The DomainDrift blog

Cisco Umbrella's legacy APIs are ending. Watching domain and DNS change, signed.

Legacy Umbrella APIs and offers reached end of life through 2023 and 2024. For the domain and DNS watch, a signed record.

2026-08-16

Cisco has retired a series of legacy Umbrella pieces on a rolling schedule: the legacy Umbrella APIs reached end of life on 1 September 2023, the roaming client on 2 April 2024, and several legacy offers and virtual-appliance versions through 2024. Teams built on the older surfaces have been given migration deadlines. (Source: Cisco Umbrella end-of-sale and end-of-life notices, 2023 and 2024.)

The piece that is easy to lose in a migration

Among the things people pulled from Umbrella Investigate was passive-DNS and domain history: what a domain resolved to over time, and how its records moved. When an API you built on is retired, that continuity is exactly what a migration puts at risk.

A record that is built to be checked

DomainDrift continuously reads the public surface of a domain and keeps a dated record of every change to its DNS, certificates, mail and hosting. It stays in one lane: the observation and the record, alongside whatever enforcement you already run. Every reading is signed at the moment of capture and dated on a public chain, so the history is one a third party can verify, offline, without an account.

A signature proves who took a reading and that it has not changed; the chain anchor proves when it existed. Correctness stays a separate question you check yourself, against keys we publish. Signing is added trust. See how to verify.

If the part you cared about was seeing domain and DNS change and holding a provable history of it, that is what DomainDrift keeps.

Type any company at domaindrift.io and watch its domain get read apart, signed and dated. Looking is free; keeping the record is an account.

← All posts