The DomainDrift blog
How to watch a vendor’s domain posture without asking the vendor for anything.
You do not need a vendor’s cooperation to watch their public infrastructure change. Here is how, and how to prove it.
2026-08-16
A vendor's infrastructure is part of your risk, and it moves without telling you. A certificate lapses, mail moves to a new provider, a nameserver changes at the registrar. You rarely hear about any of it, and by the time an assessment comes around, the moment has passed.
The public surface is enough
Everything you need to watch a vendor's domain posture is public: DNS records, certificate transparency logs, registry records, and a reachability probe. None of it needs the vendor's cooperation, a login on their side, or software installed anywhere. That is why a watch can reach domains you do not control and start a record before you ever raise a question.
Turn the reading into a record
Reading the surface is the easy half. The half that matters for vendor risk is the record: a dated, signed history you can put in front of a vendor, an auditor, or an insurer. DomainDrift signs every reading at capture and dates it on a public chain, so "the vendor's cert was expiring three weeks before the outage" is a receipt you can produce on the day it matters.
A signature proves who took a reading and that it has not changed; the chain anchor proves when it existed. Correctness stays a separate question you check yourself, against keys we publish. Signing is added trust. See how to verify.
Put a vendor's domains under watch and you get the change the day it happens, plus a history that predates the question. Group your vendors, and one feed covers the estate.
Type any company at domaindrift.io and watch its domain get read apart, signed and dated. Looking is free; keeping the record is an account.