Website Tech Stack Detector + DNS & WHOIS Lookup avatar

Website Tech Stack Detector + DNS & WHOIS Lookup

Pricing

from $2.00 / 1,000 domain analyses

Go to Apify Store
Website Tech Stack Detector + DNS & WHOIS Lookup

Website Tech Stack Detector + DNS & WHOIS Lookup

Detect the tech stack of any website: CMS, ecommerce platform, analytics, CDN and 7,600+ technologies, plus email provider, DNS host and WHOIS (RDAP) data.

Pricing

from $2.00 / 1,000 domain analyses

Rating

0.0

(0)

Developer

Dave West

Dave West

Maintained by Community

Actor stats

1

Bookmarked

2

Total users

1

Monthly active users

21 hours ago

Last modified

Share

Find out what any website is built with: CMS, ecommerce platform, analytics and tag managers, CDN and hosting, JavaScript frameworks, payment providers, marketing tools and 7,600+ other technologies. Each domain also gets SEO signals (HTTPS, HTTP/2, robots.txt, sitemap), its email provider (Google Workspace, Microsoft 365, ...), DNS host, SaaS verification records and domain WHOIS data via RDAP (registrar, creation and expiry dates).

Paste a list of domains and get one clean row per domain, ready for CSV, Excel, Google Sheets or your CRM. One plain HTTP request per homepage, no browser, so it is fast and cheap: about $3 per 1,000 domains with everything switched on.

Use cases

  • Lead generation by technology: build lists of stores on Shopify, WooCommerce, Magento or BigCommerce, sites using HubSpot, Klaviyo or Intercom, or companies on Google Workspace vs. Microsoft 365. Use the onlyWithTech filter and pay only for matching domains.
  • Sales prospecting: qualify accounts before outreach. Which CMS, which analytics, which payment provider, how old is the domain, which SaaS tools have they verified their domain with?
  • Competitor research: see the stack behind competitors' sites (platform, CDN, A/B testing, reviews, chat, consent tools) and how it changes over time.
  • SEO audits at scale: check HTTPS, HTTP/2, robots.txt, sitemap presence and Googlebot access for hundreds of sites at once. For a deep page-by-page audit of one site, use Sitemap SEO Audit & Monitor.
  • Market research: measure the market share of platforms in a country or niche with the run summary (technology counts and most common stacks).
  • Domain portfolio and security checks: registrar, expiry dates, EPP status, DMARC policy, SPF senders.

What is detected

AreaExamplesOutput fields
CMSWordPress, Drupal, Joomla, Webflow, Wix, Squarespace, HubSpot CMS, Contentful, Sanity, Ghostcms
Ecommerce platformShopify, WooCommerce, Magento, BigCommerce, PrestaShop, Shopware, Squarespace Commerceecommerce
Analytics & tag managersGoogle Analytics, Google Tag Manager, Matomo, Hotjar, Plausible, New Relicanalytics, tagManagers
CDN & hostingCloudflare, Fastly, Akamai, Amazon CloudFront, Vercel, Netlify, WP Engine, Kinstacdn, hosting
Frameworks & languagesReact, Next.js, Vue, Nuxt, Angular, Svelte, Astro, Laravel, PHP, Node.jsjsFrameworks, webFrameworks, programmingLanguages
Marketing & salesKlaviyo, Mailchimp, HubSpot, Marketo, Intercom, Zendesk, DriftmarketingAutomation, liveChat
PaymentsStripe, PayPal, Shop Pay, Klarna, Afterpay, Apple Paypayments
Moreadvertising pixels, cookie consent, A/B testing, reviews, page builders, WordPress plugins, Shopify apps, security headersadvertising, cookieConsent, abTesting, reviews, pageBuilders, themesAndPlugins, security
SEO signalsHTTPS, HTTP/2, HTTP/3 advertised, redirects, robots.txt, sitemap URL, Googlebot access, title, meta description, languagehttps, http2, robotsTxtPresent, sitemapUrl, ...
DNSA/AAAA, MX → email provider, NS → DNS host, SPF senders, TXT verification records (Google, Microsoft 365, Meta, Stripe, Atlassian, OpenAI, ...), DMARC policyemailProvider, dnsHost, spfServices, saasVerifications, dmarcPolicy
WHOIS (RDAP)registrar, created / updated / expiry dates, domain age, EPP statusregistrar, domainCreatedAt, domainExpiresAt, domainAgeYears, domainStatus

Every technology comes with its categories, the version where the site reveals it (e.g. WordPress 6.6.2, Nginx 1.25.3), a confidence score (0-100) and detectedBy (the evidence: headers, cookies, meta, script URLs, HTML, DOM, implied, or DNS/IP). Detection uses response headers, cookies, meta tags, script and stylesheet URLs, inline scripts and the HTML/DOM of the homepage.

Privacy: the RDAP lookup returns registrar-level data only. Registrant names, emails, phone numbers and addresses are never output, even when a registry publishes them.

Quick start

  1. Paste your domains (one per line; example.com, www.example.com and full URLs all work).
  2. Keep DNS + WHOIS enrichment on if you want email provider, DNS host and registration data.
  3. Optional: add Shopify (or any technology) under Only output sites using these technologies to get a lead list.
  4. Run, then download the dataset as CSV/Excel/JSON or open the HTML report.

Leave the domain list empty for a free preview on five example sites (nothing is charged).

Input example

{
"domains": ["ruggable.com", "wordpress.org", "https://www.coolblue.nl", "stripe.com"],
"enrichDnsWhois": true,
"checkSeoFiles": true,
"onlyWithTech": [],
"onlyWithCategory": [],
"minConfidence": 50,
"maxConcurrency": 10
}

Lead list of Shopify stores that use Klaviyo:

{ "domains": ["..."], "onlyWithTech": ["Klaviyo"], "onlyWithCategory": ["Ecommerce"] }

Within one filter list any entry may match (OR); when both lists are given, both must match (AND). Technology names are matched exactly and case-insensitively, and onlyWithTech also matches email providers, DNS hosts and SaaS records (e.g. Google Workspace, HubSpot, Stripe).

Output

One flat row per domain. technologies is an array of objects; all other list fields are comma-separated strings, so CSV and Excel exports stay readable. Real example (shortened technologies):

{
"domain": "ruggable.com",
"finalUrl": "https://ruggable.com/",
"statusCode": 200,
"blocked": false,
"technologies": [
{ "name": "Cloudflare", "categories": ["CDN"], "version": null, "confidence": 100, "detectedBy": ["headers"] },
{ "name": "Contentful", "categories": ["CMS"], "version": null, "confidence": 100, "detectedBy": ["html"] },
{ "name": "Next.js", "categories": ["JavaScript frameworks", "Web frameworks"], "version": null, "confidence": 100, "detectedBy": ["headers"] },
{ "name": "Shopify", "categories": ["Ecommerce", "CMS"], "version": null, "confidence": 50, "detectedBy": ["dom"] }
],
"technologyNames": "Cloudflare, Cloudflare Bot Management, Cloudflare Browser Insights, Contentful, Google Tag Manager, HSTS, Next.js, Node.js, Open Graph, React, Swiper, Vercel, Webpack, Shopify",
"technologyCount": 14,
"cms": "Contentful, Shopify",
"ecommerce": "Shopify",
"tagManagers": "Google Tag Manager",
"cdn": "Cloudflare",
"title": "Washable Rugs & Washable Area Rugs by Ruggable | Ruggable US",
"https": true,
"http2": true,
"robotsTxtPresent": true,
"sitemapPresent": true,
"sitemapUrl": "https://ruggable.com/sitemap.xml",
"emailProvider": "Mimecast",
"dnsHost": "Cloudflare",
"saasVerifications": "Airtable, Anthropic, Apple, Atlassian, Google Search Console, Jamf, Klaviyo, Microsoft 365, Notion, Shopify, Smartsheet, Zoom",
"dmarcPolicy": "quarantine",
"registrar": "GoDaddy.com, LLC",
"domainCreatedAt": "2009-11-20T02:32:02.000Z",
"domainExpiresAt": "2031-11-20T02:32:02.000Z",
"domainAgeYears": 16.9,
"chargedEvents": ["domain-analyzed", "dns-rdap-enrichment"]
}

More real results from a test run (October 2026):

DomainPlatformCDN / hostingEmail provider
allbirds.comShopifyCloudflareMicrosoft 365
techcrunch.comWordPress (WordPress VIP, Yoast SEO)-Mimecast
porterandyork.comWordPress + WooCommerce, ElementorCloudflare, WP EngineGoogle Workspace
huel.comShopify + Sanity, Next.jsVercel, ImgixGoogle Workspace
wix.comWix, ReactGoogle Cloud CDNGoogle Workspace
mozilla.orgWagtail-Google Workspace
coolblue.nlcustom (Emotion)Amazon CloudFrontGoogle Workspace

Dataset views: Overview, Technologies, SEO signals, DNS & WHOIS and Blocked & failed.

The key-value store also contains:

  • SUMMARY: technology counts and market share across all domains, most common stacks (e.g. Cloudflare + Shopify), category breakdowns, email providers, DNS hosts, SaaS records, blocked and failed domains, charges.
  • OUTPUT.html: a one-page HTML report with the same numbers and a domain table.

Blocked sites

Some big-brand websites sit behind bot protection (Cloudflare, Akamai, DataDome, AWS WAF, Vercel, ...) and answer a plain request with a challenge page, HTTP 403 or HTTP 429. Those rows are returned with blocked: true and a blockedReason, still include DNS, email provider and WHOIS data and the detections that the response headers reveal (e.g. Cloudflare, DataDome), and are not charged as an analysed domain. Hosted platforms are also recognised from the site's IP address (Shopify, Squarespace, Wix, Vercel, Netlify, GitHub Pages), so a rate-limited Shopify store still shows up as Shopify (detectedBy: ["dns"], confidence 75) and matches a Shopify filter.

Expect a share of large consumer brands to be partly blocked, and some busy Shopify stores to answer with HTTP 429 when many requests come from cloud servers. Small and medium sites are rarely affected. The Actor does not use proxies or headless browsers to get around protections.

Pricing

Pay per event, no subscription:

EventPriceWhen
Domain analysed (domain-analyzed)$0.002per domain row whose homepage was fetched and analysed (technologies + SEO signals)
DNS + WHOIS enrichment (dns-rdap-enrichment)$0.001per domain when enrichment is on and DNS returned records
  • 1,000 domains with everything on: about $3. Without enrichment: about $2.
  • Free: domains that do not resolve or never answer (DNS failure, timeout, connection or TLS error), blocked/challenged homepages (only the enrichment is charged when it returned data), domains removed by your filters, and preview runs with an empty domain list.
  • The run stops cleanly when your maximum total charge per run is reached, so you never pay more than you set.

FAQ

How accurate is the detection? It uses an open, MIT-licensed database of 7,600+ technology fingerprints and checks headers, cookies, meta tags, script URLs, inline scripts and the HTML of the homepage. Platforms (CMS, ecommerce, CDN, server) are detected very reliably. Tools that are injected later by JavaScript (for example analytics loaded through a tag manager) can be missed because the page is not rendered in a browser.

Why only the homepage? The stack is almost always site-wide and the homepage reveals it. One request per site keeps runs fast and cheap.

Some fields are empty for a domain. Why? Empty means "not detected": the site may not use that kind of tool, or it is loaded in a way that a plain HTTP request cannot see. expiresAt is missing for some country-code domains whose registry does not publish it, and some TLDs (for example .de, .so, .io) have no public RDAP server, which is noted in enrichmentError.

Is it polite to the websites? Yes. Each site gets at most three small requests (robots.txt, homepage, sitemap check) with an honest User-Agent; robots.txt is respected by default, and the default concurrency is 10 different sites in parallel.

Can I filter for several technologies? Yes: onlyWithTech: ["Shopify", "WooCommerce", "BigCommerce"] keeps a domain if any of them is found. Add onlyWithCategory to require a category as well.

Can I run it on a schedule or via API? Yes, like every Apify Actor: schedule it in the Console, call it from the API, or connect it to Make, Zapier, n8n or Google Sheets.

Does it return personal data? No. Only technical and registrar-level information is collected; registrant contact data from WHOIS/RDAP is deliberately dropped.

Credits and licenses

Technology fingerprints and categories come from projectdiscovery/wappalyzergo v0.3.3 (MIT License, Copyright (c) 2021 ProjectDiscovery, Inc.). The data is vendored unmodified in data/ with its license (data/LICENSE.md, data/NOTICE.md). Registration data comes from the registries' public RDAP services via the IANA bootstrap registry.

Support

Found a wrong or missing detection? Open an issue on the Actor's Issues tab with the domain and what you expected.