Security & Website Pain Prospect Finder for MSPs avatar

Security & Website Pain Prospect Finder for MSPs

Pricing

$15.00 / 1,000 company scoreds

Go to Apify Store
Security & Website Pain Prospect Finder for MSPs

Security & Website Pain Prospect Finder for MSPs

Turn a list of company websites into a scored, pitch-ready prospect list. Finds spoofable email domains (DMARC/SPF/DKIM), expired SSL, sites down, outdated WordPress/PHP, no HTTPS and expiring domains — with evidence, a 0-100 opportunity score and a cold-open line.

Pricing

$15.00 / 1,000 company scoreds

Rating

0.0

(0)

Developer

Probelane

Probelane

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

an hour ago

Last modified

Share

Security & Website Pain Prospect Finder

Paste a list of company websites. Get back a ranked prospect list your sales team can work today: each company's biggest security or website problem, the exact proof, why it costs them money, an opportunity score from 0 to 100, and a one-line cold opener.

Built for MSPs, cybersecurity firms, web agencies, IT consultants and email-deliverability specialists who sell to small and mid-sized businesses. A plain lead list tells you who exists. This tells you who has a problem you can fix, and gives you the opener.

  • 🎯 One sales-ready row per company, sorted best prospect first
  • 🔎 Evidence you can quote: the actual DMARC/SPF record, certificate dates, HTTP status, software version or missing header
  • 💬 Plain-English "why it matters" (for example "anyone can send email as @acme.com → invoice-fraud risk") plus a suggested offer and a cold-open line
  • 📊 Opportunity score 0–100 to prioritise call lists and sequences
  • 💸 Pay only for companies you receive. Invalid inputs, non-existent domains and companies below your minimum score are free.
  • 🛡️ Passive and public only: DNS lookups, one homepage visit, a TLS handshake and a registry lookup. No port scanning, no logins, no exploitation.

What it finds

SignalExample evidenceWhy buyers care
Spoofable email domain: no DMARC, or DMARC p=noneNo DMARC TXT record at _dmarc.acme.com. SPF: "v=spf1 include:spf.protection.outlook.com ~all"Anyone can send email as @acme.com, the setup behind fake-invoice and "our bank details changed" scams. Gmail, Yahoo and Microsoft now require DMARC for bulk senders.
Broken SPF: missing, +all, two records, more than 10 lookupsSPF: "v=spf1 a mx include:… +all"Their own invoices and quotes land in spam, and forged mail gets through
No DKIMNo DKIM key on 59 common selectorsWeaker deliverability, and fails the Gmail/Yahoo sender rules
SSL expired, invalid or expiringCertificate … valid to 2026-07-23, error: certificate has expiredBrowsers show a full-page warning and visitors leave
No HTTPS / no HTTP→HTTPS redirectTLS on acme.com:443 failed; site served at http://www.acme.com/Chrome marks the site "Not secure", so contact-form leads drop
Website down, 5xx, suspended or placeholderGET https://acme.com/ → HTTP 503 / page title "Domain Registered"Lost enquiries. This is a strong web-agency lead.
Slow websiteGET https://www.acme.com/: 9,500 msVisitors bounce and Google ranks the site lower
Outdated or end-of-life software: WordPress, PHP, Drupal, Joomla, Magento 1, jQuery below 3.5WordPress 6.0.16 (current 7.1) / X-Powered-By: PHP/7.4.33Prime target for automated hacking bots. A natural lead for a maintenance retainer.
Domain expired or expiring within 30 daysRegistry expiry date: 2026-10-26If auto-renew is off, the website and every mailbox go dark
Missing security headers / version leaksMissing: HSTS, Content-Security-Policy, X-Frame-OptionsFails client security questionnaires

Every row also includes the detected stack (CMS and version, PHP, hosting/CDN, certificate issuer) and the mail provider (Microsoft 365, Google Workspace, Proofpoint, or "hosting-provider mail", which is often a migration opportunity).

Example output

Real run on 51 small accountants, law firms and dental practices in South Africa and the USA (company names anonymised):

#CompanyScoreSeverityTop problemEvidenceCold-open line
1Example Tax & Accounting81criticalDomain can be spoofed: no DMARC recordNo DMARC TXT record at _dmarc.example-tax.com. SPF: none."Quick heads-up: anyone can currently send email that looks like it's from @example-tax.com because there's no DMARC record. I can send you the exact DNS fix; it takes about 15 minutes."
2Example Attorneys Inc.81criticalDomain can be spoofed: no DMARC record (+ outdated WordPress 6.0)No DMARC TXT record … SPF: "v=spf1 +a +mx … ~all""Quick heads-up: anyone can currently send email that looks like it's from @example-attorneys.co.za…"
4Example Accounting & Tax76criticalSSL certificate expiredCertificate for example.co.za: issuer Sectigo Limited, valid to 2026-07-23T23:59:59Z"Visitors to example.co.za currently get a browser security warning (certificate expired). It's usually a same-day fix."
18Example Labour Law68highDomain can be spoofed: DMARC is monitor-only (+ host placeholder page instead of a website)_dmarc.example.co.za: "v=DMARC1; p=none;""Your DMARC record for @example.co.za is still on p=none, which means spoofed emails using your domain still get delivered…"
22Example CPA52highNo HTTPS: site only works over plain HTTPTLS on example.com:443 failed; site served at http://www.example.com/"Chrome shows example.com as 'Not secure' because it has no HTTPS…"

From that run: 30 of 51 firms with mailboxes on their domain could be spoofed (no DMARC or p=none), 1 had an expired certificate, 2 had no HTTPS at all, 1 showed a host "coming soon" page instead of a website, 3 had a domain expiring within 30 days, and 10 were running vulnerable jQuery, outdated WordPress or end-of-life PHP.

Full row (JSON, abridged):

{
"rank": 1,
"company": "Example Tax & Accounting",
"domain": "example-tax.com",
"website": "https://www.example-tax.com/",
"opportunityScore": 81,
"severity": "critical",
"topProblem": "Domain can be spoofed: no DMARC record",
"evidence": "No DMARC TXT record at _dmarc.example-tax.com. SPF: none.",
"whyItMattersCommercially": "Anyone can send email that appears to come from @example-tax.com and receivers have no instruction to block it — the setup behind invoice-fraud and 'our bank details changed' scams…",
"suggestedPitch": "Email-authentication hardening: publish DMARC (p=none + reporting), fix SPF/DKIM, move to p=reject in 4–6 weeks, then monthly DMARC monitoring.",
"coldOpenLine": "Quick heads-up: anyone can currently send email that looks like it's from @example-tax.com because there's no DMARC record — I can send you the exact DNS fix, it takes about 15 minutes.",
"otherSignals": "[high] No SPF record | [medium] No DKIM signing key found | [low] Missing security headers (grade F)",
"signalCount": 4,
"detectedStack": "ProSites · SSL: ZeroSSL GmbH",
"mailProvider": "Google Workspace",
"niche": "CPA",
"location": "Boise ID US",
"source": "input",
"checkedAt": "2026-10-07T03:47:12Z",
"signals": [ { "code": "no_dmarc", "severity": "critical", "problem": "…", "evidence": "…" } ]
}

How to use it

  1. Add companies. Use any of these:
    • Company websites: one per line, as a domain, URL or email. You can add labels separated by commas: acme.co.za, Acme Attorneys, law firm, Durban.
    • CSV / Google Sheet URL: a public CSV link. Columns are detected by name (domain/website/url, company/name, niche/industry, location/city).
    • Discovery pages (optional): a public directory or member-list page you are allowed to use. The Actor collects the company websites it links to.
  2. Optionally set a niche/location label and a minimum opportunity score.
  3. Click Start. Results are sorted by opportunity score. Open the Prospects view, or download CSV / Excel / JSON.

Output views: Prospects (overview), CSV / CRM export (all flat columns), Outreach sheet (company, website, problem, opener, pitch) and Technical evidence (raw DMARC/SPF records, SSL dates, HTTP status, domain expiry). A sorted prospects.csv is also saved in the run's key-value store.

Use cases

  • MSPs and IT providers: find local firms on hosting-provider mail with no DMARC, then lead with a free "email spoofing check" and convert to Microsoft 365 / Google Workspace security and monitoring.
  • Cybersecurity consultants and vCISOs: build a target list of accountants, law firms and clinics (which handle payments and sensitive data) that are exposed to invoice fraud, and open with evidence instead of fear.
  • Web agencies: find businesses with expired SSL, no HTTPS, placeholder or suspended sites, slow pages or WordPress versions years out of date. These are ready-made redesign and maintenance-plan leads.
  • Email deliverability and DMARC vendors: segment by dmarcPolicy (none vs missing) and mail provider.
  • Account managers: run the list against your existing clients to find upsell work and fix gaps before a competitor points them out.

Pricing

Pay per event: $0.015 per company scored. That is $1.50 per 100 companies or $15 per 1,000, and there is no subscription.

  • You are charged only for companies delivered in your results.
  • Free: invalid inputs, domains that don't exist, duplicates, and companies hidden by your minimum opportunity score.
  • The Actor respects your maximum cost per run. It stops cleanly once the limit is reached and still returns a sorted list.
  • Platform usage is included in the price (no separate compute bill).
  • Apify's minimum maximum cost per run for this Actor is $0.50 (about 33 companies). Smaller lists simply cost less.

One closed deal from a 1,000-company scan typically pays for the scan many times over.

Feed it into your CRM, Sheets, Make or Zapier

  • Google Sheets: use the Export to Google Sheets integration in the run's Integrations tab, or =IMPORTDATA("https://api.apify.com/v2/datasets/<DATASET_ID>/items?format=csv&view=flat&clean=1") (a public dataset or a token-authenticated URL).
  • Make / Zapier / n8n: use the official Apify app, trigger "Actor run finished", then "Get dataset items" (view=outreach), and map company, website, topProblem and coldOpenLine into HubSpot, Pipedrive, Close, Instantly, lemlist or Apollo custom fields.
  • API: GET https://api.apify.com/v2/datasets/<DATASET_ID>/items?view=flat&format=csv, or call the Actor synchronously with run-sync-get-dataset-items.
  • Schedules: re-scan your prospect or client list monthly and alert on new critical findings (for example an SSL certificate about to expire).

Tip: put {{coldOpenLine}} as the first line of a cold email and {{evidence}} in a follow-up. Specific, verifiable observations get far more replies than generic "we do IT security" pitches.

FAQ

Is this legal and ethical? The Actor uses only public, passive information that any browser or mail server sees: DNS records, one normal homepage request, the TLS certificate and public registry (RDAP/WHOIS) data. It does no port scanning, vulnerability probing, login attempts or exploitation. Use the results responsibly: present findings helpfully, follow anti-spam and privacy laws in your region (for example CAN-SPAM, GDPR, POPIA), and honour opt-outs.

How accurate is "no DKIM"? DKIM keys sit under selector names that can't be listed. The Actor checks 59 common selectors (Microsoft 365, Google, major ESPs). A provider with a custom selector can show as "not found", so this signal is scored medium and worded carefully.

Why is a site marked slow? The time is measured for the successful homepage request (including redirects) from Apify's cloud. It is flagged above 6 seconds, which is a real-world problem, not a lab metric.

How is the opportunity score calculated? Each signal has a severity weight (critical > high > medium > low), and the weights combine with diminishing returns into a 0–100 score. Parked domains are capped near 0, and domains with no mail and no working website are capped at 35 because they are probably inactive businesses.

Does it find email addresses or phone numbers? No. It scores companies you already have, or that you discover from a public list page. Pair it with your existing enrichment tool.

How fast is it? Roughly 1–2 seconds per company at 10 in parallel. 1,000 companies take a few minutes to tens of minutes, depending on how slow the sites are.

Can I scan my own clients? Yes. Many MSPs run it monthly against their client list as a lightweight external health check.

Questions or feature requests? Open an issue on the Actor's Issues tab. We usually reply within a day.