certificates, mail authentication, and DNS drift on one continuous read, in place of a cert monitor, a DMARC platform, and a DNS watcher living in three tabs and three invoices.
For IT & Security · Continuous Estate Posture
$1-15k/yr.
Or $10/mo.
A cert monitor, a DMARC platform, and a DNS watcher: three single-job tools, $1-15k a year, and a missed renewal still ships a Saturday outage behind a full-page browser warning. DomainDrift is one watch across every plane, with the dated record you hand the auditor.
One working artifact: the signed evidence report.
Every reading DomainDrift takes is signed the moment it is observed and travels as a dated evidence report you can hand over: state, providers, registrar, expiry, email authentication, DNSSEC and subdomains, per domain, on one page. The recipient re-checks every reading themselves in the public verifier, with no account, years later. That artifact is the same on every page here. The persona only changes which part of it you foreground, on the same $10 / $29 / $99 ladder.
The math, before the feature.
The cert/DMARC/DNS stack is three single-job tools running $1-15k a year, and none of it is a record an auditor accepts. Worse than the invoice is the failure mode: a certificate 47 days out, its autorenew quietly pointed at a subdomain that no longer resolves, lapsing on a Saturday behind a full-page browser warning. One continuous read across every plane, with the dated record, puts the reading there before the Saturday and there when the auditor asks.
a domain can publish DMARC and set p=none, which enforces nothing. The reading shows the policy, so “has DMARC” is never mistaken for protected.
every reading carries a timestamp an auditor can check, so estate posture is a standing record, not a screenshot from the day someone happened to look.
“Happened on the first day of my first on-call rotation - a cert for one of the key services expired. Autorenew failed.”
A public statement, quoted verbatim. Not a customer, not affiliated with DomainDrift, and not an endorsement.
The posture read, and the estate
The product, pointed at your desk.
Publishing DMARC is not enforcing it
Mail authentication read across the whole catalog and per domain from the outside, the way the internet sees it, at /posture. The distinction a checkbox audit misses: p=none tells the world to do nothing about mail forged in your name, and it still passes “has DMARC.” SPF, DKIM, DMARC and MTA-STS are read for policy, not presence.
You catch a DMARC policy slip to p=none the day it happens, and put enforcement back before anyone leans on the gap.
The estate live, the change signed
Group your corporate domains and DomainDrift holds a live read on every one: what it runs on, who sends its mail, a 24h drift column, and a receipt you can check. Approve the estate’s current state as its baseline and every check after is compared against what you signed off, so an alert is “something changed from what you approved,” not just “something changed.” The live desk and the audit record are the same rows.
Certificates, dated before the Saturday
Every certificate dated with its issuer and expiry, so a renewal about to lapse fires an alert in Slack or a webhook before the weekend it would have failed on. DNSSEC status rides the per-domain signed report. At 47-day certificates a quarterly check is a dead process.
A cert 47 days out, autorenew pointed at a subdomain that no longer resolves; you hear it Tuesday, not Saturday.
Run the free posture read on your own domain, no account.
Group your domains, approve a baseline; a free account watches one, paid plans the estate.
Per-plane signed events land as JSON in Slack, Teams, a webhook, or a SIEM.
Certificates, mail authentication, and DNS drift on one watch, with a dated reading you hand the auditor. At 47-day certificates, a quarterly check is a dead process.
An independent, signed record, now anchored to Base
Every reading is signed the moment it is taken and chained to the one before, against published keys, and each day's most-recent readings are rolled into a single root and anchored to Base, a public chain, so the date is confirmed by the chain and not only by us. That proves who took each reading, that nobody has altered it since, and when it was taken. It is attribution, integrity, and an independent timestamp, never a claim the reading is correct: a signature can sit on a wrong observation. Anyone re-checks a reading's signature themselves at the verifier, no account, years later. The signature is the first-mover trust layer; the lasting advantage is the dated record itself, which compounds and cannot be recreated after a domain changes, or rewritten once it is anchored.
Start free
A free account puts one of your own domains under watch, keeps its history, and sends a signed alert the moment we see it change. Paid plans raise the dials; pricing is on its own page.
Free to start. No credit card. Your signed record is yours to keep and verify anywhere.