SPF · DKIM · DMARC
SPF, DKIM, DMARC, and BIMI DNS audits for domain lists
This Actor resolves DNS for domains you supply and extracts SPF, DKIM (optional selectors), DMARC, and BIMI records into deliverability-readiness rows. It is a domain DNS audit, not an email-address syntax validator.
Not inbox placement testing. Not a bulk email sender. Not the Bulk Email Syntax & MX Validator (addresses). Distinct from DMARC & Email Security Checker’s lighter SPF/DMARC/MX path.
from $9.00 / 1,000 result ($0.009 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.
Open Bulk Email DNS Audit Scraper on Apify
Bulk Email DNS Audit Scraper, not a neighboring Actor
Use this page for this Actor’s job. Use DMARC & Email Security Checker for SPF/DMARC/MX check; Use Bulk Email Syntax & MX Validator for Address syntax + MX; Use SSL/TLS Certificate Scraper for TLS cert expiry.
| This Actor | DMARC & Email Security Checker | Bulk Email Syntax & MX Validator | SSL/TLS Certificate Scraper | |
|---|---|---|---|---|
| Intent | Bulk Email DNS Audit Scraper | SPF/DMARC/MX check | Address syntax + MX | TLS cert expiry |
| Primary input | see schema | domains | emails | domains |
| What it reads | Public sources listed on the Store page | DNS TXT | user-supplied addresses | TLS handshake |
| Primary output | Dataset rows billed per live PPE | email-auth rows | syntax/MX rows | cert rows |
| Not this job | Not inbox placement testing. Not a bulk email sender. Not the Bulk Email Syntax & MX Validator (addresses). Distinct from DMARC & Email Security Checker’s lighter SPF/DMARC/MX path. | Not a full BIMI/DKIM portfolio audit | Not domain SPF/DMARC/BIMI | Not DNS email-auth records |
Store ID: taroyamada/email-deliverability-portfolio-audit. Respect source terms, robots.txt, and rate limits.
Use cases
- Agency domain portfolios
- DKIM selector + BIMI checks
- Scheduled snapshotKey DNS diffs
How is Bulk Email DNS Audit Scraper different from DMARC & Email Security Checker and Bulk Email Syntax & MX Validator?
Bulk Email DNS Audit Scraper (taroyamada/email-deliverability-portfolio-audit): This Actor resolves DNS for domains you supply and extracts SPF, DKIM (optional selectors), DMARC, and BIMI records into deliverability-readiness rows. It is a domain DNS audit, not an email-address syntax validator. Not inbox placement testing. Not a bulk email sender. Not the Bulk Email Syntax & MX Validator (addresses). Distinct from DMARC & Email Security Checker’s lighter SPF/DMARC/MX path. DMARC & Email Security Checker is for SPF/DMARC/MX check (input domains; DNS TXT; email-auth rows). Not a full BIMI/DKIM portfolio audit. Bulk Email Syntax & MX Validator is for Address syntax + MX (input emails; user-supplied addresses; syntax/MX rows). Not domain SPF/DMARC/BIMI. SSL/TLS Certificate Scraper is for TLS cert expiry (input domains; TLS handshake; cert rows). Not DNS email-auth records.
What input is required?
Live required fields: domains. Published exampleRunInput is shown below. Audit email deliverability readiness for one domain or a small portfolio using stable public DNS, transport, and sender-readiness signals.
| Field | Type | Default | Notes |
|---|---|---|---|
domains |
any[] required | empty |
required Free / starter: Domains to audit. Start with 2-3 domains for the first deliverability baseline. Expand later into larger recurring portfolios while keeping the same summary-first workflow. |
followRedirects |
boolean | true |
Follow redirects for sender-readiness checks. Follow redirects when checking the main HTTPS endpoint and the MTA-STS policy URL. |
checkDkim |
boolean | true |
Check DKIM selectors. Probe a small set of common selectors so the first run catches missing DKIM posture quickly. |
dkimSelectors |
any[] | empty |
Custom DKIM selectors. Optional custom DKIM selectors to probe instead of the built-in defaults. |
checkBimi |
boolean | true |
Check BIMI. Optional branding readiness check. Missing BIMI is treated as an opportunity signal, not a hard failure. |
delivery |
string enum | dataset |
Delivery mode (starter dataset vs webhook). Dataset mode keeps the first run lightweight while still writing the full executive summary to OUTPUT. Webhook mode sends the same summary, alert queue, and per-domain rows to your endpoint. enum: dataset, webhook |
webhookUrl |
string | empty |
Webhook URL. Required when delivery=webhook. |
snapshotKey |
string | email-deliverability-portfolio-audit |
Snapshot key for recurring audits. Reuse the same key when you move from the starter baseline to recurring monitoring so policy changes stay comparable. |
concurrency |
integer | 3 |
Parallel domain checks. Starter runs usually only need 2-3. Increase carefully for larger portfolios. min=1 max=10 |
dryRun |
boolean | false |
Dry run. Preview the full summary without saving snapshots, dataset rows, or webhooks. |
Published Store example run input (omitted fields take schema defaults):
{
"domains": [
"example.com",
"github.com"
],
"followRedirects": true,
"checkDkim": true,
"checkBimi": true,
"delivery": "dataset",
"snapshotKey": "email-deliverability-quickstart",
"concurrency": 2,
"dryRun": false
}
Run Bulk Email DNS Audit Scraper on Apify
How do dataset, webhook, and dry-run delivery work?
delivery defaults to dataset on the live schema. Dataset output is the billable surface when rows are written. webhookUrl is used when delivery is webhook (and typically not during dryRun). dryRun true validates or samples without the usual dataset/webhook side effects described on the Store schema. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.
What does a result contain?
Published README Output Example / Sample Output JSON. Treat README samples as illustrations, not a live coverage guarantee. There is no published output JSON schema on the Store page.
How is Bulk Email DNS Audit Scraper priced?
Billing is pay per event. The live Store card is from $9.00 / 1,000 result ($0.009 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE. Current PPE:
| Event | Price | Emitted when |
|---|---|---|
apify-default-dataset-item (result) |
$0.009 | Single result in the default dataset. |
apify-actor-start (Actor Start) |
$0.001 | Charged when the Actor starts running. Number of events charged depends on Actor memory (one event per GB, minimum one event). |
The published README Cost block is stale versus the live Store pricing tab. README Cost quotes actor-start $0.01; live Actor Start is $0.001. README Cost quotes dataset-item $0.003; live primary is $0.009 (result). Live: result $0.009, Actor Start $0.001. This page quotes live PPE only.
from $9.00 / 1,000 result ($0.009 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.
See Bulk Email DNS Audit Scraper pricing on Apify
Limits to keep in mind
- domains required
- DNS only; no mailbox login
- checkDkim / checkBimi flags
- Not send-time placement
- Respect source terms, robots.txt, and rate limits.
Open Bulk Email DNS Audit Scraper on Apify
Related pages
- DMARC & Email Security Checker — SPF/DMARC/MX; this Actor adds DKIM/BIMI portfolio fields.
- Bulk Email Syntax & MX Validator — Address syntax, not domain policy DNS.
- SSL/TLS Certificate Scraper — TLS certs, not email DNS.
- Tools