whatyouexpect.eu

Observed Aug 21, 2026, 04:58 UTC (3d ago). Every field below was attested with an Ed25519 signature at scan time.

This reading of whatyouexpect.eu was taken 3d ago

whatyouexpect.eu is on the survey sweep, which works its way across the whole catalog rather than returning to one name on a schedule. Putting whatyouexpect.eu under watch moves it to the fast lane, where DomainDrift re-checks it about every 5 minutes and signs each reading, so a change becomes a dated event within minutes instead of waiting for the sweep to come round.

Watch whatyouexpect.eu Watching a domain needs a DRM3 account. The reading above stays free and public either way.
Up right now
Runs onCloudflare
Email byProofpoint
Also usesMicrosoft 365
96 subdomains · tranco
Every line above is a signed observation. Check the math at the bottom of the page.
DRIFT

Steady. No change on record for whatyouexpect.eu in the last day; this reading matches the one before it. The steady record is signed like every other reading. Watch it to catch the next move the moment it lands.

HTTPS probe

Up Responding normally (2xx) 200 OK
HTTP status200
Servercloudflare
TLS protocolHTTP/2
TLS issuernot observed
Behind Cloudflareyes
Response time928 ms
DNS resolutionNOERROR
MCP This domain advertises an AI service endpoint at _mcp._tcp.
2 endpoints - withheld

Every field above is part of the same signed observation as the records below. Blank means not observed, never "none".

SIGNED-OUT VIEW Provider names, posture and counts are shown. The record values - every DNS answer, each subdomain hostname, raw TXT, IPs, cert names and WHOIS - are the product. Sign in for the full signed record, or use the API with a key.

DNS records 16

A3NS4MX2TXT6SOA1

TLS certificates 0

None.

Subdomains 96

96 subdomain hostnames observed and signed - the list itself is part of the paid record.

WILDCARD DNSobserved 2026-08-21 04:58 UTC

DomainDrift asked this domain for one hostname that nobody ever registered, and it answered. A domain that answers invented hostnames is running wildcard DNS. It is common and usually deliberate. A SaaS platform gives every customer a subdomain this way. How the check works

The proof

Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; the only network request the check makes is for the published public keys.

Verify this receipt
Ed25519 receiptthe raw cryptographic proof
Receipt ID
rcpt_d20bd7fb04c48f6d
Output Hash
1e54bf2ed59c5176d197683cbe65a1b04c08b03097868dd0966f4c8907daa869
Signature
ed25519:709bb8059474f631c6f07fddb441c1a59237d93b8582962590b2b5387ec273518daf4315217b06f2be4e3b404a7fd275070634e71ecb9391a3fc90382ac58f00
Public Key
ed25519:7aad40f2d6399c207fe2fc15aade04a78324787a355d36725cc90687f9e10cff
Parent
(genesis)
Plane
fast
CONTINUOUS INTERNET TELEMETRY24H DRIFTat least 3,058 material changesacross 1,754+ domains · 24h to ~6h ago · a floor, 18h of 24 walkedROTATION62 domains moved DNS from magpiedns.com to koaladns.com, 59 moved backa rotation loop, not a migration · 24hREGISTRAR DRIFT5 changed registrar24hNOW362 curated domains not reachable+35 vs yesterdaySITE ERRORS17,832 sites serving errorslast probe · 5xx / 404 / TLSBOT DEFENSEbot defense observed on 79,029 sites429 rate-limit / 403 bot-block, a posture signal