anom.ru

Observed Aug 29, 2026, 19:23 UTC (1h ago). Every field below was attested with an Ed25519 signature at scan time. Catalog observation, re-checked on rotation - watch it for 5-minute checks.

Not responding
Runs onCloudflare
Registered withREGRU-RU
94 subdomains · tranco
Every line above is a signed observation. Check the math at the bottom of the page.
DRIFT

Steady. No change on record for anom.ru in the last day; this reading matches the one before it. The steady record is signed like every other reading. Watch it to catch the next move the moment it lands.

HTTPS probe

Server error Server error (5xx) 521 Server Error
HTTP status521
Servercloudflare
TLS protocolHTTP/2
TLS issuernot observed
Behind Cloudflareyes
Response time515 ms
DNS resolutionNOERROR
What this reading means

The site answered with a 5xx, so the edge and TLS are working and the application behind them is not.

It does NOT mean the domain or its DNS is misconfigured - the request got all the way to an application to fail there.

What produces this, in rough order of how often
  • The origin is erroring or mid-deploy.
  • An upstream in front of the origin cannot reach it.

These are the known causes, not a diagnosis of this domain. We recorded that nothing answered; we did not measure why.

MCP This domain advertises an AI service endpoint at _mcp._tcp.
3 endpoints - withheld

Every field above is part of the same signed observation as the records below. Blank means not observed, never "none".

SIGNED-OUT VIEW Provider names, posture and counts are shown. The record values - every DNS answer, each subdomain hostname, raw TXT, IPs, cert names and WHOIS - are the product. Sign in for the full signed record, or use the API with a key.

DNS records 15

A1NS2MX1TXT10SOA1

TLS certificates 0

None.

Subdomains 94

94 subdomain hostnames observed and signed - the list itself is part of the paid record.

WILDCARD DNSobserved 2026-08-29 19:23 UTC

DomainDrift asked this domain for one hostname that nobody ever registered, and it answered. A domain that answers invented hostnames is running wildcard DNS. It is common and usually deliberate. A SaaS platform gives every customer a subdomain this way. How the check works

The proof

Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; the only network request the check makes is for the published public keys.

Verify this receipt
Ed25519 receiptthe raw cryptographic proof
Receipt ID
rcpt_470af6ac455bf8e7
Output Hash
19b7125ff5d8b864b282fb55bab754fe8dd1088a36463ed783443309aca2ba04
Signature
ed25519:306605cc49cbf8b816fb1f49e793760e9de76f417de4ae488f4eb987d5ffac4f04104b91faef7ac7c8411158cfcb43e67b667494908e2d27cae4ebf457547c04
Public Key
ed25519:7aad40f2d6399c207fe2fc15aade04a78324787a355d36725cc90687f9e10cff
Parent
(genesis)
Plane
fast
CONTINUOUS INTERNET TELEMETRY24H DRIFT8,857 material changesacross 6,876 domains · 24h to ~2h ago · +1,320 vs yesterdayROTATION54 domains moved DNS from kirklanddc.com to koaladns.com, 53 moved backa rotation loop, not a migration · 24hEMAIL DRIFT2 domains switched email provider24hCERT DRIFT1 domains switched issuing CA24hREGISTRAR DRIFT2 changed registrar24hNOW554 curated domains not reachablelast probe, steadySITE ERRORS17,774 sites serving errorslast probe · 5xx / 404 / TLSBOT DEFENSEbot defense observed on 79,256 sites429 rate-limit / 403 bot-block, a posture signal