Bulk DMARC, SPF & DKIM Checker — Email Domain Security Audit avatar

Bulk DMARC, SPF & DKIM Checker — Email Domain Security Audit

Pricing

from $3.00 / 1,000 domain auditeds

Go to Apify Store
Bulk DMARC, SPF & DKIM Checker — Email Domain Security Audit

Bulk DMARC, SPF & DKIM Checker — Email Domain Security Audit

Check SPF, DKIM, DMARC, MX, BIMI, MTA-STS, TLS-RPT and DNSSEC for thousands of domains. Get a 0-100 score, A–F grade, spoofability flag, Gmail/Yahoo bulk-sender compliance and exact fixes. DNS-only, no API key.

Pricing

from $3.00 / 1,000 domain auditeds

Rating

0.0

(0)

Developer

Probelane

Probelane

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

an hour ago

Last modified

Categories

Share

Audit email authentication for thousands of domains at once. For every domain, this DMARC checker tests SPF, DKIM, DMARC, MX, BIMI, MTA-STS, TLS-RPT and DNSSEC. It returns a 0–100 security score, an A–F grade, a spoofable yes/no flag, a Gmail & Yahoo bulk-sender readiness flag, and a prioritised list of issues with the exact DNS fix for each one.

The audit runs on DNS only. It sends no email, scrapes nothing and needs no API key, so it is cheap and safe to run on any list: 100 domains take about 2 minutes on the Apify platform.

What does it check?

CheckWhat you get
SPFThe record itself, a validity check, the all qualifier (‑all/~all/?all/+all), a recursive DNS-lookup count against the 10-lookup limit, broken includes, duplicate records, and detected senders (Google, Microsoft 365, SendGrid, Mailchimp, HubSpot, Amazon SES, Salesforce …)
DMARCPolicy (none/quarantine/reject), subdomain policy, pct, rua/ruf reporting addresses, alignment mode, and inheritance from the parent domain
DKIMProbes about 60 common ESP selectors plus any you add. Reports keys found, 1024-bit weak keys, revoked keys and wildcard records
MXMail servers, null MX, and mail provider detection (Google Workspace, Microsoft 365, Proofpoint, Mimecast, Cisco, Zoho …)
BIMIRecord, logo URL and VMC certificate presence
MTA-STS / TLS-RPTRecords, plus the live policy mode (enforce/testing) read from the public policy file
DNSSECWhether the domain is signed (DS record at the parent)

Who is it for?

  • MSPs and IT consultants. Audit every client domain and send each one a fix list.
  • Email deliverability agencies and cold-email teams. Check sending domains against the Google and Yahoo bulk-sender requirements (SPF + DKIM + DMARC).
  • Security teams. Find spoofable domains across a brand portfolio or supply chain.
  • Sales prospecting for agencies. Build a list of prospects whose email is spoofable or will fail Gmail/Yahoo rules, with the exact problem to open the conversation with.
  • Lead generation. Turn on "Output only domains that fail" and you get a list of companies that need DMARC help, along with the reason.

Pricing: pay per result, nothing else

This Actor uses Apify pay-per-event pricing, so the price is simple and predictable:

You payWhen
$0.003 per domain ($3 per 1,000)Once for each domain that returns a result (event domain-audited). Every charged row in the dataset has "charged": true.
$0.00005 per runApify's standard Actor-start fee.
$0Invalid inputs, domains that do not exist in DNS (status: nxdomain) and unexpected errors.

There are no platform-usage fees on top of the event price: compute, storage and traffic are included.

Run sizeCost
100 domains$0.30
1,000 domains$3.00
10,000 domains$30.00
100,000 domains$300.00

Control your spend. Set Max cost per run (Run options → "Maximum cost per run", or maxTotalChargeUsd in the API). The Actor checks your remaining budget before every domain, stops cleanly when the limit is reached and never charges beyond it. The status message tells you how many domains were left unprocessed.

Try it free. Apify's free plan includes $5 of monthly credit, enough for about 1,666 domains.

Lead-gen mode note. With Output only domains that fail switched on, passing domains are still audited and charged, but are left out of the dataset to keep your list clean. Their count is shown in the final status message and in the RUN_SUMMARY record of the run's key-value store.

Input

{
"domains": ["apify.com", "github.com", "paypal.com", "jane@takealot.co.za"],
"dkimSelectors": ["s1"],
"probeCommonSelectors": true,
"onlyFailing": false,
"failBelowScore": 70
}

Email addresses and URLs are accepted. A leading www. is stripped, and other subdomains are kept, because mail is often sent from subdomains such as mail.example.com.

Output example

{
"domain": "apify.com",
"grade": "A",
"securityScore": 97,
"spoofable": false,
"meetsGoogleYahooBulkSenderRules": true,
"mailProvider": "Google Workspace",
"spfRecord": "v=spf1 include:_spf.google.com … -all",
"spfAllQualifier": "fail (-all)",
"spfDnsLookups": 10,
"dmarcPolicy": "reject",
"dkimStatus": "found",
"dkimSelectorsFound": [{"selector": "google", "keyBits": 2048}],
"mtaStsMode": "enforce",
"bimiRecord": "v=BIMI1; l=https://…",
"topIssue": "1024-bit DKIM key on selector(s) intercom.",
"issues": [
{"severity": "low", "check": "DKIM", "issue": "1024-bit DKIM key on selector(s) intercom.", "fix": "Rotate to a 2048-bit key."}
],
"status": "ok",
"charged": true
}

Scoring

Points are awarded as follows:

  • SPF: 25
  • DMARC: 35 (reject > quarantine > none, plus pct and rua)
  • DKIM: 20
  • MX: 5
  • MTA-STS, TLS-RPT, BIMI and DNSSEC: 15 combined

Grades map to scores as A ≥ 85, B ≥ 70, C ≥ 55, D ≥ 40, F below 40. A domain that publishes v=spf1 -all is treated as non-sending and is not penalised for missing DKIM.

FAQ

Why does it say "DKIM not found" when I use DKIM? DKIM keys sit under a selector that cannot be listed from outside. The Actor tries about 60 common selectors. If your provider uses a custom one, add it in dkimSelectors. In that case dkimStatus is not_found_on_common_selectors, not a confirmed failure.

Does it send test emails? No. It only reads DNS and fetches the public MTA-STS policy file.

What is the charged field? It is true on every row you paid for, so the bill always matches the dataset. Rows for invalid or non-existent domains are delivered with an error and are free.

Can AI agents use it? Yes. It runs with limited permissions and per-result pricing, so it works through the Apify API, the Apify MCP server and other AI-agent integrations.

Can I monitor domains over time? Yes. Schedule the Actor weekly and connect it to Slack, email or Google Sheets to catch DMARC or SPF changes.

Keywords: dmarc checker, spf checker, dkim checker, bulk dmarc lookup, email deliverability, email deliverability audit, email authentication checker, spf record check, mta-sts check, bimi checker, google yahoo bulk sender requirements, cold email domain check, lead generation, sales prospecting, MSP, agencies, email security audit.