Email Deliverability & Domain Audit - SPF, DKIM, DMARC, MX avatar

Email Deliverability & Domain Audit - SPF, DKIM, DMARC, MX

Pricing

$4.00 / 1,000 domain auditeds

Go to Apify Store
Email Deliverability & Domain Audit - SPF, DKIM, DMARC, MX

Email Deliverability & Domain Audit - SPF, DKIM, DMARC, MX

Bulk-audit domains: email provider (Google Workspace, Microsoft 365...), SPF, DKIM, DMARC policy, MX, DNS host, SSL expiry, security headers and SaaS tools revealed by DNS. Deliverability score per domain.

Pricing

$4.00 / 1,000 domain auditeds

Rating

0.0

(0)

Developer

SiteProbe

SiteProbe

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

13 hours ago

Last modified

Share

Email Deliverability & Domain Audit – SPF, DKIM, DMARC, MX

Audit thousands of domains at once: which email provider they use (Google Workspace, Microsoft 365, Zoho, Proofpoint…), whether SPF, DKIM and DMARC are set up correctly, where their DNS is hosted, when their SSL certificate expires, and which SaaS tools their DNS records reveal (HubSpot, Salesforce, Atlassian, Stripe, DocuSign, Zoom, OpenAI…).

Who it's for

  • Cold email and outbound teams: segment prospects by email provider (Google vs Outlook), check your own sending domains, and avoid bounces.
  • Agencies and MSPs: find prospects with missing DMARC or weak SPF and offer them a fix.
  • Sales intelligence: detect which SaaS vendors a company uses from its DNS verification records.
  • Security and IT: monitor SSL expiry and security headers across a portfolio of domains.

What you get for each domain

  • Email provider detected from MX records, plus the full MX list.
  • SPF: the record, its policy (-all, ~all, …) and the email services it includes (SendGrid, Mailchimp, HubSpot, Amazon SES, Klaviyo…).
  • DMARC: the record, policy (none, quarantine or reject), pct and rua.
  • DKIM: keys found on 18 common selectors (google, selector1/2, k1, s1…).
  • MTA-STS, TLS-RPT, BIMI and CAA records.
  • DNS host: Cloudflare, Route 53, GoDaddy, OVHcloud, and others.
  • SaaS detected from DNS, using 50+ verification patterns.
  • Email security score (0–100) with a plain-English list of issues.
  • Optional: SSL issuer and days until expiry, TLS version, HTTPS redirect, and security headers (HSTS, CSP, X-Frame-Options…).

Example output

{
"domain": "stripe.com",
"emailProvider": "Google Workspace",
"dnsProvider": "Amazon Route 53",
"spf": {"allMechanism": "softfail", "includedSenders": []},
"dmarc": {"policy": "reject", "pct": "100"},
"dkimSelectorsFound": ["google", "s1", "s2", "mandrill"],
"saasDetectedFromDns": ["Atlassian", "DocuSign", "Linear", "OpenAI", "Stripe", "Vercel"],
"emailSecurityScore": 100,
"issues": [],
"charged": true
}

Pricing

  • $0.004 per audited domain ($4 per 1,000). No subscription.
  • Domains with no DNS records are free.
  • Set a maximum cost per run and the Actor stops cleanly when it is reached.

Notes

  • DNS is queried over encrypted DNS-over-HTTPS resolvers, with automatic failover.
  • DKIM can only be checked on known selectors. A domain that uses a custom selector may show "no DKIM found" even though DKIM is configured.
  • Only public DNS and website metadata is collected. No personal data is extracted.

Support

Open an issue in the Issues tab with a domain and the expected result. Fixes are shipped quickly.