as Microsoft 365 or Google Workspace when the records show it)
  • 🛡️ Full authentication audit: SPF syntax, all qualifier and recursive 10-DNS-lookup limit check; DMARC policy, pct, reporting addresses and reporting vendor; 35 common DKIM selectors with key size; MTA-STS, TLS-RPT, BIMI
  • 🚩 Flags spoofable domains (no DMARC or p=none) and Google/Yahoo/Microsoft bulk-sender compliance
  • 📤 Lists the services a domain sends email through (HubSpot, Salesforce, SendGrid, Mailchimp, Zendesk, Klaviyo...)
  • ⚡ DNS-only, so it's fast and cheap: $2 per 1,000 domains

What can you use it for?

You are...Use it to...
Cold email / lead gen agencySegment prospects by mailbox provider (send to Outlook leads from Outlook inboxes, Google leads from Google), and drop domains with no MX.
MSP / security consultantFind prospects with no DMARC, p=none or broken SPF. Every row comes with a ready-made list of issues to pitch.
DMARC / email security vendorBuild target lists by provider, gateway, current DMARC vendor and policy maturity.
IT / security teamAudit all of your own brands' domains, including parked ones, in one run.
Deliverability specialistCheck clients' SPF lookup counts, DKIM keys and alignment basics before a migration.

What data do you get?

  • emailProvider, emailSecurityGateway, mxRecords (each MX host classified)
  • grade (A-F), score (0-100), spoofable, bulkSenderCompliant
  • spf: record, validity, allQualifier, lookupCount, includes, senders, issues
  • dmarc: record, policy, subdomainPolicy, pct, rua/ruf, reportingVendor (dmarcian, Valimail, EasyDMARC, Red Sift, Proofpoint, Mimecast, Cloudflare...), issues
  • dkim: selectors found, key size, revoked keys
  • mtaSts, tlsRpt, bimi (logo and VMC URLs)
  • emailSendingServices: services authorised to send for the domain
  • issues: human-readable list of problems, e.g. "DMARC policy is p=none (monitoring only): spoofed mail is still delivered."
  • Flat columns (dmarcPolicy, spfValid, dkimFound, mxHosts, sendingServices) for easy spreadsheet filtering

Sample output (trimmed)

Real output for basecamp.com (trimmed):

{
"domain": "basecamp.com",
"emailProvider": "Google Workspace",
"emailSecurityGateway": null,
"grade": "B",
"score": 77,
"spoofable": false,
"dmarcPolicy": "quarantine",
"spfValid": true,
"spfLookupCount": 3,
"dkimFound": true,
"sendingServices": "Google Workspace, Mailchimp",
"issues": [
"DMARC has no rua= reporting address, so abuse goes unnoticed.",
"No MTA-STS policy: inbound mail can be downgraded to unencrypted delivery."
]
}

A domain behind a security gateway, e.g. gymshark.com, comes back as "emailProvider": "Microsoft 365" with "emailSecurityGateway": "Proofpoint" and "dmarcReportingVendor": "Proofpoint EFD".

How to use it

  1. Paste domains or email addresses (one per line). Emails are converted to their domain and duplicates removed.
  2. Click Start.
  3. Filter the Overview table by provider or grade, or export to CSV/Excel/JSON or your CRM.
curl -X POST "https://api.apify.com/v2/acts/plainsight~email-security-audit/run-sync-get-dataset-items?token=YOUR_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{"domains": ["stripe.com", "jane@basecamp.com"]}'

Pricing

$0.002 per domain audited ($2 per 1,000). Domains that don't exist (NXDOMAIN) are free.

Try it free: start a run with an empty input and it analyses 3 sample websites at no charge, so you can see the exact output format first.

FAQ

How accurate is DKIM detection? DKIM keys live under selector names that aren't published anywhere, so no tool can list them all. This Actor checks 35 selectors used by the most common providers (Google, Microsoft 365, Mailchimp, SendGrid, Proton, Fastmail, Zoho, Klaviyo and more). If none match, the report says "not found on common selectors" rather than claiming DKIM is missing.

Does it send any email? No. It only performs public DNS lookups. Nothing is sent to the domains being checked.

What counts as "spoofable"? A domain with no DMARC record, or with p=none, gives receivers no instruction to reject forged mail, so attackers can send email that appears to come from it.