CONTINUOUS INTERNET TELEMETRY24H DRIFT3,739 material changesacross 3,384 domains · last 24h · +1,823 vs yesterdayDNS DRIFT55 domains changed DNS providertop destination cloudflare.com · +25 vs yesterdayEMAIL DRIFT11 domains switched email providertop destination google.comCERT DRIFT20 domains switched issuing CA24hNOW553 curated domains not reachable+74 vs yesterdaySITE ERRORS29,202 sites serving errorslast probe · 5xx / 404 / TLSBOT DEFENSEbot defense observed on 138,679 sites429 rate-limit / 403 bot-block, a posture signal

For Cyber-Insurers · Loss Ratio, Not Attestation

An attestation is a promise.
A dated reading is evidence.

Price the posture. Argue the claim.

Cyber premiums run $15.3B → $27B by 2030, and about a third of insured losses ride a domain vector. DomainDrift prices the applicant’s real posture at underwriting and argues the claim from a dated, signed record instead of a self-attestation.

~2,050,000 domains under continuous signed watch Signed the moment it is observed Anchored daily to Base
What backs every line on this page

One working artifact: the signed evidence report.

Every reading DomainDrift takes is signed the moment it is observed and travels as a dated evidence report you can hand over: state, providers, registrar, expiry, email authentication, DNSSEC and subdomains, per domain, on one page. The recipient re-checks every reading themselves in the public verifier, with no account, years later. That artifact is the same on every page here. The persona only changes which part of it you foreground, on the same $10 / $29 / $99 ladder.

The return

The math, before the feature.

The loss ratio turns on two numbers you set at the desk: the premium priced against the real exposure, and the share of losses you can defend at claims. Price on a self-attested control and the underwriting scan is set aside at the quote. Months later forensics finds the DMARC enforcement the insured attested to was not in place on the incident date, and roughly a third of insured losses already ride a domain vector. That is the Travelers v. ICS pattern: a policy rescinded over attested-but-absent controls. DomainDrift reads the applicant’s posture continuously and keeps a dated, signed record, so the premium reflects the estate as it stands and the claim rests on a reading, not an attestation.

At underwriting
Price what is there

the applicant’s real DNS, mail, and certificate posture, read from the outside, so the premium reflects the estate as it stands, not as the application describes it.

At renewal
See the drift priced in

the posture read across the whole term, so a control that lapses is a dated reading you already hold, and the next premium moves on evidence, not a fresh questionnaire.

At claims
Defend from a record

the dated posture on the incident date, checkable against published keys, so the loss you pay or contest rests on a record instead of the insured’s attestation.

The claim turns on what was true on the incident date.
“Carriers are now denying claims when forensic review finds that the controls a policyholder attested to weren’t in place at the time of the incident.”
EmergeITS, cyber-insurance underwriting analysis (emergeits.com)

A public statement, quoted verbatim. Not a customer, not affiliated with DomainDrift, and not an endorsement.

Your desk, real captures

The applicant, read from the outside

A cyber-underwriting applicant group: the applicant’s primary domain up, its unregistered variants not reachable, each row a signed observation. No material drift in 24 hours.
A cyber-underwriting applicant group: coinbase.com up on Cloudflare with Google Workspace mail, its variants (coinbase.net, coinbase.org, coinbasecloud.com) not reachable at last probe, each row a signed observation with its own receipt. No material drift across the group in 24 hours - and quiet is a result too. Captured July 25, 2026.
The geography report: where domains are hosted versus registered, at country grain from signed ASN and RDAP observations, shown as an early-coverage preview.
Registered here, served from there: the country a domain is served from versus registered in, at country grain from signed ASN and RDAP observations. Shown honestly as an early-coverage preview - computed on 58,781 of 2,050,972 domains (2.9%) as enrichment fills in, labelled a preview and not a complete or comparative picture.
What you actually get

The product, pointed at your desk.

The posture a claim argues from

An applicant read from the outside the way the internet sees it: the domain, mail, and certificate posture on one dated, signed page. SPF, DKIM, DMARC and MTA-STS read and dated is the mail-forgery exposure you price at underwriting, and the record that settles whether it held at claims. Every certificate is dated with its issuer, so a lapse sits on the record before the incident, not reconstructed after it.

Verify it, or hand it over

The reading checks in a browser at /verify, or downloads as a signed bundle an adjuster or reinsurer can verify on their own desk against published keys, on the incident date or years later. The record a claim argues from, in place of an attestation.

Forensics dates the control to the incident; the signed reading already carried that date.

How it works
1Look one up free

Read any applicant’s posture from the outside, dated and signed, no account.

2Keep the reading

A free account keeps a domain’s history; the reading a claim needs is gathered before the incident.

3Feed the tooling

Pull signed applicant readings into underwriting and claims over the documented API.

The market
$15.3B → $27B
cyber-insurance premiums, 2024 to 2030
~33%
of insured losses tied to domain vectors
Travelers v. ICS
a policy rescinded over attested-but-absent controls

The insured’s domain and mail posture, read continuously and signed at each reading, so underwriting prices what is there and a claim argues from a dated record instead of an attestation.

An independent, signed record, now anchored to Base

Every reading is signed the moment it is taken and chained to the one before, against published keys, and each day's readings are rolled into a single root and anchored to Base, a public chain, so the date is confirmed by the chain and not only by us. That proves who took each reading, that nobody has altered it since, and when it was taken. It is attribution, integrity, and an independent timestamp, never a claim the reading is correct: a signature can sit on a wrong observation. Anyone re-checks any reading themselves at the verifier, no account, years later. The signature is the first-mover trust layer; the lasting advantage is the dated record itself, which compounds and cannot be recreated after a domain changes, or rewritten once it is anchored.

Start free

A free account puts one of your own domains under watch, keeps its history, and sends a signed alert the moment we see it change. Paid plans raise the dials; pricing is on its own page.

Free to start. No credit card. Your signed record is yours to keep and verify anywhere.