CONTINUOUS INTERNET TELEMETRY24H DRIFT201 material changesacross 161 domains · -457 vs yesterdayCERT DRIFT3 domains switched issuing CA24h · +1 vs yesterdayNOW3,808 curated domains not answering+979 vs yesterdayERRORS24,709 responded with an errorlast probe · 5xx / 404 / TLSTHROTTLED69,739 throttled or blocked our scanner429 rate-limit / 403 bot-block24H DRIFT201 material changesacross 161 domains · -457 vs yesterdayCERT DRIFT3 domains switched issuing CA24h · +1 vs yesterdayNOW3,808 curated domains not answering+979 vs yesterdayERRORS24,709 responded with an errorlast probe · 5xx / 404 / TLSTHROTTLED69,739 throttled or blocked our scanner429 rate-limit / 403 bot-block

fireblocks.io

Observed Jul 19, 2026, 12:18 UTC (1d ago). Every field below was attested with an Ed25519 signature at scan time.

Up right now
Runs onCloudflare
Email byGoogle (SPF sender)
Also usesHubSpotGoogle Search ConsoleZoomStripeMiroAtlassianSlack
9 subdomains · tranco_100k
Every line above is a signed observation. Check the math at the bottom of the page.
INFRASTRUCTURE MAPwhat fireblocks.io actually stands on - every host below is a signed observation
fireblocks.io
A / AAAA
162.159.140.52172.66.0.52
Cloudflareserves the site
NS
ns-1922.awsdns-48.co.ukns-900.awsdns-48.netns-242.awsdns-30.comns-1333.awsdns-38.org
awsdns-48.co.uk + awsdns-48.net + moreanswers its DNS
MX
mx2.hc1621-77.eu.iphmx.commx1.hc1621-77.eu.iphmx.com
Google (SPF sender)receives its email

HTTPS probe

redirect Redirecting (3xx) 301 → https://www.fireblocks.com/
HTTP status301
Servercloudflare
TLS protocolHTTP/2
TLS issuernot observed
Behind Cloudflareyes
Response time3 ms
DNS resolutionNOERROR
Redirect chain
https://www.fireblocks.com/

Every field above is part of the same signed observation as the records below. Blank means not observed, never "none".

DNS Records

A 2

  • 162.159.140.52
  • 172.66.0.52

MX 2

  • 1mx2.hc1621-77.eu.iphmx.com
  • 0mx1.hc1621-77.eu.iphmx.com

TXT 23

  • hubspot-domain-verification=NTJjOWZkZDktZjJkYy00YjE3LWI1YWUtZWNkYmYwYzA5ZGY1
  • atlassian-sending-domain-verification=221bdb5f-8062-4204-b125-8fca4b4fefa2
  • jhk03qv2dkhk4lurf7bjv0b5r7
  • ql6ldt22nnaseql3ehah032bm1
  • google-site-verification=Su2dSPhNSfx27z7fPxb9iD-_dEI3vzp9WcO7y76RohA
  • zapier-domain-verification-challenge=48d63ac2-3375-49e1-a34b-b4e6241ce3b2
  • hubspot-domain-verification=MGJmNTA5YWEtZjc4MC00ZjQyLTg5YTYtOGUyMWQwOTYxMDEw
  • knowbe4-site-verification=20068e51c62550791d46cca7510311b1
  • ZOOM_verify_SeTErThhibn0eFY6zdVJoX
  • v=spf1 include:_spf.google.com include:amazonses.com ip4:23.90.123.196 ip4:23.90.122.240 ~all

NS 4

  • ns-1922.awsdns-48.co.uk
  • ns-900.awsdns-48.net
  • ns-242.awsdns-30.com
  • ns-1333.awsdns-38.org

SOA 1

  • ns-900.awsdns-48.net awsdns-hostmaster.amazon.com

CAA 6

  • issue godaddy.com
  • issue digicert.com
  • issuewild godaddy.com
  • issuewild digicert.com
  • issuewild amazon.com
  • issue amazon.com

TLS Certificates (0)

None.

Subdomains (9)

The proof

Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; nothing leaves your machine.

Verify this receipt

Put the receipt on your own site. A live badge showing what DomainDrift observes and signs for fireblocks.io. It updates itself. It attests a signed observation - not that the site is safe.

DomainDrift signed-observation badge for fireblocks.io <a href="https://domaindrift.io/t/fireblocks.io"> <img src="https://domaindrift.io/badge/fireblocks.io.svg" width="300" height="64" alt="DomainDrift signed observations for fireblocks.io"> </a>

Ed25519 Receipt

Receipt ID
218ba3e2-34ac-4811-9400-f97b08180ee4
Output Hash
cb151a51cd3c6a928c591d949c53248a2cb87b8dac18c4dfb02b389e6f317b10
Signature
ed25519:12a04aad030b5052cecb1d6b3a3eb2d311e4bdae1a5bdfca746bb349ef23b0e2a535b49d3d0930d7fee28f0faee3212b2aaf2043c2a7b8b326ec1b06a67f0c07
Public Key
ed25519:7aad40f2d6399c207fe2fc15aade04a78324787a355d36725cc90687f9e10cff
Parent
(genesis)
Plane
fast
Verify this in your browser