CONTINUOUS INTERNET TELEMETRY24H DRIFT773 material changesacross 604 domains · +627 vs yesterdayDNS DRIFT22 domains changed DNS providertop destination cloudflare.com · +22 vs yesterdayEMAIL DRIFT9 domains switched email providertop destination outlook.com · +8 vs yesterdayCERT DRIFT16 domains switched issuing CA24h · +15 vs yesterdayNOW2,669 curated domains not answering-1,665 vs yesterdayERRORS23,963 responded with an errorlast probe · 5xx / 404 / TLSTHROTTLED90,547 throttled or blocked our scanner429 rate-limit / 403 bot-block24H DRIFT773 material changesacross 604 domains · +627 vs yesterdayDNS DRIFT22 domains changed DNS providertop destination cloudflare.com · +22 vs yesterdayEMAIL DRIFT9 domains switched email providertop destination outlook.com · +8 vs yesterdayCERT DRIFT16 domains switched issuing CA24h · +15 vs yesterdayNOW2,669 curated domains not answering-1,665 vs yesterdayERRORS23,963 responded with an errorlast probe · 5xx / 404 / TLSTHROTTLED90,547 throttled or blocked our scanner429 rate-limit / 403 bot-block

ba.no

Observed Jul 21, 2026, 17:13 UTC (2h ago). Every field below was attested with an Ed25519 signature at scan time.

Up right now
Runs onCloudflare
Email byGoogle Workspace
Secured byLet's Encrypt
Registered withRedpill Linpro AS
Also usesGoogle Search Console
tranco_100k
Every line above is a signed observation. Check the math at the bottom of the page.
INFRASTRUCTURE MAPwhat ba.no actually stands on - every host below is a signed observation
ba.no
A / AAAA
87.238.38.2
Cloudflareserves the site
NS
nsp.dnsnode.netnsu.dnsnode.netnsb.dnsnode.net
dnsnode.netanswers its DNS
MX
aspmx.l.google.comalt1.aspmx.l.google.comalt2.aspmx.l.google.comalt3.aspmx.l.google.com+1 more
Google Workspacereceives its email
TLS
ba.no
Let's Encryptissued its certificate

DNS Records

A 1

  • 87.238.38.2

MX 5

  • 1aspmx.l.google.com
  • 5alt1.aspmx.l.google.com
  • 5alt2.aspmx.l.google.com
  • 10alt3.aspmx.l.google.com
  • 10alt4.aspmx.l.google.com

TXT 3

  • v=spf1 include:_spf.aid.no -all
  • google-site-verification=zJaWxZniLZAKHwX_yG5Mxm1H0sOsE1mbhtEe8Q2rMMc
  • v=DMARC1; p=quarantine; rua=mailto:dmarcreports@amedia.no; adkim=s; aspf=s

NS 3

  • nsp.dnsnode.net
  • nsu.dnsnode.net
  • nsb.dnsnode.net

SOA 1

  • ns-foo.i.bitbit.net hostmaster.redpill-linpro.com

TLS Certificates (3)

Common NameIssuerExpires
ba.no C=US, O=Let's Encrypt, CN=YR2 Thu, 17 Sep 2026 09:10:23 +0000
YR2 C=US, O=ISRG, CN=Root YR Sat, 02 Sep 2028 23:59:59 +0000
Root YR C=US, O=Internet Security Research Group, CN=ISRG Root X1 Thu, 02 Sep 2032 23:59:59 +0000

Subdomains (0)

None observed.

The proof

Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; nothing leaves your machine.

Verify this receipt

Put the receipt on your own site. A live badge showing what DomainDrift observes and signs for ba.no. It updates itself. It attests a signed observation - not that the site is safe.

DomainDrift signed-observation badge for ba.no <a href="https://domaindrift.io/t/ba.no"> <img src="https://domaindrift.io/badge/ba.no.svg" width="300" height="64" alt="DomainDrift signed observations for ba.no"> </a>

Ed25519 Receipt

Receipt ID
rcpt_dfc3839ae3516023
Output Hash
aca681a69c70c20eb9a4e7d22d40ea9999c9bf6b31c0befa388f93b8384fe22a
Signature
ed25519:42c53b2b35f93b1bd77f942ec7fb7e2ef618e71a747c2ab81812df4e7bbe4a80f77318e09db3512322049cb35f8157d5c6881570f6af82e1e0e4d7cc3aaeaa00
Public Key
ed25519:178c3bd0f57d9d64b83cc4630753381e1a465005a2bbba3d032371f24af0bfd8
Parent
(genesis)
Plane
fast
Verify this in your browser