The domain layer, checked continuously. Evidence when someone asks.
Certificates, DNSSEC, email spoofing protection and dangling records watched without you remembering to look, with per-plane signed events routed where your team works and a record you can show an auditor.
~2,050,000 domains tracked267,000 re-scanned every daySigned the moment it is observed
Sound familiar?
“Happened on the first day of my first on-call rotation - a cert for one of the key services expired. Autorenew failed, because one of the subdomains on the cert no longer resolved.”
Quoted from a public discussion. Not a customer, not affiliated with DomainDrift, and not an endorsement.
Certificates and DNSSEC, watched
Expiry date, issuing authority, DNSSEC state: all on one record, all watched. A change arrives with its context attached, not as a surprise outage on a weekend.
A certificate lapses on a Saturday and every visitor meets a full-page browser warning.
Email spoofing protection you can prove
SPF, DMARC, DKIM and MTA-STS posture is read on every scan and readable on the record. When one is missing, weak, or gets changed, you find out.
Invoices go out as your company because a DMARC policy quietly dropped to none.
Dangling records before someone claims them
A CNAME pointing at a service you no longer own is a subdomain takeover waiting to happen. It rides the same watch, flagged when the target goes stale.
How do I prove posture to an auditor?
Every observation is Ed25519 signed at the moment it is taken, timestamped, and chained to the previous scan. What a domain’s posture was on a given date is a signed record you can produce, and anyone can check it at /verify. A signature proves who observed it and that it has not been altered since; it is added trust, on the record.
How it works
1Check your posture now
Run the free posture check on your own domain, no account.
2Watch the estate
Group your domains and vendors; every plane goes under continuous watch.
3Route the signal
Per-plane signed events land as JSON in Slack, Teams, a webhook, or a SIEM.
Every reading is Ed25519 signed the moment it is taken and chained to the one before, against published keys. The verifier checks any receipt in your browser, and on any domain page the probe panel reruns the live checks from your own network: your resolver, the registry, your own route to the site. So every reading carries proof of who took it and that nobody has changed it since, including us. DomainDrift puts its name on the record, permanently.
Start free
A free account puts one of your own domains under watch, keeps its history, and sends a signed alert the moment we see it change. Paid plans raise the dials; pricing is on its own page.