ctms.vn

Observed Aug 25, 2026, 08:53 UTC (2d ago). Every field below was attested with an Ed25519 signature at scan time.

This reading of ctms.vn was taken 2d ago

ctms.vn is on the survey sweep, which works its way across the whole catalog rather than returning to one name on a schedule. Putting ctms.vn under watch moves it to the fast lane, where DomainDrift re-checks it about every 5 minutes and signs each reading, so a change becomes a dated event within minutes instead of waiting for the sweep to come round.

Watch ctms.vn Watching a domain needs a DRM3 account. The reading above stays free and public either way.
Up right now
Runs onCloudflare
2 subdomains · tranco
Every line above is a signed observation. Check the math at the bottom of the page.
DRIFT

Steady. No change on record for ctms.vn in the last day; this reading matches the one before it. The steady record is signed like every other reading. Watch it to catch the next move the moment it lands.

HTTPS probe

Up Responding normally (2xx) 200 OK
HTTP status200
Servercloudflare
TLS protocolnot observed
TLS issuernot observed
Behind Cloudflareyes
Response time222 ms
DNS resolutionNOERROR
MCP This domain advertises an AI service endpoint at _mcp._tcp.
1 endpoint - withheld

Every field above is part of the same signed observation as the records below. Blank means not observed, never "none".

SIGNED-OUT VIEW Provider names, posture and counts are shown. The record values - every DNS answer, each subdomain hostname, raw TXT, IPs, cert names and WHOIS - are the product. Sign in for the full signed record, or use the API with a key.

DNS records 5

A1NS4

TLS certificates 0

None.

Subdomains 2

2 subdomain hostnames observed and signed - the list itself is part of the paid record.

WILDCARD DNSobserved 2026-08-25 08:53 UTC

DomainDrift asked this domain for one hostname that nobody ever registered, and it answered. A domain that answers invented hostnames is running wildcard DNS. It is common and usually deliberate. A SaaS platform gives every customer a subdomain this way. How the check works

The proof

Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; the only network request the check makes is for the published public keys.

Verify this receipt
Ed25519 receiptthe raw cryptographic proof
Receipt ID
rcpt_5a55bafe4a0e01a1
Output Hash
01037837e58d0cd2e1a53b9777ee9b7e08e8bdafdd429ed79b5290925aece14a
Signature
ed25519:0f185264c488f806b5975f933ff1903b1a1505324e65e962b4a79293ca36d61186cc5f270addbb72cf1b873350ddff8e1285e5017c8b5443baed9abd94c21907
Public Key
ed25519:7aad40f2d6399c207fe2fc15aade04a78324787a355d36725cc90687f9e10cff
Parent
(genesis)
Plane
fast
CONTINUOUS INTERNET TELEMETRY24H DRIFT25,284 material changesacross 16,067 domains · 24h to ~80m agoROTATION56 domains moved DNS from magpiedns.com to koaladns.com, 56 moved backa rotation loop, not a migration · 24hREGISTRAR DRIFT3 changed registrar24hNOW558 curated domains not reachable+34 vs yesterdaySITE ERRORS17,811 sites serving errorslast probe · 5xx / 404 / TLSBOT DEFENSEbot defense observed on 78,679 sites429 rate-limit / 403 bot-block, a posture signal