CONTINUOUS INTERNET TELEMETRY24H DRIFT154 material changesacross 106 domains · +8 vs yesterdayEMAIL DRIFT1 domain switched email providertop destination xn----8sbafg9clhjcp.bgCERT DRIFT1 domains switched issuing CA24hNOW4,345 curated domains not answeringlast probe, steadyERRORS28,297 responded with an errorlast probe · 5xx / 404 / TLSTHROTTLED85,123 throttled or blocked our scanner429 rate-limit / 403 bot-blockMOVERgov.brAll nameservers removed (domain is dark)24H DRIFT154 material changesacross 106 domains · +8 vs yesterdayEMAIL DRIFT1 domain switched email providertop destination xn----8sbafg9clhjcp.bgCERT DRIFT1 domains switched issuing CA24hNOW4,345 curated domains not answeringlast probe, steadyERRORS28,297 responded with an errorlast probe · 5xx / 404 / TLSTHROTTLED85,123 throttled or blocked our scanner429 rate-limit / 403 bot-blockMOVERgov.brAll nameservers removed (domain is dark)

3s.pl

Observed Jul 18, 2026, 20:29 UTC (2d ago). Every field below was attested with an Ed25519 signature at scan time.

Up right now
Runs onCloudflare
Email byMicrosoft 365
Also usesAtlassian
6 subdomains · tranco_100k
Every line above is a signed observation. Check the math at the bottom of the page.
INFRASTRUCTURE MAPwhat 3s.pl actually stands on - every host below is a signed observation
3s.pl
A / AAAA
89.108.209.176
Cloudflareserves the site
NS
ns1.3s.plns2.3s.pl
3s.planswers its DNS
MX
3s-pl.mail.protection.outlook.com
Microsoft 365receives its email

HTTPS probe

redirect Redirecting (3xx) 301 → https://www.play.pl/duze-firmy
HTTP status301
Servercloudflare
TLS protocolHTTP/2
TLS issuernot observed
Behind Cloudflareyes
Response time1312 ms
DNS resolutionNOERROR
Redirect chain
https://www.play.pl/duze-firmy

Every field above is part of the same signed observation as the records below. Blank means not observed, never "none".

DNS Records

A 1

  • 89.108.209.176

MX 1

  • 53s-pl.mail.protection.outlook.com

TXT 5

  • v=spf1 mx a include:spf.protection.outlook.com include:_spf.atlassian.net ip4:85.14.85.213/32 ip4:89.25.150.17/32 ip4:89.25.150.20/32 ip4:89.25.195.51/32 ip4:89.25.150.23/32 ip4:188.117.146.108/32 ip4:188.117.157.165/32 ip4:188.117.185.90/32 -all
  • 1182af2da67db2557a805f058295884a16604976d24692c9f00fce054eb0b8a
  • atlassian-sending-domain-verification=9437e988-9250-45c9-8fb2-ec5f22532375
  • atlassian-domain-verification=3VlY/gzJhTy23oPk/i2EPV51pCF9XXZnAGaqjnwPlvwXY5O9duNB7hzUvtcaprPO
  • v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@3s.pl; ruf=mailto:dmarc-failures@3s.pl; sp=quarantine; aspf=r;

NS 2

  • ns1.3s.pl
  • ns2.3s.pl

SOA 1

  • ns1.3s.pl hostmaster.3s.pl

TLS Certificates (0)

None.

Subdomains (6)

The proof

Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; nothing leaves your machine.

Verify this receipt

Put the receipt on your own site. A live badge showing what DomainDrift observes and signs for 3s.pl. It updates itself. It attests a signed observation - not that the site is safe.

DomainDrift signed-observation badge for 3s.pl <a href="https://domaindrift.io/t/3s.pl"> <img src="https://domaindrift.io/badge/3s.pl.svg" width="300" height="64" alt="DomainDrift signed observations for 3s.pl"> </a>

Ed25519 Receipt

Receipt ID
c94d626c-5243-44a5-a4eb-2ff85ca5d9ab
Output Hash
5cbc5df10149bb741c23d042150086ae36d3b44886ec970c74ab2db119cfd902
Signature
ed25519:18dd00ac7a55704370f4e7a5d5e9839b02d84f2fc8678aeae443f35657dfb89d9745eb63259412ff6fb0a91bf67485f65e0436ba005f58e5401493f69dfa980a
Public Key
ed25519:7aad40f2d6399c207fe2fc15aade04a78324787a355d36725cc90687f9e10cff
Parent
(genesis)
Plane
fast
Verify this in your browser