# Email Security Checker: SPF, DMARC, DKIM & Mail Provider (`redfoxscout/email-security-checker`) Actor

Check SPF, DMARC, DKIM, BIMI and MTA-STS for any list of domains from public DNS, and see each domain's email provider (Google Workspace, Microsoft 365, Proofpoint...) and sending tools (SendGrid, HubSpot, Mailchimp). Plain-English issues per domain.

- **URL**: https://apify.com/redfoxscout/email-security-checker.md
- **Developed by:** [Red Fox Scout](https://apify.com/redfoxscout) (community)
- **Categories:** Developer tools, Lead generation
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $0.75 / 1,000 domains

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.
Since this Actor supports Apify Store discounts, the price gets lower the higher subscription plan you have.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

Find the domains that can be spoofed. For every domain you get a **spoofable** yes or no with the reason, a **posture score** from 0 to 100 with an **A-F grade**, and an ordered **fix list** with the exact DNS records to publish. It reads the email setup from public DNS too: the **email provider**, **MX**, **SPF** (including the lookups inside its includes), **DMARC**, **DKIM** (built-in and your own selectors), **DNSSEC**, **MTA-STS**, **TLS-RPT**, **BIMI** and the name servers.

**Price: $1 per 1,000 domains checked.** Domains that don't exist are free. Apify's free plan ($5 monthly credit) covers about 5,000 domains a month.

[![Which of these domains can be spoofed (no DMARC enforcement): real output preview (Which domains can be spoofed: verdict, grade and the first fix per domain)](https://raw.githubusercontent.com/TikTop-Data/apify-store-assets/main/images/email-security-checker-output.png)](https://console.apify.com/actors/nbZkXDhFtTvHwAgLZ)

### Questions it answers

- Which of my domains can be spoofed, and what should each one publish to stop it?
- Which domains are stuck at DMARC p=none, or have no DMARC at all?
- Does this company use Google Workspace or Microsoft 365 for email?
- Is this SPF record valid once its includes are counted, or over the 10-lookup limit?
- Which email marketing and helpdesk tools does a company send from?
- Which domains have DNSSEC on and working?

### Who uses this

- 📬 **Email deliverability consultants and MSPs:** audit SPF, DKIM and DMARC across every client domain in one run.
- 🛡️ **IT and security teams:** find spoofable domains and weak policies across a domain portfolio, on a schedule.
- 💼 **Sales and RevOps:** use the email provider and sending tools as a technology signal for lead lists (who runs Microsoft 365, who sends with HubSpot).

### Why this Email Security Checker

- 🎣 **Spoofable or not:** a yes or no with the reason, so you know which domains anyone could send mail as.
- 📈 **Posture score and A-F grade**, with the scoring rules published below.
- 🛠️ **Fix list with exact records** to publish for DMARC, SPF, MTA-STS and TLS-RPT.
- 📮 **Full email DNS:** provider, MX, SPF lookups, DKIM (your own selectors too), DNSSEC, BIMI and name servers.
- 🔔 **Change alerts** when a domain's email setup changes.
- 💰 **$1 per 1,000 domains**, domains that don't exist are free.

### How to use the Email Security Checker

1. Click **Try for free** (a free Apify account is enough).
2. Paste domains, one per line (`acme.com`). URLs work too. Your own DKIM selectors and the other checks are under **Checks**.
3. Click **Start**. Each domain takes a second or two.
4. Sort by `postureScore` to see the weakest domains first, or filter `spoofable` to true. Download as JSON, CSV or Excel.

### Input

| Field | Default | What it does |
|---|---|---|
| `urls` | – | Domains, one per line (`acme.com`). URLs work too; `www.` is dropped. |
| `onlySpoofable` | false | Return only the domains that can be spoofed. The others are left out and free, so a big list costs only the hits. |
| `useApexDomain` | false | Check the registrable domain instead of the host you gave: `mail.acme.co.uk` is checked as `acme.co.uk`. |
| `dkimSelectors` | \[] | Your mail provider's DKIM selectors (up to 20), checked on top of the built-in list. Find one in the `s=` tag of a `DKIM-Signature` header in mail the domain sent. |
| `expandSpfIncludes` | true | Count the DNS lookups inside every `include:` and `redirect=` as receivers do (`spfLookupCountExpanded`). Off counts only the top-level record. |
| `checkDnssec` | true | Check DNSSEC (`dnssecStatus`) through public DNS-over-HTTPS resolvers (Cloudflare, with Google as fallback). |
| `recordTypes` | \[] | Raw records to add to each row as `dnsRecords`: any of `CAA`, `CNAME`, `A`, `AAAA`, `NS`, `MX`, `TXT`. |
| `maxConcurrency` | 20 | Domains checked in parallel. |
| `requestTimeoutSecs` | 30 | Give up on a domain after this long. |

Example input (the one behind the output below):

```json
{ "urls": ["apify.com", "intel.com"] }
```

### Output

One row per domain. Real rows from a local run of the input above, shortened:

```json
{
  "inputUrl": "apify.com",
  "url": "apify.com",
  "domain": "apify.com",
  "emailDomain": "apify.com",
  "mailProvider": "Google Workspace",
  "mxProviders": ["Google Workspace"],
  "mxRecords": [{ "host": "aspmx.l.google.com", "priority": 1 }, "..."],
  "spfRecord": "v=spf1 a mx include:_spf.google.com include:mailgun.org include:amazonses.com include:19497222.spf05.hubspotemail.net -all",
  "spfValid": true,
  "spfAll": "-all",
  "spfLookupCount": 6,
  "spfLookupCountExpanded": 10,
  "spfSenders": ["Google Workspace", "Amazon SES", "Mailgun", "HubSpot"],
  "dmarcRecord": "v=DMARC1; p=reject; sp=reject; pct=100; rua=mailto:dmarc-reports@apify.com; ri=604800",
  "dmarcPolicy": "reject",
  "dkimSelectorsFound": ["google"],
  "dnssecStatus": "signed",
  "mtaSts": true,
  "mtaStsMode": "enforce",
  "tlsRpt": true,
  "spoofable": false,
  "spoofableReason": "DMARC p=reject covers all mail",
  "postureScore": 100,
  "grade": "A",
  "scoreBreakdown": { "dmarc": 40, "spf": 20, "dkim": 15, "mtaSts": 10, "tlsRpt": 5, "dnssec": 10 },
  "recommendations": [],
  "issueCount": 0,
  "issues": [],
  "error": null,
  "checkedAt": "..."
}
```

New fields sit next to the existing ones: `spoofable`, `spoofableReason`, `postureScore`, `grade`, `scoreBreakdown`, `recommendations`, `dnssecStatus`, `nsRecords`, `aRecords`, `aaaaRecords`, `soaRecord`, `spfLookupCountExpanded`, `mxProviders` and `dnsRecords`. `soaRecord.contact` is the zone's published contact mailbox (from the SOA record), useful for reaching the domain's DNS admin. With `expandSpfIncludes` on, `spfValid` and the SPF lookup issue use the full count.

Export as JSON, CSV or Excel, or connect Google Sheets, Slack or a webhook through Apify integrations.

### Example tasks

Ready-made inputs you can open, change and run:

- [Which of these domains can be spoofed (no DMARC enforcement)](https://apify.com/redfoxscout/email-security-checker/examples/spoofable-domain-finder)
- [DMARC policy checker for many domains](https://apify.com/redfoxscout/email-security-checker/examples/dmarc-policy-checker)
- [SPF record checker and validator in bulk](https://apify.com/redfoxscout/email-security-checker/examples/spf-record-checker)

### Find spoofable domains

Turn on **Only spoofable domains** (`onlySpoofable`) to get just the spoofable ones; the other domains are free.

A domain is **spoofable** when someone can send mail that claims to be from it and have it delivered. The verdict is yes when any of these is true:

- it has no DMARC record, or the record has no valid `p=` policy, or there are two DMARC records;
- DMARC is `p=none`: spoofed mail is reported but still delivered;
- DMARC covers less than 100% of mail (`pct`);
- SPF ends in `+all`, so any server passes SPF for the domain.

A softfail (`~all`) on its own does not make a domain spoofable when DMARC rejects or quarantines all of its mail.

**Posture score (0-100).** Each part earns points:

| Part | Points | Full marks | Fewer points |
|---|---|---|---|
| DMARC | 40 | `p=reject` at pct 100 | `p=quarantine` 30 (20 below pct 100); `p=reject` below pct 100: 30; `p=none` 10; no valid record 0 |
| SPF | 20 | one record (6), ends in `-all` (8), at most 10 lookups with includes counted (6) | ends in `~all` 5, `?all` 1, `+all` 0; over 10 lookups 0 |
| DKIM | 15 | a key on a selector checked | no key found 0 |
| MTA-STS | 10 | `mode: enforce` (10) | `mode: testing` 7; record with no readable policy 4 |
| TLS-RPT | 5 | record published | none 0 |
| DNSSEC | 10 | signed and validating | unsigned or broken 0 |

DKIM, MTA-STS and TLS-RPT count only for domains that receive mail. A part that does not apply is left out, and the score is scaled to the parts that do. Null-MX domains are scored on DMARC, SPF and DNSSEC.

**Grade:** A from 90, B from 75, C from 60, D from 40, F below that. A spoofable domain is at most D.

**Fix list.** Fixes that stop spoofing come first, then the rest by points gained. Each fix says what to do. Where the record can be written exactly from the domain's current records, the fix includes the `record` (host, type and value) to publish: DMARC, SPF, MTA-STS, TLS-RPT and null MX. DKIM keys and DNSSEC DS records come from your mail provider and DNS host, so those fixes have no record. Mailboxes named in suggested records (`dmarc@`, `tls-reports@`) must exist to receive reports.

Real output for intel.com from a local run, shortened:

```json
{
  "domain": "intel.com",
  "spoofable": true,
  "spoofableReason": "DMARC p=none: spoofed mail is reported but still delivered",
  "postureScore": 30,
  "grade": "F",
  "recommendations": [
    { "priority": 1, "area": "DMARC", "action": "Raise DMARC from p=none to p=quarantine, then to p=reject ...", "record": { "host": "_dmarc.intel.com", "type": "TXT", "value": "v=DMARC1; p=quarantine; sp=none; fo=1; rua=mailto:dmarc.notification@intel.com" }, "scoreGain": 20 },
    { "priority": 2, "area": "DKIM", "action": "No key was found on the selectors checked ...", "record": null, "scoreGain": 15 },
    "...",
    { "priority": 5, "area": "TLS-RPT", "action": "Publish TLS-RPT ...", "record": { "host": "_smtp._tls.intel.com", "type": "TXT", "value": "v=TLSRPTv1; rua=mailto:tls-reports@intel.com" }, "scoreGain": 5 }
  ]
}
```

### Check websites from another Actor (Google Maps leads, lead lists)

Have a list from Google Maps Scraper or any other Actor? Pick its dataset under **Websites from another Actor**. This Actor reads the `website` field (or the field you name, e.g. `url`, `domain` or `contact.website`) and checks every site. No copy and paste.

To run it automatically after every scrape, add an Actor-to-Actor integration to the source Actor or task with this input:

```json
{ "datasetId": "{{resource.defaultDatasetId}}", "datasetUrlField": "website" }
```

### Use in Clay

Add each account's email setup to a Clay table:

1. In Clay, open **Settings**, then **Connections**, then **Add Connection**, pick **Apify** and paste your Apify API token (Apify Console, **Settings**, **API & Integrations**).
2. In your table, select **Add enrichment**, search for **Apify** and pick **Run Apify Actor**.
3. Choose this Actor (`redfoxscout/email-security-checker`, ID `nbZkXDhFtTvHwAgLZ`) and paste this as the input, inserting your domain column where it says `/Domain` (Clay's rule: quotes around the key, none around the column token):

```json
{ "urls": [/Domain] }
```

4. Map the output fields you need: `spoofable`, `grade`, `postureScore`, `mailProvider`, `dmarcPolicy`, `spfValid`, `issueCount` and `issues`.

Clay runs the Actor once per row, so each row costs one Actor start plus $0.001 per domain. For thousands of rows, run the Actor once on the whole list instead.

### Change alerts

Give the run a **Change alert name** (e.g. `clients-weekly`) and put it on an Apify schedule. Each row then gets `changeStatus` (`new`, `changed` or `unchanged`) and `changedFields`, compared with the previous run of the same name, so you see when a domain changes its mail provider, SPF, DMARC, MTA-STS, DNSSEC or its score. Turn on **Only new and changed sites** and each run's dataset is just the change report; unchanged sites are still checked and charged as usual. Add Apify's Slack or email integration to get the report delivered.

### Notes

- Uses public DNS only, plus the public MTA-STS policy file when one is announced, and public DNS-over-HTTPS resolvers for DNSSEC. No emails are sent and no mail servers are contacted.
- DKIM keys can't be listed from DNS. Only the built-in selectors and the ones you give are checked, so "not found" means not on those. Revoked keys (an empty `p=`) don't count.
- A domain whose DNSSEC is broken usually fails the DNS lookup itself (SERVFAIL). It then shows as an error row, which is free.
- SPF lookups follow RFC 7208, with a limit of 30 DNS queries and 10 seconds per domain. A very large include tree is counted only as far as those limits allow, so its count is a minimum.
- Domains with a null MX record (`MX 0 .`) say they never receive email. They show as `No email (null MX)`, and DKIM, MTA-STS and TLS-RPT are not scored for them.
- `domain` is the host you gave; `emailDomain` is the domain whose records were checked. They differ when `useApexDomain` is on.
- `dmarcReportsTo` lists only the domains of the DMARC report addresses. `dmarcRecord` shows the record as published, so any report mailbox in it appears there too.
- The MTA-STS record in a fix uses `id=1`. Change the id whenever you change the policy file.
- DMARC, SPF and MTA-STS fixes come from the records the domain publishes now. Review each record before you publish it, because it replaces the current one.

### What this Actor does not do

It does not send mail, test whether a spoofed message gets through, or contact mail servers. It reads the records a domain publishes, so it cannot see DKIM keys on selectors it doesn't check. It does not log in or solve CAPTCHAs; the only contact it returns is the SOA mailbox the domain publishes in DNS.

### How much does it cost?

- **Domain checked:** $0.001 per domain ($1 per 1,000).
- **Actor start:** $0.00005 per GB of memory (default 1 GB = $0.00005 per run).
- Domains that don't exist: free.

| Domains | Cost |
|---|---|
| 100 | about $0.10 |
| 1,000 | about $1 |
| 10,000 | about $10 |

Apify's free plan includes $5 of credit every month, enough for about 5,000 domains. Paid Apify plans get Store discounts of up to 25%. You can set a maximum cost per run; the Actor stops cleanly when it's reached.

### FAQ

**Is this legal?** It reads public DNS records, the same ones every mail server reads before delivering a message. No emails are sent and no personal data is collected.

**Can I check my clients' domains every week?** Yes. Put the run on an Apify schedule with a change alert name and you get only the domains whose setup changed.

**Why does a domain show no DKIM key when it sends signed mail?** It probably uses a selector we don't check. The selector is in the `s=` tag of the `DKIM-Signature` header of any email the domain sends. Add it under **Extra DKIM selectors**.

**Why is my SPF over 10 lookups when it was fine before?** Earlier versions counted only the top-level record. Receivers count the lookups inside each include, so the full count is the one that matters. Turn off **Count SPF lookups through includes** to get the top-level count.

### Related Actors

- [Website Tech Stack Detector](https://apify.com/redfoxscout/tech-stack-detector): what a site is built with, including the email provider from DNS.
- [Bulk URL Status & SSL Checker](https://apify.com/redfoxscout/url-status-ssl-checker): status codes, redirects, security headers and SSL expiry.

# Actor input Schema

## `urls` (type: `array`):

Email domains, one per line, e.g. acme.com. URLs work too. Or use "Websites from another Actor" below.

## `startUrls` (type: `array`):

Same as the list above, in Apify's standard start-URL format (handy when another tool or Actor passes startUrls).

## `onlySpoofable` (type: `boolean`):

Return only domains that can be spoofed (no DMARC, p=none, partial pct or SPF +all). Other domains are left out of the results and are free.

## `datasetId` (type: `string`):

Check the websites in another Actor run's results, e.g. Google Maps Scraper or any lead list. Pick the dataset here, or in an Actor-to-Actor integration set it to {{resource.defaultDatasetId}}. Its websites are added to the list above.

## `datasetUrlField` (type: `string`):

The dataset field that holds the website or URL, e.g. website (Google Maps Scraper), url or domain. Dot paths like contact.website work. If it is empty, website, url and domain are tried.

## `maxDatasetItems` (type: `integer`):

Read at most this many rows from that dataset.

## `monitorName` (type: `string`):

Name this list (e.g. "clients-weekly") to compare each run with the previous run of the same name. Every row then gets changeStatus (new, changed or unchanged) and changedFields. Best on an Apify schedule.

## `onlyChanges` (type: `boolean`):

Needs a change alert name. Unchanged sites are still checked and charged as usual, but left out of the results, so each run's dataset is your change report.

## `useApexDomain` (type: `boolean`):

Check the registrable domain instead of the host you gave: mail.acme.com is checked as acme.com, and mail.acme.co.uk as acme.co.uk. Off by default, so each host is checked as given.

## `dkimSelectors` (type: `array`):

Your mail provider's DKIM selectors (up to 20), checked on top of the built-in list. Find them in the s= tag of a DKIM-Signature header in mail the domain sent. Default: none.

## `expandSpfIncludes` (type: `boolean`):

Follow every include: and redirect= in the SPF record and count the DNS lookups each one needs, as receivers do (the limit is 10). On by default. Off counts only the top-level record.

## `checkDnssec` (type: `boolean`):

Check whether the domain is DNSSEC-signed and the signature validates, using public DNS-over-HTTPS resolvers. On by default; no extra charge.

## `recordTypes` (type: `array`):

Raw records to add to each row as dnsRecords. Any of CAA, CNAME, A, AAAA, NS, MX, TXT. Default: none; the usual records are already in each row.

## `maxConcurrency` (type: `integer`):

How many sites to check at once.

## `requestTimeoutSecs` (type: `integer`):

Give up on a site after this long.

## `proxyConfiguration` (type: `object`):

Off by default. Turn on if some sites block or rate-limit the checks.

## Actor input object example

```json
{
  "urls": [
    "apify.com",
    "github.com",
    "stripe.com"
  ],
  "onlySpoofable": false,
  "datasetUrlField": "website",
  "maxDatasetItems": 10000,
  "onlyChanges": false,
  "useApexDomain": false,
  "dkimSelectors": [],
  "expandSpfIncludes": true,
  "checkDnssec": true,
  "recordTypes": [],
  "maxConcurrency": 20,
  "requestTimeoutSecs": 30,
  "proxyConfiguration": {
    "useApifyProxy": false
  }
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "urls": [
        "apify.com",
        "github.com",
        "stripe.com"
    ]
};

// Run the Actor and wait for it to finish
const run = await client.actor("redfoxscout/email-security-checker").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "urls": [
        "apify.com",
        "github.com",
        "stripe.com",
    ] }

# Run the Actor and wait for it to finish
run = client.actor("redfoxscout/email-security-checker").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "urls": [
    "apify.com",
    "github.com",
    "stripe.com"
  ]
}' |
apify call redfoxscout/email-security-checker --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,redfoxscout/email-security-checker"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/nbZkXDhFtTvHwAgLZ/builds/ASwbxTUuqO7LaYc8X/openapi.json
