the applicant’s real DNS, mail, and certificate posture, read from the outside, so the premium reflects the estate as it stands, not as the application describes it.
For Cyber-Insurers · Loss Ratio, Not Attestation
An attestation is a promise.
A dated reading is evidence.
Price the posture. Argue the claim.
Cyber premiums run $15.3B → $27B by 2030, and about a third of insured losses ride a domain vector. DomainDrift prices the applicant’s real posture at underwriting and argues the claim from a dated, signed record instead of a self-attestation.
One working artifact: the signed evidence report.
Every reading DomainDrift takes is signed the moment it is observed and travels as a dated evidence report you can hand over: state, providers, registrar, expiry, email authentication, DNSSEC and subdomains, per domain, on one page. The recipient re-checks every reading themselves in the public verifier, with no account, years later. That artifact is the same on every page here. The persona only changes which part of it you foreground, on the same $10 / $29 / $99 ladder.
The math, before the feature.
The loss ratio turns on two numbers you set at the desk: the premium priced against the real exposure, and the share of losses you can defend at claims. Price on a self-attested control and the underwriting scan is set aside at the quote. Months later forensics finds the DMARC enforcement the insured attested to was not in place on the incident date, and roughly a third of insured losses already ride a domain vector. That is the Travelers v. ICS pattern: a policy rescinded over attested-but-absent controls. DomainDrift reads the applicant’s posture continuously and keeps a dated, signed record, so the premium reflects the estate as it stands and the claim rests on a reading, not an attestation.
the posture read across the whole term, so a control that lapses is a dated reading you already hold, and the next premium moves on evidence, not a fresh questionnaire.
the dated posture on the incident date, checkable against published keys, so the loss you pay or contest rests on a record instead of the insured’s attestation.
“Carriers are now denying claims when forensic review finds that the controls a policyholder attested to weren’t in place at the time of the incident.”
A public statement, quoted verbatim. Not a customer, not affiliated with DomainDrift, and not an endorsement.
The applicant, read from the outside
The product, pointed at your desk.
The posture a claim argues from
An applicant read from the outside the way the internet sees it: the domain, mail, and certificate posture on one dated, signed page. SPF, DKIM, DMARC and MTA-STS read and dated is the mail-forgery exposure you price at underwriting, and the record that settles whether it held at claims. Every certificate is dated with its issuer, so a lapse sits on the record before the incident, not reconstructed after it.
Verify it, or hand it over
The reading checks in a browser at /verify, or downloads as a signed bundle an adjuster or reinsurer can verify on their own desk against published keys, on the incident date or years later. The record a claim argues from, in place of an attestation.
Forensics dates the control to the incident; the signed reading already carried that date.
Read any applicant’s posture from the outside, dated and signed, no account.
A free account keeps a domain’s history; the reading a claim needs is gathered before the incident.
Pull signed applicant readings into underwriting and claims over the documented API.
The insured’s domain and mail posture, read continuously and signed at each reading, so underwriting prices what is there and a claim argues from a dated record instead of an attestation.
An independent, signed record, now anchored to Base
Every reading is signed the moment it is taken and chained to the one before, against published keys, and each day's readings are rolled into a single root and anchored to Base, a public chain, so the date is confirmed by the chain and not only by us. That proves who took each reading, that nobody has altered it since, and when it was taken. It is attribution, integrity, and an independent timestamp, never a claim the reading is correct: a signature can sit on a wrong observation. Anyone re-checks any reading themselves at the verifier, no account, years later. The signature is the first-mover trust layer; the lasting advantage is the dated record itself, which compounds and cannot be recreated after a domain changes, or rewritten once it is anchored.
Start free
A free account puts one of your own domains under watch, keeps its history, and sends a signed alert the moment we see it change. Paid plans raise the dials; pricing is on its own page.
Free to start. No credit card. Your signed record is yours to keep and verify anywhere.