Company Enrichment Scraper — Address, Emails & Tech Stack avatar

Company Enrichment Scraper — Address, Emails & Tech Stack

Pricing

from $3.20 / 1,000 company enricheds

Go to Apify Store
Company Enrichment Scraper — Address, Emails & Tech Stack

Company Enrichment Scraper — Address, Emails & Tech Stack

Turn a list of domains into company profiles: legal name, office address, emails, phones, LinkedIn & socials, tech stack, email provider, SaaS tools from DNS, domain age, VAT/registration numbers, hiring. HTTP-only. $3.20/1,000 companies.

Pricing

from $3.20 / 1,000 company enricheds

Rating

0.0

(0)

Developer

Mr Zack

Mr Zack

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

3 days ago

Last modified

Share

Give it a list of company websites or domains and get back one clean company profile per domain: company & legal name, office address (street, city, postal code, country), emails, phones, LinkedIn and other socials, VAT & registration numbers, tech stack (CMS, e-commerce, analytics, ad pixels, chat, payments), email provider and SaaS tools verified in DNS, domain age, careers page & ATS.

$3.20 per 1,000 companies. Websites that can't be reached, invalid inputs and duplicates are never charged. HTTP-only — no browser, no login, no API keys.

Who this is for

  • Sales & SDR teams — turn a raw domain list (CRM export, Google Maps results, event attendee list) into sales-ready rows: who they are, where they sit, how to reach them, what they already use.
  • Agencies — qualify prospects in one pass: runsPaidAds (Meta/Google/LinkedIn/TikTok pixels present) + cms + ecommercePlatform tell you who needs what.
  • SaaS go-to-market — find companies on a competitor's stack (techStack, verifiedTools, emailSendingServices) or on Google Workspace vs Microsoft 365 (emailProvider).
  • Data & RevOps — fill missing firmographics (legal entity, country, founded year, domain age) and de-duplicate accounts by registration number.
  • AI agents (MCP) — "who is behind acme.de, where are they based, and how do I contact them?" is one call with a predictable price.

What you get per company

FieldExampleHow it's found
companyName / legalNameOctopus Energy / Octopus Energy LimitedJSON-LD, site name, imprint, © line
address, street, city, region, postalCode, country182 Oxford Street, London W1D 1NNJSON-LD / microdata / imprint & contact pages (US, UK, EU, CA, AU, ID formats)
primaryEmail, emails, emailDetailshello@octopus.energymailto, text, Cloudflare-protected, JSON-LD — ranked: company-domain first, real inboxes (info@, sales@, people) before privacy@/legal@
primaryPhone, phones+448081966842tel: links, JSON-LD, phone lines — normalised to E.164 when the country is known
linkedinUrl, facebookUrl, instagramUrl, xUrl, youtubeUrl, tiktokUrl, githubUrl, otherSocialslinks + JSON-LD sameAs
vatId, registrationNumber, registrationCourtDE176055816, HRB 263370, Stuttgartimprint/legal pages (EU VAT, German HR, UK Companies House, KvK, SIREN, ABN, CNPJ, NIB…)
description, businessType, foundedYear, founders, logoUrl, faviconUrl, languagemeta tags + JSON-LD
techStack, cms, ecommercePlatform, analytics, advertisingPixels, runsPaidAds, marketingTools, supportTools, paymentProviders, hostingShopify, ["Meta Pixel","Google Ads"]135+ fingerprints on scripts, headers and cookies, plus the site's public Google Tag Manager container for ad pixels fired through GTM — never on the visible text (a site that mentions Salesforce is not reported as using it)
emailProvider, mxHostsGoogle WorkspaceDNS MX
emailSendingServices["HubSpot","SendGrid"]DNS SPF
verifiedTools["Atlassian","Stripe","OpenAI"]DNS TXT verification records — SaaS accounts the company has set up
dmarcPolicyrejectDNS DMARC
domainCreatedAt, domainAgeYears, domainExpiresAt, registrar1995-09-12, 31RDAP (not every country TLD publishes it, e.g. .de)
contactPageUrl, aboutPageUrl, legalPageUrl, teamPageUrl, careersPageUrl, atsProvider, isHiringpage discovery + ATS fingerprints (Greenhouse, Lever, Ashby…)
dataCompleteness880–100: how much of the profile was filled
status, error, pagesCrawled, crawlErrors, checkedAttransparency

Every field is always present — empty when the website doesn't publish it, never guessed. Unreachable websites produce a free row with status: "failed" and the reason (domain does not exist, HTTP 403…), so you can see exactly what happened to every input.

Input

FieldDefaultWhat it does
websites3 examplesDomains or URLs, one per line. Emails (jane@acme.com) become their domain
datasetId + websiteField— / websiteEnrich another Actor's results directly (Google Maps scrapers, lead lists…). Nested fields as dot paths: company.website
maxPagesPerSite6Homepage + contact, imprint/legal, about, team, privacy, careers. More pages never cost more
includeDnsInteltrueEmail provider, SPF tools, TXT-verified SaaS, DMARC
includeDomainAgetrueRDAP registration date & registrar
maxConcurrency10Websites in parallel
proxyConfigurationApify ProxyOnly used when a website blocks the direct request
{ "websites": ["octopus.energy", "personio.de", "https://www.allbirds.com"] }

Schedule it / chain it

  • Chain after a lead source: run a Google Maps or directory scraper, then this Actor with datasetId = that run's dataset and websiteField = the field holding the website. Every business becomes a full company profile.
  • Keep your CRM fresh: schedule a monthly run over your account list (Console → Schedules) and watch techStack, emailProvider, isHiring and runsPaidAds change over time.
  • Verify the emails: pipe primaryEmail into our Bulk Email Verifier before sending.

For AI agents & MCP

  • Minimal input: {"websites": ["<domain>"]}.
  • Output: one flat JSON object per domain, stable field names (table above), arrays for multi-value fields.
  • Price is predictable: $0.0032 per company profile; failed websites cost $0. Crawl depth never changes the price.
  • Honest failures: a website that can't be reached is a free status: "failed" row with a reason — never a fake profile.

Honest limits

Websites that render everything with JavaScript (some single-page apps) or that block automated requests expose less data — you still get DNS intel, domain age and a failed/sparse row, not invented values. Addresses are read in US, UK, Canadian, Australian, European and Indonesian formats; other formats may be missed. Pages in legacy encodings (Shift_JIS, windows-1251, Latin-1…) are decoded correctly. A subdomain (blog.acme.com) gets the DNS intel of the company domain (acme.com). Links to files (PDF, zip…), parked or for-sale domains, and addresses that resolve to private/internal networks are skipped for free. founders exists only when the site publishes them in structured data.

  • Contact Details Scraper (tactful_anvil/contact-details-scraper) — deeper email/phone/social extraction with MX-verified emails.
  • Bulk Email Verifier (tactful_anvil/bulk-email-verifier) — verify the emails you found.
  • Company Hiring Signals (tactful_anvil/company-hiring-signals-scraper) — every open role from the company's ATS.
  • Ad Budget Signals (tactful_anvil/ad-budget-signals) — does a domain run Google/LinkedIn ads?

Changelog

  • 0.1.1 (2026-10-01) — legacy page encodings decoded (Japanese Shift_JIS sites no longer show garbled names); subdomains get the company domain's email provider & SaaS tools; short/redirecting domains named after their real brand (fb.com → Facebook); far-away servers with IPv6 records no longer time out; huge pages/file links read only as far as needed (steady memory); max-cost limit no longer stops early when sites in progress fail; parked / for-sale domains are free failed rows (were billed as sparse profiles); paymentProviders also from DNS proof (Stripe verification) + Adyen, Braintree, Affirm, Square, Mollie, Razorpay, Midtrans; alias domains without mail use the real site's DNS; long lists on small memory finish cleanly before the timeout.
  • 0.1.0 (2026-09-25) — first release.