razor-returns.de

Observed Aug 11, 2026, 05:28 UTC (7d ago). Every field below was attested with an Ed25519 signature at scan time.

This reading of razor-returns.de was taken 7d ago

razor-returns.de is on the survey sweep, which works its way across the whole catalog rather than returning to one name on a schedule. Putting razor-returns.de under watch moves it to the fast lane, where DomainDrift re-checks it about every 5 minutes and signs each reading, so a change becomes a dated event within minutes instead of waiting for the sweep to come round.

Watch razor-returns.de Watching a domain needs a DRM3 account. The reading above stays free and public either way.
Guarded by a firewall
Runs onCloudflare
Secured byZeroSSL GmbH
tranco
Every line above is a signed observation. Check the math at the bottom of the page.
DRIFT

Steady. No change on record for razor-returns.de in the last day; this reading matches the one before it. The steady record is signed like every other reading. Watch it to catch the next move the moment it lands.

INFRASTRUCTURE MAPwhat razor-returns.de actually stands on - every host below is a signed observation
razor-returns.de
A / AAAA
168.119.165.93
Cloudflareserves the site
NS
ns1.redirectdom.comns2.redirectdom.com
redirectdom.comanswers its DNS
TLS
razor-returns.de
ZeroSSL GmbHissued its certificate

DNS Records

A 1

  • 168.119.165.93

NS 2

  • ns1.redirectdom.com
  • ns2.redirectdom.com

SOA 1

  • ns1.redirectdom.com dnsmaster.ns1.redirectdom.com

DMARC_RECORDS 1

  • v=spf1 -all

TLS Certificates (3)

Common NameIssuerExpires
razor-returns.de C=AT, O=ZeroSSL GmbH, CN=ZeroSSL ECC DV SSL CA 2 Mon, 09 Nov 2026 23:59:59 +0000
ZeroSSL ECC DV SSL CA 2 C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication Root E46 Sun, 23 Sep 2035 23:59:59 +0000
Sectigo Public Server Authentication Root E46 C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust ECC Certification Authority Mon, 18 Jan 2038 23:59:59 +0000

Subdomains (0)

None observed.

WILDCARD DNSobserved 2026-08-10 07:18 UTC

DomainDrift asked this domain for one hostname that nobody ever registered, and it answered. A domain that answers invented hostnames is running wildcard DNS. It is common and usually deliberate. A SaaS platform gives every customer a subdomain this way. How the check works

The proof

Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; the only network request the check makes is for the published public keys.

Verify this receipt

Ed25519 Receipt

Receipt ID
rcpt_5eb8d2ccb4466a71
Output Hash
142f2c39f074998c2c5f7e3610b4657039327a4151a7e46ef78fadc66b049d48
Signature
ed25519:11c11dae79f991395a8a677cdcaedaef685c6856ab6e8e5582fd07fdf81a3803ee8e7eab7c45e9ec44b2af1b83c65c9f787ee0b8937e94656e6a6ce3c867590f
Public Key
ed25519:4859bb613d650e12dd7478cc307c73a8712fabc115a9dc59f65534ed3c09a8f9
Parent
(genesis)
Plane
fast
Verify this in your browser
CONTINUOUS INTERNET TELEMETRY24H DRIFT35,025 material changesacross 31,732 domains · 24h to ~3h ago · -6,226 vs yesterdayROTATION79 domains moved DNS from magpiedns.com to kirklanddc.com, 73 moved backa rotation loop, not a migration · 24hEMAIL DRIFT6 domains switched email provider24hNOW489 curated domains not reachablelast probe, steadySITE ERRORS33,767 sites serving errorslast probe · 5xx / 404 / TLSBOT DEFENSEbot defense observed on 116,231 sites429 rate-limit / 403 bot-block, a posture signal