Request a tool
All toolsAutomationsGuidesMCP serverRequest a toolPlatformsCategories
Domain Inspector icon

Domain Inspector

Check many domains at once. Get DNS, WHOIS registrar and expiry, TLS dates, redirects, security headers, robots and tech. $1.50 per 1,000.

116 runs on Apify $0.0015 per domain ($1.5 / 1,000)
Run this in the cloudRun on Apify →

Developer & Research Tools

How it works

  1. 1
    Open it on Apify

    Hit Run on Apify — it opens the tool in the cloud, no install.

  2. 2
    Set the inputs

    Adjust domains, domain, maxConcurrency (sensible defaults are pre-filled).

  3. 3
    Click Run

    The tool runs on Apify’s cloud and collects the data for you.

  4. 4
    Export the results

    Download as JSON, CSV or Excel, or pipe straight into your app, Google Sheets, or an AI agent.

Pricing

$0.0015 per domain = $1.5 per 1,000

You are charged forWhenPrice
DomainOne successfully inspected domain.$0.0015

Pay-per-event pricing: you are billed per result, not per subscription. Billing is handled by Apify on your own account. These are the live Apify store prices, in effect since 2026-07-25, and they are what you are actually charged.

Inputs

FieldWhat it doesType
domainsDomains or public HTTP(S) URLs to inspect, one per line. URLs are reduced to their hostname. Duplicates are removed. Maximum 500.array
domainOptional single-domain shortcut. It is combined with the domains list.string
maxConcurrencyNumber of domains inspected at once. Keep this modest to avoid DNS and target-site rate limits.integer
requestTimeoutSecsTimeout for each DNS, RDAP, HTTP, or TLS operation. A hard per-domain deadline is also applied.integer
maxRedirectsMaximum redirects followed separately for HTTP, HTTPS, robots.txt, and sitemap.xml. Every redirect target is safety-checked.integer
checkRdapLook up public registration dates, status, registrar, nameservers, and handle where the registry provides RDAP data.boolean
checkWebInspect both HTTP and HTTPS status, redirect chains, final URL, title, metadata, security headers, and basic technology signals.boolean
checkTlsInspect the certificate on port 443, including validity dates, issuer, subject, SANs, fingerprint, and Node.js trust result.boolean
checkRobotsAndSitemapCheck standard robots.txt and sitemap.xml locations on the best working web origin.boolean

What you get

A structured dataset — each result includes fields like:

domainokhttpsStatushttpStatustitlednsAtlsExpiresAtregistrationExpiresAttechnologieswarningsCountinspectedAt

Export every run as JSON, CSV or Excel, or send it to your app, a database, Google Sheets, or an AI agent.

Related tools in Developer & Research Tools

Other ready-to-run tools in the same category — all pay-per-use on the Apify cloud.

GitHub Scraper iconDeveloper & Research Tools

GitHub Scraper

Search GitHub repos and users: stars, forks, language, topics, licence, plus user bio, company and followers. No token needed. $0.90 per 1,000 rows.

18 use cases

Stack Overflow / Stack Exchange Scraper iconDeveloper & Research Tools

Stack Overflow / Stack Exchange Scraper

Search Stack Overflow and Stack Exchange by keyword or tag. Score, answer count, views, reputation and body text. $2 per 1,000 questions.

2 use cases

Package Registry Scraper (npm + PyPI) iconDeveloper & Research Tools

Package Registry Scraper (npm + PyPI)

Get npm and PyPI package metadata as JSON. Version, license, author, repo, keywords and npm monthly downloads. $2 per 1,000 packages.

2 use cases

arXiv Scraper iconDeveloper & Research Tools

arXiv Scraper

Search arXiv papers by title, author, abstract or category. Get full abstracts, authors, categories, DOI, dates and PDF links. $2 per 1,000 papers.

2 use cases

OpenAlex Scholarly Works Scraper iconDeveloper & Research Tools

OpenAlex Scholarly Works Scraper

Search 250M+ OpenAlex papers with no API key. Get titles, authors, venue, year, citations, DOI, OA links and full abstracts. $2.00 per 1,000 papers.

2 use cases

Crossref Scholarly Works Scraper iconDeveloper & Research Tools

Crossref Scholarly Works Scraper

Search 150M+ papers on Crossref: DOI, title, authors, journal, publisher, date, citations and abstract. No API key. $1.00 per 1,000 works.

2 use cases

See all Developer & Research Tools →

Domain Inspector: DNS, registration, certificates and what a site runs, one row per domain

Paste a list of domains and get one row each: the DNS records, who the registrar is and when the registration expires, the certificate on port 443 with its expiry date, the redirect chain, the security headers, robots.txt, sitemap.xml and a few signals about what the site is built with.

Registration data comes from RDAP, which is the registry-run replacement for the old WHOIS port. Not every registry publishes it, so on some country domains the registrar and the expiry date come back empty while everything else on the row is filled in.

InputDomains or URLs, up to 500 per run
OutputOne row per domain
Ceiling500 domains per run
Account neededNone, and no API key
Price$1.50 per 1,000 domains, flat on every plan

🔍 What Domain Inspector does

Each domain gets four independent checks, and you can switch any of them off.

DNS resolves A, AAAA, MX, NS, TXT and CAA, reporting per-record errors rather than collapsing them into one failure. RDAP asks the registry for the registrar, the status codes, the nameservers and the registration, update and expiry dates. Certificates connect on port 443 and report the issuer, the subject, the alternative names, both validity dates, days left and whether Node's trust store accepts the chain. Web requests both http:// and https://, follows the redirects, and reads the final status, the page title, the canonical URL, the Open Graph block, the security headers and a short list of technology signals.

If robots.txt and sitemap.xml checking is on, both are fetched from whichever origin answered best, and any sitemap URLs declared in robots.txt come back with them.

Anything that went wrong without killing the row lands in warnings, with warningsCount beside it so you can sort by how messy a domain is.

📥 What you give it

{
  "domains": ["github.com", "example.org", "https://news.ycombinator.com/"],
  "maxConcurrency": 5,
  "requestTimeoutSecs": 8,
  "checkRdap": true,
  "checkTls": true
}
FieldDefaultWhat it is
domainsbox starts at github.comDomains or full URLs, one per line. A URL is reduced to its hostname. Up to 500.
domainnoneA single domain, added to the list above. Handy for a task or an API call with one target.
maxConcurrency5How many domains are inspected at once, 1 to 20. Keep it modest or DNS and the sites themselves start rate limiting you.
requestTimeoutSecs8The limit on each individual lookup, 3 to 20. There is a deadline on the whole domain as well.
maxRedirects5How many hops to follow, up to 10. Every hop is safety checked.
checkRdaponRegistration data from the registry.
checkWebonThe HTTP and HTTPS requests, the redirect chain, headers and page metadata.
checkTlsonThe certificate on port 443.
checkRobotsAndSitemaponrobots.txt and sitemap.xml.
proxyConfigurationoffOptional network settings for the web requests only. DNS, RDAP and the certificate check always connect directly.

example.com and www.example.com are two different domains here. Both get inspected, both get a row, and both count against your total. Deduplication only catches exact repeats.

The 500 limit is applied before duplicates are removed, and the single domain field is added at the end of the list. So a list of 500 with repeats in it can push your single domain out.

Setting maxRedirects to 0 does not switch redirects off. It falls back to 5.

📤 What you get back

The flat summary fields from a real row, with the nested blocks left out here because a full row runs to several thousand characters:

{
  "ok": true,
  "domain": "github.com",
  "inspectedAt": "2026-09-14T05:42:44.663Z",
  "httpsStatus": 200,
  "httpStatus": 200,
  "title": "GitHub · Change is constant. GitHub keeps you ahead. · GitHub",
  "dnsA": ["140.82.114.3"],
  "dnsAAAA": [],
  "tlsExpiresAt": "2026-11-29T23:59:59.000Z",
  "registrationExpiresAt": "2028-10-09T18:20:50.000Z",
  "technologies": ["React", "Server: github.com"],
  "warningsCount": 0
}

Under those sit the full blocks. From the same row, the certificate one:

"tls": {
  "available": true,
  "authorized": true,
  "authorizationError": null,
  "protocol": "TLSv1.3",
  "subject": { "CN": "github.com" },
  "issuer": { "C": "GB", "O": "Sectigo Limited", "CN": "Sectigo Public Server Authentication CA DV E36" },
  "subjectAlternativeNames": ["github.com", "www.github.com"],
  "validFrom": "2026-09-01T00:00:00.000Z",
  "expiresAt": "2026-11-29T23:59:59.000Z",
  "daysUntilExpiry": 76,
  "serialNumber": "A59EBDB596751DB7F5C095079613953C",
  "fingerprint256": "46:B6:01:EE:08:B4:18:CF:8A:3A:1E:..."
}
BlockWhat is in it
dnsa, aaaa, mx, ns, txt, caa, plus errors keyed by record type and hasData.
rdapregistrar, statuses, nameservers, registeredAt, updatedAt, expiresAt, handle. available: false when the registry publishes nothing.
tlsThe certificate, as above. authorized is Node's own trust verdict, and authorizationError says why when it is false.
http, httpsSeparate blocks per scheme: status, finalUrl, redirects, redirectCount, metadata, responseHeaders, securityHeaders, technologies.
robots, sitemappresent, status, finalUrl, and any sitemaps declared in robots.txt.
warningsPlain sentences naming anything that went wrong but did not stop the row.

The overview table in the console shows the flat summary only. Switch to JSON or All fields for the nested blocks.

🧾 Reading the output

Three kinds of row can land in your dataset.

RowHow to spot itCharged
An inspected domainok: true and a domainyes
The sample row_sample: trueno
A diagnosticok: false and an errorCodeno

Filter on _sample being absent, not on ok. The sample row also carries ok: true.

CodeWhat it means
BAD_INPUTThe entry was not a domain: a bare IP address, a single word with no dot, or something that would not parse. The input field on the row shows what you sent.
INSPECTION_FAILEDEvery check came back empty. Usually an unregistered or misspelled domain.

A BAD_INPUT row has no domain field, only input, so it shows in the overview table as a line with the domain column blank.

▶️ How to run it

1. Open Domain Inspector and click Try for free. 2. Paste your domains into Domains or URLs, one per line. 3. Leave the four check boxes on for a full row, or switch off the ones you do not need. 4. Click Start. Rows land once every domain has finished, so a long list stays quiet for a while. 5. Download the dataset as JSON, CSV or Excel, or read it from the Apify API.

💰 How much does it cost?

$1.50 per 1,000 domains. Flat on every Apify plan, no volume tiers.

You pay per domain that came back with something. A parked domain counts, because it still has DNS and registration data. A domain where every check came back empty does not, and neither does the sample row or an invalid entry.

💡 What people use it for

  • Watching certificate and registration expiry across a portfolio, on a schedule, sorted by

daysUntilExpiry.

  • Auditing security headers across every domain a company owns, in one pass.
  • Checking a list of acquisition targets or suppliers before a first email: is the site live, who

registered it, what is it built with.

  • Confirming a migration actually landed, by reading the redirect chain and the final URL.
  • Finding the domains in a list that no longer resolve at all.

🚧 What it does not do

  • No JavaScript. The title, metadata and technology signals come from the HTML the server sent,

so a site that renders everything client side looks emptier than it is.

  • Technology detection is a short list of signals, not a full fingerprinting suite. Treat

technologies as a hint.

  • RDAP only. There is no fallback to the old port-43 WHOIS, so registries that publish neither

come back with available: false.

  • 500 domains per run, counted before duplicates are removed.
  • Nothing is delivered until every domain has finished. A run that is aborted partway through

writes no rows at all, so split very large lists.

  • A domain pointing at a private address gets its web and certificate checks skipped, with a

warning saying so. DNS and registration still come back.

  • One certificate, on port 443. No other ports, no chain download, no revocation check.
  • No subdomain discovery. It inspects exactly what you give it.
  • No traffic, ranking or backlink figures.

🧭 Which site checker do you need?

If you wantUse
DNS, registration, certificates and headers for a list of domainsThis one
To crawl a site and read what is on its pagesWebsite Intelligence Crawler
Traffic estimates and audience data for a domainSimilarWeb Traffic Scraper
A picture of the page rather than its headersWebsite Screenshot Generator
To check whether an email address is deliverableEmail Verification

❓ Questions people ask

Do I need an API key for any of this? No. DNS, RDAP and certificates are all public lookups.

Why is the registrar empty on some domains? That registry does not publish RDAP. There is no second source here, so the field stays empty rather than being guessed.

Can I check subdomains? Only ones you list yourself. It does not go looking for them.

How long does 500 domains take? It depends on Concurrent domains and how fast the targets answer. Raise it carefully: past a point the other end starts refusing.

Why did I get nothing back from a run I stopped early? Rows are written once every domain has been inspected. Stop it before then and nothing is written.

Is this legal? DNS, RDAP and certificates are published for public lookup, and robots.txt and sitemap.xml are files sites publish deliberately. Apify's write-up on scraping and the law is a good starting point, and we are not lawyers.

🆘 If something breaks

Open the Issues tab on the actor page. Send the run ID and the domain that behaved oddly. The warnings array on the row usually explains it, and errorCode names it when the whole row failed.