visit-mannheim.de
Observed Aug 2, 2026, 16:48 UTC (28m ago). Every field below was attested with an Ed25519 signature at scan time. Catalog observation, re-checked on rotation - watch it for 5-minute checks.
DomainDrift asked this domain for a TXT record at a name nobody registers, and got an answer back. A domain that answers a name that was never created is answering names in general, and that is wildcard DNS.
Wildcard DNS clusters around domain parking, dynamic DNS and catch-all hosting. It is also a real attack surface: if every invented hostname resolves, then a hostname an attacker invents resolves too, which is the ground state for subdomain takeover and for phishing hosted under a name that looks legitimate.
This is evidence of wildcard behaviour, not a proven fact. It rests on one control name: a domain could legitimately serve a TXT record at exactly that name for an unrelated reason, and a wildcard that answers address records but not TXT records would not be caught here at all. What this reading is and is not.
DNS Records
A 1
185.88.213.174
MX 5
0visitmannheim-de01c.mail.protection.outlook.com20mx02.hornetsecurity.com10mx01.hornetsecurity.com40mx04.hornetsecurity.com30mx03.hornetsecurity.com
TXT 3
facebook-domain-verification=2xhwmvnctfjvcb5of81bamtj9bvqg1v=spf1 include:spf.protection.outlook.com include:spf.hornetsecurity.com include:_spf.google.com -allMS=ms65952969
NS 2
ns81.domaincontrol.comns82.domaincontrol.com
SOA 1
ns81.domaincontrol.com dns.jomax.net
MCP_RECORDS 1
v=spf1 include:spf.protection.outlook.com include:spf.hornetsecurity.com include:_spf.google.com -all
DMARC_RECORDS 1
v=DMARC1; p=none
BIMI_RECORDS 1
v=spf1 include:spf.protection.outlook.com include:spf.hornetsecurity.com include:_spf.google.com -all
MTA_STS_RECORDS 1
v=spf1 include:spf.protection.outlook.com include:spf.hornetsecurity.com include:_spf.google.com -all
TLS Certificates (4)
| Common Name | Issuer | Expires |
|---|---|---|
visit-mannheim.de |
C=US, O=Let's Encrypt, CN=YE2 | Fri, 16 Oct 2026 11:37:44 +0000 |
YE2 |
C=US, O=ISRG, CN=Root YE | Sat, 02 Sep 2028 23:59:59 +0000 |
Root YE |
C=US, O=Internet Security Research Group, CN=ISRG Root X2 | Thu, 02 Sep 2032 23:59:59 +0000 |
ISRG Root X2 |
C=US, O=Internet Security Research Group, CN=ISRG Root X1 | Thu, 02 Sep 2032 23:59:59 +0000 |
Subdomains (1)
Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; nothing leaves your machine.
Verify this receiptEd25519 Receipt
- Receipt ID
rcpt_a93b176c96cdcc5c- Output Hash
d8e15d8a9d4e7ee043062f1c1feed7d62b66d9c93f918217acd6bd6b45836b6b- Signature
ed25519:cfa265bfd446243d6586d1bca4dc24fbe6eb0f1e51207be8c2ecdd9dd50ad01380df41957c6fb7773d61129bf6f55715ae256251cd530ffe040572c1120b6802- Public Key
ed25519:4859bb613d650e12dd7478cc307c73a8712fabc115a9dc59f65534ed3c09a8f9- Parent
(genesis)- Plane
- fast