lilnymph.com
Observed Aug 8, 2026, 08:29 UTC (just now). Every field below was attested with an Ed25519 signature at scan time. Catalog observation, re-checked on rotation - watch it for 5-minute checks.
DomainDrift asked this domain for a TXT record at a name nobody registers, and got an answer back. A domain that answers a name that was never created is answering names in general, and that is wildcard DNS.
Wildcard DNS clusters around domain parking, dynamic DNS and catch-all hosting. It is also a real attack surface: if every invented hostname resolves, then a hostname an attacker invents resolves too, which is the ground state for subdomain takeover and for phishing hosted under a name that looks legitimate.
This is evidence of wildcard behaviour, not a proven fact. It rests on one control name: a domain could legitimately serve a TXT record at exactly that name for an unrelated reason, and a wildcard that answers address records but not TXT records would not be caught here at all. What this reading is and is not.
HTTPS probe
The site answered with a 5xx, so the edge and TLS are working and the application behind them is not.
It does NOT mean the domain or its DNS is misconfigured - the request got all the way to an application to fail there.
- The origin is erroring or mid-deploy.
- An upstream in front of the origin cannot reach it.
These are the known causes, not a diagnosis of this domain. We recorded that nothing answered; we did not measure why.
_mcp._tcp.
v=spf1 ip6:fdec:ae16:fda7::/48 -allEvery field above is part of the same signed observation as the records below. Blank means not observed, never "none".
DNS Records
A 3
172.237.129.236172.237.129.108172.237.129.242
MX 1
1mail.eye-mail.net
TXT 4
v=spf1 ip6:fdec:ae16:fda7::/48 -allv=spf1 ip6:fdec:ae16:fda7::/48 -allv=DKIM1; (detected)v=spf1 ip6:fdec:ae16:fda7::/48 -all
NS 2
ns2.ns306.parklogic.comns1.ns306.parklogic.com
SOA 1
ns1.parklogic.com hostmaster.lilnymph.com
TLS Certificates (0)
None.
Subdomains (104)
- accounts.lilnymph.com
- admin.lilnymph.com
- api.lilnymph.com
- app.lilnymph.com
- assets.lilnymph.com
- auth.lilnymph.com
- beta.lilnymph.com
- billing.lilnymph.com
- blog.lilnymph.com
- build.lilnymph.com
- cache.lilnymph.com
- canary.lilnymph.com
- cashew.dns.lilnymph.com
- cashew.lilnymph.com
- cdn.lilnymph.com
- checkout.lilnymph.com
- ci.lilnymph.com
- comune.lilnymph.com
- connect.lilnymph.com
- connor.dns.lilnymph.com
- connor.lilnymph.com
- console.lilnymph.com
- dashboard.lilnymph.com
- db.lilnymph.com
- demo.lilnymph.com
- dev.lilnymph.com
- dns.lilnymph.com
- docs.lilnymph.com
- edge.lilnymph.com
- explorer.dns.lilnymph.com
- explorer.lilnymph.com
- faq.lilnymph.com
- gamma.lilnymph.com
- gateway.lilnymph.com
- git.lilnymph.com
- gitlab.lilnymph.com
- grafana.lilnymph.com
- graphql.lilnymph.com
- grpc.lilnymph.com
- health.lilnymph.com
- help.lilnymph.com
- id.lilnymph.com
- images.lilnymph.com
- imap.lilnymph.com
- img.lilnymph.com
- ingest.dns.lilnymph.com
- jenkins.lilnymph.com
- kb.lilnymph.com
- login.lilnymph.com
- m.lilnymph.com
Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; the only network request the check makes is for the published public keys.
Verify this receiptEd25519 Receipt
- Receipt ID
rcpt_b89145c388b67cd0- Output Hash
6e081407191823a7e6a4b341727fd84da9bb77a21f6168e238e8370b01c092a6- Signature
ed25519:e33dd527d404bb1c6f6ac954bf45275c69d5c6dc669a8f2c74113326e48085647335387a925e8530c6f82d6f284f1f6bacd5c251fc64dc1401162565ed98c501- Public Key
ed25519:7aad40f2d6399c207fe2fc15aade04a78324787a355d36725cc90687f9e10cff- Parent
(genesis)- Plane
- fast