CONTINUOUS INTERNET TELEMETRY24H DRIFT7,622 material changesacross 7,471 domains · last 24h · -1,212 vs yesterdayDNS DRIFT207 domains changed DNS providertop destination cloudflare.com · -70 vs yesterdayEMAIL DRIFT48 domains switched email providertop destination outlook.com · -6 vs yesterdayCERT DRIFT66 domains switched issuing CA24h · -7 vs yesterdayNOW511 curated domains not reachable-46 vs yesterdaySITE ERRORS34,039 sites serving errorslast probe · 5xx / 404 / TLSBOT DEFENSEbot defense observed on 146,447 sites429 rate-limit / 403 bot-block, a posture signal

For IT & Security · Continuous Estate Posture

$1-15k/yr.
Or $10/mo.

A cert monitor, a DMARC platform, and a DNS watcher: three single-job tools, $1-15k a year, and a missed renewal still ships a Saturday outage behind a full-page browser warning. DomainDrift is one watch across every plane, with the dated record you hand the auditor.

~2,050,000 domains under continuous signed watch Signed the moment it is observed Anchored daily to Base
What backs every line on this page

One working artifact: the signed evidence report.

Every reading DomainDrift takes is signed the moment it is observed and travels as a dated evidence report you can hand over: state, providers, registrar, expiry, email authentication, DNSSEC and subdomains, per domain, on one page. The recipient re-checks every reading themselves in the public verifier, with no account, years later. That artifact is the same on every page here. The persona only changes which part of it you foreground, on the same $10 / $29 / $99 ladder.

The return

The math, before the feature.

The cert/DMARC/DNS stack is three single-job tools running $1-15k a year, and none of it is a record an auditor accepts. Worse than the invoice is the failure mode: a certificate 47 days out, its autorenew quietly pointed at a subdomain that no longer resolves, lapsing on a Saturday behind a full-page browser warning. One continuous read across every plane, with the dated record, puts the reading there before the Saturday and there when the auditor asks.

One watch
Every plane, one record

certificates, mail authentication, and DNS drift on one continuous read, in place of a cert monitor, a DMARC platform, and a DNS watcher living in three tabs and three invoices.

The distinction
Enforcing, not just present

a domain can publish DMARC and set p=none, which enforces nothing. The reading shows the policy, so “has DMARC” is never mistaken for protected.

The record
Dated, not a screenshot

every reading carries a timestamp an auditor can check, so estate posture is a standing record, not a screenshot from the day someone happened to look.

The cert expires on a Saturday. One watch already caught it.
“Happened on the first day of my first on-call rotation - a cert for one of the key services expired. Autorenew failed.”
dvratil, Hacker News ↗

A public statement, quoted verbatim. Not a customer, not affiliated with DomainDrift, and not an endorsement.

Your desk, real captures

The posture read, and the estate

The DMARC posture read across the domains with an email-auth reading, broken down per source list: how many publish DMARC, and how many of those publish p=none, which enforces nothing.
Mail authentication, read across the 1,133,797 domains with an email-auth reading: 46% publish DMARC, and 51% of those set p=none, which enforces nothing. Broken down per source list (tranco, majestic, tranco_100k and more): publishing DMARC is not enforcing it. Policy read from the outside, in aggregate and per cohort. July 2026.
A corporate estate under watch: each domain monitored, with a live view and a daily report a click away.
The estate on one watch: a corporate group (Corp Estate - Shopify) with each domain monitored, a live view and a daily report a click away, and any domain you name added within minutes. The live desk and the audit record are the same rows.
What you actually get

The product, pointed at your desk.

Publishing DMARC is not enforcing it

Mail authentication read across the whole catalog and per domain from the outside, the way the internet sees it, at /posture. The distinction a checkbox audit misses: p=none tells the world to do nothing about mail forged in your name, and it still passes “has DMARC.” SPF, DKIM, DMARC and MTA-STS are read for policy, not presence.

You catch a DMARC policy slip to p=none the day it happens, and put enforcement back before anyone leans on the gap.

The estate live, the change signed

Group your corporate domains and DomainDrift holds a live read on every one: what it runs on, who sends its mail, a 24h drift column, and a receipt you can check. Approve the estate’s current state as its baseline and every check after is compared against what you signed off, so an alert is “something changed from what you approved,” not just “something changed.” The live desk and the audit record are the same rows.

Certificates, dated before the Saturday

Every certificate dated with its issuer and expiry, so a renewal about to lapse fires an alert in Slack or a webhook before the weekend it would have failed on. DNSSEC status rides the per-domain signed report. At 47-day certificates a quarterly check is a dead process.

A cert 47 days out, autorenew pointed at a subdomain that no longer resolves; you hear it Tuesday, not Saturday.

How it works
1Check posture free

Run the free posture read on your own domain, no account.

2Watch the estate

Group your domains, approve a baseline; a free account watches one, paid plans the estate.

3Route the signal

Per-plane signed events land as JSON in Slack, Teams, a webhook, or a SIEM.

The market
47 days
max certificate lifetime by 2029: about 8x more renewals to not miss
51%
of domains that publish DMARC set p=none, which enforces nothing (DomainDrift reading)
$10/mo
entry to one watch across certificates, mail, and DNS, in one dated record

Certificates, mail authentication, and DNS drift on one watch, with a dated reading you hand the auditor. At 47-day certificates, a quarterly check is a dead process.

An independent, signed record, now anchored to Base

Every reading is signed the moment it is taken and chained to the one before, against published keys, and each day's most-recent readings are rolled into a single root and anchored to Base, a public chain, so the date is confirmed by the chain and not only by us. That proves who took each reading, that nobody has altered it since, and when it was taken. It is attribution, integrity, and an independent timestamp, never a claim the reading is correct: a signature can sit on a wrong observation. Anyone re-checks a reading's signature themselves at the verifier, no account, years later. The signature is the first-mover trust layer; the lasting advantage is the dated record itself, which compounds and cannot be recreated after a domain changes, or rewritten once it is anchored.

Start free

A free account puts one of your own domains under watch, keeps its history, and sends a signed alert the moment we see it change. Paid plans raise the dials; pricing is on its own page.

Free to start. No credit card. Your signed record is yours to keep and verify anywhere.