Domain Security Posture Checker โ DNS, SPF, DMARC, TLS
Pricing
from $150.00 / 1,000 domain reports
Domain Security Posture Checker โ DNS, SPF, DMARC, TLS
One-call security report card per domain โ WHOIS, DNS, SPF/DMARC email auth, SSL/TLS expiry, with a posture score and grade. No login.
Pricing
from $150.00 / 1,000 domain reports
Rating
0.0
(0)
Developer
Actor stats
0
Bookmarked
2
Total users
1
Monthly active users
11 days ago
Last modified
Categories
Share
๐ Domain Security Posture Checker ยท DNS ยท SPF ยท DMARC ยท TLS
One call returns a security report card per domain โ WHOIS age, DNS, SPF/DMARC email auth, SSL/TLS expiry โ with a posture score and grade. For security, due-diligence, and sales-engineering teams.
โก What you get
| Field | Description |
|---|---|
score / grade | Overall posture (0-100, A-D) |
hasSPF / spf | SPF record + value |
hasDMARC / dmarcPolicy | DMARC + policy |
sslIssuer / sslExpires / sslDaysLeft | TLS health |
registrar / created / expires | WHOIS via RDAP |
mx / nameservers / a | DNS |
findings | Human-readable issues |
๐ฏ Use cases
- Security teams scoring third-party domains
- M&A / due-diligence quick risk checks
- Sales engineering pre-call audits
- Email deliverability (SPF/DMARC) audits
๐ Sample inputs
{"domains":["stripe.com","github.com"]}
{"domains":["yourcompany.com"]}
๐ฆ Sample output
{"domain":"stripe.com","score":90,"grade":"A","hasSPF":true,"hasDMARC":true,"dmarcPolicy":"reject","sslIssuer":"DigiCert Inc","sslDaysLeft":312,"findings":[]}
๐ Sample Output
๐ How it works
- DNS โ A/MX/NS/TXT via DNS-over-HTTPS (Cloudflare).
- Email auth โ parses SPF and
_dmarcDMARC policy. - TLS โ reads the port-443 certificate (issuer, expiry).
- WHOIS โ registrar + dates via RDAP.
- Score โ weighted posture score + grade + findings.
๐ Related Actors
๐ฐ Pricing Example
Pay-per-event: $0.005 per run + $0.15 per domain report (domain-report).
| Domains | Cost |
|---|---|
| 50 | ~$7.50 |
| 200 | ~$30.00 |
| 1,000 | ~$150.00 |
| Apify's $5 free credit covers ~33 domains. Start free โ |
โ๏ธ Legal & data sources
Public DNS (DoH), public RDAP/WHOIS, and a standard TLS handshake on port 443 โ all public, no login. Identified User-Agent.
โ FAQ
A vulnerability scanner? No โ a posture/hygiene report, not an intrusive scan. DKIM? SPF + DMARC checked; DKIM (selector-specific) on the roadmap. Fresh? Live at run time. Key? No. Bulk? Yes. Scoring? Weighted across SPF, DMARC policy, TLS, and DNS.
๐ Troubleshooting
- SSL invalid/unreachable โ host may not serve TLS on 443.
- No WHOIS โ some TLDs have limited RDAP.
- Low score โ check
findings. - Subdomain โ pass the registrable domain.
๐ท๏ธ About NexGenData
Structured public-data tools for analysts, developers, and operators. thenextgennexus.com.
