~2,051,000 domains tracked · one independent record of how the web is run
Know what your domain runs on, and when it moves
You get who runs its DNS, mail and hosting, its certificate issuer and expiry dates, and whether it is answering right now.
We watch your domain and tell you the moment we see it change: the site stops answering, the certificate is about to expire, your mail setup moved, the registration is running out.
familymobile.com moved its nameservers 13 minutes ago
Graded from our last HTTPS probe of the home page, not this second: OK answered, WARN answered but refused us, ERROR did not answer.
What you get
Five things stop being your problem. You do not have to remember to check any of them.
Your site goes down, you hear first
A hosting change breaks the site on a Friday evening, and you are the first to know, in time to fix it before Monday. Check a domain now →Your domain never expires by surprise
The registrar’s renewal notice goes to an inbox nobody reads; you get a clear heads-up in good time and keep the name. Check an expiry date →Visitors never hit a certificate warning
A certificate heading for a Saturday expiry gets flagged days early, so every visitor keeps landing on the padlock. Check a certificate →Stop people sending email as your company
You spot the mail setting that would let someone else send as your company, and close it before anyone tries. Check email security →Nobody changes your setup without you knowing
An old vendor still has access and edits a DNS record; you see the before and after within minutes and can put it back. How monitoring works →41,982 changes across 40,107 domains, in the last 24 hours
That is 2.0% of 1,983,403 probed curated domains.
- security-benefit.com Started blocking our probe: HTTP 200 → HTTP 403 2 hours ago
- campuspress.com Mail now handled by google.com googlemail.comgoogle.com 3 hours ago
- skyscanner.es Nameservers moved: ns-1333.awsdns-38.org, ns-1615.awsdns-09.co.uk, ns-68.awsdn… → ns-1501.awsdns-59.org, ns-1999.awsdns-57.co.uk, ns-278.awsd… 2 hours ago
- bundesregierung.de Site went down: HTTP 200 → HTTP 400 3 hours ago
- popular.com Started blocking our probe: HTTP 200 → HTTP 403 3 hours ago
What it does
Each is a door into the same signed record. Open any of them.
- Look up any domain and see who runs it Type in a domain and see who handles its DNS, email, certificates and hosting, when the registration expires, whether the site is answering, and what all of that looked like last month.
- What changed on the internet today Every day we publish what actually moved across the domains we check: who switched providers, which companies are gaining and losing customers, what went dark, and where security settings are getting better or worse.
- Watch your own domains Add a domain and we re-check it as often as every 5 minutes, then send you a message in Slack, Teams, Discord, email or anywhere that takes a webhook as soon as we see something material change.
- Get it in writing Download any domain record as a report you can print, send to a client, attach to an insurance or compliance form, or keep for the day someone asks what your setup looked like on a specific date.
- Use this data in your own tools Everything on this site is available over a documented REST API, through an MCP server so an AI assistant can look domains up for you, and pay-per-call for agents that would rather settle one request than hold an account.
What a paid plan gets you
Everything above answers what a domain is running and whether it moved. A paid plan is for when the answer has to hold up: more than one domain, alerts routed to the people who fix things, a state you signed off on, and a file you can hand to somebody who is going to check it.
Domain monitoring
A whole estate, every plan raises itA registered account proves the thing works on the names you care most about. An agency book, a vendor list, or a defensive portfolio runs to dozens, and each of them breaks on its own schedule.
Change alerts
Higher subscription capsEnough subscriptions to route by who fixes what: certificates to the engineers, registration and billing to whoever holds the card, everything on one client to the person who owns that client.
Domain groups
Paid plan onlyA portfolio is not a list. Group by client, by brand or by environment and you get one alert feed and one report per group, instead of doing the same setup once per domain and reconciling it by hand.
Approved baselines
Paid plan onlyYou decide once what correct looks like. After that a drift is not just news, it is an exception that stays open until a human closes it. That is the difference between watching changes and controlling them.
Signed evidence bundles
Pro and up, with a monthly allowanceThe day a client, an auditor or an insurer asks what your setup looked like on a date, you send one file that answers it and carries its own proof. It still verifies after we are out of the loop.
The metered REST API
More volume every dayEnough volume every day to put this behind your own dashboard, your own runbook or your own agent, and stop rationing calls against an allowance sized for trying it out.
If the registered allowance covers your names and the daily boards answer your questions, you are already using the product as intended and there is nothing here you need.
See what plans cost →Every reading is signed the moment we take it
Each observation is Ed25519-signed at capture and chained to the one before it. A single reading proves it came from DomainDrift and was not altered afterwards; the chain proves none were quietly inserted or dropped. A record you download carries its receipts, so anyone can verify it offline against our published keys, with no account.
This is attribution and integrity, not a claim that we got the reading right - a signature can sit on a wrong observation. What it buys you is accountability: if we ever record something wrong, the signature is exactly what lets you prove we said it, and when, and hold the record to it.
Which do I actually need?
Pick the line that sounds like you. Some of these send you somewhere else first, and say so. That candor is the point: the tool that admits where it does not fit is the one worth trusting where it does.
Your registrar dashboard, with auto-renew on and the billing card current. That is the direct fix and it costs nothing extra. Come here when the portfolio is spread across several registrars and you want expiry, certificates and DNSSEC in one place, plus an alert if a nameserver quietly moves.
Uptime monitoring with proper on-call routing. Detection speed and escalation are that category’s engineering, and a five-minute watch is not a substitute. Run this beside it to answer the question that follows the page: what changed underneath just before it stopped answering.
Passive DNS history plus a threat intelligence feed. Depth of archive and analyst verdicts are what that work needs, and a record that starts at our start date does not reach back a decade. We are useful in that investigation for the current picture and for producing a citable artifact.
Attack surface discovery first. Finding unknown assets is its own discipline and it should come before any watch list is drawn. Once the inventory exists, this is the layer that keeps watching it.
This, as an export that verifies offline against published keys, with the caveat that the record starts when we started watching. For certificate issuance before that date, the public transparency logs are an independent and equally checkable source.
Start with your own domain
Check any domain right now with no account. A DRM3 account puts your first domain under watch, keeps its history, and alerts you the moment something changes.