mein-senec.de

Observed Aug 16, 2026, 17:44 UTC (2h ago). Every field below was attested with an Ed25519 signature at scan time. Catalog observation, re-checked on rotation - watch it for 5-minute checks.

Up right now
Runs onM-net Telekommunikations
Secured byDigiCert
Also usesGlobalSign
tranco
Every line above is a signed observation. Check the math at the bottom of the page.
EVIDENCE OF WILDCARD DNSobserved 2026-08-16 17:44 UTC

DomainDrift asked this domain for a TXT record at a name nobody registers, and got an answer back. A domain that answers a name that was never created is answering names in general, and that is wildcard DNS.

Wildcard DNS clusters around domain parking, dynamic DNS and catch-all hosting. It is also a real attack surface: if every invented hostname resolves, then a hostname an attacker invents resolves too, which is the ground state for subdomain takeover and for phishing hosted under a name that looks legitimate.

This is evidence of wildcard behaviour, not a proven fact. It rests on one control name: a domain could legitimately serve a TXT record at exactly that name for an unrelated reason, and a wildcard that answers address records but not TXT records would not be caught here at all. What this reading is and is not.

INFRASTRUCTURE MAPwhat mein-senec.de actually stands on - every host below is a signed observation
mein-senec.de
A / AAAA
185.36.117.224
M-net Telekommunikationsserves the site
NS
ns2.fn-ns.netns3.fn-ns.dens1.fn-ns.netns4.fn-ns.de
fn-ns.net + fn-ns.deanswers its DNS
MX
mail.mein-senec.de
mein-senec.dereceives its email
TLS
*.mein-senec.de
DigiCert Incissued its certificate

DNS Records

A 1

  • 185.36.117.224

MX 1

  • 10mail.mein-senec.de

TXT 4

  • kdxf22rlvhxdnjqxl2wn9869wr4vtt4g
  • _nho6vkjxe2tbv5r3caf7bwm0n8zxnwg
  • _globalsign-domain-verification=-SSSL9wfzDOjtTGjTgJfeYYiINUlXveZfhi6HVm_yU
  • _4zr2u1w3h7b9o1pqafrn0y40wssv7or

NS 4

  • ns2.fn-ns.net
  • ns3.fn-ns.de
  • ns1.fn-ns.net
  • ns4.fn-ns.de

SOA 1

  • ns1.fn-ns.net hostmaster.internetwire.de

MCP_RECORDS 2

  • _cszdldwlexyqoyd2ev29b55suu3djeq
  • r0fl05y3wnvv5b0zw0qkqh1gjrw7bhfz

DMARC_RECORDS 2

  • _cszdldwlexyqoyd2ev29b55suu3djeq
  • r0fl05y3wnvv5b0zw0qkqh1gjrw7bhfz

BIMI_RECORDS 2

  • _cszdldwlexyqoyd2ev29b55suu3djeq
  • r0fl05y3wnvv5b0zw0qkqh1gjrw7bhfz

MTA_STS_RECORDS 2

  • r0fl05y3wnvv5b0zw0qkqh1gjrw7bhfz
  • _cszdldwlexyqoyd2ev29b55suu3djeq

TLS Certificates (2)

Common NameIssuerExpires
*.mein-senec.de C=US, O=DigiCert Inc, 2.5.4.11=www.digicert.com, CN=Thawte TLS RSA CA G1 Thu, 07 Jan 2027 23:59:59 +0000
Thawte TLS RSA CA G1 C=US, O=DigiCert Inc, 2.5.4.11=www.digicert.com, CN=DigiCert Global Root G2 Tue, 02 Nov 2027 12:24:25 +0000

Subdomains (0)

None observed.

The proof

Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; the only network request the check makes is for the published public keys.

Verify this receipt

Ed25519 Receipt

Receipt ID
rcpt_ac71c7b115b3eb3a
Output Hash
870cd6939c34bfc368bf0d055bd72a9694dcf8edc769f2f2a34d2df3548bbc21
Signature
ed25519:37b9f8017ff5e85b922ad8c0180339c547179e7493714a5af1201c20425c1a4adf7d03fb52bf0e2d3311af9977ff2269d4df73146f7d121627af20ddbf99210b
Public Key
ed25519:4859bb613d650e12dd7478cc307c73a8712fabc115a9dc59f65534ed3c09a8f9
Parent
(genesis)
Plane
fast
Verify this in your browser
CONTINUOUS INTERNET TELEMETRY24H DRIFT39,710 material changesacross 37,679 domains · 24h to ~2h ago · -1,849 vs yesterdayROTATION66 domains moved DNS from magpiedns.com to koaladns.com, 66 moved backa rotation loop, not a migration · 24hEMAIL DRIFT3 domains switched email provider24hNOW595 curated domains not reachable+100 vs yesterdaySITE ERRORS35,880 sites serving errorslast probe · 5xx / 404 / TLSBOT DEFENSEbot defense observed on 116,382 sites429 rate-limit / 403 bot-block, a posture signal