CyberMax
Home › Use cases › DomainDNA

Screen applicant and policyholder domains for basic email and web hygiene

For: cyber insurance

Underwriters and brokers want quick outside-in signals before a deeper review. DomainDNA reads public DNS, RDAP and each homepage and returns DMARC policy, SPF qualifier, TLS certificate expiry, security headers and domain age per applicant, in one CSV.

How cyber insurance teams use DomainDNA

  1. Export the applicant or policyholder domains to a list.
  2. Run DomainDNA on Apify with the list; download the CSV.
  3. Flag rows with DMARC missing or none, SPF ending in +all, a certificate expiring soon, or weak security headers.
  4. Schedule monitor mode on the book to be told when a policyholder's DMARC, certificate or headers change.

These are public, company-level technical facts, useful as a first screen. They are not a security rating and not advice.

DomainDNA output table: tech stack, email provider, DMARC and domain age per domain
Real output from the DomainDNA tool on Apify

Real run on Apify, 23 Sep 2026

DomainTech found (first 3)Email onDMARCDomain age
shopify.comShopify, Tailwind CSS, CloudflareGoogle Workspacereject21 years
hubspot.comHubSpot CMS, Cloudflare, Google Tag ManagerGoogle Workspacereject21 years
docker.comWordPress, Fastly, NginxGoogle Workspacequarantine31 years
github.comContentful, GitHub PagesMicrosoft 365quarantine18 years
mailchimp.comAkamai, FullStory, OneTrustCisco Secure Emailreject25 years

Source: products/domain-intel/store/listing.json (real run of the DomainDNA tool on Apify, 23 Sep 2026).

FAQ

Does it scan ports or test for vulnerabilities?

No. It reads only public DNS, RDAP and the public homepage.

What does a book of 1,000 domains cost?

$4 per full check; monitor mode charges only the domains that changed.

DomainDNA: full guide with prices and alternatives · All use cases · Store