{
  "openapi": "3.0.1",
  "info": {
    "title": "Domain Intel — WHOIS (RDAP), DNS, Email Security, SSL",
    "description": "Domain intelligence for security, due diligence and AI agents: registrar, dates and status via RDAP, DNS over HTTPS, SPF/DMARC/DKIM audit, certificate history and subdomains from CT logs, website security headers and tech, risk flags. No API key.",
    "version": "0.1",
    "x-build-id": "SLqv8FGXA3xWoeLOx"
  },
  "servers": [
    {
      "url": "https://api.apify.com/v2"
    }
  ],
  "paths": {
    "/acts/yadroo~domain-intel/run-sync-get-dataset-items": {
      "post": {
        "operationId": "run-sync-get-dataset-items-yadroo-domain-intel",
        "x-openai-isConsequential": false,
        "summary": "Executes an Actor, waits for its completion, and returns Actor's dataset items in response.",
        "tags": [
          "Run Actor"
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/inputSchema"
              }
            }
          }
        },
        "parameters": [
          {
            "name": "token",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "Enter your Apify token here"
          }
        ],
        "responses": {
          "200": {
            "description": "OK"
          }
        }
      }
    },
    "/acts/yadroo~domain-intel/runs": {
      "post": {
        "operationId": "runs-sync-yadroo-domain-intel",
        "x-openai-isConsequential": false,
        "summary": "Executes an Actor and returns information about the initiated run in response.",
        "tags": [
          "Run Actor"
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/inputSchema"
              }
            }
          }
        },
        "parameters": [
          {
            "name": "token",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "Enter your Apify token here"
          }
        ],
        "responses": {
          "200": {
            "description": "OK",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/runsResponseSchema"
                }
              }
            }
          }
        }
      }
    },
    "/acts/yadroo~domain-intel/run-sync": {
      "post": {
        "operationId": "run-sync-yadroo-domain-intel",
        "x-openai-isConsequential": false,
        "summary": "Executes an Actor, waits for completion, and returns the OUTPUT from Key-value store in response.",
        "tags": [
          "Run Actor"
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/inputSchema"
              }
            }
          }
        },
        "parameters": [
          {
            "name": "token",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "Enter your Apify token here"
          }
        ],
        "responses": {
          "200": {
            "description": "OK"
          }
        }
      }
    }
  },
  "components": {
    "schemas": {
      "inputSchema": {
        "type": "object",
        "required": [
          "domains"
        ],
        "properties": {
          "domains": {
            "title": "Domains",
            "type": "array",
            "description": "Domain names to profile — one row per domain. URLs and hosts are accepted and normalized (\"https://www.Example.com/x\" → \"example.com\"; IDNs → punycode). Sub-domains are walked up to the registered name for RDAP. Invalid entries, IP addresses and internal names (localhost, *.local, *.internal…) are skipped with a warning; duplicates collapse. Max 500 per run; how many finish within the run's timeout depends on the modules (README → Limits) — the rest is listed in SUMMARY.notProcessed and not charged.",
            "items": {
              "type": "string"
            }
          },
          "includeRdap": {
            "title": "Registration data (RDAP / WHOIS successor)",
            "type": "boolean",
            "description": "Registrar, IANA registrar id, abuse contact, registration / expiry / update dates, domain age, EPP status codes, DNSSEC and nameservers. Uses the IANA bootstrap so every gTLD and most ccTLDs work; TLDs without RDAP (e.g. .io, .co, .us, .kz, .ru, .de) return `rdapError` instead of data.",
            "default": true
          },
          "includeDns": {
            "title": "DNS records (DNS over HTTPS)",
            "type": "boolean",
            "description": "Resolve the record types below via Google or Cloudflare DoH. Adds `dns` (per type), `dnsStatus` (NOERROR / NXDOMAIN) and `ipAddresses`.",
            "default": true
          },
          "dnsRecordTypes": {
            "title": "DNS record types",
            "type": "array",
            "description": "Which record types to query. Valid: A, AAAA, CNAME, MX, NS, TXT, SOA, CAA, SRV, PTR, DS, DNSKEY, TLSA, HTTPS, SVCB, NAPTR.",
            "default": [
              "A",
              "AAAA",
              "CNAME",
              "MX",
              "NS",
              "TXT",
              "SOA",
              "CAA"
            ],
            "items": {
              "type": "string"
            }
          },
          "dnsResolver": {
            "title": "DoH resolver",
            "enum": [
              "google",
              "cloudflare"
            ],
            "type": "string",
            "description": "Public resolver used for all DNS queries. Switch if one is rate-limiting you or to compare views.",
            "default": "google"
          },
          "includeEmailSecurity": {
            "title": "Email security (MX, SPF, DMARC, DKIM, MTA-STS, BIMI)",
            "type": "boolean",
            "description": "Parses SPF (mechanisms, includes, `all` qualifier, DNS-lookup count, issues) and DMARC (policy, pct, rua/ruf, alignment, issues), detects the mail provider from MX, probes DKIM selectors, MTA-STS and BIMI records. Adds `email`, `spfRecord`, `dmarcPolicy`.",
            "default": true
          },
          "dkimSelectors": {
            "title": "DKIM selectors to probe",
            "type": "array",
            "description": "Selectors checked at `<selector>._domainkey.<domain>` (Google Workspace = google, Microsoft 365 = selector1/selector2, Mailchimp = k1, Postmark = pm…). Max 30. Empty list = skip DKIM.",
            "default": [
              "google",
              "selector1",
              "selector2",
              "default",
              "k1",
              "mail",
              "s1",
              "dkim",
              "mandrill",
              "smtp",
              "zoho",
              "pm",
              "krs",
              "mailgun",
              "amazonses"
            ],
            "items": {
              "type": "string"
            }
          },
          "includeCerts": {
            "title": "SSL certificates (Certificate Transparency via crt.sh)",
            "type": "boolean",
            "description": "Certificate history for the domain and all its sub-domains from CT logs: issuer, names, validity, wildcard flag, plus `certificateIssuers` counts and `latestCertificate`. crt.sh is the slowest source (often 30–90 s per domain) and fails under load (then the row has `certsError`): it limits a run with every module on to about 45 domains; turn it off for big lists.",
            "default": true
          },
          "certsLimit": {
            "title": "Max certificates per domain",
            "minimum": 0,
            "maximum": 1000,
            "type": "integer",
            "description": "Newest certificates kept in `certificates` (deduplicated pre-cert/leaf pairs). `certificatesTotal` always reports the full count. 0 = counts and subdomains only.",
            "default": 50
          },
          "certsExcludeExpired": {
            "title": "Exclude expired certificates",
            "type": "boolean",
            "description": "Only currently valid certificates (crt.sh `exclude=expired`). Faster for old domains, but historic sub-domains disappear too.",
            "default": false
          },
          "includeSubdomains": {
            "title": "Discover sub-domains from certificates",
            "type": "boolean",
            "description": "Collects every hostname under the domain that ever appeared in a certificate (wildcards excluded) into `subdomains` / `subdomainsFound`. Needs `includeCerts`: with certificates off it does nothing.",
            "default": true
          },
          "subdomainsLimit": {
            "title": "Max sub-domains",
            "minimum": 0,
            "maximum": 10000,
            "type": "integer",
            "description": "Cap on the `subdomains` array (sorted alphabetically). `subdomainsFound` is the uncapped count.",
            "default": 500
          },
          "includeHttp": {
            "title": "Website probe (HTTP/HTTPS, redirects, security headers, tech)",
            "type": "boolean",
            "description": "Requests https://domain/ (falls back to http://), follows up to 6 redirects, records status, final URL, redirect chain, page title, server/powered-by, whether plain HTTP upgrades to HTTPS, grades security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy → A–F) and detects the stack (CDN, framework, CMS, tag manager). Adds `http`, `httpStatus`, `websiteTitle`, `securityGrade`, `technologies`, `finalUrl`, `missingSecurityHeaders`, `responseMs`. Never connects to private, loopback or other reserved addresses: every redirect hop is checked.",
            "default": true
          },
          "httpTimeoutSecs": {
            "title": "HTTP timeout (seconds)",
            "minimum": 3,
            "maximum": 60,
            "type": "integer",
            "description": "Timeout of each website-probe request: the HTTPS homepage with its redirects, the plain-HTTP fallback, the HTTP→HTTPS upgrade check.",
            "default": 15
          },
          "expiresWithinDays": {
            "title": "Flag `expires_soon` within (days)",
            "minimum": 1,
            "maximum": 3650,
            "type": "integer",
            "description": "Domains whose registration expires within this many days get the `expires_soon` flag (renewal / takeover monitoring).",
            "default": 30
          },
          "newlyRegisteredDays": {
            "title": "Flag `newly_registered` if younger than (days)",
            "minimum": 1,
            "maximum": 3650,
            "type": "integer",
            "description": "Young domains are a phishing / fraud signal; adjust the threshold to your policy.",
            "default": 90
          },
          "fields": {
            "title": "Output fields",
            "type": "array",
            "description": "Keep only these top-level fields, in this order, e.g. [\"registrar\", \"expiresAt\", \"flags\"]. `domain` and `fetchedAt` are always kept (first, unless you list them). Letter case is corrected; unknown names are ignored with a warning in SUMMARY.warnings (nested paths like email.provider → use the top-level `mailProvider`); a list with no known name, or only fields of switched-off modules, fails the run before any domain is looked up (only the run start is charged). Empty = full row.",
            "items": {
              "type": "string"
            }
          },
          "requestDelayMs": {
            "title": "Gap between requests to one host (ms)",
            "minimum": 0,
            "maximum": 5000,
            "type": "integer",
            "description": "Minimum gap between two requests to the same RDAP server or crt.sh. Lower values are raised to each service's published per-IP limit: crt.sh and rdap.org 1 s, registry RDAP servers 0.5 s. DNS-over-HTTPS queries are paced separately (at most 20 at a time, 100 per second). Raise it to be gentler.",
            "default": 200
          }
        }
      },
      "runsResponseSchema": {
        "type": "object",
        "properties": {
          "data": {
            "type": "object",
            "properties": {
              "id": {
                "type": "string"
              },
              "actId": {
                "type": "string"
              },
              "userId": {
                "type": "string"
              },
              "startedAt": {
                "type": "string",
                "format": "date-time",
                "example": "2025-01-08T00:00:00.000Z"
              },
              "finishedAt": {
                "type": "string",
                "format": "date-time",
                "example": "2025-01-08T00:00:00.000Z"
              },
              "status": {
                "type": "string",
                "example": "READY"
              },
              "meta": {
                "type": "object",
                "properties": {
                  "origin": {
                    "type": "string",
                    "example": "API"
                  },
                  "userAgent": {
                    "type": "string"
                  }
                }
              },
              "stats": {
                "type": "object",
                "properties": {
                  "inputBodyLen": {
                    "type": "integer",
                    "example": 2000
                  },
                  "rebootCount": {
                    "type": "integer",
                    "example": 0
                  },
                  "restartCount": {
                    "type": "integer",
                    "example": 0
                  },
                  "resurrectCount": {
                    "type": "integer",
                    "example": 0
                  },
                  "computeUnits": {
                    "type": "integer",
                    "example": 0
                  }
                }
              },
              "options": {
                "type": "object",
                "properties": {
                  "build": {
                    "type": "string",
                    "example": "latest"
                  },
                  "timeoutSecs": {
                    "type": "integer",
                    "example": 300
                  },
                  "memoryMbytes": {
                    "type": "integer",
                    "example": 1024
                  },
                  "diskMbytes": {
                    "type": "integer",
                    "example": 2048
                  }
                }
              },
              "buildId": {
                "type": "string"
              },
              "defaultKeyValueStoreId": {
                "type": "string"
              },
              "defaultDatasetId": {
                "type": "string"
              },
              "defaultRequestQueueId": {
                "type": "string"
              },
              "buildNumber": {
                "type": "string",
                "example": "1.0.0"
              },
              "containerUrl": {
                "type": "string"
              },
              "usage": {
                "type": "object",
                "properties": {
                  "ACTOR_COMPUTE_UNITS": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATASET_READS": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATASET_WRITES": {
                    "type": "integer",
                    "example": 0
                  },
                  "KEY_VALUE_STORE_READS": {
                    "type": "integer",
                    "example": 0
                  },
                  "KEY_VALUE_STORE_WRITES": {
                    "type": "integer",
                    "example": 1
                  },
                  "KEY_VALUE_STORE_LISTS": {
                    "type": "integer",
                    "example": 0
                  },
                  "REQUEST_QUEUE_READS": {
                    "type": "integer",
                    "example": 0
                  },
                  "REQUEST_QUEUE_WRITES": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATA_TRANSFER_INTERNAL_GBYTES": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATA_TRANSFER_EXTERNAL_GBYTES": {
                    "type": "integer",
                    "example": 0
                  },
                  "PROXY_RESIDENTIAL_TRANSFER_GBYTES": {
                    "type": "integer",
                    "example": 0
                  },
                  "PROXY_SERPS": {
                    "type": "integer",
                    "example": 0
                  },
                  "PROXY_UNBLOCKER_UNITS": {
                    "type": "integer",
                    "example": 0
                  }
                }
              },
              "usageTotalUsd": {
                "type": "number",
                "example": 0.00005
              },
              "usageUsd": {
                "type": "object",
                "properties": {
                  "ACTOR_COMPUTE_UNITS": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATASET_READS": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATASET_WRITES": {
                    "type": "integer",
                    "example": 0
                  },
                  "KEY_VALUE_STORE_READS": {
                    "type": "integer",
                    "example": 0
                  },
                  "KEY_VALUE_STORE_WRITES": {
                    "type": "number",
                    "example": 0.00005
                  },
                  "KEY_VALUE_STORE_LISTS": {
                    "type": "integer",
                    "example": 0
                  },
                  "REQUEST_QUEUE_READS": {
                    "type": "integer",
                    "example": 0
                  },
                  "REQUEST_QUEUE_WRITES": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATA_TRANSFER_INTERNAL_GBYTES": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATA_TRANSFER_EXTERNAL_GBYTES": {
                    "type": "integer",
                    "example": 0
                  },
                  "PROXY_RESIDENTIAL_TRANSFER_GBYTES": {
                    "type": "integer",
                    "example": 0
                  },
                  "PROXY_SERPS": {
                    "type": "integer",
                    "example": 0
                  },
                  "PROXY_UNBLOCKER_UNITS": {
                    "type": "integer",
                    "example": 0
                  }
                }
              }
            }
          }
        }
      }
    }
  }
}