You want the data, not a dashboard.

The signed record of any domain, as an API.

Read any domain’s DNS, TLS, WHOIS, ASN and robots as JSON. Every reading is Ed25519 signed and carries its receipt, so you can verify it in your own code. The first domain needs no key. A key opens the full record, the history, and the change feed. Built for developers, data teams and agents.

~809,000 domains tracked 92,000 scans a day Signed the moment it is observed
An abandoned DNS record is an open door.
“A 2024 study confirmed 20,904 hijacks of abandoned cloud resources whose DNS records still pointed at infrastructure that had been released, and a third of them stayed hijacked for more than 65 days.”
a USENIX NSDI 2024 study of cloud resource hijacking (arXiv) ↗

Quoted from a public discussion. Not a customer, not affiliated with DomainDrift, and not an endorsement.

Try it with one curl, no key

Call the domain endpoint with no key and no account. You get a reduced, current preview: the provider names, the certificate issuer and expiry, reachability, and the receipt that points at the full signed record. Keyless calls are throttled to one every 15 seconds per address. Enough to prove it works.

A five-second curl in a terminal, before anyone signs up for anything.

The full signed record, on a key

A DRM3 account mints a key. Send it as a header and every call returns the complete record: all nine DNS types, TLS certificates, WHOIS, ASN and robots, plus the per-domain history and the receipt chain. One request answers for any of ~809,000 tracked domains. Open the API console.

The change feed, not a nightly scrape

Pull structured deltas with sync cursors, so you resume where you stopped and never re-read a page. Hold the stream open for events as scans and changes land. Each delta carries the value before and the value after, dated. There is no HTML to parse.

A domain moves its nameservers at 02:00; your pipeline has the before and after by 02:05.

Pay for volume, or per call

Volume runs on DRM3 credits, the same wallet every DRM3 app uses, and every metered response carries its own meter in the headers so a client paces itself. An autonomous agent can settle a single call rather than hold an account, or connect over MCP. The agents page shows the machine door and its current terms.

An agent needs one lookup at 03:00 and would rather pay a cent than hold an account.

How it works

1Curl a domain

One domain, latest, signed. No account. A reduced preview in seconds.

2Get your key

A DRM3 account mints a key. Send it as a header for the full record and higher volume.

3Verify in code

Resolve any receipt at /verify, or against the published keys. Check a reading yourself, no account.

How you check it yourself

Every reading is Ed25519 signed the moment it is taken and chained to the one before, against published keys. The verifier checks any receipt in your browser: you hash the short proof path yourself and compare it to the root we published. A signature proves who took a reading and that nobody has changed it since, including us - it does not, on its own, make the reading correct. DomainDrift puts its name on the record, permanently.

Start with one domain

A DRM3 account puts one domain of your choosing under watch, keeps its history, and sends a signed alert the moment we see it change. See a sample report. Paid plans raise the dials; what it costs is on its own page.

One domain to start. No credit card. Your signed record is yours to keep and verify anywhere.

CONTINUOUS INTERNET TELEMETRY24H DRIFT4,232 material changesacross 2,655 domains · last 24h · -20,867 vs yesterdayROTATION56 domains moved DNS from kirklanddc.com to koaladns.com, 51 moved backa rotation loop, not a migration · 24hREGISTRAR DRIFT3 changed registrar24hNOW560 curated domains not reachablelast probe, steadySITE ERRORS17,820 sites serving errorslast probe · 5xx / 404 / TLSBOT DEFENSEbot defense observed on 78,600 sites429 rate-limit / 403 bot-block, a posture signal