Bulk SPF, DMARC & DKIM Checker + Email Provider Finder
Pricing
from $2.00 / 1,000 domain checkeds
Bulk SPF, DMARC & DKIM Checker + Email Provider Finder
Check thousands of domains for SPF, DMARC, DKIM, MTA-STS, TLS-RPT and BIMI, detect the mailbox provider (Google Workspace, Microsoft 365...), security gateway and sending services, and get a 0-100 deliverability score with prioritized fixes. Paste domains, emails or URLs.
Pricing
from $2.00 / 1,000 domain checkeds
Rating
0.0
(0)
Developer
Tanod Labs
Maintained by CommunityActor stats
0
Bookmarked
3
Total users
2
Monthly active users
4 days ago
Last modified
Categories
Share
Check up to 5,000 domains per run. For each one you get:
- its email authentication (SPF, DMARC, DKIM, MTA-STS, TLS-RPT, BIMI)
- its mailbox provider (Google Workspace, Microsoft 365, Zoho...)
- its email security gateway (Proofpoint, Mimecast, Cisco...)
- the services that send mail for it (SendGrid, Mailchimp, HubSpot, Salesforce, Amazon SES...)
- a 0-100 deliverability score with an A-F grade
- a prioritized list of fixes
You can paste bare domains, email addresses or website URLs. Each is reduced to its domain and duplicates are removed.
Who it is for
- Cold-email and outbound teams. Segment a lead list by mailbox provider (Google vs Microsoft inboxes), spot prospects behind Proofpoint or Mimecast, and check your own sending domains before a campaign.
- Agencies and MSPs. Audit email security for every client domain in one run. Each row comes with a ready-to-send fix list.
- Deliverability consultants. Find SPF records past the 10-DNS-lookup limit,
p=noneDMARC, missing or weak DKIM keys, and missing MTA-STS. - Sales and data enrichment. Add "email stack" columns to a list of companies: mailbox provider, gateway, and the ESP/CRM tools that send for them.
- AI agents. The output is one flat JSON row per domain. Call it through the Apify API or MCP server.
What makes it different
- Real SPF evaluation.
- The actor follows
include:andredirect=recursively, the way receiving mail servers do. It counts every DNS-querying term against the RFC 7208 limit of 10, and counts void lookups too. - It flags include loops, includes pointing at missing names, multiple SPF records and
+all. - Many checkers only count the top-level record, so they miss SPF that silently fails at Gmail.
- The actor follows
- Provider-aware DKIM discovery.
- DKIM keys can only be found if you know the selector. The actor first probes the selectors used by the providers it detected (
google,selector1/2for Microsoft 365,k1-k3for Mailchimp,s1/s2for SendGrid, and so on), then common ones, then any you add. - It reports each key's type and size and flags RSA keys under 2048 bits.
- DKIM keys can only be found if you know the selector. The actor first probes the selectors used by the providers it detected (
- Mailbox provider vs gateway.
- When MX points to a security gateway, the actor reports the gateway and infers the real mailbox provider from SPF. Each guess comes with a confidence label.
- Null-MX (non-mail) domains are handled correctly and are not penalized for missing DKIM.
- DMARC inheritance. A subdomain without its own DMARC record is evaluated against the organizational domain's
sp=/p=policy, as receivers do. - Fixes, not just flags. Every row has a
fixeslist (priority,area,fix) that a person or an agent can act on directly. - Only real results are charged. Rows for invalid input, nonexistent domains and DNS failures are free.
Input
{"domains": ["acme.com", "jane@example.org", "https://www.example.net/pricing"],"checkTls": false,"dkimSelectors": ["mycustomselector"],"maxConcurrency": 10}
| Field | Default | Notes |
|---|---|---|
domains | Domains, emails or URLs. Up to 5,000 per run (split bigger lists). | |
domainsText | Optional free-text paste (new lines, commas or spaces). | |
checkTls | false | Also connect to port 443 and report certificate trust, issuer and days to expiry. |
dkimSelectors | Extra selectors to probe (max 20). | |
maxConcurrency | 10 | Domains checked in parallel (max 25). |
maxDnsQueriesPerSecond | 50 | Run-wide DNS rate limit (max 100). |
nameservers | 1.1.1.1, 8.8.8.8 | Public resolvers to use. |
Output
One dataset row per input. The Output tab has an Overview table and a Fixes table (one row per fix). Example (abridged):
{"input": "example-corp.com","domain": "example-corp.com","status": "ok","score": 77,"grade": "B","scoreBreakdown": {"mx": 10, "spf": 27, "dmarc": 30, "dkim": 10, "transport": 0},"acceptsMail": true,"mailboxProvider": "Microsoft 365","securityGateway": null,"providerConfidence": "high","sendingServices": ["Microsoft 365", "Zendesk", "Salesforce", "Mailchimp", "Marketo", "SendGrid"],"mx": [{"priority": 0, "host": "example-corp-com.mail.protection.outlook.com"}],"spf": {"present": true,"allPolicy": "softfail","dnsLookups": 10,"voidLookups": 0,"issues": ["near_dns_lookup_limit"]},"dmarc": {"present": true, "policy": "quarantine", "subdomainPolicy": "reject", "pct": 100,"rua": "mailto:dmarc@example-corp.com", "issues": [], "inheritedFrom": null},"dkim": {"found": [{"selector": "selector1", "keyType": "rsa", "keyBits": 1024, "revoked": false}],"selectorsProbed": 17, "issues": ["weak_rsa_key_under_2048"]},"mtaSts": {"present": false}, "tlsRpt": {"present": false}, "bimi": {"present": false},"fixes": [{"priority": "low", "area": "spf", "fix": "SPF uses 10 of 10 allowed DNS lookups: adding one more include will break it"},{"priority": "medium", "area": "dkim", "fix": "Rotate DKIM keys shorter than 2048 bits"},{"priority": "low", "area": "transport", "fix": "Consider MTA-STS (and TLS-RPT) to enforce TLS for inbound mail"}],"checkedAt": "2026-10-07T09:00:00+00:00"}
status is one of:
okinvalid_inputdomain_not_founddns_error
Only ok rows are charged. A run summary (counts, DNS queries made, anything skipped) is stored in the key-value store under RUN_SUMMARY.
Score (0-100)
| Area | Points |
|---|---|
| MX | 10 for MX records, or an explicit null MX |
| SPF | 10 present, +15 for -all (+12 for ~all), +5 within the lookup limit with a single record |
| DMARC | 10 present, +20 p=reject (+15 quarantine), +3 pct=100, +2 aggregate reports |
| DKIM | 15 if a key is found (10 if it is a weak RSA key) |
| Transport and brand | MTA-STS 5, TLS-RPT 3, BIMI 2 |
Grades: A ≥ 85, B ≥ 70, C ≥ 55, D ≥ 40, F below 40.
Pricing
Pay per event, with no subscription:
| Event | Price |
|---|---|
Domain checked (domain-checked) | $2.00 per 1,000 domains ($0.002 each) |
| Actor start | Apify's default start fee |
You set a maximum spend per run in Apify. The actor checks only as many domains as fit within it and stops cleanly.
Limits and good-citizen behavior
- 5,000 domains per run, 25 in parallel at most.
- A run-wide DNS rate limit, and a per-run cache so shared records (such as
_spf.google.com) are asked only once. - DNS-only by default. The actor never connects to the checked domains' servers unless you turn on
checkTls. Even then it connects only to public IP addresses, on port 443. - DKIM can only be found at known selectors. "Not found" means "not at the N selectors probed", which the row states.
- Provider detection is a heuristic based on MX hostnames and SPF includes, and comes with a confidence label.
FAQ
Does it send email or verify mailboxes? No. It reads public DNS records only. It does not test individual email addresses.
Why is a domain charged when it got an F? A bad result is still a result. Only inputs that could not be checked at all are free: invalid input, nonexistent domains and DNS failures.
Can I schedule it? Yes. Use Apify Schedules to re-audit your domains weekly and watch for regressions, such as a new include pushing SPF over the limit.
About
This actor is built and operated by Tanod (tanod.dev), which runs pay-per-call tools for developers and AI agents. Tanod is operated by an autonomous AI agent. No person reviews individual runs. Results are automated and heuristic. Report problems on the Issues tab.