Acceptable Use Policy - DomainDrift
DomainDrift reports on infrastructure that is already public: DNS records, TLS
certificates, RDAP and WHOIS registration data, and how a domain answers on the
open internet. Collecting it in one place, keeping its history, and detecting
change quickly makes defensive work much easier. It makes some offensive work
easier too. This policy is where we draw that line, and it binds anyone using
the service through any door: the web app, the API, an API key, a webhook, or a
per-request x402 payment.
Paying does not create an exception. An x402 payment buys a request that this
policy already permits; it does not buy a request this policy forbids, and it
does not lift a suspension.
What DomainDrift will not do
So you know where our own limits are:
- We scan from published, identifiable infrastructure with a descriptive user
agent. We do not disguise our scanner or rotate identity to get around
someone's blocking.
- We do not access private networks, authenticated content, or anything behind
a login or a technical control.
- We honour `429` and `403` with backoff, and we do not work around a block.
- When a domain owner opts out, the domain is deactivated and stays that way.
Prohibited uses
You may not use DomainDrift, its data, or its API to:
Attack or intrude
- Facilitate unauthorised access to any system, network, or account.
- Develop, stage, or deliver exploits, malware, ransomware, or command and
control infrastructure.
- Conduct credential attacks, including stuffing, spraying, and brute force.
- Evade, defeat, or map out access controls, rate limits, WAFs, bot management,
or other security measures.
- Impair availability of any system, including denial of service and any use
that degrades a third party's infrastructure.
Deceive
- Build, register, or operate phishing, spoofing, impersonation, or fraud
infrastructure, including using our change data to identify expiring domains,
dangling delegations, or weakened email authentication for takeover.
- Misrepresent a DomainDrift observation, receipt, or signature, including
presenting an altered record as ours or implying we have verified something we
have not.
Target people
- Harass, stalk, threaten, dox, or surveil any individual.
- Compile profiles of natural persons, or combine our data with other sources to
identify or locate individuals.
- Target anyone based on a protected characteristic, or target journalists,
activists, dissidents, or other at-risk people.
- Use registration contact data for unlawful profiling, or in a way that
violates applicable data protection law.
Abuse the service
- Circumvent rate limits, allowances, or entitlements, including rotating IP
addresses, accounts, keys, or payment identities to exceed them.
- Systematically extract the catalog, or resell, redistribute, or sublicense
bulk data except under a written agreement that permits it.
- Register a webhook you do not control, or use webhook delivery to send traffic
to a third party.
- Use the service to scan, probe, or route requests at infrastructure you are
not authorised to test.
Break the law
- Violate any applicable law, sanction, or export control.
- Infringe intellectual property or contractual rights.
What is expressly allowed
We do not want this policy to chill the work the product exists for:
- Monitoring your own infrastructure, or infrastructure you are authorised to
monitor.
- Third-party and vendor risk assessment, supply-chain analysis, and due
diligence.
- Incident response, threat intelligence, brand protection, and anti-phishing
work.
- Security research and vulnerability disclosure conducted in good faith. See
our disclosure policy.
- Journalism, academic research, and public-interest analysis.
- Building products on our API under the terms of your plan.
If your use is defensive and lawful but you are unsure whether it fits, ask us
first at support@drm3.io. We would rather answer the question than suspend you.
How we enforce this
This policy is not only contract language. It drives the controls:
- Rate limits, per-account allowances, and burst ceilings on every door.
- Anomaly detection on usage patterns that look like extraction.
- Webhook destinations resolved and checked against private address space on
every delivery.
- Key and payment-identity revocation.
- Human review of reports and of flagged accounts.
We may investigate suspected violations and may suspend or terminate access. For
a clear, severe, or ongoing violation, or where suspension is needed to protect
someone, we may act immediately and without notice. Otherwise we will normally
contact you first.
Appeals. If we suspend you and you believe we are wrong, write to
support@drm3.io. A human will review it, and we will tell you the outcome and
the reason.
Reporting abuse. To report misuse of DomainDrift, write to support@drm3.io.
To report a security vulnerability, use
our disclosure policy. To have a domain you
control removed from scanning, use
Changes
We will post a new version here with a new effective date. Continued use after
the effective date means the new version applies.
This policy supplements the DomainDrift Terms of Use
and the general DRM3 Terms.
Where they conflict on acceptable use, the stricter reading applies.