Bulk DMARC, SPF & DKIM Checker avatar

Bulk DMARC, SPF & DKIM Checker

Pricing

from $5.00 / 1,000 checked domains

Go to Apify Store
Bulk DMARC, SPF & DKIM Checker

Bulk DMARC, SPF & DKIM Checker

Email security of many domains from public DNS: can the domain be spoofed, Gmail/Yahoo/Microsoft bulk sender readiness, SPF, DMARC, DKIM, MTA-STS, BIMI, DNSSEC, blocklists and lookalikes. Grade, fixes and sales hook.

Pricing

from $5.00 / 1,000 checked domains

Rating

0.0

(0)

Developer

Attila Kis

Attila Kis

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

2 days ago

Last modified

Share

Give the Actor a list of domains. For each domain it checks the email security setup in public DNS and returns a grade (A–F), every problem with a fix, and a one-sentence sales hook.

Made for MSPs and security consultants who prospect with "your domain can be spoofed", for cold-email and deliverability agencies, and for IT teams that audit their own domains. Thousands of domains per run (about 100 seconds per 1,000 domains at the default 2 GB memory); no email is sent.

What is checked

CheckDetails
SPFRecord count, syntax, all rule (+all, ?all, missing), DNS lookup count against the limit of 10 (includes are followed), void lookups (limit 2), includes that do not exist, ptr, sending services (Google Workspace, Microsoft 365, Mailchimp, SendGrid and about 40 more)
DMARCRecord count, syntax, policy for the domain, subdomains and non-existent subdomains, testing mode (t=y) and pct, alignment, report providers (dmarcian, Valimail, EasyDMARC, Red Sift and others), report authorization for external report addresses (RFC 9990), tags removed by the new DMARC standard (RFC 9989). A subdomain uses the policy of its organization when it has no own record
DKIMKeys at about 40 common selectors plus your own; key type, RSA key size, testing flag, revoked and broken keys
MXMail provider, security gateway (Mimecast, Proofpoint, Barracuda, …), own mail server, null MX, MX hosts that do not resolve
MTA-STS and TLS-RPTRecord, policy file (one HTTPS request), mode, max_age, and whether the policy lists every MX host. A mismatch in enforce mode stops mail from senders that use MTA-STS
BIMIRecord, logo, certificate; BIMI without an enforced DMARC policy
DNSSECThe domain is signed
BlocklistsOwn mail server IPs and single IPs in SPF on SpamCop, PSBL, UCEPROTECT level 1 and Mailspike. Shared provider IPs (Google, Microsoft, …) are not checked: their listing says nothing about your domain
Lookalike domains (optional)About 100–300 typo, homoglyph and suffix variants (paypa1.com, pyapal.com, paypal.net). Reported: registered variants, which can receive email, and whether they share name servers or own mail servers with your domain

A domain without MX records and without senders in SPF is checked as a domain that sends no mail: it needs v=spf1 -all and p=reject so nobody can spoof it. DKIM, MTA-STS and DMARC reports are not required for it.

Ready-made answers

FieldWhat it answers
spoofingCan somebody send email as this domain? spoofable yes/no, status (protected = DMARC reject, spam_folder = quarantine, not_protected, unknown), the reasons, and whether subdomains are protected. Only an enforced DMARC policy stops forged From addresses; SPF and DKIM alone do not
bulkSenderGmail, Yahoo and Microsoft bulk sender rules (rejected with error 550 since May 2026): ready, not_ready, unknown or not_applicable, with missing and unverified items. Checked from DNS: valid SPF, a DKIM key, a DMARC record (at least p=none), reverse DNS of the servers that SPF allows. Not visible in DNS: one-click unsubscribe, the spam complaint rate, alignment of each sending service, TLS of sent mail
suggestedRecordsRecords to paste into DNS: a repaired SPF record (merged records, ip4: added to bare IPs, ptr and dead includes removed, ~all added), the next DMARC step (none → quarantine → reject, removed tags dropped, reports added), v=spf1 -all + p=reject + null MX for a domain without mail, and a TLS-RPT record. No suggestion when the fix needs knowledge that DNS does not have (unknown terms, more than 10 lookups)
servicesServices the DNS shows: mail provider, sending services (SPF), DKIM signers, DMARC report service and about 60 TXT verification records (HubSpot, Atlassian, DocuSign, Zoom, Stripe, OpenAI, …). No extra query

Every suggested record has safeToPublish. true: the record cannot stop legitimate mail (it repairs a record that receivers already reject as broken, only adds monitoring or reports, or locks a domain that sends no mail). false: review first, because some legitimate mail can fail after it (DMARC quarantine/reject step, SPF built from the mail provider, merged SPF records, removed +all or ptr, a report address you must fill in).

Report addresses in suggestedRecords are kept only when they belong to a report service or a role mailbox (dmarc@, postmaster@, …); other addresses become <your-report-address>.

Grade

Every finding has a severity. Score = 100 minus 40 per critical, 20 per high, 10 per medium and 3 per low finding. Grade: A ≥ 90, B ≥ 75, C ≥ 60, D ≥ 40, F below 40. Info findings (for example "BIMI could show your logo") do not change the score.

Input

{
"domains": ["acme.com", "https://www.example.org/contact", "info@shop.example.net"],
"checkLookalikes": false
}
  • domains: up to 10,000 domains, website URLs or email addresses. Only the domain is used; an email address is never written to the output. www. is removed; other subdomains are checked as given.
  • sourceDatasetId and sourceField: read domains from another Actor's dataset, for example the website field of a Google Maps export.
  • checkDkim, extraDkimSelectors, checkMtaSts, checkBlocklists, checkLookalikes, maxConcurrency.

Sample output

Shortened result for a fictional domain:

{
"domain": "acme-hotel.com",
"status": "checked",
"grade": "C",
"score": 71,
"summary": "Grade C: DMARC policy is none (monitor only); No DKIM key found among 42 common selectors.",
"salesHook": "DMARC of acme-hotel.com only monitors (p=none): forged email still reaches inboxes.",
"spoofing": {"spoofable": true, "status": "not_protected", "reasons": ["DMARC policy is none (monitor only)"], "subdomainsProtected": false},
"bulkSender": {"status": "unknown", "missing": [], "unverified": ["DKIM (no key among 42 common selectors)"]},
"services": ["Microsoft 365", "Google site verification"],
"suggestedRecords": [
{"type": "TXT", "name": "_dmarc.acme-hotel.com", "value": "v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@acme-hotel.com;",
"safeToPublish": false,
"reason": "Next step p=quarantine, when the reports show that all your senders pass; added reports to dmarc-reports@acme-hotel.com (create the mailbox)."}
],
"mail": {"receivesMail": true, "mxHosts": ["acme-hotel-com.mail.protection.outlook.com"], "providers": ["Microsoft 365"]},
"spf": {"record": "v=spf1 include:spf.protection.outlook.com -all", "valid": true, "allQualifier": "fail", "lookupCount": 1},
"dmarc": {"policy": "none", "effectivePolicy": "none", "enforced": false, "reportDomains": []},
"dkim": {"selectorsChecked": 42, "found": false, "keys": []},
"findings": [
{"id": "dmarc_policy_none", "severity": "medium", "title": "DMARC policy is none (monitor only)",
"fix": "Read the reports, fix the senders, then move to p=quarantine and p=reject."},
{"id": "dkim_not_found", "severity": "medium", "title": "No DKIM key found among 42 common selectors",
"fix": "Turn on DKIM signing at every sending service and publish the keys."}
]
}

Use the Overview view or the overviewCsv output link for a spreadsheet: one row per domain with grade, score, summary, sales hook, spoofable, bulk sender status, services, mail provider, SPF, DMARC, DKIM, MTA-STS, BIMI and DNSSEC.

Each item has a status: checked, not_found (the domain does not exist), error (DNS failed) or invalid (the input is not a domain). incompleteChecks lists checks whose DNS lookups failed; a failed lookup is never reported as "missing".

Pricing

Pay per event:

  • $0.005 per checked domain (domain-checked).
  • $0.025 per lookalike scan (lookalike-scan): an extra event per checked domain, only when checkLookalikes is on.
  • Domains that do not exist, DNS errors and invalid inputs are free.

Set a maximum charge for the run; the Actor stops cleanly when the next domain would go over it.

Limits

  • DKIM: DNS cannot list DKIM selectors. "Not found among 42 common selectors" does not prove that the domain has no DKIM. Add selectors you know (from the s= tag of an email header) in extraDkimSelectors.
  • No SMTP: the Actor sends no email and does not connect to mail servers (port 25 is closed on the platform). STARTTLS support is not checked.
  • Lookalikes: the owner of a variant is not known (no WHOIS). Same name servers or same own mail servers are a hint that the variant belongs to you, not proof. Large brands register many variants themselves.
  • Blocklists: only the free lists above. Before each run the Actor tests every list with its test address; a list that does not answer correctly from the platform is not used (see blocklistsUsed in the run summary).
  • Subdomains of hosting platforms (for example shop.webflow.io) inherit DMARC from the platform domain.

Personal data

The Actor reads public DNS records only. DMARC and TLS-RPT report addresses can contain a person's name, so only their domain is returned. No WHOIS data, no names, no email addresses.

Run summary

The key-value store record RUN_SUMMARY has counts by status and grade, duplicates, the blocklists used, DNS query and error counts, and the run time.