Bulk WHOIS Domain Lookup: RDAP, DNS, SSL & Security Headers avatar

Bulk WHOIS Domain Lookup: RDAP, DNS, SSL & Security Headers

Pricing

from $3.00 / 1,000 domain analyzeds

Go to Apify Store
Bulk WHOIS Domain Lookup: RDAP, DNS, SSL & Security Headers

Bulk WHOIS Domain Lookup: RDAP, DNS, SSL & Security Headers

Bulk WHOIS / RDAP domain lookup: registrar, domain age, creation and expiry dates, plus DNS records (MX, SPF, DMARC, email provider), SSL certificate expiry and a security-headers grade, in one call per domain. No personal data. $0.003 per domain; unregistered domains are free.

Pricing

from $3.00 / 1,000 domain analyzeds

Rating

0.0

(0)

Developer

Ventura WorkAlong

Ventura WorkAlong

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

5 hours ago

Last modified

Share

Bulk WHOIS Domain Lookup: RDAP, DNS, SSL Certificate & Security Headers

Bulk WHOIS Domain Lookup runs four domain checks in one call: WHOIS/RDAP registration data (registrar, domain age, expiry), DNS records, the SSL certificate, and HTTP security headers. For each domain you get:

  1. Registration data: registrar, creation, expiry and update dates, domain age, statuses, nameservers and DNSSEC. It comes from RDAP, the official, structured successor to WHOIS. No personal data: registrant and other contacts are never returned.
  2. DNS: A, AAAA, MX, NS, TXT, CAA and SOA records, plus the SPF record, the DMARC policy and the detected email provider (Google Workspace, Microsoft 365, Zoho, and others).
  3. SSL certificate: whether it's valid (trusted chain and matching hostname), issuer, expiry date and days left, SANs, key type and TLS version.
  4. Security headers: a 0–100 score and A+–F grade for HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and COOP. It also checks the HTTP→HTTPS redirect and flags server version disclosure.

$0.003 per domain. Invalid, unregistered and completely unreachable domains are free.

How to look up WHOIS data for a list of domains

  1. Paste domains, hostnames or URLs into Domains, one per line.
  2. Optional: switch off sections you don't need (it's faster; the price is the same).
  3. Click Start. The Overview table shows registrar, created and expiry dates, email provider, DMARC, SSL days left and headers grade per domain. Export to CSV/Excel or use the API.

Use cases

  • AI agents (MCP): "Is this domain legit? How old is it? Who hosts its email?" One cheap call answers all of it.
  • KYB, fraud and vendor checks: domain age, registrar, valid SSL, DMARC enforcement.
  • Sales and lead enrichment: email provider (Google vs Microsoft), DNS host, security posture.
  • Security and IT monitoring: expiring certificates and domains, missing security headers, weak SPF/DMARC across a portfolio of domains.

Input

FieldWhat it doesDefault
domainsDomains, hostnames or URLs. Registration is looked up for the registrable domain (shop.bbc.co.uk → bbc.co.uk). SSL and headers use the host you give; a bare domain falls back to www. if needed.required
includeRegistrationRDAP registration datatrue
includeDnsDNS records + SPF/DMARC/email providertrue
includeSslTLS certificate check on port 443true
includeSecurityHeadersOne homepage request; header grade + HTTPS redirecttrue
respectRobotsTxtSkip the homepage request if robots.txt disallows ittrue
maxConcurrencyDomains in parallel (1–10)5

Switching sections off doesn't change the price. It only makes runs faster.

Output (one item per domain)

Real output for apify.com (2026-10-03, shortened):

{
"input": "apify.com", "domain": "apify.com", "host": "apify.com", "status": "ok",
"summary": {
"registrar": "Amazon Registrar, Inc.", "createdAt": "2009-06-02T17:14:10Z", "expiresAt": "2035-06-02T17:14:10Z",
"ageDays": 6331, "emailProvider": "Google Workspace", "hasSpf": true, "dmarcPolicy": "reject",
"sslValid": true, "sslIssuer": "Amazon", "sslDaysUntilExpiry": 105, "securityGrade": "B"
},
"registration": {
"registered": true, "registrar": "Amazon Registrar, Inc.", "registrarIanaId": "468",
"registrarAbuseEmail": "trustandsafety@support.aws.com", "statuses": ["client transfer prohibited"],
"nameservers": ["ns-1225.awsdns-25.org", "..."], "dnssec": true, "rdapServer": "rdap.verisign.com",
"contactsRedacted": true, "contactRolesOmitted": []
},
"dns": { "mx": [{ "priority": 1, "host": "aspmx.l.google.com" }], "spf": { "all": "-all" }, "dmarc": { "policy": "reject" } },
"ssl": { "valid": true, "issuerOrganization": "Amazon", "notAfter": "2027-01-16T23:59:59+00:00", "tlsVersion": "TLSv1.3" },
"securityHeaders": { "score": 70, "grade": "B", "missing": ["referrer-policy", "permissions-policy", "cross-origin-opener-policy"], "notes": ["CSP allows 'unsafe-inline' scripts"], "httpsRedirect": true },
"sectionsOk": ["registration", "dns", "ssl", "securityHeaders"],
"error": null
}
  • status: ok is charged. not_registered and failed are free.
  • If one section fails (e.g. no HTTPS), the others still return, and error says which section failed and why.
  • The Overview dataset view is a flat table with one row per domain.

Security-header scoring (transparent, our own heuristic)

HeaderPoints
Strict-Transport-Security, max-age ≥ 180 days (shorter: 12)25
Content-Security-Policy enforced (report-only: 10)25
X-Frame-Options DENY/SAMEORIGIN, or CSP frame-ancestors10
X-Content-Type-Options: nosniff10
Referrer-Policy (not unsafe-url)10
Permissions-Policy10
Cross-Origin-Opener-Policy10

Grades: A+ ≥ 95, A ≥ 80, B ≥ 65, C ≥ 50, D ≥ 30, F < 30. Headers are only one part of security. A good grade doesn't mean a site is secure.

Limits (please read)

  • Some ccTLDs have no RDAP, including .io, .de, .co, .eu, .jp, .us and .me (per the IANA bootstrap registry, 2026-09-30). For those domains the registration section returns an error. DNS, SSL and headers still work, and the domain is still charged because those sections answered. Filter those TLDs out first if you only need registration data.
  • No personal data, by design. You won't get registrant names, emails, phones or addresses, even where a registry publishes them. You do get the registrar's public abuse contact, which is a business role contact.
  • Registry rate limits. Each registry server gets at most 1 request per second, and one run makes at most 2,000 registration lookups. A 2,000-domain list of .com names therefore takes about 35 minutes. Lookups past the cap return an error and the other sections still run. Split huge lists into several runs.
  • RDAP shows the registry's view. Some registries omit expiry dates or registrar details.
  • The SSL check looks at port 443 on the first reachable address only. It doesn't test every server behind a load balancer, and it isn't a full TLS configuration audit (no cipher-suite scan).
  • The headers check fetches the homepage once. Bot-protected sites may answer 403. The grade then reflects that error page, and httpStatus shows it.
  • DNS uses public resolvers at query time. Results can differ by location (GeoDNS).

Acceptable use

Registry terms (e.g. Verisign's RDAP terms) allow lawful use only. They forbid using the data for unsolicited marketing (spam) and high-volume automated querying. By using this Actor you agree to follow those terms. This Actor is meant for checks, research, security and enrichment, not for building spam lists. The rate limits above are fixed for that reason.

Responsible operation

  • One homepage request per domain (plus robots.txt and an HTTP→HTTPS check), with an identifying user agent (DomainLookupBot). robots.txt is honored by default.
  • Private and internal addresses are refused.
  • Contact data, SOA mailbox (RNAME) and DMARC report addresses are dropped before output.

Pricing

Pay per event: $0.003 per domain analyzed (domain-analyzed). Invalid, unregistered and unreachable domains are free. Your run stops cleanly at your maximum total charge.

FAQ

Is RDAP the same as WHOIS?

RDAP is the official successor to WHOIS, run by the same registries. It returns the same registration facts (registrar, creation, expiry, status, nameservers) as structured JSON. Since 2025, gTLD registries are no longer required to run port-43 WHOIS, so RDAP is the reliable source.

How do I check domain age in bulk?

Every result has summary.ageDays and summary.createdAt. Sort the Overview table by the Created column, or the full export by summary.ageDays.

Why is registration data missing for some domains?

Some ccTLDs (.io, .de, .co, .eu, .jp, .us, .me) publish no RDAP service. See Limits.

Does it return the owner's name or email?

No, by design. Registrant contacts are personal data and are never returned.