Any website's tech stack and email security, one call
One call per domain: the site's tech stack with the evidence for each technology (103+ fingerprints), its email provider, SPF and DMARC policy, domain age and registrar, security headers and robots/sitemap/llms.txt. For sales and marketing teams, security reviews, agencies and AI agents. 25 free domains a day, no key; plans from $5 (one-time pack) or $19/month.
Opens Stripe's billing portal: invoices, payment method, cancel.



Who it's for
Anyone who needs to know what a company's website runs on and how its email is set up, for one domain or a whole list.
Qualify leads by stack: Shopify or WooCommerce, HubSpot or Marketo, Google Workspace or Microsoft 365.
Check a vendor's SPF, DMARC policy, security headers and domain age before you trust its email.
See a prospect's CMS, analytics and tag manager before the first call.
An MCP tool that answers "what does this site run on, and is its email protected?" in plain JSON.
Try it
Type any domain, URL or work email. Prefilled with a real site.
Raw JSON response
Real sample output
Captured from a live call to this API.
{
"check": "report",
"results": [
{
"input": "stripe.com",
"domain": "stripe.com",
"reachable": true,
"errors": [],
"dns": {
"a": [
"198.137.150.41",
"198.202.176.41"
],
"aaaa": [],
"ns": [
"ns-1087.awsdns-07.org",
"ns-1882.awsdns-43.co.uk",
"ns-423.awsdns-52.com",
"ns-705.awsdns-24.net"
]
},
"email": {
"mxProvider": "Google Workspace",
"mx": [
"aspmx.l.google.com",
"alt1.aspmx.l.google.com",
"alt2.aspmx.l.google.com",
"aspmx2.googlemail.com",
"aspmx3.googlemail.com"
],
"spf": {
"present": true,
"record": "v=spf1 ip4:198.2.180.60/32 ip4:13.111.2.227/32 include:spf1.stripe.com include:greenhouse-outbound-mail.stripe.com include:_spf.qualtrics.com ~all",
"allQualifier": "softfail",
"includes": [
"spf1.stripe.com",
"greenhouse-outbound-mail.stripe.com",
"_spf.qualtrics.com"
],
"multipleRecords": false
},
"dmarc": {
"present": true,
"record": "v=DMARC1; p=reject; pct=100; fo=1; rua=mailto:dmarc-reports@stripe.com; ruf=mailto:dmarc-forensics@stripe.com;",
"policy": "reject",
"subdomainPolicy": null,
"pct": 100,
"rua": true
}
},
"verifications": [
"apple",
"atlassian",
"canva",
"docker",
"facebook",
"google"
],
"url": "https://stripe.com/",
"finalUrl": "https://stripe.com/",
"statusCode": 200,
"blocked": false,
"title": "Stripe | Financial Infrastructure to Grow Your Revenue",
"description": "Stripe is a financial services platform that helps all types of businesses accept payments, build flexible billing models, and manage money movement.",
"language": "en-US",
"technologies": [
{
"name": "Next.js",
"category": "JS framework",
"evidence": "html: /_next/static/"
}
],
"securityHeaders": {
"strictTransportSecurity": true,
"contentSecurityPolicy": true,
"xFrameOptions": true,
"xContentTypeOptions": true,
"referrerPolicy": true,
"permissionsPolicy": false,
"score": "5/6"
},
"registration": {
"registrar": "SafeNames Ltd.",
"createdAt": "1995-09-12T04:00:00Z",
"updatedAt": "2025-10-01T01:39:51Z",
"expiresAt": "2027-09-11T04:00:00Z",
"ageDays": 11342,
"status": [
"client delete prohibited",
"client transfer prohibited",
"client update prohibited",
"server delete prohibited",
"server transfer prohibited",
"server update prohibited"
]
},
"files": {
"robotsTxt": true,
"sitemapXml": false,
"llmsTxt": true,
"securityTxt": true
},
"exists": true,
"summary": "stripe.com: email on Google Workspace, DMARC p=reject, domain 31y old.",
"analyzedAt": "2026-10-01T07:47:30.978Z",
"cached": false
}
],
"count": 1
}Limits, plainly
Free and rate limited so it stays fast for everyone. Loop over longer lists (report: 1 domain per call; email-security: 5; tech: 3; registration: 10). For 10,000-domain lists, CSV export, TLS certificate checks and a monitor mode that returns only changed domains, the DomainDNA tool on the Apify Store does the same checks in bulk.
- Domains per call: /api/report 1, /api/email-security 5, /api/tech 3, /api/registration 10; 10 calls a minute per IP on the free tier.
- Free tier: 25 domains a day per IP, no key. Paid keys from $5 (one-time pack) or $19/month (see Get an API key).
- Each domain in a call counts as one check (duplicates in the same call count once). Failed calls are not counted. Answers are cached for 1 hour per domain and check (cached: true).
- Tech detection reads the homepage the way a browser would (first 300 KB); sites behind a bot wall come back with blocked: true and a partial list. No TLS certificate check (Workers cannot read certificates; the Apify tool has it).
- Registration dates come from the registry's own RDAP server; a few country TLDs publish none, and some registries (.org) rate-limit busy periods (registration: null with the reason in errors; retry later, and successful answers are cached).
How the price compares
Per domain looked up. Rival list prices were read from their public pricing pages on 1 Oct 2026.
| Who | Plan | Lookups | Per 1,000 domains |
|---|---|---|---|
| Wappalyzer Pro | $250/month | 5,000 API credits/month | $50.00 |
| BuiltWith Basic | $295/month | tech lookups + lists (2 technologies) | n/a (subscription) |
| host.io Basic | $99/month | 10,000 requests/month | $9.90 |
| TheirStack API | $49/month | 1,500 credits (about 500 company tech stacks) | about $98 |
| DomainDNA API Scout | $19/month | 5,000 domains/month | $3.80 |
| DomainDNA API pay as you go | $5 once, never expires | 1,000 domains | $5.00 |
Wappalyzer and BuiltWith crawl the web and keep history; DomainDNA reads the site, DNS and RDAP live on each call, adds the email side (provider, SPF, DMARC) and domain age in the same answer, and shows the evidence behind every technology.
Checking 10,000 domains, or watching a list?
DomainDNA on the Apify Store runs the same checks on lists of any size, adds the TLS certificate (issuer, expiry), exports CSV/Excel, and has a monitor mode that returns only the domains whose stack, email setup or registration changed since the last run.
Get an API key
Domain intelligence API: a website's tech stack with the evidence for each technology, its email provider (Google Workspace, Microsoft 365, Proofpoint...), SPF and DMARC policy, DNS, domain age, registrar and expiry (RDAP), security headers and robots/sitemap/llms/security.txt, read live per call. BuiltWith and Wappalyzer API alternative. Keys work on the REST API and the MCP server; no Apify account needed.
14-day money-back promise: if it doesn't work as described, email us within 14 days and we fix it or refund you in full. Refund terms.
15,000 domain checks a month · 60 per minute
Get Analyst keyor $490/year, 2 months free40,000 domain checks a month · 120 per minute
Get Platform keyor $990/year, 2 months freePay with card, Apple Pay, Google Pay or Link through Stripe Checkout (sales tax/VAT handled by Stripe). Your key appears on the page you return to right after checkout: save it. Manage or cancel any time at domaindna-api.cybermax-tools.workers.dev/manage. Send it as x-api-key: YOUR_KEY (or Authorization: Bearer YOUR_KEY, which MCP clients support). Check usage at /key. Failed calls are not counted. Tech-lookup APIs are priced for big crawled databases: Wappalyzer Pro $250/month for 5,000 API credits ($50 per 1,000), BuiltWith from $295/month, host.io Basic $99/month for 10,000 requests, TheirStack $49/month for about 500 company tech stacks (pricing pages read 1 Oct 2026). DomainDNA: $5 pay-as-you-go for 1,000 domain checks (no expiry) or Scout $19/month for 5,000 ($3.80 per 1,000), with email security and domain age in the same answer.
curl -s "https://domaindna-api.cybermax-tools.workers.dev/api/report?..." -H "x-api-key: YOUR_KEY"
# MCP (Claude Desktop, Cursor, VS Code)
{ "mcpServers": { "domaindna-api": { "type": "http", "url": "https://domaindna-api.cybermax-tools.workers.dev/mcp",
"headers": { "Authorization": "Bearer YOUR_KEY" } } } }
# Usage so far
curl -s https://domaindna-api.cybermax-tools.workers.dev/key -H "x-api-key: YOUR_KEY"Use the API
JSON over HTTPS, CORS enabled, no key. GET for quick calls, POST a JSON body for lists. Spec: openapi.json · llms.txt
curl -s "https://domaindna-api.cybermax-tools.workers.dev/api/report?domain=stripe.com"
# lists: POST a JSON body
curl -s -X POST https://domaindna-api.cybermax-tools.workers.dev/api/report \
-H "content-type: application/json" \
-d '{"domains":["stripe.com"]}'import requests
r = requests.post("https://domaindna-api.cybermax-tools.workers.dev/api/report",
json={"domains":["stripe.com"]}, timeout=30)
r.raise_for_status()
for row in r.json()["results"]:
print(row)Endpoints: /api/report everything about one domain: tech stack, email security, dns, registration, site files · /api/email-security email provider, spf and dmarc for up to 5 domains · /api/tech tech stack of up to 3 websites, with evidence · /api/registration domain age, registrar and expiry for up to 10 domains (rdap)
Add it to your AI agent (MCP)
A remote MCP server at https://domaindna-api.cybermax-tools.workers.dev/mcp (streamable HTTP, no auth). Read-only tools with JSON schemas, so agents know exactly what to send.
// Claude Desktop, Cursor, VS Code, any MCP client (remote, no key)
{
"mcpServers": {
"domaindna-api": { "type": "http", "url": "https://domaindna-api.cybermax-tools.workers.dev/mcp" }
}
}
# Claude Code
claude mcp add --transport http domaindna-api https://domaindna-api.cybermax-tools.workers.dev/mcp
# Tools: domain_report, email_security, tech_stack, domain_registration
# e.g. domain_report({"domains":["stripe.com"]})domain_report
Tech stack (with evidence), email provider, SPF, DMARC, DNS, RDAP registration (age, registrar, expiry), security headers and site files for one domain, URL or email.email_security
MX provider, SPF record and all qualifier, DMARC policy, pct and rua, A/AAAA/NS and TXT verifications for 1-5 domains.tech_stack
Technologies (CMS, e-commerce, frameworks, analytics, tag managers, CDN, chat...) with the evidence for each, plus security headers, for 1-3 websites.domain_registration
RDAP registration (registrar, created, updated, expires, age in days, status) for 1-10 domains.
FAQ
Why not BuiltWith or Wappalyzer?
They are the big tech-lookup brands, with crawled history and lead lists, priced for that: BuiltWith from $295/month, Wappalyzer Pro $250/month for 5,000 API credits (their pricing pages, 1 Oct 2026). If you need the live stack, the email setup and the domain age for your own domains, a Scout key ($5 (one-time pack) or $19/month) covers 5,000 domains a month, with evidence for each technology.
Why not run dig and whois myself?
You can, one domain at a time. DomainDNA does the DNS (MX, SPF, DMARC, NS, TXT), the RDAP lookup at the right registry, the homepage fingerprinting and the site-file checks in one call, names the email provider and gives one JSON shape for every domain.
How fresh is it?
Live: every answer is read at the time of the call, then cached for 1 hour per domain and check (cached: true in the result).
What if a site blocks bots?
Some sites answer automated visits with a challenge page. Those come back with blocked: true and whatever the page showed; DNS, email and registration still work because they do not touch the website.
Is there a key or a cost?
The free tier needs no key: 25 domain checks a day per IP. Paid keys: pay as you go: $5 for 1,000 domain checks that never expire (no subscription); or monthly: Scout $19/month for 5,000 domain checks, Analyst $49/month for 15,000 domain checks, Platform $99/month for 40,000 domain checks. Yearly billing gives 2 months free. Every domain in a call counts as one check; up to 1 domain per /api/report call, 5 per /api/email-security, 3 per /api/tech and 10 per /api/registration. Send the key as the x-api-key header. No surprise overage charges; cancel any time.
Can I use it from Claude, Cursor or another AI agent?
Yes. Add the MCP server URL below (with your key as a Bearer token for paid limits). Tools: domain_report, email_security, tech_stack and domain_registration.
Where does the data come from, and is it legal to use?
Each call reads only public information about the domains you send: the public homepage and its robots.txt, sitemap.xml, llms.txt and security.txt, public DNS (DNS over HTTPS) and the registry's public RDAP record. No login, no personal data, nothing stored except a 1-hour cache. Not affiliated with BuiltWith, Wappalyzer or any registry.