CONTINUOUS INTERNET TELEMETRY24H DRIFT658 material changesacross 559 domainsDNS DRIFT2 domains changed DNS providertop destination kirklanddc.comCERT DRIFT2 domains switched issuing CA24hNOW2,845 curated domains not answeringlast probe, steadyERRORS18,851 responded with an errorlast probe · 5xx / 404 / TLSTHROTTLED49,541 throttled or blocked our scanner429 rate-limit / 403 bot-block24H DRIFT658 material changesacross 559 domainsDNS DRIFT2 domains changed DNS providertop destination kirklanddc.comCERT DRIFT2 domains switched issuing CA24hNOW2,845 curated domains not answeringlast probe, steadyERRORS18,851 responded with an errorlast probe · 5xx / 404 / TLSTHROTTLED49,541 throttled or blocked our scanner429 rate-limit / 403 bot-block

mailplus.nl

Observed Jul 19, 2026, 05:26 UTC (19h ago). Every field below was attested with an Ed25519 signature at scan time.

Up right now
Runs onCloudflare
Also usesGoogle Search Console
11 subdomains · tranco_100k
Every line above is a signed observation. Check the math at the bottom of the page.
INFRASTRUCTURE MAPwhat mailplus.nl actually stands on - every host below is a signed observation
mailplus.nl
A / AAAA
46.31.50.211
Cloudflareserves the site
NS
rory.ns.cloudflare.combrianna.ns.cloudflare.com
cloudflare.comanswers its DNS
MX
hosting01.spotler.net
spotler.netreceives its email

HTTPS probe

redirect Redirecting (3xx) 301 → https://spotler.nl/
HTTP status301
Servercloudflare
TLS protocolHTTP/2
TLS issuernot observed
Behind Cloudflareyes
Response time434 ms
DNS resolutionNOERROR
Redirect chain
https://spotler.nl/

Every field above is part of the same signed observation as the records below. Blank means not observed, never "none".

DNS Records

A 1

  • 46.31.50.211

MX 1

  • 10hosting01.spotler.net

TXT 5

  • google-site-verification=gXIM2li7BXT8xSIq-cthdzelczXE8hag1ptPMfFPszU
  • google-site-verification=H2WQvjsRU9UC6mXaTbQv9m1gYp8SKJmCDhln4wRR3IA
  • v=spf1 include:_spf.spotlergroup.com -all
  • v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc-reports@spotler.services; ruf=mailto:dmarc-forensic@spotler.services; fo=0:1:d:s; adkim=r; aspf=r;
  • v=DNSSEC1; (detected)

NS 2

  • rory.ns.cloudflare.com
  • brianna.ns.cloudflare.com

SOA 1

  • brianna.ns.cloudflare.com dns.cloudflare.com

CAA 13

  • issue ssl.com
  • issuewild comodoca.com
  • issue comodoca.com
  • issue sectigo.com
  • issue letsencrypt.org
  • issuewild digicert.com; cansignhttpexchanges=yes
  • iodef mailto:caa@spotler.services
  • issuewild pki.goog; cansignhttpexchanges=yes
  • issue geotrust.com
  • issue digicert.com; cansignhttpexchanges=yes

TLS Certificates (0)

None.

Subdomains (11)

The proof

Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; nothing leaves your machine.

Verify this receipt

Put the receipt on your own site. A live badge showing what DomainDrift observes and signs for mailplus.nl. It updates itself. It attests a signed observation - not that the site is safe.

DomainDrift signed-observation badge for mailplus.nl <a href="https://domaindrift.io/t/mailplus.nl"> <img src="https://domaindrift.io/badge/mailplus.nl.svg" width="300" height="64" alt="DomainDrift signed observations for mailplus.nl"> </a>

Ed25519 Receipt

Receipt ID
1a1c17a5-f32a-417e-8604-f0ec70083d71
Output Hash
63d8229611c7629773a4e135790a645eb400ba08792664373c33001f0fe1f802
Signature
ed25519:d19c816739c95c783b2ec0d105046476e716b3010a3666551fcbc5cb3441566b0a3446ba3d1fbdaea4f8f05514a02b7749fc0d58c3b50e7a07fbadaaa5001e0e
Public Key
ed25519:7aad40f2d6399c207fe2fc15aade04a78324787a355d36725cc90687f9e10cff
Parent
(genesis)
Plane
fast
Verify this in your browser