# Domain Intelligence: WHOIS/RDAP, DNS, Subdomains, SSL, $2/1k (`transparent_meteorite/domain-intelligence-lookup`) Actor

Bulk domain lookup from public protocols: RDAP registration (registrar, created, expires, nameservers, age), DNS over HTTPS (A, AAAA, MX, NS, TXT with SPF and DMARC parsed), subdomains from certificate transparency, SSL certificate expiry and key HTTP security headers. $0.002 per domain.

- **URL**: https://apify.com/transparent_meteorite/domain-intelligence-lookup.md
- **Developed by:** [Open Data Actors](https://apify.com/transparent_meteorite) (community)
- **Categories:** Developer tools, SEO tools, Lead generation
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

Pay per event

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

## Domain Intelligence Lookup: WHOIS/RDAP, DNS, subdomains, SSL and security headers at $0.002 per domain

![Domain Intelligence on Apify](https://api.apify.com/v2/key-value-stores/9BAn0msnxToXlD9TO/records/banner-domain-intelligence-lookup.png)

![Domain Intelligence sample output table](https://api.apify.com/v2/key-value-stores/9BAn0msnxToXlD9TO/records/output-domain-intelligence-lookup.png)

- **In short:** Domain Intelligence Lookup (Apify actor `transparent_meteorite/domain-intelligence-lookup`) looks up registration, DNS, email-security, subdomain, SSL and HTTP security-header facts for a list of domains from public protocols.
- **Who it is for:** security and IT teams, email deliverability consultants, domain investors, sales teams qualifying accounts.
- **Input:** a list of domains, max domains, include subdomains, max subdomains, check SSL, check headers.
- **Output:** registrar, creation and expiry dates, domain age, nameservers, A/AAAA/MX/NS/TXT records, parsed SPF and DMARC, subdomains, SSL issuer and expiry, security headers.
- **Price:** $0.002 per domain plus $0.00005 per run start. Pay per result, no subscription; Apify's free plan credit covers a first test.
- **Limits:** RDAP data depends on the registry (some ccTLDs return little); subdomains are only those seen in certificate transparency logs.

**Key facts**

- Actor name: Domain Intelligence Lookup
- Actor ID: `transparent_meteorite/domain-intelligence-lookup`
- Store page: https://apify.com/transparent_meteorite/domain-intelligence-lookup
- Data source: RDAP, DNS over HTTPS, certificate transparency logs and the live site
- Pricing model: pay per event (`apify-actor-start` $0.00005, `domain-looked-up` $0.002)
- Output formats: JSON, CSV, Excel, XML, HTML table, RSS (Apify dataset)
- Access: Apify Console, REST API, JavaScript/Python clients, schedules, webhooks, Apify MCP server
- Login or third-party API key needed: no, only an Apify account
- Also known as: WHOIS API, bulk domain lookup, DMARC checker, SPF record checker, subdomain finder, SSL expiry checker
- Maintainer: transparent_meteorite (independent developer)
- Last updated: 2026-10-07

**Paste a list of domains; get registration data, DNS records with SPF and DMARC parsed, subdomains from certificate transparency, the TLS certificate and HTTP security headers, one row per domain.**

Everything comes from public protocols: RDAP (the WHOIS successor), DNS over HTTPS (Cloudflare, Google as fallback), public certificate transparency logs (crt.sh, Cert Spotter as fallback), a TLS handshake on port 443 and one HTTPS request to the homepage. No API keys, no browser, no proxies. A section that fails (for example crt.sh timing out) is reported in the row's `errors` field and never fails the whole row.

### Quick start

Press **Start** with the prefilled form (example.com, apify.com, github.com). Or use your own list:

```json
{
  "domains": ["example.com", "apify.com", "github.com"],
  "maxDomains": 3,
  "includeSubdomains": true,
  "maxSubdomains": 50,
  "checkSsl": true,
  "checkHeaders": true
}
```

URLs such as `https://www.example.com/page` are reduced to their host. Malformed entries (IPs, ports, credentials, reserved TLDs) are skipped, listed in the run log and not charged.

### Input

| Field | Default | What it does |
|---|---|---|
| `domains` | example.com, apify.com, github.com | Domains to look up (required) |
| `maxDomains` | 100 (1-5000) | Cap on domains looked up and charged this run |
| `includeSubdomains` | true | Query certificate transparency for subdomain names |
| `maxSubdomains` | 200 (1-5000) | Cap on names returned per domain (`subdomainCount` still shows the full count) |
| `checkSsl` | true | Read the TLS certificate on port 443 |
| `checkHeaders` | true | Fetch the homepage and score six security headers |

### Output

One row per domain. Main fields:

| Field | What it is |
|---|---|
| `domain`, `registrableDomain`, `checkedAt` | Normalized host, its registrable domain, timestamp |
| `registered` | true, false (confirmed non-existent) or null (unknown) |
| `registrar`, `createdAt`, `expiresAt`, `updatedAt`, `ageDays` | RDAP registration data |
| `nameservers`, `status` | RDAP nameservers and status flags |
| `dns` | A, AAAA, MX, NS, TXT, CNAME records and DNS status |
| `hasSpf`, `hasDmarc`, `dmarcPolicy` | SPF and DMARC presence, DMARC policy (none, quarantine, reject) |
| `subdomainCount`, `subdomains`, `certificatesSeen`, `subdomainsSource` | Names seen in public certificates |
| `sslIssuer`, `sslValidTo`, `sslDaysLeft`, `ssl` | Certificate issuer, expiry and full detail |
| `securityHeadersScore`, `securityHeaders` | Score 0-6 for HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy |
| `answered` | How many sections returned an answer |
| `errors` | Present only when a section failed or was skipped, one message per section |

### Pricing

Pay per event, no subscription:

| Event | Price |
|---|---|
| Actor start | $0.00005 per run |
| Domain looked up | $0.002 per domain ($2 per 1,000) |

A domain is charged once, only when at least one section returned an answer (a confirmed non-existent domain counts). Malformed input is free.

### Use from AI agents (MCP, ChatGPT, Claude, Perplexity)

Domain Intelligence Lookup works as a tool for AI assistants through the official Apify MCP server. Add this server URL to any MCP client (Claude Desktop, Claude Code, Cursor, ChatGPT connectors, VS Code):

```
https://mcp.apify.com/?actors=transparent_meteorite/domain-intelligence-lookup
```

Claude Desktop / Cursor config:

```json
{
  "mcpServers": {
    "apify": {
      "url": "https://mcp.apify.com/?actors=transparent_meteorite/domain-intelligence-lookup",
      "headers": { "Authorization": "Bearer <YOUR_APIFY_TOKEN>" }
    }
  }
}
```

Then ask in plain language, for example: "How do I check SPF and DMARC for many domains at once?"

Call it directly over HTTP (runs the actor and returns the dataset items in one request):

```bash
curl -X POST "https://api.apify.com/v2/acts/transparent_meteorite~domain-intelligence-lookup/run-sync-get-dataset-items?token=$APIFY_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"domains": ["example.com", "apify.com", "github.com"], "maxDomains": 3, "includeSubdomains": true, "maxSubdomains": 50, "checkSsl": true, "checkHeaders": true}'
```

Python:

```python
from apify_client import ApifyClient
client = ApifyClient("<YOUR_APIFY_TOKEN>")
run = client.actor("transparent_meteorite/domain-intelligence-lookup").call(run_input={"domains": ["example.com", "apify.com", "github.com"], "maxDomains": 3, "includeSubdomains": true, "maxSubdomains": 50, "checkSsl": true, "checkHeaders": true})
for item in client.dataset(run["defaultDatasetId"]).iterate_items():
    print(item)
```

The same actor works in n8n, Make, Zapier, LangChain, LlamaIndex and CrewAI through their Apify integrations.

#### Questions people ask

**How do I check SPF and DMARC for many domains at once?**
Give the domains to this actor; each row includes the parsed SPF and DMARC records.

**Is there a cheap bulk WHOIS API?**
This actor returns RDAP registration data (the successor to WHOIS) at $0.002 per domain.

**Can it find subdomains?**
Yes, from certificate transparency logs, up to maxSubdomains per domain.

### Limits and notes

- crt.sh is often slow; the actor falls back to Cert Spotter, and on failure the row still returns with `subdomainsError`. Subdomain lists reflect only names that appear in public certificates, not a full DNS enumeration.
- SSL and header checks are skipped for hosts that do not resolve or resolve only to private addresses (SSRF guard).
- RDAP data depends on the registry; some TLDs return less, and registrant contact details are not requested or returned.
- Public lookups are rate limited upstream; very large lists run slower because crt.sh requests are spaced out.
- Only public protocol data is read. Nothing is guessed, and no personal data is collected beyond what a registry publishes in the fields above.

### Changelog

- 2026-10-07: added plain-language summary, key facts, AI-agent (MCP) section and question-style FAQ; refreshed Store SEO metadata.

# Actor input Schema

## `domains` (type: `array`):

Domain names to look up, one per row, for example example.com. A URL such as https://www.example.com/page is reduced to its host. Malformed entries are skipped, listed in the run summary and never charged.

## `maxDomains` (type: `integer`):

Cap on domains looked up (and charged) this run.

## `includeSubdomains` (type: `boolean`):

Query crt.sh for names seen in public certificates. crt.sh can be slow; on timeout the row still returns with a subdomainsError field.

## `maxSubdomains` (type: `integer`):

Cap on subdomain names returned per domain (subdomainCount still shows the full count).

## `checkSsl` (type: `boolean`):

Open a TLS connection to port 443 and read the certificate issuer, validity dates and days left.

## `checkHeaders` (type: `boolean`):

Request the site homepage over HTTPS and report HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.

## Actor input object example

```json
{
  "domains": [
    "example.com",
    "apify.com",
    "github.com"
  ],
  "maxDomains": 100,
  "includeSubdomains": true,
  "maxSubdomains": 200,
  "checkSsl": true,
  "checkHeaders": true
}
```

# Actor output Schema

## `overview` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "domains": [
        "example.com",
        "apify.com",
        "github.com"
    ]
};

// Run the Actor and wait for it to finish
const run = await client.actor("transparent_meteorite/domain-intelligence-lookup").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "domains": [
        "example.com",
        "apify.com",
        "github.com",
    ] }

# Run the Actor and wait for it to finish
run = client.actor("transparent_meteorite/domain-intelligence-lookup").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "domains": [
    "example.com",
    "apify.com",
    "github.com"
  ]
}' |
apify call transparent_meteorite/domain-intelligence-lookup --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,transparent_meteorite/domain-intelligence-lookup"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/RpmCtUq0qJd5gmekn/builds/L7dulgWaIMHgUzh1z/openapi.json
