CONTINUOUS INTERNET TELEMETRY24H DRIFT3,765 material changesacross 3,405 domains · last 24h · +1,849 vs yesterdayDNS DRIFT55 domains changed DNS providertop destination cloudflare.com · +25 vs yesterdayEMAIL DRIFT11 domains switched email providertop destination google.comCERT DRIFT20 domains switched issuing CA24hNOW553 curated domains not reachable+74 vs yesterdaySITE ERRORS29,202 sites serving errorslast probe · 5xx / 404 / TLSBOT DEFENSEbot defense observed on 138,679 sites429 rate-limit / 403 bot-block, a posture signal

For Brand & Fraud · Faster Takedowns, Evidence That Holds

The lookalike,
caught on the record.

878,111 lookalike domains were registered to attack brands in 2024 (Interisle). The return: a takedown that lands faster, on a dated record captured while the site was live. Honest status: reliable attack-time capture of a brand-new lookalike lands as the fast-scan lane ships.

~2,050,000 domains under continuous signed watch Signed the moment it is observed Anchored daily to Base
What backs every line on this page

One working artifact: the signed evidence report.

Every reading DomainDrift takes is signed the moment it is observed and travels as a dated evidence report you can hand over: state, providers, registrar, expiry, email authentication, DNSSEC and subdomains, per domain, on one page. The recipient re-checks every reading themselves in the public verifier, with no account, years later. That artifact is the same on every page here. The persona only changes which part of it you foreground, on the same $10 / $29 / $99 ladder.

The return

The math, before the feature.

The return is a takedown that lands faster and holds when the case escalates. With roughly 989,000 phishing attacks in Q4 2024 alone (APWG), the hard part is rarely spotting the lookalike; it is proving what it was after its DNS and certificate have moved. DomainDrift watches the domains you name and keeps a dated, signed record of each one as it changes, so what the site looked like while it was live is already on file when you file the report.

Captured
Kept while it was live

a watched domain’s DNS, mail, and certificate on the record as they change, so the evidence exists before the site rotates its infrastructure and a screenshot would go stale.

It holds up
When the case escalates

every record is dated and checkable, so the abuse report, the ICANN complaint, and the court filing rest on evidence the registrar cannot wave off as a doctored image.

Honest status
Fast-scan is shipping

for a domain already under watch, changes are captured today. Reliable capture of a brand-new lookalike the moment it goes live lands as the fast-scan lane ships. We frame it as coming, not as live.

A day in the life

Capture the lookalike before its infrastructure rotates.

10:02

A lookalike of your domain goes live, harvesting customer logins. You screenshot it.

By noon

The registrar asks for proof. The site has already rotated its DNS and swapped its certificate; your screenshot is stale.

Under watch

Because the domain was under watch, DomainDrift already kept a dated record of its DNS, mail, and certificate from while it was live. The takedown, the ICANN complaint, and the court filing hold.

Your desk, real captures

The genuine brand, on the record

A brand-protection watch group for PayPal: the genuine paypal.com up as the baseline, beside lookalike spellings on the watchlist, most not reachable at last probe, each row a signed observation.
A brand-protection watch group. The genuine paypal.com, up on Fastly, is the baseline here. Not an attacker: the lookalike spellings on the watchlist (paypa1.com, paypal-account.com, paypal-secure.com, paypall.com, secure-paypal.com) are what it is measured against, most not reachable at last probe, each row a signed observation with its own receipt. Captured July 25, 2026.
What you actually get

The product, pointed at your desk.

The real brand, on the record

Protection starts from the genuine brand itself, read from the outside and put on the record, so you have a baseline to measure a lookalike against: the real brand’s IPs, mail, and certificate, plus who is allowed to send email as it. A fraudulent copy gives itself away by how far its record drifts from the genuine one. The genuine domain is the yardstick, never the fraud.

A copy is caught by how far its record drifts from the genuine brand’s reading.

Watch the marks, hear the change

Group your marks and known lookalikes and get told the moment one changes, over a signed webhook. Every record is dated and checkable, so what a watched site looked like while it was live is already on file, and a registrar or a court can open and verify it in their own browser after the site is gone.

The honest status, said plainly

For a domain already under watch, changes are captured today. The fast lane that makes capture of a brand-new lookalike reliable the moment it goes live is in progress; we frame it as coming, not as live. A dated reading kept while a site was live can be added to, never recreated after the site rotates.

How it works
1Look one up free

Read any domain from the outside, dated and signed, with no account.

2Watch the marks

Group your marks and known lookalikes; a free account watches one, paid plans the watchlist.

3Take the bundle

Pull a domain’s dated record as a bundle a registrar or a court can open and verify.

The market
878,111
maliciously registered phishing domains in 2024 (Interisle)
~989K
phishing attacks in Q4 2024 (APWG)
$2.9B → $6.3B
the brand-protection market, 2024 to 2032

A dated record of the malicious site’s DNS, mail, and certificate, kept from while it was live, that still holds when the registrar, ICANN, or a court asks for proof. Reliable capture of a brand-new lookalike the moment it goes live lands as the fast-scan lane ships.

An independent, signed record, now anchored to Base

Every reading is signed the moment it is taken and chained to the one before, against published keys, and each day's readings are rolled into a single root and anchored to Base, a public chain, so the date is confirmed by the chain and not only by us. That proves who took each reading, that nobody has altered it since, and when it was taken. It is attribution, integrity, and an independent timestamp, never a claim the reading is correct: a signature can sit on a wrong observation. Anyone re-checks any reading themselves at the verifier, no account, years later. The signature is the first-mover trust layer; the lasting advantage is the dated record itself, which compounds and cannot be recreated after a domain changes, or rewritten once it is anchored.

Start free

A free account puts one of your own domains under watch, keeps its history, and sends a signed alert the moment we see it change. Paid plans raise the dials; pricing is on its own page.

Free to start. No credit card. Your signed record is yours to keep and verify anywhere.