Acceptable Use Policy - DomainDrift

DRM3 Labs Corp. · Version 1.0 · Effective July 20, 2026

DomainDrift reports on infrastructure that is already public: DNS records, TLS

certificates, RDAP and WHOIS registration data, and how a domain answers on the

open internet. Collecting it in one place, keeping its history, and detecting

change quickly makes defensive work much easier. It makes some offensive work

easier too. This policy is where we draw that line, and it binds anyone using

the service through any door: the web app, the API, an API key, a webhook, or a

per-request x402 payment.

Paying does not create an exception. An x402 payment buys a request that this

policy already permits; it does not buy a request this policy forbids, and it

does not lift a suspension.

What DomainDrift will not do

So you know where our own limits are:

  • We scan from published, identifiable infrastructure with a descriptive user

agent. We do not disguise our scanner or rotate identity to get around

someone's blocking.

  • We do not access private networks, authenticated content, or anything behind

a login or a technical control.

  • We honour `429` and `403` with backoff, and we do not work around a block.
  • When a domain owner opts out, the domain is deactivated and stays that way.

Prohibited uses

You may not use DomainDrift, its data, or its API to:

Attack or intrude

  • Facilitate unauthorised access to any system, network, or account.
  • Develop, stage, or deliver exploits, malware, ransomware, or command and

control infrastructure.

  • Conduct credential attacks, including stuffing, spraying, and brute force.
  • Evade, defeat, or map out access controls, rate limits, WAFs, bot management,

or other security measures.

  • Impair availability of any system, including denial of service and any use

that degrades a third party's infrastructure.

Deceive

  • Build, register, or operate phishing, spoofing, impersonation, or fraud

infrastructure, including using our change data to identify expiring domains,

dangling delegations, or weakened email authentication for takeover.

  • Misrepresent a DomainDrift observation, receipt, or signature, including

presenting an altered record as ours or implying we have verified something we

have not.

Target people

  • Harass, stalk, threaten, dox, or surveil any individual.
  • Compile profiles of natural persons, or combine our data with other sources to

identify or locate individuals.

  • Target anyone based on a protected characteristic, or target journalists,

activists, dissidents, or other at-risk people.

  • Use registration contact data for unlawful profiling, or in a way that

violates applicable data protection law.

Abuse the service

  • Circumvent rate limits, allowances, or entitlements, including rotating IP

addresses, accounts, keys, or payment identities to exceed them.

  • Systematically extract the catalog, or resell, redistribute, or sublicense

bulk data except under a written agreement that permits it.

  • Register a webhook you do not control, or use webhook delivery to send traffic

to a third party.

  • Use the service to scan, probe, or route requests at infrastructure you are

not authorised to test.

Break the law

  • Violate any applicable law, sanction, or export control.
  • Infringe intellectual property or contractual rights.

What is expressly allowed

We do not want this policy to chill the work the product exists for:

  • Monitoring your own infrastructure, or infrastructure you are authorised to

monitor.

  • Third-party and vendor risk assessment, supply-chain analysis, and due

diligence.

  • Incident response, threat intelligence, brand protection, and anti-phishing

work.

  • Security research and vulnerability disclosure conducted in good faith. See

our disclosure policy.

  • Journalism, academic research, and public-interest analysis.
  • Building products on our API under the terms of your plan.

If your use is defensive and lawful but you are unsure whether it fits, ask us

first at support@drm3.io. We would rather answer the question than suspend you.

How we enforce this

This policy is not only contract language. It drives the controls:

  • Rate limits, per-account allowances, and burst ceilings on every door.
  • Anomaly detection on usage patterns that look like extraction.
  • Webhook destinations resolved and checked against private address space on

every delivery.

  • Key and payment-identity revocation.
  • Human review of reports and of flagged accounts.

We may investigate suspected violations and may suspend or terminate access. For

a clear, severe, or ongoing violation, or where suspension is needed to protect

someone, we may act immediately and without notice. Otherwise we will normally

contact you first.

Appeals. If we suspend you and you believe we are wrong, write to

support@drm3.io. A human will review it, and we will tell you the outcome and

the reason.

Reporting abuse. To report misuse of DomainDrift, write to support@drm3.io.

To report a security vulnerability, use

our disclosure policy. To have a domain you

control removed from scanning, use

the opt-out form.

Changes

We will post a new version here with a new effective date. Continued use after

the effective date means the new version applies.

This policy supplements the DomainDrift Terms of Use

and the general DRM3 Terms.

Where they conflict on acceptable use, the stricter reading applies.

Reporting a vulnerability? Scope, safe harbour and what we commit to are on the security policy. This page supplements the general DRM3 Terms of Use and Privacy Policy. Questions: legal@drm3.io.
CONTINUOUS INTERNET TELEMETRY24H DRIFT29,879 material changesacross 23,492 domains · 24h to ~4h agoROTATION61 domains moved DNS from koaladns.com to magpiedns.com, 55 moved backa rotation loop, not a migration · 24hCERT DRIFT1 domains switched issuing CA24hREGISTRAR DRIFT3 changed registrar24hNOW610 curated domains not reachablelast probe, steadySITE ERRORS17,392 sites serving errorslast probe · 5xx / 404 / TLSBOT DEFENSEbot defense observed on 79,534 sites429 rate-limit / 403 bot-block, a posture signal