Domain Inspector
Check many domains at once. Get DNS, WHOIS registrar and expiry, TLS dates, redirects, security headers, robots and tech. $1.50 per 1,000.
How it works
- 1Open it on Apify
Hit Run on Apify — it opens the tool in the cloud, no install.
- 2Set the inputs
Adjust
domains,domain,maxConcurrency(sensible defaults are pre-filled). - 3Click Run
The tool runs on Apify’s cloud and collects the data for you.
- 4Export the results
Download as JSON, CSV or Excel, or pipe straight into your app, Google Sheets, or an AI agent.
Pricing
$0.0015 per domain = $1.5 per 1,000
| You are charged for | When | Price |
|---|---|---|
| Domain | One successfully inspected domain. | $0.0015 |
Pay-per-event pricing: you are billed per result, not per subscription. Billing is handled by Apify on your own account. These are the live Apify store prices, in effect since 2026-07-25, and they are what you are actually charged.
Inputs
| Field | What it does | Type |
|---|---|---|
domains | Domains or public HTTP(S) URLs to inspect, one per line. URLs are reduced to their hostname. Duplicates are removed. Maximum 500. | array |
domain | Optional single-domain shortcut. It is combined with the domains list. | string |
maxConcurrency | Number of domains inspected at once. Keep this modest to avoid DNS and target-site rate limits. | integer |
requestTimeoutSecs | Timeout for each DNS, RDAP, HTTP, or TLS operation. A hard per-domain deadline is also applied. | integer |
maxRedirects | Maximum redirects followed separately for HTTP, HTTPS, robots.txt, and sitemap.xml. Every redirect target is safety-checked. | integer |
checkRdap | Look up public registration dates, status, registrar, nameservers, and handle where the registry provides RDAP data. | boolean |
checkWeb | Inspect both HTTP and HTTPS status, redirect chains, final URL, title, metadata, security headers, and basic technology signals. | boolean |
checkTls | Inspect the certificate on port 443, including validity dates, issuer, subject, SANs, fingerprint, and Node.js trust result. | boolean |
checkRobotsAndSitemap | Check standard robots.txt and sitemap.xml locations on the best working web origin. | boolean |
What you get
A structured dataset — each result includes fields like:
domainokhttpsStatushttpStatustitlednsAtlsExpiresAtregistrationExpiresAttechnologieswarningsCountinspectedAtExport every run as JSON, CSV or Excel, or send it to your app, a database, Google Sheets, or an AI agent.
Related tools in Developer & Research Tools
Other ready-to-run tools in the same category — all pay-per-use on the Apify cloud.
GitHub Scraper
Search GitHub repos and users: stars, forks, language, topics, licence, plus user bio, company and followers. No token needed. $0.90 per 1,000 rows.
Stack Overflow / Stack Exchange Scraper
Search Stack Overflow and Stack Exchange by keyword or tag. Score, answer count, views, reputation and body text. $2 per 1,000 questions.
Package Registry Scraper (npm + PyPI)
Get npm and PyPI package metadata as JSON. Version, license, author, repo, keywords and npm monthly downloads. $2 per 1,000 packages.
arXiv Scraper
Search arXiv papers by title, author, abstract or category. Get full abstracts, authors, categories, DOI, dates and PDF links. $2 per 1,000 papers.
OpenAlex Scholarly Works Scraper
Search 250M+ OpenAlex papers with no API key. Get titles, authors, venue, year, citations, DOI, OA links and full abstracts. $2.00 per 1,000 papers.
Crossref Scholarly Works Scraper
Search 150M+ papers on Crossref: DOI, title, authors, journal, publisher, date, citations and abstract. No API key. $1.00 per 1,000 works.
Where this tool sits
Domain Inspector: DNS, registration, certificates and what a site runs, one row per domain
Paste a list of domains and get one row each: the DNS records, who the registrar is and when the registration expires, the certificate on port 443 with its expiry date, the redirect chain, the security headers, robots.txt, sitemap.xml and a few signals about what the site is built with.
Registration data comes from RDAP, which is the registry-run replacement for the old WHOIS port. Not every registry publishes it, so on some country domains the registrar and the expiry date come back empty while everything else on the row is filled in.
| Input | Domains or URLs, up to 500 per run |
| Output | One row per domain |
| Ceiling | 500 domains per run |
| Account needed | None, and no API key |
| Price | $1.50 per 1,000 domains, flat on every plan |
🔍 What Domain Inspector does
Each domain gets four independent checks, and you can switch any of them off.
DNS resolves A, AAAA, MX, NS, TXT and CAA, reporting per-record errors rather than collapsing them into one failure. RDAP asks the registry for the registrar, the status codes, the nameservers and the registration, update and expiry dates. Certificates connect on port 443 and report the issuer, the subject, the alternative names, both validity dates, days left and whether Node's trust store accepts the chain. Web requests both http:// and https://, follows the redirects, and reads the final status, the page title, the canonical URL, the Open Graph block, the security headers and a short list of technology signals.
If robots.txt and sitemap.xml checking is on, both are fetched from whichever origin answered best, and any sitemap URLs declared in robots.txt come back with them.
Anything that went wrong without killing the row lands in warnings, with warningsCount beside it so you can sort by how messy a domain is.
📥 What you give it
{
"domains": ["github.com", "example.org", "https://news.ycombinator.com/"],
"maxConcurrency": 5,
"requestTimeoutSecs": 8,
"checkRdap": true,
"checkTls": true
}
| Field | Default | What it is |
|---|---|---|
domains | box starts at github.com | Domains or full URLs, one per line. A URL is reduced to its hostname. Up to 500. |
domain | none | A single domain, added to the list above. Handy for a task or an API call with one target. |
maxConcurrency | 5 | How many domains are inspected at once, 1 to 20. Keep it modest or DNS and the sites themselves start rate limiting you. |
requestTimeoutSecs | 8 | The limit on each individual lookup, 3 to 20. There is a deadline on the whole domain as well. |
maxRedirects | 5 | How many hops to follow, up to 10. Every hop is safety checked. |
checkRdap | on | Registration data from the registry. |
checkWeb | on | The HTTP and HTTPS requests, the redirect chain, headers and page metadata. |
checkTls | on | The certificate on port 443. |
checkRobotsAndSitemap | on | robots.txt and sitemap.xml. |
proxyConfiguration | off | Optional network settings for the web requests only. DNS, RDAP and the certificate check always connect directly. |
example.com and www.example.com are two different domains here. Both get inspected, both get a row, and both count against your total. Deduplication only catches exact repeats.
The 500 limit is applied before duplicates are removed, and the single domain field is added at the end of the list. So a list of 500 with repeats in it can push your single domain out.
Setting maxRedirects to 0 does not switch redirects off. It falls back to 5.
📤 What you get back
The flat summary fields from a real row, with the nested blocks left out here because a full row runs to several thousand characters:
{
"ok": true,
"domain": "github.com",
"inspectedAt": "2026-09-14T05:42:44.663Z",
"httpsStatus": 200,
"httpStatus": 200,
"title": "GitHub · Change is constant. GitHub keeps you ahead. · GitHub",
"dnsA": ["140.82.114.3"],
"dnsAAAA": [],
"tlsExpiresAt": "2026-11-29T23:59:59.000Z",
"registrationExpiresAt": "2028-10-09T18:20:50.000Z",
"technologies": ["React", "Server: github.com"],
"warningsCount": 0
}
Under those sit the full blocks. From the same row, the certificate one:
"tls": {
"available": true,
"authorized": true,
"authorizationError": null,
"protocol": "TLSv1.3",
"subject": { "CN": "github.com" },
"issuer": { "C": "GB", "O": "Sectigo Limited", "CN": "Sectigo Public Server Authentication CA DV E36" },
"subjectAlternativeNames": ["github.com", "www.github.com"],
"validFrom": "2026-09-01T00:00:00.000Z",
"expiresAt": "2026-11-29T23:59:59.000Z",
"daysUntilExpiry": 76,
"serialNumber": "A59EBDB596751DB7F5C095079613953C",
"fingerprint256": "46:B6:01:EE:08:B4:18:CF:8A:3A:1E:..."
}
| Block | What is in it |
|---|---|
dns | a, aaaa, mx, ns, txt, caa, plus errors keyed by record type and hasData. |
rdap | registrar, statuses, nameservers, registeredAt, updatedAt, expiresAt, handle. available: false when the registry publishes nothing. |
tls | The certificate, as above. authorized is Node's own trust verdict, and authorizationError says why when it is false. |
http, https | Separate blocks per scheme: status, finalUrl, redirects, redirectCount, metadata, responseHeaders, securityHeaders, technologies. |
robots, sitemap | present, status, finalUrl, and any sitemaps declared in robots.txt. |
warnings | Plain sentences naming anything that went wrong but did not stop the row. |
The overview table in the console shows the flat summary only. Switch to JSON or All fields for the nested blocks.
🧾 Reading the output
Three kinds of row can land in your dataset.
| Row | How to spot it | Charged |
|---|---|---|
| An inspected domain | ok: true and a domain | yes |
| The sample row | _sample: true | no |
| A diagnostic | ok: false and an errorCode | no |
Filter on _sample being absent, not on ok. The sample row also carries ok: true.
| Code | What it means |
|---|---|
BAD_INPUT | The entry was not a domain: a bare IP address, a single word with no dot, or something that would not parse. The input field on the row shows what you sent. |
INSPECTION_FAILED | Every check came back empty. Usually an unregistered or misspelled domain. |
A BAD_INPUT row has no domain field, only input, so it shows in the overview table as a line with the domain column blank.
▶️ How to run it
1. Open Domain Inspector and click Try for free. 2. Paste your domains into Domains or URLs, one per line. 3. Leave the four check boxes on for a full row, or switch off the ones you do not need. 4. Click Start. Rows land once every domain has finished, so a long list stays quiet for a while. 5. Download the dataset as JSON, CSV or Excel, or read it from the Apify API.
💰 How much does it cost?
$1.50 per 1,000 domains. Flat on every Apify plan, no volume tiers.
You pay per domain that came back with something. A parked domain counts, because it still has DNS and registration data. A domain where every check came back empty does not, and neither does the sample row or an invalid entry.
💡 What people use it for
- Watching certificate and registration expiry across a portfolio, on a schedule, sorted by
daysUntilExpiry.
- Auditing security headers across every domain a company owns, in one pass.
- Checking a list of acquisition targets or suppliers before a first email: is the site live, who
registered it, what is it built with.
- Confirming a migration actually landed, by reading the redirect chain and the final URL.
- Finding the domains in a list that no longer resolve at all.
🚧 What it does not do
- No JavaScript. The title, metadata and technology signals come from the HTML the server sent,
so a site that renders everything client side looks emptier than it is.
- Technology detection is a short list of signals, not a full fingerprinting suite. Treat
technologies as a hint.
- RDAP only. There is no fallback to the old port-43 WHOIS, so registries that publish neither
come back with available: false.
- 500 domains per run, counted before duplicates are removed.
- Nothing is delivered until every domain has finished. A run that is aborted partway through
writes no rows at all, so split very large lists.
- A domain pointing at a private address gets its web and certificate checks skipped, with a
warning saying so. DNS and registration still come back.
- One certificate, on port 443. No other ports, no chain download, no revocation check.
- No subdomain discovery. It inspects exactly what you give it.
- No traffic, ranking or backlink figures.
🧭 Which site checker do you need?
| If you want | Use |
|---|---|
| DNS, registration, certificates and headers for a list of domains | This one |
| To crawl a site and read what is on its pages | Website Intelligence Crawler |
| Traffic estimates and audience data for a domain | SimilarWeb Traffic Scraper |
| A picture of the page rather than its headers | Website Screenshot Generator |
| To check whether an email address is deliverable | Email Verification |
❓ Questions people ask
Do I need an API key for any of this? No. DNS, RDAP and certificates are all public lookups.
Why is the registrar empty on some domains? That registry does not publish RDAP. There is no second source here, so the field stays empty rather than being guessed.
Can I check subdomains? Only ones you list yourself. It does not go looking for them.
How long does 500 domains take? It depends on Concurrent domains and how fast the targets answer. Raise it carefully: past a point the other end starts refusing.
Why did I get nothing back from a run I stopped early? Rows are written once every domain has been inspected. Stop it before then and nothing is written.
Is this legal? DNS, RDAP and certificates are published for public lookup, and robots.txt and sitemap.xml are files sites publish deliberately. Apify's write-up on scraping and the law is a good starting point, and we are not lawyers.
🆘 If something breaks
Open the Issues tab on the actor page. Send the run ID and the domain that behaved oddly. The warnings array on the row usually explains it, and errorCode names it when the whole row failed.