mega-f.ru

Observed Aug 2, 2026, 17:38 UTC (13d ago). Every field below was attested with an Ed25519 signature at scan time.

This reading of mega-f.ru was taken 13d ago

mega-f.ru is on the survey sweep, which works its way across the whole catalog rather than returning to one name on a schedule. Putting mega-f.ru under watch moves it to the fast lane, where DomainDrift re-checks it about every 5 minutes and signs each reading, so a change becomes a dated event within minutes instead of waiting for the sweep to come round.

Watch mega-f.ru Watching a domain needs a DRM3 account. The reading above stays free and public either way.
Not responding
Signed observation on record.
Also usesMicrosoft 365GlobalSign
majestic
Every line above is a signed observation. Check the math at the bottom of the page.
EVIDENCE OF WILDCARD DNSobserved 2026-08-07 18:21 UTC

DomainDrift asked this domain for a TXT record at a name nobody registers, and got an answer back. A domain that answers a name that was never created is answering names in general, and that is wildcard DNS.

Wildcard DNS clusters around domain parking, dynamic DNS and catch-all hosting. It is also a real attack surface: if every invented hostname resolves, then a hostname an attacker invents resolves too, which is the ground state for subdomain takeover and for phishing hosted under a name that looks legitimate.

This is evidence of wildcard behaviour, not a proven fact. It rests on one control name: a domain could legitimately serve a TXT record at exactly that name for an unrelated reason, and a wildcard that answers address records but not TXT records would not be caught here at all. What this reading is and is not.

INFRASTRUCTURE MAPwhat mega-f.ru actually stands on - every host below is a signed observation
mega-f.ru
A / AAAA
45.9.26.252
unattributedserves the site
NS
ns1.mf-t.runs2.mf-t.runs3-l2.nic.runs4-l2.nic.ru+3 more
mf-t.ru + nic.ruanswers its DNS
MX
mx01.lancloud.rumx02.lancloud.rumx03.lancloud.rumx04.lancloud.ru
lancloud.rureceives its email

DNS Records

A 1

  • 45.9.26.252

MX 4

  • 10mx01.lancloud.ru
  • 10mx02.lancloud.ru
  • 10mx03.lancloud.ru
  • 10mx04.lancloud.ru

TXT 5

  • MS=ms64611019
  • yandex-verification: 87bba1a2e7446aa1
  • v= spf1 +a +mx include:lancloud.ru ~all
  • globalsign-domain-verification=riiIh_qaWwQm2IXcqEKF_UWKOXW74nDMBBbbHtp_lO
  • YBY7+luuJ8LP81Svm7fr9iK84P+lZBJ0ShmY6/EBnZVJOvwb5wrjgoIwvzZ2osC1c1JbX9ISW9VJW1MD5+ES0A==

NS 7

  • ns1.mf-t.ru
  • ns2.mf-t.ru
  • ns3-l2.nic.ru
  • ns4-l2.nic.ru
  • ns8-l2.nic.ru
  • ns4-cloud.nic.ru
  • ns8-cloud.nic.ru

SOA 1

  • ns3-l2.nic.ru golovanov.mega-f.ru

SRV 1

  • autodiscover.lancloud.ru:443 p1

TLS Certificates (0)

None.

Subdomains (0)

None observed.

The proof

Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; the only network request the check makes is for the published public keys.

Verify this receipt

Ed25519 Receipt

Receipt ID
rcpt_d52e6964f71dd640
Output Hash
61955d69b6198cb6ff7a22049fa8c5f9b72eb38e74dd0f33a6789868d1c841c1
Signature
ed25519:1aa2469b23498e6b0cbaaa8f472290ec12c49639e4aa94c4b8f36cbefbe9173e26edf809880932889636689605bc7ba46d148a41d7f793dd27e5b43a4c121b07
Public Key
ed25519:4859bb613d650e12dd7478cc307c73a8712fabc115a9dc59f65534ed3c09a8f9
Parent
(genesis)
Plane
fast
Verify this in your browser
CONTINUOUS INTERNET TELEMETRY24H DRIFT41,600 material changesacross 39,907 domains · 24h to ~75m ago · +41 vs yesterdayROTATION54 domains moved DNS from koaladns.com to magpiedns.com, 51 moved backa rotation loop, not a migration · 24hNOW507 curated domains not reachablelast probe, steadySITE ERRORS36,326 sites serving errorslast probe · 5xx / 404 / TLSBOT DEFENSEbot defense observed on 116,850 sites429 rate-limit / 403 bot-block, a posture signal