Screen applicant and policyholder domains for basic email and web hygiene
Underwriters and brokers want quick outside-in signals before a deeper review. DomainDNA reads public DNS, RDAP and each homepage and returns DMARC policy, SPF qualifier, TLS certificate expiry, security headers and domain age per applicant, in one CSV.
How cyber insurance teams use DomainDNA
- Export the applicant or policyholder domains to a list.
- Run DomainDNA on Apify with the list; download the CSV.
- Flag rows with DMARC missing or none, SPF ending in +all, a certificate expiring soon, or weak security headers.
- Schedule monitor mode on the book to be told when a policyholder's DMARC, certificate or headers change.
These are public, company-level technical facts, useful as a first screen. They are not a security rating and not advice.

Real run on Apify, 23 Sep 2026
| Domain | Tech found (first 3) | Email on | DMARC | Domain age |
|---|---|---|---|---|
| shopify.com | Shopify, Tailwind CSS, Cloudflare | Google Workspace | reject | 21 years |
| hubspot.com | HubSpot CMS, Cloudflare, Google Tag Manager | Google Workspace | reject | 21 years |
| docker.com | WordPress, Fastly, Nginx | Google Workspace | quarantine | 31 years |
| github.com | Contentful, GitHub Pages | Microsoft 365 | quarantine | 18 years |
| mailchimp.com | Akamai, FullStory, OneTrust | Cisco Secure Email | reject | 25 years |
Source: products/domain-intel/store/listing.json (real run of the DomainDNA tool on Apify, 23 Sep 2026).
FAQ
Does it scan ports or test for vulnerabilities?
No. It reads only public DNS, RDAP and the public homepage.
What does a book of 1,000 domains cost?
$4 per full check; monitor mode charges only the domains that changed.
DomainDNA: full guide with prices and alternatives · All use cases · Store