CONTINUOUS INTERNET TELEMETRY24H DRIFT167 material changesacross 120 domains · +21 vs yesterdayEMAIL DRIFT1 domain switched email providertop destination xn----8sbafg9clhjcp.bgCERT DRIFT1 domains switched issuing CA24hNOW4,498 curated domains not answering+164 vs yesterdayERRORS29,606 responded with an errorlast probe · 5xx / 404 / TLSTHROTTLED87,620 throttled or blocked our scanner429 rate-limit / 403 bot-blockMOVERgov.brAll nameservers removed (domain is dark)24H DRIFT167 material changesacross 120 domains · +21 vs yesterdayEMAIL DRIFT1 domain switched email providertop destination xn----8sbafg9clhjcp.bgCERT DRIFT1 domains switched issuing CA24hNOW4,498 curated domains not answering+164 vs yesterdayERRORS29,606 responded with an errorlast probe · 5xx / 404 / TLSTHROTTLED87,620 throttled or blocked our scanner429 rate-limit / 403 bot-blockMOVERgov.brAll nameservers removed (domain is dark)

ba.no

Observed Jul 17, 2026, 16:57 UTC (4d ago). Every field below was attested with an Ed25519 signature at scan time.

Up right now
Runs onCloudflare
Email byGoogle Workspace
Registered withRedpill Linpro AS
Also usesGoogle Search Console
7 subdomains · tranco_100k
Every line above is a signed observation. Check the math at the bottom of the page.
INFRASTRUCTURE MAPwhat ba.no actually stands on - every host below is a signed observation
ba.no
A / AAAA
87.238.38.2
Cloudflareserves the site
NS
nsu.dnsnode.netnsp.dnsnode.netnsb.dnsnode.net
dnsnode.netanswers its DNS
MX
alt1.aspmx.l.google.comaspmx.l.google.comalt3.aspmx.l.google.comalt4.aspmx.l.google.com+1 more
Google Workspacereceives its email

HTTPS probe

redirect Redirecting (3xx) 301 → https://www.ba.no/
HTTP status301
Servercloudflare
TLS protocolHTTP/2
TLS issuernot observed
Behind Cloudflareyes
Response time700 ms
DNS resolutionNOERROR
Redirect chain
https://www.ba.no/

Every field above is part of the same signed observation as the records below. Blank means not observed, never "none".

DNS Records

A 1

  • 87.238.38.2

MX 5

  • 5alt1.aspmx.l.google.com
  • 1aspmx.l.google.com
  • 10alt3.aspmx.l.google.com
  • 10alt4.aspmx.l.google.com
  • 5alt2.aspmx.l.google.com

TXT 4

  • v=spf1 include:_spf.aid.no -all
  • google-site-verification=zJaWxZniLZAKHwX_yG5Mxm1H0sOsE1mbhtEe8Q2rMMc
  • v=DMARC1; p=quarantine; rua=mailto:dmarcreports@amedia.no; adkim=s; aspf=s
  • v=DKIM1; (detected)

NS 3

  • nsu.dnsnode.net
  • nsp.dnsnode.net
  • nsb.dnsnode.net

SOA 1

  • ns-foo.i.bitbit.net hostmaster.redpill-linpro.com

TLS Certificates (0)

None.

Subdomains (7)

The proof

Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; nothing leaves your machine.

Verify this receipt

Put the receipt on your own site. A live badge showing what DomainDrift observes and signs for ba.no. It updates itself. It attests a signed observation - not that the site is safe.

DomainDrift signed-observation badge for ba.no <a href="https://domaindrift.io/t/ba.no"> <img src="https://domaindrift.io/badge/ba.no.svg" width="300" height="64" alt="DomainDrift signed observations for ba.no"> </a>

Ed25519 Receipt

Receipt ID
f03f1af6-b3e9-4533-94f7-25866b6ed2a9
Output Hash
70b936369dc2375f31294b9aecac94dde44d52fe5acfdebe35e7ea88433f875b
Signature
ed25519:c78c55ed1d9133c54fc6e8b450a2bff892e65e85dd41c20b9bb3a656df007f59ecfcf47750bcf3dba12984c414eabdb8a0ca8d4ae8240ee7aa2d68b250f8730a
Public Key
ed25519:7aad40f2d6399c207fe2fc15aade04a78324787a355d36725cc90687f9e10cff
Parent
(genesis)
Plane
fast
Verify this in your browser