Hoppa till innehållet
← All data tools

SSL certificate checker and DNS lookup for many domains

Checks a list of domains in one run. Each row has the DNS records, SPF and DMARC parsed into fields, the SSL certificate served on port 443 with expiry and issuer, and a status with the issues in plain words.

Open in Apify Store

For each domain the tool asks DNS for A, AAAA, MX, NS, TXT and CAA records, parses the SPF and DMARC records, and opens a TLS handshake on port 443 to read the certificate: issuer, valid from and to, days left, subject alternative names, protocol, and whether it is trusted and matches the name. No API key and no third-party service is involved.

Every row ends in ok, warning or error and a list of findings such as "SSL: the certificate expires in 28 days." A run with empty input checks three example domains. With onlyNew set to true, a daily run returns only the domains where something changed, for example a renewed certificate, a new MX host or a changed SPF record.

Sample from a real run

3 rows (selected fields) from run ztclapyJ55ATHgYIl on 6 October 2026, exactly as the tool returned them.

domainstatusissuessslDaysLeftsslIssuerspfAlldmarcPolicymxHosts
nightwave.sewarningDMARC: Policy p=none only monitors: spoofed mail is not stopped., No CAA record: any certificate authority may issue certificates.66WE1~nonemx1.pub.mailpod12-cph3.one.com, mx2.pub.mailpod12-cph3.one.com, mx3.pub.mailpod12-cph3.one.com, mx4.pub.mailpod12-cph3.one.com
example.comwarningDMARC: No rua tag: the domain gets no aggregate reports., No CAA record: any certificate authority may issue certificates.80Cloudflare TLS Issuing ECC CA 3-reject
wikipedia.orgwarningSSL: the certificate expires in 28 days.28YE2~rejectmx-in1001.wikimedia.org, mx-in2001.wikimedia.org

Fields

Every row has these fields. Field names are stable between versions.

FieldWhat it holds
domainThe host name that was checked, lower case ASCII
statuserror when something is broken (the domain does not exist, the certificate has expired, is not valid for the name or is not trusted, no TLS answer), warning when something should be fixed (certificate expires soon, missing MX, SPF, DMARC or CAA, weak SPF or DMARC), else ok
issuesEvery finding behind the status, errors first
sslDaysLeftWhole days until the certificate expires, negative after expiry
sslValidToCertificate expiry time, ISO 8601 in UTC
sslIssuerName of the issuing CA certificate, for example R11 or WE1
mxHostsMail servers, lowest priority number first
nameserversNS records
spfAllQualifier of the SPF all mechanism: - (fail), ~ (softfail), ? (neutral) or + (pass)
dmarcPolicyDMARC p value: none, quarantine or reject
dnsAll records: a, aaaa, mx, ns, txt, caa, and spf (record, all, includes, lookupCount, warnings) and dmarc (record, policy, subdomainPolicy, pct, reportDomains, alignmentDkim, alignmentSpf, warnings)
sslissuer, issuerOrganization, subject, validFrom, validTo, daysLeft, san, serialNumber, fingerprintSha256, protocol, isTrusted, trustError, hostnameMatches
sslErrorWhy no certificate could be read, for example a timeout or a refused connection
checkedAtTime of the check, ISO 8601 in UTC
changeFingerprintShort hash of the domain's state, used by onlyNew. It changes when a record, the certificate or the status changes

Input example

Paste it into the JSON tab of the actor in Apify Console, or send it to the Apify API.

{
  "checks": [
    "dns",
    "ssl"
  ],
  "domains": [
    "nightwave.se",
    "example.com",
    "wikipedia.org"
  ],
  "onlyNew": false,
  "maxResults": 50,
  "expiryWarningDays": 30
}

What people use it for

  • Certificate renewals. A daily list of every domain whose certificate expires within your warning window, across your own sites, subdomains and customers.
  • E-mail authentication audits. See which domains lack SPF or DMARC, use +all, exceed the 10 lookup limit or still have the policy p=none.
  • DNS change watch. Get a row when the MX, NS or TXT records of an important domain change.

Price

2 USD per 1 000 domains, plus Apify platform usage.

A run with the default input checks three domains and costs 0.006 USD in results. The run on 6 October 2026 shown above checked them in about 2 seconds. maxResults caps every run (default 50), and duplicates and invalid entries are not charged.

Run it on a schedule

Set onlyNew to true and add the actor to a schedule in Apify Console (for example the cron expression 0 7 * * * for 07:00 every day). The actor remembers what it has already delivered for the same input, in a named key-value store in your own Apify account (nightwave-state-domain-inspector), and each run returns and charges only what is new. The first run returns everything in the selection. A run with nothing new finishes with 0 rows and costs nothing beyond platform usage.

Source and license

The tool uses only open Internet protocols and asks each domain's own servers: DNS (RFC 1035) for the records, SPF (RFC 7208), DMARC (RFC 7489) and CAA (RFC 8659), and the TLS handshake (RFC 8446) on port 443. It sends no HTTP request and downloads no page. WHOIS and RDAP registration data are not included.

There is no third-party data source and no terms of use to accept. The output contains only what the domain owner publishes in DNS and in the certificate. DMARC report addresses are reduced to their domain, so no mailbox names end up in the output.

Try it

The tool runs on Apify. Apify handles your account, the runs and the payment, and you can try it with the input above before you schedule anything.

Open in Apify Store

Built and maintained by Nightwave AB. Questions or bugs: kontakt@nightwave.se