CONTINUOUS INTERNET TELEMETRY24H DRIFT7,286 material changesacross 6,972 domains · +6,377 vs yesterdayDNS DRIFT493 domains changed DNS providertop destination parity.domains · +467 vs yesterdayEMAIL DRIFT96 domains switched email providertop destination google.com · +88 vs yesterdayCERT DRIFT166 domains switched issuing CA24h · +143 vs yesterdayNOW1,702 curated domains not answering-1,008 vs yesterdayERRORS20,841 responded with an errorlast probe · 5xx / 404 / TLSTHROTTLED92,977 throttled or blocked our scanner429 rate-limit / 403 bot-block

DomainDrift for auditors and assurance teams

Posture on a date, with evidence you can check yourself.

An attestation is only as good as your ability to re-check it. Every DomainDrift observation is signed when it is made and committed to by a receipt: the hash of the observed data, the signature, and the public key that produced it. The keys are published, the receipts are public, and the verifier runs in your browser. Below is not a sample: it is the latest signed observation on the record right now.

The latest signed observation, live

Pulled from the record as this page was built. Any receipt resolves the same way.

lawfuel.com
observed2026-07-22T14:18:47.999124266+00:00
planefast
receiptrcpt_411c68b311d24b04
output hashsha256:d87f82410…
6,958,513scan observations recordedeach signed at the moment of observation

Verify it yourself, offline

Three steps, none of which require an account or this site being reachable.

  1. Pull the receipt. Resolve any receipt id at /receipts/<id>, or export a domain's signed evidence bundle. A receipt commits to the observed bytes: an output hash, an Ed25519 signature, and the public key that produced it.
  2. Check the key. The signing keys are published at /.well-known/domaindrift-keys.json with their validity windows, so you can confirm the key was DomainDrift's and was valid when the observation was made.
  3. Run the verifier. The open-source drm3-provenance verifier (@drm3/sdk on npm) checks the signature and, where the signed payload is archived, that the payload hashes to the receipt's output hash. The browser verifier runs the same checks and works offline once loaded.

A signature proves who made an observation and that it has not been altered since. It does not, on its own, make the observation correct. It is added accountability: attribution and integrity you can check, permanently on the record.

Three steps in

1 · Try it, no account
curl https://domaindrift.io/connor/v1/domains/example.com

One keyless request every 15 seconds per IP, for any domain in the catalog. It returns a reduced preview record with a receipt pointer you can resolve right away.

2 · Free account

Opens the complete signed record and every list in full, puts one of your own domains under watch, and adds signed webhook alerts. 60 API requests a day, refreshed at midnight UTC.

Start free →
3 · When you outgrow free

Business unlocks signed evidence-bundle exports and point-in-time history across the estates you audit.

Prices load live from the offer catalog; a tier that is not on sale yet says so. Full pricing →