Domain trust

Domain portfolio SSL, DMARC, and security-header remediation audits

This Actor audits hostnames you supply for TLS expiry, DMARC/SPF (and optional DKIM selectors), redirect-aware security headers, and a remediation summary. Optional Google Web Risk is off by default and needs reputationApiKey.

Not a penetration test, RDAP registry dump, or HTTP broken-link crawl. Core checks use public TLS/DNS/headers; Web Risk is an add-on.

from $10.00 / 1,000 delivered monitoring result rows ($0.01 per new or changed row). No Actor Start. Unchanged runs with emitUnchanged false are free (0 rows / 0 charge). Max 200 domains.

Open Domain Trust Reputation Scraper on Apify

Domain Trust Reputation Scraper, not a neighboring Actor

Use this page for this Actor’s job. Use SSL/TLS Certificate Scraper for TLS certs only; Use DMARC & Email Security Checker for Email-auth DNS only; Use RDAP Domain Monitor for RDAP registration/expiry.

This Actor SSL/TLS Certificate Scraper DMARC & Email Security Checker RDAP Domain Monitor
Intent Domain Trust Reputation Scraper TLS certs only Email-auth DNS only RDAP registration/expiry
Primary input domains domains max 200 domains domains
What it reads Public sources listed on the Store page TLS handshake DNS TXT RDAP
Primary output Dataset rows billed per live PPE cert rows DMARC/SPF/DKIM rows registration rows
Not this job Not a penetration test, RDAP registry dump, or HTTP broken-link crawl. Core checks use public TLS/DNS/headers; Web Risk is an add-on. Not bundled DMARC+headers executive summary Not TLS expiry + header bundle Not TLS/header scoring

Store ID: taroyamada/domain-trust-monitor. Respect source terms, robots.txt, and rate limits.

Use cases

How is Domain Trust Reputation Scraper different from SSL/TLS Certificate Scraper and DMARC & Email Security Checker?

Domain Trust Reputation Scraper (taroyamada/domain-trust-monitor): This Actor audits hostnames you supply for TLS expiry, DMARC/SPF (and optional DKIM selectors), redirect-aware security headers, and a remediation summary. Optional Google Web Risk is off by default and needs reputationApiKey. Not a penetration test, RDAP registry dump, or HTTP broken-link crawl. Core checks use public TLS/DNS/headers; Web Risk is an add-on. SSL/TLS Certificate Scraper is for TLS certs only (input domains max 200; TLS handshake; cert rows). Not bundled DMARC+headers executive summary. DMARC & Email Security Checker is for Email-auth DNS only (input domains; DNS TXT; DMARC/SPF/DKIM rows). Not TLS expiry + header bundle. RDAP Domain Monitor is for RDAP registration/expiry (input domains; RDAP; registration rows). Not TLS/header scoring.

What input is required?

Live required fields: domains. exampleRunInput uses example.com + github.com, checkDkim true, snapshotKey domain-security-audit-quickstart, concurrency 2. Schema prefill adds cloudflare.com; snapshotKey default is domain-trust-monitor-snapshots; concurrency default 3. Keep emitUnchanged false on schedules.

Field Type Default Notes
domains array required empty Free / starter: Domains / URLs to audit. Free / starter quickstart: begin with 2-3 domains for a fast first success. Paid expansion: grow into larger recurring portfolios (for example 5-25+ domains) while keeping the …
port integer 443 HTTPS / TLS port. Port used for SSL/TLS expiry and trust checks across the portfolio.
expiryWarningDays integer 30 SSL + domain expiry warning window (days). Flag certificates or domains that expire within this many days.
followRedirects boolean true Follow redirects before header audit. Follow redirects before scoring the final site's security headers.
checkDkim boolean true Check DKIM selectors. Probe common selectors so the first run catches missing DKIM alongside SPF and DMARC.
dkimSelectors array empty Custom DKIM selectors. Optional DKIM selectors to check instead of the built-in defaults.. maxItems=20
delivery string dataset Delivery mode (free / starter dataset vs paid webhook). Free / starter path: dataset keeps the first run low-friction and still writes the full summary to OUTPUT. Paid expansion path: webhook sends the same summary + …
webhookUrl string empty Webhook URL. Advanced delivery only: required when delivery is webhook. The payload includes the executive summary, flattened remediation list, and per-domain results.
snapshotKey string domain-trust-monitor-snapshots Snapshot key for recurring audits. Keep this stable when you move from the free / starter quickstart to richer recurring audits so SSL, DMARC, header, and ownership changes stay comparable run to run.
concurrency integer 3 Parallel domain checks. Free / starter default 3 is usually enough for 2-3 domains. Increase it for paid expansion portfolios when you want broader coverage in one run.
enableReputationLookup boolean false Paid expansion: Add Google Web Risk. Paid expansion add-on: layer Google Web Risk on top of the core bundled audit when you want a richer threat signal or stronger client-ready narrative.
reputationApiKey string empty Paid expansion: Google Web Risk API key. Required only for the paid Google Web Risk overlay.
reputationThreatTypes array empty Paid expansion: Web Risk threat types. Threat types to query when the paid Web Risk overlay is enabled.. maxItems=3
emitUnchanged boolean false Emit unchanged rows. Write stable rows to the default dataset. Keep this off for recurring monitoring so unchanged runs produce zero dataset rows and zero result charges.
dryRun boolean false Dry run. Preview the audit without saving snapshots, dataset rows, or sending webhooks. Useful for validation, but leave it off for the free / starter baseline or paid recurring runs you want to keep.

Published Store example run input (omitted fields take schema defaults):

{
  "domains": [
    "example.com",
    "github.com"
  ],
  "port": 443,
  "expiryWarningDays": 30,
  "followRedirects": true,
  "checkDkim": true,
  "delivery": "dataset",
  "snapshotKey": "domain-security-audit-quickstart",
  "concurrency": 2,
  "dryRun": false
}

Run Domain Trust Reputation Scraper on Apify

How do dataset, webhook, and dry-run delivery work?

delivery defaults to dataset on the live schema. Dataset output is the billable surface when rows are written. webhookUrl is used when delivery is webhook (and typically not during dryRun). dryRun true validates or samples without the usual dataset/webhook side effects described on the Store schema. emitUnchanged controls whether unchanged watches write rows. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.

What does a result contain?

Published README Output Example / Sample Output JSON.

{
  "meta": {
    "executiveSummary": {
      "overallStatus": "attention_needed",
      "brief": "1 of 2 domains needs action. Highest-risk issue: 5 alert(s): DMARC record is missing.",
      "recommendedCadence": "daily",
      "topDomains": [
        {
          "domain": "example.com",
          "severity": "high",
          "trustScore": 41,
          "brief": "5 alert(s): DMARC record is missing."
        }
      ]
    },
    "runProfile": {
      "tier": "starter",
      "label": "Starter first-success path"
    },
    "usageAdvisories": {
      "summary": "1 usage/recovery advisory signal active for this run.",
      "signals": [
        {
          "id": "starter_portfolio_boundary",
          "limit": "3 domains in the starter quickstart"
        }
      ]
    },
    "upgradeSuggestions": [
      {
        "type": "schedule",
        "templateId": "portfolio_watch",
        "cadence": "daily",
        "title": "Promote this baseline to a recurring portfolio watch"
      }
    ],
    "nextWorkflow": {
      "type": "same_actor_template",
      "id": "action_needed_webhook",
      "title": "Next best step: Webhook Remediation Queue"
    }
  },
  "alerts": [
    {
      "domain": "example.com",
      "severity": "high",
      "component": "dns",
      "type": "dmarc_missing_or_weak",
      "message": "DMARC record is missing."
    },
    {
      "domain": "example.com",
      "severity": "high",
      "component": "rdap",
      "type": "domain_expiring_soon",
      "message": "Domain expires in 28 days"
    }
  ],
  "results": [
    {
      "domain": "example.com",
      "severity": "high",
      "recommendedActions": [
        "Publish an enforced DMARC policy (quarantine or reject) with aggregate reporting.",
        "Renew the domain registration before the expiry window closes.",
        "Add the missing critical security headers (HSTS, CSP, X-Content-Type-Options, X-Frame-Options)."
      ]
    }
  ]
}

There is no published output JSON schema on the Store page.

How is Domain Trust Reputation Scraper priced?

Billing is pay per event. The live Store card is from $10.00 / 1,000 delivered monitoring result rows ($0.01 per new or changed row). No Actor Start. Unchanged runs with emitUnchanged false are free (0 rows / 0 charge). Max 200 domains. Current PPE:

Event Price Emitted when
apify-default-dataset-item (Delivered monitoring result row) $0.01 Charged only when a new or changed monitoring result row is delivered. Unchanged runs are free.

from $10.00 / 1,000 delivered monitoring result rows ($0.01 per new or changed row). No Actor Start. Unchanged runs with emitUnchanged false are free (0 rows / 0 charge). Max 200 domains.

See Domain Trust Reputation Scraper pricing on Apify

Limits to keep in mind

Open Domain Trust Reputation Scraper on Apify

Related pages