CONTINUOUS INTERNET TELEMETRY24H DRIFT746 material changesacross 258 domains · last 24h · -61 vs yesterdayDNS DRIFT2 domains changed DNS providertop destination domaincontrol.comNOW464 curated domains not reachable+42 vs yesterdaySITE ERRORS17,643 sites serving errorslast probe · 5xx / 404 / TLSBOT DEFENSEbot defense observed on 100,854 sites429 rate-limit / 403 bot-block, a posture signal

~2,050,000 domains in the catalog · 335,000 re-scanned every day

Find out before your customers do

We watch your domain and tell you the moment something changes: the site stops answering, the certificate is about to expire, your mail setup moved, the registration is running out. The message reaches you in Slack, Teams, Discord, a webhook, or your inbox while there is still time to fix it.

Domains in the catalog
~2,050,000
Re-scanned every day
335,000
Every domain re-checked within
under 7 days

What you get

Five things stop being your problem. You do not have to remember to check any of them.

Your site goes down, you hear first

We try your site continuously and record whether it answered. If it stops answering, or starts answering with an error, you get a message.

Friday evening, a hosting change breaks the site, and nobody tells you until Monday’s sales are gone. Check a domain now →

Your domain never expires by surprise

We read the registration record and watch the expiry date, the registrar, and any hold the registry places on it. You get told well before the date, and again if anything about the registration changes.

The card on file at the registrar expired, the renewal notice went to an inbox nobody reads, and the domain lapses. Check an expiry date →

Visitors never hit a certificate warning

We track your certificate’s expiry date and who issued it. You get warned before it lapses, and told if the issuer changes.

The certificate expires on a Saturday and every visitor gets a full-page browser warning saying your site is not safe. Check a certificate →

Stop people sending email as your company

We check the settings that decide whether a stranger can send email that looks like it came from you. If they are missing, weak, or get changed, you find out.

A customer pays a fake invoice sent from an address with your company name on it. Check email security →

Nobody changes your setup without you knowing

We record who runs your DNS, your email, your hosting and your content delivery, and compare it every few minutes. A move, a removal, or a security setting switched off becomes an alert with the before and after attached.

An old agency still has access, edits a DNS record, and mail stops flowing two hours later with nobody able to say what changed. How monitoring works →
Free, no account, no card

Check any domain right now

8 one-question checks that give you a straight answer in a few seconds. Run one on your own domain before you decide anything.

WHOIS LookupWho owns this domain?
Domain ExpiryWhen does this domain expire?
DNS Health CheckIs this domain’s DNS healthy?
Email Security CheckCan someone fake email from this domain?
SSL Certificate CheckIs this domain’s certificate valid?
DNSSEC CheckIs this domain protected from DNS tampering?
DNS PropagationHas this domain’s DNS propagated?
Blacklist CheckIs this domain’s IP on a blocklist?

Which one are you?

The same data, pointed at a different job.

I run a small businessPut your website and email under watch in about two minutes, and get a message when something changes.
I look after clients’ domainsHold every client domain in one place, with groups, one alert feed, and a report you can send them.
I own a lot of domainsEvery expiry date, registrar and nameserver across the whole portfolio on one screen, with alerts on all of it.
I handle IT or security hereCertificates, DNSSEC, email spoofing protection and dangling records checked continuously, with a record you can show an auditor.
I am building somethingThe same data over a documented REST API, an MCP server for AI assistants, and pay-per-call for agents.
Any domain, yours or not

Look up any domain and see who runs it

Type in a domain and see who handles its DNS, email, certificates and hosting, when the registration expires, whether the site is answering, and what all of that looked like last month.

What you getWithout signing upno account, no cardFree accountno cardPaid plansee pricingAPI and agentsAPI · MCP · pay-per-call
Live domain previewOne request, no account needed: who runs the nameservers, mail and CDN, the certificate issuer and expiry date, and whether the site is answering. Without signing up: 1 request / 15s per IPFree account: The complete recordPaid plan: The complete recordAPI and agents: The complete record
The complete signed recordEvery DNS record, certificate, subdomain and probe result we hold for a domain, with its receipt. Without signing up: not includedFree account: includedPaid plan: includedAPI and agents: included
Time machineA durable, shareable URL for a domain at a point in time. The latest snapshot is public and free. Without signing up: Latest snapshotFree account: Full historyPaid plan: Full historyAPI and agents: Full history
Receipt verificationResolve any receipt by id and check the signature yourself. Published signing keys, verifiable offline. Without signing up: includedFree account: includedPaid plan: includedAPI and agents: included
Published signing keysThe public keys every receipt is signed with, at a well-known URL, so verification never depends on asking us. Without signing up: includedFree account: includedPaid plan: includedAPI and agents: included
Published every day, free to read

What changed on the internet today

Every day we publish what actually moved across the domains we check: who switched providers, which companies are gaining and losing customers, what went dark, and where security settings are getting better or worse.

What you getWithout signing upno account, no cardFree accountno cardPaid plansee pricingAPI and agentsAPI · MCP · pay-per-call
What changed todayThe day in seven readings: DNS, email and certificate movement, plus who is unreachable, erroring, or blocking scanners. Without signing up: includedFree account: includedPaid plan: includedAPI and agents: JSON + RSS
Provider migrationsWho gained and who lost, drawn as flows. Net, not gross: a provider that gained 40 and lost 38 churned, and the page says so. Without signing up: includedFree account: includedPaid plan: includedAPI and agents: included
Provider concentrationWho answers for the internet: standing share per lane, and how few providers it takes to cover half of it. Without signing up: includedFree account: includedPaid plan: includedAPI and agents: included
ReachabilityWhat is not reachable, what answered with an error, and what is blocking our scanner, with the composition behind each. Without signing up: includedFree account: includedPaid plan: includedAPI and agents: included
Security postureCertificate expiry, email authentication (SPF, DMARC, DKIM, MTA-STS), DNSSEC and dangling-CNAME exposure across the index. Without signing up: includedFree account: includedPaid plan: includedAPI and agents: included
The provider mapThe index drawn by who runs what, so concentration is something you can see rather than read. Without signing up: includedFree account: includedPaid plan: includedAPI and agents: included
Provider leaderboardsThe standing board per provider: who they serve, and what moved this week. Without signing up: Top 3 + the true totalFree account: includedPaid plan: includedAPI and agents: included
Catalog browsing and searchEvery tracked domain by category, service, and certificate authority, searchable by name, IP, provider, registrar or ASN. Without signing up: Top 3 + the true totalFree account: includedPaid plan: includedAPI and agents: included
Live change streamServer-sent events: changes, scans and receipts as they happen, plus a JSON fallback. Without signing up: JSON + RSS feedsFree account: includedPaid plan: includedAPI and agents: included
The part you set up once

Watch your own domains

Add a domain and we re-check it every five minutes, then send you a message in Slack, Teams, Discord, email or anywhere that takes a webhook the moment something material changes.

What you getWithout signing upno account, no cardFree accountno cardPaid plansee pricingAPI and agentsAPI · MCP · pay-per-call
Domain monitoringYour domains on the 5-minute watch lane, with the full signed record kept for each check. Without signing up: not includedFree account: Your first domainPaid plan: More domains, every plan raises itAPI and agents: not included
Change alertsWebhooks into Slack, Teams, Discord or anything that takes a POST, signed with an HMAC so you can verify the sender. Without signing up: not includedFree account: includedPaid plan: Higher subscription capsAPI and agents: not included
Certificate watchKnow before a certificate expires, and the moment the issuing authority changes on a domain you own. Without signing up: not includedFree account: includedPaid plan: includedAPI and agents: not included
Domain groupsManage and alert on a portfolio as one unit rather than domain by domain. Without signing up: not includedFree account: not includedPaid plan: includedAPI and agents: not included
Approved baselinesSign off a known-good record. From then on, anything that drifts from it is flagged until you approve the new state. Without signing up: not includedFree account: not includedPaid plan: includedAPI and agents: not included
Status badgeAn embeddable badge for a domain you monitor, served straight from the signed record. Without signing up: includedFree account: includedPaid plan: includedAPI and agents: included
For the day someone asks

Get it in writing

Download any domain record as a report you can print, send to a client, attach to an insurance or compliance form, or keep for the day someone asks what your setup looked like on a specific date.

What you getWithout signing upno account, no cardFree accountno cardPaid plansee pricingAPI and agentsAPI · MCP · pay-per-call
Signed evidence bundlesA complete, portable record for a domain with every receipt attached, verifiable offline after we are out of the loop. Without signing up: not includedFree account: includedPaid plan: includedAPI and agents: Account keys only
Printable evidence reportThe same record as a report you can print or hand over, formatted for a human reader. Without signing up: not includedFree account: includedPaid plan: includedAPI and agents: not included
CSV exportThe same filtered set you are looking at, as a download, for a spreadsheet or a warehouse. Without signing up: not includedFree account: includedPaid plan: includedAPI and agents: included
Offline verificationThe published verifier and key set, so anyone can check a bundle without an account or a network call to us. Without signing up: includedFree account: includedPaid plan: includedAPI and agents: included
If you are building something

Use this data in your own tools

Everything on this site is available over a documented REST API, through an MCP server so an AI assistant can look domains up for you, and pay-per-call for agents that would rather settle one request than hold an account.

What you getWithout signing upno account, no cardFree accountno cardPaid plansee pricingAPI and agentsAPI · MCP · pay-per-call
The metered REST APIOne documented door for everything on this page, with OpenAPI 3.1 and a live playground. Without signing up: Keyless preview endpointFree account: A free key, daily allowancePaid plan: More volume every dayAPI and agents: included
MCP serverConnect an AI assistant directly: the same tools, the same keys, the same pay gate as the API. Without signing up: not includedFree account: includedPaid plan: includedAPI and agents: included
x402 pay-per-callFor an agent that would rather settle one request than hold an account: call with no key, get a price, pay on Base, retry. Without signing up: Settle per requestFree account: not includedPaid plan: not includedAPI and agents: included
Machine-readable discoveryllms.txt, OpenAPI, a domain sitemap and well-known key endpoints, so a crawler or agent can find the shape on its own. Without signing up: includedFree account: includedPaid plan: includedAPI and agents: included
API playgroundRun a real request against the live API from the browser, before you write any code. Without signing up: includedFree account: includedPaid plan: includedAPI and agents: included
No account at any point

Free checks, no signup

8 single-answer tools for the questions people actually search: one domain in, one clear verdict out. Free, bookmarkable, and no account at any point.

What you getWithout signing upno account, no cardFree accountno cardPaid plansee pricingAPI and agentsAPI · MCP · pay-per-call
WHOIS LookupWho owns this domain? Without signing up: includedFree account: includedPaid plan: includedAPI and agents: In the record
Domain ExpiryWhen does this domain expire? Without signing up: includedFree account: includedPaid plan: includedAPI and agents: In the record
DNS Health CheckIs this domain’s DNS healthy? Without signing up: includedFree account: includedPaid plan: includedAPI and agents: In the record
Email Security CheckCan someone fake email from this domain? Without signing up: includedFree account: includedPaid plan: includedAPI and agents: In the record
SSL Certificate CheckIs this domain’s certificate valid? Without signing up: includedFree account: includedPaid plan: includedAPI and agents: In the record
DNSSEC CheckIs this domain protected from DNS tampering? Without signing up: includedFree account: includedPaid plan: includedAPI and agents: In the record
DNS PropagationHas this domain’s DNS propagated? Without signing up: includedFree account: includedPaid plan: includedAPI and agents: In the record
Blacklist CheckIs this domain’s IP on a blocklist? Without signing up: includedFree account: includedPaid plan: includedAPI and agents: In the record
The part that matters when someone asks

Every reading is signed the moment we take it

Each observation is Ed25519-signed at capture and chained to the one before it, so the record is tamper-evident end to end: a single reading proves it came from DomainDrift and was not altered afterwards, and the chain proves none were quietly inserted or dropped. A record you download carries its receipts, so anyone can verify it offline against our published keys, with no account and without asking us.

This is attribution and integrity, not a claim that we got the reading right - a signature can sit on a wrong observation. What it buys you is accountability: if we ever record something wrong, the signature is exactly what lets you prove we said it, and when, and hold the record to it.

Check any receipt yourselfResolve a receipt by id and verify the signature.
Our keys are publishedAt a fixed address, so checking never depends on asking us.
Download the whole recordEvery receipt attached, verifiable offline with no account.
A straight answer, sometimes to a different tool

Which do I actually need?

Pick the line that sounds like you. Some of these send you somewhere else first, and say so. That candor is the point: the tool that admits where it does not fit is the one worth trusting where it does.

Start with your registrar dashboard

Your registrar dashboard, with auto-renew on and the billing card current. That is the direct fix and it costs nothing extra. Come here when the portfolio is spread across several registrars and you want expiry, certificates and DNSSEC in one place, plus an alert if a nameserver quietly moves.

Start with uptime monitoring

Uptime monitoring with proper on-call routing. Detection speed and escalation are that category’s engineering, and a five-minute watch is not a substitute. Run this beside it to answer the question that follows the page: what changed underneath just before it stopped answering.

Start with passive DNS and a threat feed

Passive DNS history plus a threat intelligence feed. Depth of archive and analyst verdicts are what that work needs, and a record that starts at our start date does not reach back a decade. We are useful in that investigation for the current picture and for producing a citable artifact.

Start with attack surface discovery

Attack surface discovery first. Finding unknown assets is its own discipline and it should come before any watch list is drawn. Once the inventory exists, this is the layer that keeps watching it.

this is the tool for it

This, as an export that verifies offline against published keys, with the honest caveat that the record starts when we started watching. For certificate issuance before that date, the public transparency logs are an independent and equally checkable source.

Start with your own domain

Check any domain right now with no account. A free account puts your first domain under watch, keeps its history, and alerts you the moment something changes.