SSL certificate checker and DNS lookup for many domains
Checks a list of domains in one run. Each row has the DNS records, SPF and DMARC parsed into fields, the SSL certificate served on port 443 with expiry and issuer, and a status with the issues in plain words.
For each domain the tool asks DNS for A, AAAA, MX, NS, TXT and CAA records, parses the SPF and DMARC records, and opens a TLS handshake on port 443 to read the certificate: issuer, valid from and to, days left, subject alternative names, protocol, and whether it is trusted and matches the name. No API key and no third-party service is involved.
Every row ends in ok, warning or error and a list of findings such as "SSL: the certificate expires in 28 days." A run with empty input checks three example domains. With onlyNew set to true, a daily run returns only the domains where something changed, for example a renewed certificate, a new MX host or a changed SPF record.
Sample from a real run
3 rows (selected fields) from run ztclapyJ55ATHgYIl on 6 October 2026, exactly as the tool returned them.
domain | status | issues | sslDaysLeft | sslIssuer | spfAll | dmarcPolicy | mxHosts |
|---|---|---|---|---|---|---|---|
| nightwave.se | warning | DMARC: Policy p=none only monitors: spoofed mail is not stopped., No CAA record: any certificate authority may issue certificates. | 66 | WE1 | ~ | none | mx1.pub.mailpod12-cph3.one.com, mx2.pub.mailpod12-cph3.one.com, mx3.pub.mailpod12-cph3.one.com, mx4.pub.mailpod12-cph3.one.com |
| example.com | warning | DMARC: No rua tag: the domain gets no aggregate reports., No CAA record: any certificate authority may issue certificates. | 80 | Cloudflare TLS Issuing ECC CA 3 | - | reject | |
| wikipedia.org | warning | SSL: the certificate expires in 28 days. | 28 | YE2 | ~ | reject | mx-in1001.wikimedia.org, mx-in2001.wikimedia.org |
Fields
Every row has these fields. Field names are stable between versions.
| Field | What it holds |
|---|---|
domain | The host name that was checked, lower case ASCII |
status | error when something is broken (the domain does not exist, the certificate has expired, is not valid for the name or is not trusted, no TLS answer), warning when something should be fixed (certificate expires soon, missing MX, SPF, DMARC or CAA, weak SPF or DMARC), else ok |
issues | Every finding behind the status, errors first |
sslDaysLeft | Whole days until the certificate expires, negative after expiry |
sslValidTo | Certificate expiry time, ISO 8601 in UTC |
sslIssuer | Name of the issuing CA certificate, for example R11 or WE1 |
mxHosts | Mail servers, lowest priority number first |
nameservers | NS records |
spfAll | Qualifier of the SPF all mechanism: - (fail), ~ (softfail), ? (neutral) or + (pass) |
dmarcPolicy | DMARC p value: none, quarantine or reject |
dns | All records: a, aaaa, mx, ns, txt, caa, and spf (record, all, includes, lookupCount, warnings) and dmarc (record, policy, subdomainPolicy, pct, reportDomains, alignmentDkim, alignmentSpf, warnings) |
ssl | issuer, issuerOrganization, subject, validFrom, validTo, daysLeft, san, serialNumber, fingerprintSha256, protocol, isTrusted, trustError, hostnameMatches |
sslError | Why no certificate could be read, for example a timeout or a refused connection |
checkedAt | Time of the check, ISO 8601 in UTC |
changeFingerprint | Short hash of the domain's state, used by onlyNew. It changes when a record, the certificate or the status changes |
Input example
Paste it into the JSON tab of the actor in Apify Console, or send it to the Apify API.
{
"checks": [
"dns",
"ssl"
],
"domains": [
"nightwave.se",
"example.com",
"wikipedia.org"
],
"onlyNew": false,
"maxResults": 50,
"expiryWarningDays": 30
}What people use it for
- Certificate renewals. A daily list of every domain whose certificate expires within your warning window, across your own sites, subdomains and customers.
- E-mail authentication audits. See which domains lack SPF or DMARC, use
+all, exceed the 10 lookup limit or still have the policyp=none. - DNS change watch. Get a row when the MX, NS or TXT records of an important domain change.
Price
2 USD per 1 000 domains, plus Apify platform usage.
A run with the default input checks three domains and costs 0.006 USD in results. The run on 6 October 2026 shown above checked them in about 2 seconds. maxResults caps every run (default 50), and duplicates and invalid entries are not charged.
Run it on a schedule
Set onlyNew to true and add the actor to a schedule in Apify Console (for example the cron expression 0 7 * * * for 07:00 every day). The actor remembers what it has already delivered for the same input, in a named key-value store in your own Apify account (nightwave-state-domain-inspector), and each run returns and charges only what is new. The first run returns everything in the selection. A run with nothing new finishes with 0 rows and costs nothing beyond platform usage.
Source and license
The tool uses only open Internet protocols and asks each domain's own servers: DNS (RFC 1035) for the records, SPF (RFC 7208), DMARC (RFC 7489) and CAA (RFC 8659), and the TLS handshake (RFC 8446) on port 443. It sends no HTTP request and downloads no page. WHOIS and RDAP registration data are not included.
There is no third-party data source and no terms of use to accept. The output contains only what the domain owner publishes in DNS and in the certificate. DMARC report addresses are reduced to their domain, so no mailbox names end up in the output.
Try it
The tool runs on Apify. Apify handles your account, the runs and the payment, and you can try it with the input above before you schedule anything.
Built and maintained by Nightwave AB. Questions or bugs: kontakt@nightwave.se