Bulk WHOIS Domain Lookup: RDAP, DNS, SSL & Security Headers
Pricing
from $3.00 / 1,000 domain analyzeds
Bulk WHOIS Domain Lookup: RDAP, DNS, SSL & Security Headers
Bulk WHOIS / RDAP domain lookup: registrar, domain age, creation and expiry dates, plus DNS records (MX, SPF, DMARC, email provider), SSL certificate expiry and a security-headers grade, in one call per domain. No personal data. $0.003 per domain; unregistered domains are free.
Pricing
from $3.00 / 1,000 domain analyzeds
Rating
0.0
(0)
Developer
Ventura WorkAlong
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
5 hours ago
Last modified
Categories
Share
Bulk WHOIS Domain Lookup: RDAP, DNS, SSL Certificate & Security Headers
Bulk WHOIS Domain Lookup runs four domain checks in one call: WHOIS/RDAP registration data (registrar, domain age, expiry), DNS records, the SSL certificate, and HTTP security headers. For each domain you get:
- Registration data: registrar, creation, expiry and update dates, domain age, statuses, nameservers and DNSSEC. It comes from RDAP, the official, structured successor to WHOIS. No personal data: registrant and other contacts are never returned.
- DNS: A, AAAA, MX, NS, TXT, CAA and SOA records, plus the SPF record, the DMARC policy and the detected email provider (Google Workspace, Microsoft 365, Zoho, and others).
- SSL certificate: whether it's valid (trusted chain and matching hostname), issuer, expiry date and days left, SANs, key type and TLS version.
- Security headers: a 0–100 score and A+–F grade for HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and COOP. It also checks the HTTP→HTTPS redirect and flags server version disclosure.
$0.003 per domain. Invalid, unregistered and completely unreachable domains are free.
How to look up WHOIS data for a list of domains
- Paste domains, hostnames or URLs into Domains, one per line.
- Optional: switch off sections you don't need (it's faster; the price is the same).
- Click Start. The Overview table shows registrar, created and expiry dates, email provider, DMARC, SSL days left and headers grade per domain. Export to CSV/Excel or use the API.
Use cases
- AI agents (MCP): "Is this domain legit? How old is it? Who hosts its email?" One cheap call answers all of it.
- KYB, fraud and vendor checks: domain age, registrar, valid SSL, DMARC enforcement.
- Sales and lead enrichment: email provider (Google vs Microsoft), DNS host, security posture.
- Security and IT monitoring: expiring certificates and domains, missing security headers, weak SPF/DMARC across a portfolio of domains.
Input
| Field | What it does | Default |
|---|---|---|
domains | Domains, hostnames or URLs. Registration is looked up for the registrable domain (shop.bbc.co.uk → bbc.co.uk). SSL and headers use the host you give; a bare domain falls back to www. if needed. | required |
includeRegistration | RDAP registration data | true |
includeDns | DNS records + SPF/DMARC/email provider | true |
includeSsl | TLS certificate check on port 443 | true |
includeSecurityHeaders | One homepage request; header grade + HTTPS redirect | true |
respectRobotsTxt | Skip the homepage request if robots.txt disallows it | true |
maxConcurrency | Domains in parallel (1–10) | 5 |
Switching sections off doesn't change the price. It only makes runs faster.
Output (one item per domain)
Real output for apify.com (2026-10-03, shortened):
{"input": "apify.com", "domain": "apify.com", "host": "apify.com", "status": "ok","summary": {"registrar": "Amazon Registrar, Inc.", "createdAt": "2009-06-02T17:14:10Z", "expiresAt": "2035-06-02T17:14:10Z","ageDays": 6331, "emailProvider": "Google Workspace", "hasSpf": true, "dmarcPolicy": "reject","sslValid": true, "sslIssuer": "Amazon", "sslDaysUntilExpiry": 105, "securityGrade": "B"},"registration": {"registered": true, "registrar": "Amazon Registrar, Inc.", "registrarIanaId": "468","registrarAbuseEmail": "trustandsafety@support.aws.com", "statuses": ["client transfer prohibited"],"nameservers": ["ns-1225.awsdns-25.org", "..."], "dnssec": true, "rdapServer": "rdap.verisign.com","contactsRedacted": true, "contactRolesOmitted": []},"dns": { "mx": [{ "priority": 1, "host": "aspmx.l.google.com" }], "spf": { "all": "-all" }, "dmarc": { "policy": "reject" } },"ssl": { "valid": true, "issuerOrganization": "Amazon", "notAfter": "2027-01-16T23:59:59+00:00", "tlsVersion": "TLSv1.3" },"securityHeaders": { "score": 70, "grade": "B", "missing": ["referrer-policy", "permissions-policy", "cross-origin-opener-policy"], "notes": ["CSP allows 'unsafe-inline' scripts"], "httpsRedirect": true },"sectionsOk": ["registration", "dns", "ssl", "securityHeaders"],"error": null}
status:okis charged.not_registeredandfailedare free.- If one section fails (e.g. no HTTPS), the others still return, and
errorsays which section failed and why. - The Overview dataset view is a flat table with one row per domain.
Security-header scoring (transparent, our own heuristic)
| Header | Points |
|---|---|
| Strict-Transport-Security, max-age ≥ 180 days (shorter: 12) | 25 |
| Content-Security-Policy enforced (report-only: 10) | 25 |
| X-Frame-Options DENY/SAMEORIGIN, or CSP frame-ancestors | 10 |
| X-Content-Type-Options: nosniff | 10 |
| Referrer-Policy (not unsafe-url) | 10 |
| Permissions-Policy | 10 |
| Cross-Origin-Opener-Policy | 10 |
Grades: A+ ≥ 95, A ≥ 80, B ≥ 65, C ≥ 50, D ≥ 30, F < 30. Headers are only one part of security. A good grade doesn't mean a site is secure.
Limits (please read)
- Some ccTLDs have no RDAP, including .io, .de, .co, .eu, .jp, .us and .me (per the IANA bootstrap registry, 2026-09-30). For those domains the registration section returns an error. DNS, SSL and headers still work, and the domain is still charged because those sections answered. Filter those TLDs out first if you only need registration data.
- No personal data, by design. You won't get registrant names, emails, phones or addresses, even where a registry publishes them. You do get the registrar's public abuse contact, which is a business role contact.
- Registry rate limits. Each registry server gets at most 1 request per second, and one run makes at most 2,000 registration lookups. A 2,000-domain list of
.comnames therefore takes about 35 minutes. Lookups past the cap return an error and the other sections still run. Split huge lists into several runs. - RDAP shows the registry's view. Some registries omit expiry dates or registrar details.
- The SSL check looks at port 443 on the first reachable address only. It doesn't test every server behind a load balancer, and it isn't a full TLS configuration audit (no cipher-suite scan).
- The headers check fetches the homepage once. Bot-protected sites may answer 403. The grade then reflects that error page, and
httpStatusshows it. - DNS uses public resolvers at query time. Results can differ by location (GeoDNS).
Acceptable use
Registry terms (e.g. Verisign's RDAP terms) allow lawful use only. They forbid using the data for unsolicited marketing (spam) and high-volume automated querying. By using this Actor you agree to follow those terms. This Actor is meant for checks, research, security and enrichment, not for building spam lists. The rate limits above are fixed for that reason.
Responsible operation
- One homepage request per domain (plus robots.txt and an HTTP→HTTPS check), with an identifying user agent (
DomainLookupBot). robots.txt is honored by default. - Private and internal addresses are refused.
- Contact data, SOA mailbox (RNAME) and DMARC report addresses are dropped before output.
Pricing
Pay per event: $0.003 per domain analyzed (domain-analyzed). Invalid, unregistered and unreachable domains are free. Your run stops cleanly at your maximum total charge.
FAQ
Is RDAP the same as WHOIS?
RDAP is the official successor to WHOIS, run by the same registries. It returns the same registration facts (registrar, creation, expiry, status, nameservers) as structured JSON. Since 2025, gTLD registries are no longer required to run port-43 WHOIS, so RDAP is the reliable source.
How do I check domain age in bulk?
Every result has summary.ageDays and summary.createdAt. Sort the Overview table by the Created column, or the full export by summary.ageDays.
Why is registration data missing for some domains?
Some ccTLDs (.io, .de, .co, .eu, .jp, .us, .me) publish no RDAP service. See Limits.
Does it return the owner's name or email?
No, by design. Registrant contacts are personal data and are never returned.
Related Actors
- Tech Stack Detector: CMS, ecommerce platform and analytics for the same domains.
- Sitemap URL Extractor and PageSpeed Insights Bulk Checker.