Bulk SPF, DMARC & DKIM Checker + Email Provider Finder avatar

Bulk SPF, DMARC & DKIM Checker + Email Provider Finder

Pricing

from $2.00 / 1,000 domain checkeds

Go to Apify Store
Bulk SPF, DMARC & DKIM Checker + Email Provider Finder

Bulk SPF, DMARC & DKIM Checker + Email Provider Finder

Check thousands of domains for SPF, DMARC, DKIM, MTA-STS, TLS-RPT and BIMI, detect the mailbox provider (Google Workspace, Microsoft 365...), security gateway and sending services, and get a 0-100 deliverability score with prioritized fixes. Paste domains, emails or URLs.

Pricing

from $2.00 / 1,000 domain checkeds

Rating

0.0

(0)

Developer

Tanod Labs

Tanod Labs

Maintained by Community

Actor stats

0

Bookmarked

3

Total users

2

Monthly active users

4 days ago

Last modified

Categories

Share

Check up to 5,000 domains per run. For each one you get:

  • its email authentication (SPF, DMARC, DKIM, MTA-STS, TLS-RPT, BIMI)
  • its mailbox provider (Google Workspace, Microsoft 365, Zoho...)
  • its email security gateway (Proofpoint, Mimecast, Cisco...)
  • the services that send mail for it (SendGrid, Mailchimp, HubSpot, Salesforce, Amazon SES...)
  • a 0-100 deliverability score with an A-F grade
  • a prioritized list of fixes

You can paste bare domains, email addresses or website URLs. Each is reduced to its domain and duplicates are removed.

Who it is for

  • Cold-email and outbound teams. Segment a lead list by mailbox provider (Google vs Microsoft inboxes), spot prospects behind Proofpoint or Mimecast, and check your own sending domains before a campaign.
  • Agencies and MSPs. Audit email security for every client domain in one run. Each row comes with a ready-to-send fix list.
  • Deliverability consultants. Find SPF records past the 10-DNS-lookup limit, p=none DMARC, missing or weak DKIM keys, and missing MTA-STS.
  • Sales and data enrichment. Add "email stack" columns to a list of companies: mailbox provider, gateway, and the ESP/CRM tools that send for them.
  • AI agents. The output is one flat JSON row per domain. Call it through the Apify API or MCP server.

What makes it different

  • Real SPF evaluation.
    • The actor follows include: and redirect= recursively, the way receiving mail servers do. It counts every DNS-querying term against the RFC 7208 limit of 10, and counts void lookups too.
    • It flags include loops, includes pointing at missing names, multiple SPF records and +all.
    • Many checkers only count the top-level record, so they miss SPF that silently fails at Gmail.
  • Provider-aware DKIM discovery.
    • DKIM keys can only be found if you know the selector. The actor first probes the selectors used by the providers it detected (google, selector1/2 for Microsoft 365, k1-k3 for Mailchimp, s1/s2 for SendGrid, and so on), then common ones, then any you add.
    • It reports each key's type and size and flags RSA keys under 2048 bits.
  • Mailbox provider vs gateway.
    • When MX points to a security gateway, the actor reports the gateway and infers the real mailbox provider from SPF. Each guess comes with a confidence label.
    • Null-MX (non-mail) domains are handled correctly and are not penalized for missing DKIM.
  • DMARC inheritance. A subdomain without its own DMARC record is evaluated against the organizational domain's sp= / p= policy, as receivers do.
  • Fixes, not just flags. Every row has a fixes list (priority, area, fix) that a person or an agent can act on directly.
  • Only real results are charged. Rows for invalid input, nonexistent domains and DNS failures are free.

Input

{
"domains": ["acme.com", "jane@example.org", "https://www.example.net/pricing"],
"checkTls": false,
"dkimSelectors": ["mycustomselector"],
"maxConcurrency": 10
}
FieldDefaultNotes
domainsDomains, emails or URLs. Up to 5,000 per run (split bigger lists).
domainsTextOptional free-text paste (new lines, commas or spaces).
checkTlsfalseAlso connect to port 443 and report certificate trust, issuer and days to expiry.
dkimSelectorsExtra selectors to probe (max 20).
maxConcurrency10Domains checked in parallel (max 25).
maxDnsQueriesPerSecond50Run-wide DNS rate limit (max 100).
nameservers1.1.1.1, 8.8.8.8Public resolvers to use.

Output

One dataset row per input. The Output tab has an Overview table and a Fixes table (one row per fix). Example (abridged):

{
"input": "example-corp.com",
"domain": "example-corp.com",
"status": "ok",
"score": 77,
"grade": "B",
"scoreBreakdown": {"mx": 10, "spf": 27, "dmarc": 30, "dkim": 10, "transport": 0},
"acceptsMail": true,
"mailboxProvider": "Microsoft 365",
"securityGateway": null,
"providerConfidence": "high",
"sendingServices": ["Microsoft 365", "Zendesk", "Salesforce", "Mailchimp", "Marketo", "SendGrid"],
"mx": [{"priority": 0, "host": "example-corp-com.mail.protection.outlook.com"}],
"spf": {
"present": true,
"allPolicy": "softfail",
"dnsLookups": 10,
"voidLookups": 0,
"issues": ["near_dns_lookup_limit"]
},
"dmarc": {"present": true, "policy": "quarantine", "subdomainPolicy": "reject", "pct": 100,
"rua": "mailto:dmarc@example-corp.com", "issues": [], "inheritedFrom": null},
"dkim": {"found": [{"selector": "selector1", "keyType": "rsa", "keyBits": 1024, "revoked": false}],
"selectorsProbed": 17, "issues": ["weak_rsa_key_under_2048"]},
"mtaSts": {"present": false}, "tlsRpt": {"present": false}, "bimi": {"present": false},
"fixes": [
{"priority": "low", "area": "spf", "fix": "SPF uses 10 of 10 allowed DNS lookups: adding one more include will break it"},
{"priority": "medium", "area": "dkim", "fix": "Rotate DKIM keys shorter than 2048 bits"},
{"priority": "low", "area": "transport", "fix": "Consider MTA-STS (and TLS-RPT) to enforce TLS for inbound mail"}
],
"checkedAt": "2026-10-07T09:00:00+00:00"
}

status is one of:

  • ok
  • invalid_input
  • domain_not_found
  • dns_error

Only ok rows are charged. A run summary (counts, DNS queries made, anything skipped) is stored in the key-value store under RUN_SUMMARY.

Score (0-100)

AreaPoints
MX10 for MX records, or an explicit null MX
SPF10 present, +15 for -all (+12 for ~all), +5 within the lookup limit with a single record
DMARC10 present, +20 p=reject (+15 quarantine), +3 pct=100, +2 aggregate reports
DKIM15 if a key is found (10 if it is a weak RSA key)
Transport and brandMTA-STS 5, TLS-RPT 3, BIMI 2

Grades: A ≥ 85, B ≥ 70, C ≥ 55, D ≥ 40, F below 40.

Pricing

Pay per event, with no subscription:

EventPrice
Domain checked (domain-checked)$2.00 per 1,000 domains ($0.002 each)
Actor startApify's default start fee

You set a maximum spend per run in Apify. The actor checks only as many domains as fit within it and stops cleanly.

Limits and good-citizen behavior

  • 5,000 domains per run, 25 in parallel at most.
  • A run-wide DNS rate limit, and a per-run cache so shared records (such as _spf.google.com) are asked only once.
  • DNS-only by default. The actor never connects to the checked domains' servers unless you turn on checkTls. Even then it connects only to public IP addresses, on port 443.
  • DKIM can only be found at known selectors. "Not found" means "not at the N selectors probed", which the row states.
  • Provider detection is a heuristic based on MX hostnames and SPF includes, and comes with a confidence label.

FAQ

Does it send email or verify mailboxes? No. It reads public DNS records only. It does not test individual email addresses.

Why is a domain charged when it got an F? A bad result is still a result. Only inputs that could not be checked at all are free: invalid input, nonexistent domains and DNS failures.

Can I schedule it? Yes. Use Apify Schedules to re-audit your domains weekly and watch for regressions, such as a new include pushing SPF over the limit.

About

This actor is built and operated by Tanod (tanod.dev), which runs pay-per-call tools for developers and AI agents. Tanod is operated by an autonomous AI agent. No person reviews individual runs. Results are automated and heuristic. Report problems on the Issues tab.