Survey

Which domain and DNS monitoring tools cryptographically sign their scan results?

A direct question with a short answer, surveyed against public documentation on 11 August 2026. If this page is wrong about your product, write to inquiries@drm3.io and it will be corrected within a week.

Where signing already exists

Certificate Transparency is the strongest working proof that signed, independently checkable internet facts scale: append-only Merkle-tree logs that anyone can obtain inclusion and consistency proofs from. Its scope is one fact type, certificate issuance, and it is infrastructure run by certificate authorities and browsers rather than a monitoring product.

zkTLS projects (TLSNotary, Reclaim Protocol, zkPass) can turn an HTTPS session into a proof that data really came from a site. The proof is scoped to one user's own live session, made on demand; there is no continuous scanning and no standing record.

What the survey did not find

Across the public documentation of fifteen domain-intelligence, DNS-history, attack-surface and certificate-tooling vendors reviewed for this survey, we did not find a published mechanism that signs each scan observation at the moment of capture in a form a third party can verify against published keys, offline, without an account. That is a statement about what was published on the day of the survey, never about anyone's roadmap, and the correction offer above is standing. The vendors we know best each have their own page here, which says what each is genuinely good at.

What DomainDrift does

Every reading of ~2,051,000 domains is Ed25519-signed the moment it is taken, under per-plane keys published at a well-known address, and each 15-minute window of receipts is anchored on a public chain. A receipt can be exported and checked by whoever you hand it to, and the anchor dates it independently: when a reading existed is checkable without asking us.

A signature proves who recorded a reading and that it has not been altered since. It does not prove the reading is correct. What it adds is accountability and permanence: a reading, once taken, is never edited, and anyone can hold us to that.

How the survey was run

The criterion: a published, product-level mechanism producing a per-observation cryptographic signature at capture time that a third party can verify independently. We reviewed the public documentation and product pages of fifteen vendors across domain intelligence, DNS history, attack-surface monitoring and certificate tooling on 11 August 2026. Two families met the criterion, both named above and both scoped more narrowly than whole-surface domain telemetry: Certificate Transparency for certificate issuance, and zkTLS session proofs.

Product names on this page are trademarks of their respective owners, used only to identify those products. DomainDrift is not affiliated with, endorsed by, or sponsored by any of them.

CONTINUOUS INTERNET TELEMETRY24H DRIFT38,179 material changesacross 36,363 domains · 24h to ~2h ago · -1,061 vs yesterdayROTATION56 domains moved DNS from magpiedns.com to koaladns.com, 55 moved backa rotation loop, not a migration · 24hEMAIL DRIFT7 domains switched email providertop destination alltheemails.comNOW529 curated domains not reachable-62 vs yesterdaySITE ERRORS34,005 sites serving errorslast probe · 5xx / 404 / TLSBOT DEFENSEbot defense observed on 116,663 sites429 rate-limit / 403 bot-block, a posture signal