# Domain Security Audit (TLS, HTTP headers, redirects, robots) (`webdatatools/domain-security-audit`) Actor

Domain Security Audit checks TLS certificate validity, HSTS/CSP and other HTTP security headers, the redirect chain and robots.txt/llms.txt AI-bot rules for any list of domains — one scored, graded row per domain.

- **URL**: https://apify.com/webdatatools/domain-security-audit.md
- **Developed by:** [Murat Uzun](https://apify.com/webdatatools) (community)
- **Categories:** Developer tools, SEO tools, Business
- **Stats:** 1 total users, 0 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $3.00 / 1,000 results

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.
Since this Actor supports Apify Store discounts, the price gets lower the higher subscription plan you have.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

### What is Domain Security Audit?

Domain Security Audit is an Apify Actor that checks a **TLS certificate, the HTTP → HTTPS redirect chain, HTTP security headers, cookie flags, and robots.txt / llms.txt AI-crawler rules** for any list of domains, and returns **one scored, graded row per domain**. TLS comes straight from a `node:tls` handshake on port 443; everything else is a plain `fetch` — no proxies, no headless browser, no anti-bot wall. Each row gets a `securityScore` (0-100), a `securityGrade` (A-F) and an `issues` array in plain English ("No HSTS header", "TLS certificate expires in 9 day(s)") that drops straight into a client report or a sales-prospecting sheet.

### Why use Domain Security Audit?

- **Security consultants and MSPs** — score a prospect list in minutes instead of running `curl -I` and `openssl s_client` on each site by hand.
- **Sales and lead-scoring teams** — a low `securityGrade` or an expiring certificate is a concrete opener for an outbound e-mail.
- **SEO and content teams** — `aiBotsDisallowed` and `llmsTxtExists` show whether a site blocks GPTBot/ClaudeBot/Google-Extended or publishes an `llms.txt`, which matters for AI-search visibility.
- **Internal audits** — run it on a schedule against your own domain portfolio to catch a certificate about to expire or a header that regressed after a deploy.

### How to use Domain Security Audit

1. Paste your domains into **Domains**. Bare domains, full URLs and `www.` prefixes are all accepted and normalised: `https://www.apify.com/store` becomes `apify.com`.
2. Leave **Check TLS certificate**, **Check HTTP security headers**, **Follow redirect chain** and **Check robots.txt and llms.txt** all on for the full audit; turn any of them off to skip that section and save a couple of seconds per domain.
3. Raise **Max concurrency** for large lists, click **Start**, then export the dataset as JSON, CSV, Excel or HTML from the **Overview**, **TLS certificate** or **Headers, redirects & robots** views.

### Input

| Parameter | Type | Default | Description |
| --- | --- | --- | --- |
| `domains` | array | `["apify.com"]` | Domains to audit, one row each |
| `checkTls` | boolean | `true` | Connect on port 443 and read the peer certificate |
| `checkHeaders` | boolean | `true` | Read HSTS, CSP, X-Frame-Options and other headers on the final URL |
| `followRedirects` | boolean | `true` | Follow the `http://` → final-URL redirect chain (up to 10 hops) |
| `checkRobots` | boolean | `true` | Fetch `/robots.txt` (AI-bot rules) and `/llms.txt` |
| `maxConcurrency` | integer | `5` | Domains audited in parallel (1-20) |

### Output

Domain Security Audit extracts 40+ fields per domain across four areas. You can download the dataset in various formats such as JSON, HTML, CSV or Excel.

| Field group | Example fields | Description |
| --- | --- | --- |
| TLS certificate | `certValidFrom`, `certValidTo`, `certDaysUntilExpiry`, `certIssuerOrg`, `certIssuerCN`, `certSubjectCN`, `certSanCount`, `certAuthorized`, `tlsProtocol` | Peer certificate read from a raw `node:tls` handshake, chain-validity flag and negotiated TLS version |
| Redirects | `finalUrl`, `redirectHops`, `redirectChain`, `httpsRedirect`, `wwwRedirect` | The hop-by-hop path from `http://<domain>/` to the final URL |
| HTTP headers | `hasHsts`, `hstsMaxAge`, `hstsIncludeSubdomains`, `hstsPreload`, `hasCsp`, `cspHasUnsafeInline`, `xFrameOptions`, `xContentTypeOptions`, `referrerPolicy`, `permissionsPolicy`, `server`, `xPoweredBy`, `cacheControl`, `cookieCount`, `secureCookieCount`, `httpOnlyCookieCount`, `sameSiteCookieCount` | Security headers and cookie flags on the final response |
| robots.txt / llms.txt | `robotsStatus`, `robotsDisallowAll`, `robotsSitemapCount`, `aiBotsDisallowed`, `llmsTxtExists`, `llmsTxtTitle`, `llmsTxtSize` | Which AI crawlers (GPTBot, ClaudeBot, Google-Extended, PerplexityBot…) are blocked, and whether an `llms.txt` exists |
| Score | `securityScore`, `securityGrade`, `issues` | 0-100 score, A-F grade and a plain-English findings list |
| Meta | `domain`, `error`, `scrapedAt` | Normalised hostname, failure reason if the domain was unreachable, and the audit timestamp |

### Example input

```json
{
    "domains": ["apify.com", "example.com", "neverssl.com"],
    "checkTls": true,
    "checkHeaders": true,
    "followRedirects": true,
    "checkRobots": true,
    "maxConcurrency": 5
}
```

### Example output

```json
{
    "domain": "apify.com",
    "certAuthorized": true,
    "certDaysUntilExpiry": 62,
    "certIssuerOrg": "Let's Encrypt",
    "tlsProtocol": "TLSv1.3",
    "finalUrl": "https://apify.com/",
    "redirectHops": 1,
    "httpsRedirect": true,
    "hasHsts": true,
    "hstsMaxAge": 63072000,
    "hasCsp": false,
    "xFrameOptions": "SAMEORIGIN",
    "robotsDisallowAll": false,
    "aiBotsDisallowed": [],
    "llmsTxtExists": false,
    "securityScore": 75,
    "securityGrade": "B",
    "issues": ["No Content-Security-Policy header"],
    "scrapedAt": "2026-09-12T15:45:00.000Z"
}
```

### Pricing

Domain Security Audit uses pay-per-event pricing: **$0.005 per domain result, i.e. $5 per 1,000 domains**, plus a negligible actor-start fee, platform usage included. Each domain is one TLS handshake, up to 10 HTTP redirect hops, one headers fetch and two text fetches (robots.txt, llms.txt), so compute cost stays in the cents even for a few hundred domains. Set **Maximum cost per run** and the Actor trims the domain list to what the budget covers instead of overspending.

### Domain Security Audit vs. manual `curl`/`openssl` checks

Checking one domain's TLS expiry, headers and robots.txt by hand means `openssl s_client`, `curl -I` and a manual read of `/robots.txt` — three tools per domain with no structured output. Domain Security Audit runs all of that for an entire list in parallel and returns one flat, scored dataset row per domain, ready to filter, sort or pipe into a CRM.

### Using Domain Security Audit with AI agents and MCP

Domain Security Audit is pay-per-event with limited permissions — the two requirements for an Actor to be callable through the Apify MCP server at `mcp.apify.com`. An agent passes `domains` and gets back a scored, graded row per domain it can reason over directly ("which of these ten prospects have the weakest header hygiene?"). The same run works from n8n, Make, Zapier and LangChain through Apify's integrations.

### FAQ

**How is the score calculated?** HTTPS redirect +20, valid/trusted certificate +20 (certificate has more than 14 days left +5), HSTS +15, CSP +10, X-Frame-Options +5, X-Content-Type-Options +5, Referrer-Policy +5, Permissions-Policy +5, no `X-Powered-By` leak +5, all cookies carry the `Secure` flag +5. Grades: A ≥ 85, B ≥ 70, C ≥ 50, D ≥ 30, else F.

**Why does `neverssl.com` score low?** It intentionally serves plain HTTP with no TLS certificate at all (it exists to test captive portals), so it loses every TLS- and HTTPS-redirect point.

**What happens with a domain that doesn't resolve?** The row still comes back — with `error` set to the failure reason and every other field `null` — instead of failing the whole run.

**Is this legal to run?** Yes. TLS certificates, HTTP response headers, `robots.txt` and `llms.txt` are all public information a server sends to anyone who connects; no personal data is collected.

**Can I export to CSV or Excel?** Yes, from the Output tab or the API, with ready-made **Overview**, **TLS certificate** and **Headers, redirects & robots** views.

### Related Actors

Part of the **webdatatools** web-intelligence suite — every Actor is pay-per-event, reads public data
without a login, and returns one clean row per entity:

Browse the whole suite at [webdatatools](https://paulet4a-commits.github.io/webdatatools/), or call ten of
these Actors straight from Claude, Cursor or Cline with the
[webdatatools MCP server](https://github.com/paulet4a-commits/webdatatools-mcp-server).

**Website & domain intelligence**

- [Email Extractor — Website Contact & Social Finder](https://apify.com/webdatatools/contact-extractor) — e-mails, phones and social profiles per domain
- [Tech Stack Detector — Wappalyzer & BuiltWith Alternative](https://apify.com/webdatatools/tech-stack-detector) — CMS, e-commerce, analytics, pixels and payments per domain
- [Domain DNS & Email Security Checker](https://apify.com/webdatatools/dns-email-security-checker) — SPF, DKIM, DMARC, MX provider, registrar and domain age
- [Subdomain Finder (Certificate Transparency)](https://apify.com/webdatatools/subdomain-finder) — every subdomain seen in CT logs, with a live DNS check
- [Bulk Core Web Vitals & PageSpeed Audit](https://apify.com/webdatatools/core-web-vitals-audit) — Lighthouse scores, LCP, CLS, INP and top fixes per URL
- [On-Page SEO Audit](https://apify.com/webdatatools/seo-page-audit) — title, meta, headings, links, images and schema issues per page
- [Sitemap URL Extractor & Change Monitor](https://apify.com/webdatatools/sitemap-extractor) — every sitemap URL, or new and removed pages between runs
- [Wayback Machine Snapshot & Page Change Tracker](https://apify.com/webdatatools/wayback-page-diff) — how a page changed over time, or every archived snapshot
- [Bulk Domain WHOIS & RDAP Lookup](https://apify.com/webdatatools/domain-whois-rdap) — registrar, dates, status and nameservers per domain
- [Web Scraper — CSS Selector & Data Extractor](https://apify.com/webdatatools/css-selector-extractor) — pull any CSS selector off any page, one row per URL
- [Website Screenshot Generator](https://apify.com/webdatatools/website-screenshot) — full-page or viewport PNG/JPEG screenshots of any URL

**Content for AI, LLMs and RAG**

- [AI Web Search & Read: Google results as clean Markdown](https://apify.com/webdatatools/ai-web-search) — a query turned into clean Markdown from the top search results
- [Website to Markdown — Content Crawler for LLM & RAG](https://apify.com/webdatatools/website-to-markdown) — any site as clean Markdown per page, no browser
- [Article & News Extractor (clean text, author, date, markdown)](https://apify.com/webdatatools/article-extractor) — clean article text, author, date and Markdown per URL
- [Structured Data & JSON-LD Extractor (Schema.org, Open Graph)](https://apify.com/webdatatools/structured-data-extractor) — Schema.org and Open Graph data from any page
- [Google News Scraper (RSS search by keyword, topic, site)](https://apify.com/webdatatools/google-news-scraper) — news results by keyword, topic or site
- [Press Release Monitor: PR Newswire, BusinessWire, GlobeNewswire](https://apify.com/webdatatools/press-release-monitor) — PR Newswire, Business Wire and GlobeNewswire releases

**Search, video and social**

- [YouTube Shorts Scraper](https://apify.com/webdatatools/youtube-shorts-scraper) — Shorts from channels, hashtags and searches with view counts
- [Pinterest Pins Scraper](https://apify.com/webdatatools/pinterest-pins-scraper) — latest pins of public Pinterest profiles and boards
- [YouTube Transcript Scraper](https://apify.com/webdatatools/youtube-transcript-scraper) — captions and subtitles as text + timed segments, per video or channel
- [Google Search Results Scraper — SERP API](https://apify.com/webdatatools/google-search-scraper) — organic SERP results per keyword and country
- [YouTube Comments Scraper — Comments & Replies](https://apify.com/webdatatools/youtube-comments-scraper) — comments and replies with likes, no API key
- [YouTube Channel Latest Videos (RSS, no API key)](https://apify.com/webdatatools/youtube-channel-videos) — the latest 15 videos of any channel from RSS
- [YouTube Channel Scraper (videos, shorts, live)](https://apify.com/webdatatools/youtube-channel-scraper) — a channel's full video, shorts and stream list
- [YouTube Search Results Scraper (videos, channels, no API key)](https://apify.com/webdatatools/youtube-search-scraper) — videos, channels and playlists per query
- [YouTube Video Details Scraper (views, likes, description, tags)](https://apify.com/webdatatools/youtube-video-details) — views, likes, description, tags and chapters per video
- [Apple Podcasts Lookup & Episodes Scraper](https://apify.com/webdatatools/podcast-lookup) — podcast metadata and episodes from iTunes and RSS
- [Bluesky Post, Search & Profile Scraper](https://apify.com/webdatatools/bluesky-scraper) — posts, profiles, followers and threads from the AT Protocol API
- [Telegram Channel Posts Scraper](https://apify.com/webdatatools/telegram-channel-scraper) — posts, views and media flags from any public channel
- [Substack Publication & Posts Scraper](https://apify.com/webdatatools/substack-scraper) — archive, authors and paywall status per publication
- [Google Play Reviews Scraper](https://apify.com/webdatatools/google-play-reviews-scraper) — reviews, ratings, replies and app versions per app
- [App Store Reviews Scraper](https://apify.com/webdatatools/app-store-reviews-scraper) — iOS reviews and ratings per app and country
- [Google Trends Scraper](https://apify.com/webdatatools/google-trends-scraper) — interest over time, by region, and related queries per keyword
- [Google Ads Transparency Scraper](https://apify.com/webdatatools/google-ads-transparency-scraper) — ads any advertiser runs on Google, with format and dates
- [Keyword Suggestions Scraper (Google, YouTube, Amazon, Bing)](https://apify.com/webdatatools/keyword-suggestions-scraper) — autocomplete keyword ideas from four search engines
- [Bilibili Scraper (Videos, Search, Popular)](https://apify.com/webdatatools/bilibili-scraper) — Chinese video platform: views, likes, coins, danmaku, uploader
- [Mastodon Scraper (Hashtags, Accounts, Trending)](https://apify.com/webdatatools/mastodon-scraper) — public fediverse posts by hashtag, account or trending
- [Meetup Events Scraper (Search by Keyword & City)](https://apify.com/webdatatools/meetup-events-scraper) — upcoming events with RSVPs, fees, venues and groups
- [Eventbrite Scraper (Events by Keyword & City)](https://apify.com/webdatatools/eventbrite-scraper) — events by keyword and city with venue, dates and organizer

**Leads, jobs and company data**

- [Career Site Jobs API (Greenhouse, Lever, Ashby, Workday +1)](https://apify.com/webdatatools/career-site-jobs-api) — company domains in, their open jobs out, ATS detected automatically
- [Workday Jobs Scraper](https://apify.com/webdatatools/workday-jobs-scraper) — jobs with full descriptions from any Workday career site
- [Google Maps Scraper](https://apify.com/webdatatools/google-maps-scraper) — businesses with phone, website, address, rating and coordinates per search
- [LinkedIn Jobs Scraper](https://apify.com/webdatatools/linkedin-jobs-scraper) — job titles, companies, locations and full descriptions from LinkedIn job search
- [Company 360: full company profile from a domain](https://apify.com/webdatatools/company-360) — one row per domain: contacts, tech, security, hiring and company facts
- [Hiring Signals Scraper (Greenhouse, Lever, Ashby, Workable)](https://apify.com/webdatatools/hiring-signals) — open jobs and hiring velocity from 10 public ATS boards
- [Y Combinator Companies & Founders Scraper](https://apify.com/webdatatools/yc-companies-scraper) — YC startups by batch, industry and hiring status
- [Wikidata Entity & Company Enrichment (facts, IDs, links)](https://apify.com/webdatatools/wikidata-entity-enrichment) — HQ, founders, employees, revenue and social IDs per company
- [Email Validator & Verifier — Bulk Email Check](https://apify.com/webdatatools/email-validator) — syntax, MX, disposable, role and free-provider checks
- [OpenStreetMap POI Extractor (Overpass API: shops, amenities)](https://apify.com/webdatatools/overpass-poi-extractor) — shops and amenities by radius, bbox or area
- [Stock, Crypto & FX Quotes](https://apify.com/webdatatools/market-quotes) — one row per symbol from Yahoo, Binance and ECB rates
- [Remote Jobs Aggregator (RemoteOK, WWR, Hacker News)](https://apify.com/webdatatools/remote-jobs-aggregator) — one clean row per remote job, de-duplicated across feeds
- [Greenhouse Jobs Scraper](https://apify.com/webdatatools/greenhouse-jobs-scraper) — jobs with descriptions from any Greenhouse job board
- [Lever Jobs Scraper](https://apify.com/webdatatools/lever-jobs-scraper) — jobs with descriptions from any Lever careers page
- [Ashby Jobs Scraper](https://apify.com/webdatatools/ashby-jobs-scraper) — jobs, salaries and descriptions from any Ashby job board
- [SmartRecruiters Jobs Scraper](https://apify.com/webdatatools/smartrecruiters-jobs-scraper) — jobs with descriptions from any SmartRecruiters company
- [Seek Jobs Scraper (Australia & New Zealand)](https://apify.com/webdatatools/seek-jobs-scraper) — Seek job ads with salary, work type and location
- [Dice Jobs Scraper](https://apify.com/webdatatools/dice-jobs-scraper) — US tech jobs from Dice with salary and remote flag
- [AutoScout24 Scraper](https://apify.com/webdatatools/autoscout24-scraper) — European car listings with price, mileage and seller
- [Rightmove Scraper](https://apify.com/webdatatools/rightmove-scraper) — UK property for sale or rent with price and agent
- [Wellfound Jobs Scraper (AngelList Startup Jobs)](https://apify.com/webdatatools/wellfound-jobs-scraper) — startup jobs with salary and equity ranges, company size and stage
- [Yandex Maps Scraper (Places, Ratings, Phones)](https://apify.com/webdatatools/yandex-maps-scraper) — businesses in Russia, Türkiye and the CIS with phones, ratings, hours
- [Craigslist Scraper (Listings, Prices, Locations)](https://apify.com/webdatatools/craigslist-scraper) — listings in any area and category with price, date and coordinates
- [JobStreet Scraper (Malaysia, Singapore, PH, ID + JobsDB)](https://apify.com/webdatatools/jobstreet-scraper) — JobStreet and JobsDB jobs in 6 Asian countries with parsed salaries
- [InfoJobs Scraper (Spain Jobs, Salaries, Companies)](https://apify.com/webdatatools/infojobs-scraper) — Spanish jobs with salary range, contract type and full description
- [Redfin Scraper (Homes for Sale, Prices, Details)](https://apify.com/webdatatools/redfin-scraper) — US homes for sale or sold from any Redfin search, with price and details
- [Kleinanzeigen Scraper (Ads, Prices, Locations)](https://apify.com/webdatatools/kleinanzeigen-scraper) — German classifieds with price, VB flag, ZIP, city and seller type

**Developer, app and research data**

- [npm, PyPI & Crates.io Package Health Checker](https://apify.com/webdatatools/package-health-checker) — releases, downloads, deprecation and a health score
- [GitHub Repository Health & Activity Report](https://apify.com/webdatatools/github-repo-health) — stars, commits, contributors and risk flags per repo
- [VS Code Marketplace Extension Scraper (installs, ratings)](https://apify.com/webdatatools/vscode-marketplace-extensions) — installs, ratings and versions per extension
- [Chrome Web Store Extension Scraper (installs, ratings)](https://apify.com/webdatatools/chrome-web-store-extensions) — users, rating, version and developer per extension
- [Google Play Scraper](https://apify.com/webdatatools/google-play-scraper) — apps, ratings, installs, developer contact and reviews
- [App Store (iOS) App Metadata, Ratings & Top Charts Lookup](https://apify.com/webdatatools/app-store-lookup) — ratings, price, version and charts per app
- [CrossRef DOI & Citation Metadata Lookup](https://apify.com/webdatatools/crossref-doi-lookup) — papers, authors, journals and citation counts
- [FDA Recalls & Adverse Events Monitor (openFDA)](https://apify.com/webdatatools/openfda-recall-monitor) — food, drug and device recalls from openFDA
- [iCal / ICS Calendar Feed to Events Extractor](https://apify.com/webdatatools/ical-calendar-extractor) — any public calendar feed as event rows
- [Shopify Store Products Scraper](https://apify.com/webdatatools/shopify-products-scraper) — catalog, prices, variants and stock per store
- [Hacker News Search & Front Page Scraper](https://apify.com/webdatatools/hacker-news-scraper) — stories, comments and points by query or front page
- [GitHub Trending Repositories Scraper](https://apify.com/webdatatools/github-trending-scraper) — trending repos and developers by language and period
- [Stack Overflow & Stack Exchange Q\&A Scraper](https://apify.com/webdatatools/stackexchange-scraper) — questions, answers and scores by query, tag or site
- [Bulk Image Downloader](https://apify.com/webdatatools/bulk-image-downloader) — download image URLs to storage with size, dimensions and a ZIP
- [Google Flights Scraper (Prices, Airlines, Stops)](https://apify.com/webdatatools/google-flights-scraper) — flight prices, airlines, times, stops and CO2 by route and date
- [Google Hotels Scraper (Prices, Ratings, Reviews)](https://apify.com/webdatatools/google-hotels-scraper) — hotel prices per night, stars, rating and reviews by city and dates
- [AliExpress Scraper (Search Products & Prices)](https://apify.com/webdatatools/aliexpress-scraper) — AliExpress search results with USD price, discount and rank
- [Lazada Scraper (Products, Prices, Sold, Ratings)](https://apify.com/webdatatools/lazada-scraper) — Lazada products in 6 countries with price, rating, units sold and seller

### Support and feedback

Found a header worth tracking, an AI crawler that should be added to the robots.txt check, or a parsing bug? Open an issue on the **Issues** tab.

# Actor input Schema

## `domains` (type: `array`):

Enter the domains to audit, one row is returned per domain, e.g. apify.com. Full URLs and www. prefixes are accepted and stripped automatically (https://www.apify.com/store becomes apify.com), so you can paste a list straight out of your CRM.

## `checkTls` (type: `boolean`):

Connect on port 443 and read the peer certificate's validity dates, issuer, subject, SAN count, days until expiry and whether the chain is trusted. Turn off to skip this and save a few seconds per domain.

## `checkHeaders` (type: `boolean`):

Read HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, Server, X-Powered-By, Cache-Control and cookie flags from the final response after redirects.

## `followRedirects` (type: `boolean`):

Start at http://<domain>/ and follow Location headers manually (up to 10 hops) to find the final URL, whether it upgrades to HTTPS and whether it adds or drops the www. prefix. Turn off to check the headers of http://<domain>/ directly with no redirect following.

## `checkRobots` (type: `boolean`):

Fetch /robots.txt (disallow-all detection, sitemap count, and which AI crawlers such as GPTBot, ClaudeBot and Google-Extended are blocked) and /llms.txt (presence, title, size).

## `maxConcurrency` (type: `integer`):

Enter how many domains to audit in parallel, e.g. 5. Each domain needs a TLS handshake plus up to 10 redirect hops and 2 text fetches; raise this for large lists, lower it if a target starts rate-limiting you.

## `inputDatasetId` (type: `string`):

Take the items from another Actor run's dataset, e.g. "aBcD1234". Combined with the list above.

## `inputField` (type: `string`):

Column holding the value, e.g. "domain" (the default). Array columns are flattened.

## Actor input object example

```json
{
  "domains": [
    "apify.com",
    "example.com"
  ],
  "checkTls": true,
  "checkHeaders": true,
  "followRedirects": true,
  "checkRobots": true,
  "maxConcurrency": 5
}
```

# Actor output Schema

## `domains` (type: `string`):

All audited domains — download as JSON, CSV, Excel or HTML.

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "domains": [
        "apify.com",
        "example.com"
    ],
    "checkTls": true,
    "checkHeaders": true,
    "followRedirects": true,
    "checkRobots": true,
    "maxConcurrency": 5
};

// Run the Actor and wait for it to finish
const run = await client.actor("webdatatools/domain-security-audit").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {
    "domains": [
        "apify.com",
        "example.com",
    ],
    "checkTls": True,
    "checkHeaders": True,
    "followRedirects": True,
    "checkRobots": True,
    "maxConcurrency": 5,
}

# Run the Actor and wait for it to finish
run = client.actor("webdatatools/domain-security-audit").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "domains": [
    "apify.com",
    "example.com"
  ],
  "checkTls": true,
  "checkHeaders": true,
  "followRedirects": true,
  "checkRobots": true,
  "maxConcurrency": 5
}' |
apify call webdatatools/domain-security-audit --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,webdatatools/domain-security-audit"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/SELey4npMakiVA1vf/builds/m7htEO6CL6X6MDUNF/openapi.json
