1win-qwin.top

Observed Aug 25, 2026, 20:26 UTC (1h ago). Every field below was attested with an Ed25519 signature at scan time. Catalog observation, re-checked on rotation - watch it for 5-minute checks.

Not responding
Runs onCloudflare
96 subdomains · tranco
Every line above is a signed observation. Check the math at the bottom of the page.
DRIFT

Steady. No change on record for 1win-qwin.top in the last day; this reading matches the one before it. The steady record is signed like every other reading. Watch it to catch the next move the moment it lands.

HTTPS probe

Server error Server error (5xx) 520 Server Error
HTTP status520
Servercloudflare
TLS protocolHTTP/2
TLS issuernot observed
Behind Cloudflareyes
Response time413 ms
DNS resolutionNOERROR
What this reading means

The site answered with a 5xx, so the edge and TLS are working and the application behind them is not.

It does NOT mean the domain or its DNS is misconfigured - the request got all the way to an application to fail there.

What produces this, in rough order of how often
  • The origin is erroring or mid-deploy.
  • An upstream in front of the origin cannot reach it.

These are the known causes, not a diagnosis of this domain. We recorded that nothing answered; we did not measure why.

MCP This domain advertises an AI service endpoint at _mcp._tcp.
1 endpoint - withheld

Every field above is part of the same signed observation as the records below. Blank means not observed, never "none".

SIGNED-OUT VIEW Provider names, posture and counts are shown. The record values - every DNS answer, each subdomain hostname, raw TXT, IPs, cert names and WHOIS - are the product. Sign in for the full signed record, or use the API with a key.

DNS records 11

A3NS2MX1TXT4SOA1

TLS certificates 0

None.

Subdomains 96

96 subdomain hostnames observed and signed - the list itself is part of the paid record.

WILDCARD DNSobserved 2026-08-25 20:27 UTC

DomainDrift asked this domain for one hostname that nobody ever registered, and it answered. A domain that answers invented hostnames is running wildcard DNS. It is common and usually deliberate. A SaaS platform gives every customer a subdomain this way. How the check works

The proof

Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; the only network request the check makes is for the published public keys.

Verify this receipt
Ed25519 receiptthe raw cryptographic proof
Receipt ID
rcpt_f22eb25c5b2eeeed
Output Hash
216e616ac4776fc43537ce6c20176479b9045827dfb2f55ebf0e6030996b2be4
Signature
ed25519:bd0a9ca33f359ff5a4e24b8234e2ca1b9feecacd6a15989d75b278ab25aa2c464c53b3eb33c84d5e872b30644d07de7710fd6a4e9a56d77bb33bd3f91f3a0d0d
Public Key
ed25519:7aad40f2d6399c207fe2fc15aade04a78324787a355d36725cc90687f9e10cff
Parent
(genesis)
Plane
fast
CONTINUOUS INTERNET TELEMETRY24H DRIFT6,512 material changesacross 4,838 domains · last 24hDNS DRIFT96 domains changed DNS providertop destination koaladns.com · +13 vs yesterdayEMAIL DRIFT2 domains switched email provider24hREGISTRAR DRIFT2 changed registrar24hNOW509 curated domains not reachable+89 vs yesterdaySITE ERRORS17,749 sites serving errorslast probe · 5xx / 404 / TLSBOT DEFENSEbot defense observed on 78,750 sites429 rate-limit / 403 bot-block, a posture signal