Domain trust
Domain portfolio SSL, DMARC, and security-header remediation audits
This Actor audits hostnames you supply for TLS expiry, DMARC/SPF (and optional DKIM selectors), redirect-aware security headers, and a remediation summary. Optional Google Web Risk is off by default and needs reputationApiKey.
Not a penetration test, RDAP registry dump, or HTTP broken-link crawl. Core checks use public TLS/DNS/headers; Web Risk is an add-on.
from $10.00 / 1,000 delivered monitoring result rows ($0.01 per new or changed row). No Actor Start. Unchanged runs with emitUnchanged false are free (0 rows / 0 charge). Max 200 domains.
Open Domain Trust Reputation Scraper on Apify
Domain Trust Reputation Scraper, not a neighboring Actor
Use this page for this Actor’s job. Use SSL/TLS Certificate Scraper for TLS certs only; Use DMARC & Email Security Checker for Email-auth DNS only; Use RDAP Domain Monitor for RDAP registration/expiry.
| This Actor | SSL/TLS Certificate Scraper | DMARC & Email Security Checker | RDAP Domain Monitor | |
|---|---|---|---|---|
| Intent | Domain Trust Reputation Scraper | TLS certs only | Email-auth DNS only | RDAP registration/expiry |
| Primary input | domains |
domains max 200 | domains | domains |
| What it reads | Public sources listed on the Store page | TLS handshake | DNS TXT | RDAP |
| Primary output | Dataset rows billed per live PPE | cert rows | DMARC/SPF/DKIM rows | registration rows |
| Not this job | Not a penetration test, RDAP registry dump, or HTTP broken-link crawl. Core checks use public TLS/DNS/headers; Web Risk is an add-on. | Not bundled DMARC+headers executive summary | Not TLS expiry + header bundle | Not TLS/header scoring |
Store ID: taroyamada/domain-trust-monitor. Respect source terms, robots.txt, and rate limits.
Use cases
- SSL expiry watchlists
- DMARC/SPF/DKIM posture across a portfolio
- Remediation-queue webhooks
- Optional Web Risk overlay
How is Domain Trust Reputation Scraper different from SSL/TLS Certificate Scraper and DMARC & Email Security Checker?
Domain Trust Reputation Scraper (taroyamada/domain-trust-monitor): This Actor audits hostnames you supply for TLS expiry, DMARC/SPF (and optional DKIM selectors), redirect-aware security headers, and a remediation summary. Optional Google Web Risk is off by default and needs reputationApiKey. Not a penetration test, RDAP registry dump, or HTTP broken-link crawl. Core checks use public TLS/DNS/headers; Web Risk is an add-on. SSL/TLS Certificate Scraper is for TLS certs only (input domains max 200; TLS handshake; cert rows). Not bundled DMARC+headers executive summary. DMARC & Email Security Checker is for Email-auth DNS only (input domains; DNS TXT; DMARC/SPF/DKIM rows). Not TLS expiry + header bundle. RDAP Domain Monitor is for RDAP registration/expiry (input domains; RDAP; registration rows). Not TLS/header scoring.
What input is required?
Live required fields: domains. exampleRunInput uses example.com + github.com, checkDkim true, snapshotKey domain-security-audit-quickstart, concurrency 2. Schema prefill adds cloudflare.com; snapshotKey default is domain-trust-monitor-snapshots; concurrency default 3. Keep emitUnchanged false on schedules.
| Field | Type | Default | Notes |
|---|---|---|---|
domains |
array required | empty |
Free / starter: Domains / URLs to audit. Free / starter quickstart: begin with 2-3 domains for a fast first success. Paid expansion: grow into larger recurring portfolios (for example 5-25+ domains) while keeping the … |
port |
integer | 443 |
HTTPS / TLS port. Port used for SSL/TLS expiry and trust checks across the portfolio. |
expiryWarningDays |
integer | 30 |
SSL + domain expiry warning window (days). Flag certificates or domains that expire within this many days. |
followRedirects |
boolean | true |
Follow redirects before header audit. Follow redirects before scoring the final site's security headers. |
checkDkim |
boolean | true |
Check DKIM selectors. Probe common selectors so the first run catches missing DKIM alongside SPF and DMARC. |
dkimSelectors |
array | empty |
Custom DKIM selectors. Optional DKIM selectors to check instead of the built-in defaults.. maxItems=20 |
delivery |
string | dataset |
Delivery mode (free / starter dataset vs paid webhook). Free / starter path: dataset keeps the first run low-friction and still writes the full summary to OUTPUT. Paid expansion path: webhook sends the same summary + … |
webhookUrl |
string | empty |
Webhook URL. Advanced delivery only: required when delivery is webhook. The payload includes the executive summary, flattened remediation list, and per-domain results. |
snapshotKey |
string | domain-trust-monitor-snapshots |
Snapshot key for recurring audits. Keep this stable when you move from the free / starter quickstart to richer recurring audits so SSL, DMARC, header, and ownership changes stay comparable run to run. |
concurrency |
integer | 3 |
Parallel domain checks. Free / starter default 3 is usually enough for 2-3 domains. Increase it for paid expansion portfolios when you want broader coverage in one run. |
enableReputationLookup |
boolean | false |
Paid expansion: Add Google Web Risk. Paid expansion add-on: layer Google Web Risk on top of the core bundled audit when you want a richer threat signal or stronger client-ready narrative. |
reputationApiKey |
string | empty |
Paid expansion: Google Web Risk API key. Required only for the paid Google Web Risk overlay. |
reputationThreatTypes |
array | empty |
Paid expansion: Web Risk threat types. Threat types to query when the paid Web Risk overlay is enabled.. maxItems=3 |
emitUnchanged |
boolean | false |
Emit unchanged rows. Write stable rows to the default dataset. Keep this off for recurring monitoring so unchanged runs produce zero dataset rows and zero result charges. |
dryRun |
boolean | false |
Dry run. Preview the audit without saving snapshots, dataset rows, or sending webhooks. Useful for validation, but leave it off for the free / starter baseline or paid recurring runs you want to keep. |
Published Store example run input (omitted fields take schema defaults):
{
"domains": [
"example.com",
"github.com"
],
"port": 443,
"expiryWarningDays": 30,
"followRedirects": true,
"checkDkim": true,
"delivery": "dataset",
"snapshotKey": "domain-security-audit-quickstart",
"concurrency": 2,
"dryRun": false
}
Run Domain Trust Reputation Scraper on Apify
How do dataset, webhook, and dry-run delivery work?
delivery defaults to dataset on the live schema. Dataset output is the billable surface when rows are written. webhookUrl is used when delivery is webhook (and typically not during dryRun). dryRun true validates or samples without the usual dataset/webhook side effects described on the Store schema. emitUnchanged controls whether unchanged watches write rows. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.
What does a result contain?
Published README Output Example / Sample Output JSON.
{
"meta": {
"executiveSummary": {
"overallStatus": "attention_needed",
"brief": "1 of 2 domains needs action. Highest-risk issue: 5 alert(s): DMARC record is missing.",
"recommendedCadence": "daily",
"topDomains": [
{
"domain": "example.com",
"severity": "high",
"trustScore": 41,
"brief": "5 alert(s): DMARC record is missing."
}
]
},
"runProfile": {
"tier": "starter",
"label": "Starter first-success path"
},
"usageAdvisories": {
"summary": "1 usage/recovery advisory signal active for this run.",
"signals": [
{
"id": "starter_portfolio_boundary",
"limit": "3 domains in the starter quickstart"
}
]
},
"upgradeSuggestions": [
{
"type": "schedule",
"templateId": "portfolio_watch",
"cadence": "daily",
"title": "Promote this baseline to a recurring portfolio watch"
}
],
"nextWorkflow": {
"type": "same_actor_template",
"id": "action_needed_webhook",
"title": "Next best step: Webhook Remediation Queue"
}
},
"alerts": [
{
"domain": "example.com",
"severity": "high",
"component": "dns",
"type": "dmarc_missing_or_weak",
"message": "DMARC record is missing."
},
{
"domain": "example.com",
"severity": "high",
"component": "rdap",
"type": "domain_expiring_soon",
"message": "Domain expires in 28 days"
}
],
"results": [
{
"domain": "example.com",
"severity": "high",
"recommendedActions": [
"Publish an enforced DMARC policy (quarantine or reject) with aggregate reporting.",
"Renew the domain registration before the expiry window closes.",
"Add the missing critical security headers (HSTS, CSP, X-Content-Type-Options, X-Frame-Options)."
]
}
]
}
There is no published output JSON schema on the Store page.
How is Domain Trust Reputation Scraper priced?
Billing is pay per event. The live Store card is from $10.00 / 1,000 delivered monitoring result rows ($0.01 per new or changed row). No Actor Start. Unchanged runs with emitUnchanged false are free (0 rows / 0 charge). Max 200 domains. Current PPE:
| Event | Price | Emitted when |
|---|---|---|
apify-default-dataset-item (Delivered monitoring result row) |
$0.01 | Charged only when a new or changed monitoring result row is delivered. Unchanged runs are free. |
from $10.00 / 1,000 delivered monitoring result rows ($0.01 per new or changed row). No Actor Start. Unchanged runs with emitUnchanged false are free (0 rows / 0 charge). Max 200 domains.
See Domain Trust Reputation Scraper pricing on Apify
Limits to keep in mind
- Max 200 domains
- port 1–65535 default 443
- Web Risk needs a Google Cloud API key, not Safe Browsing non-commercial keys
- Passive only
- Respect source terms, robots.txt, and rate limits.
Open Domain Trust Reputation Scraper on Apify
Related pages
- SSL/TLS Certificate Scraper — Certificate-only; this Actor adds DMARC/headers remediation.
- DMARC & Email Security Checker — Email DNS only.
- RDAP Domain Monitor — Registry/RDAP data, not TLS handshakes.
- Security Headers Checker — OWASP HTTP header grades only
- Tools