asco.org
Observed Aug 3, 2026, 00:43 UTC (7d ago). Every field below was attested with an Ed25519 signature at scan time.
asco.org is on the survey sweep, which works its way across the whole catalog rather than returning to one name on a schedule. Putting asco.org under watch moves it to the fast lane, where DomainDrift re-checks it about every 5 minutes and signs each reading, so a change becomes a dated event within minutes instead of waiting for the sweep to come round.
Watch asco.org Watching a domain needs a DRM3 account. The reading above stays free and public either way.DomainDrift asked this domain for a TXT record at a name nobody registers, and got an answer back. A domain that answers a name that was never created is answering names in general, and that is wildcard DNS.
Wildcard DNS clusters around domain parking, dynamic DNS and catch-all hosting. It is also a real attack surface: if every invented hostname resolves, then a hostname an attacker invents resolves too, which is the ground state for subdomain takeover and for phishing hosted under a name that looks legitimate.
This is evidence of wildcard behaviour, not a proven fact. It rests on one control name: a domain could legitimately serve a TXT record at exactly that name for an unrelated reason, and a wildcard that answers address records but not TXT records would not be caught here at all. What this reading is and is not.
DNS Records
A 4
18.238.80.12118.238.80.4718.238.80.7118.238.80.41
MX 3
10mx1.asco.iphmx.com20mx2.asco.iphmx.com30smtp.asco.org
TXT 41
3udhdp6vr3fj5i2ac5fsaaa1406883a2355cdea79aa271045762a08d094b72d141ca7830d9a28974ef14c8365b@ 3600 IN TXT adobe-idp-site-verification=14fb9397d12ba236fb2b9dec4bc44c14ddd58b94a62aeae49c83ce2db36efb6b@ apple-domain-verification=M7lm2xIPV57fOqd9Donotreply@asco.orgHwCX3HhmzjUzsxvl0rkVy0d8SzVuWWZxsjgl22Dud4yrANHUpElkKe0Coc1Wg9b5b1Laoibo6FMjEbrX8lpsNg==MS=ms40377815SpyCloud-verification=ab89ec97022baef58aaa68ff63edab0590efe1c1Wdxmky5vEftLPuNaKAIArZNKDJLaKccuO8H02fg+k4gF6rS53iZEqkghlbITC1xd3/vfe2IOXNYwfPHNm9VGxw==ZOOM_verify_1TiEju7zQzYRSjs3CcHyUP
NS 4
ns-1033.awsdns-01.orgns-1786.awsdns-31.co.ukns-705.awsdns-24.netns-95.awsdns-11.com
SOA 1
ns-95.awsdns-11.com awsdns-hostmaster.amazon.com
MCP_RECORDS 1
a69bfbcb5d654c87a3945d38b435d2e0
DMARC_RECORDS 1
v=DMARC1; p=none;
BIMI_RECORDS 1
a69bfbcb5d654c87a3945d38b435d2e0
MTA_STS_RECORDS 1
a69bfbcb5d654c87a3945d38b435d2e0
TLS Certificates (3)
| Common Name | Issuer | Expires |
|---|---|---|
asco.org |
C=US, O=Amazon, CN=Amazon RSA 2048 M01 | Wed, 25 Nov 2026 23:59:59 +0000 |
Amazon RSA 2048 M01 |
C=US, O=Amazon, CN=Amazon Root CA 1 | Fri, 23 Aug 2030 22:21:28 +0000 |
Amazon Root CA 1 |
C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Services Root Certificate Authority - G2 | Thu, 31 Dec 2037 01:00:00 +0000 |
Subdomains (0)
None observed.
Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; the only network request the check makes is for the published public keys.
Verify this receiptEd25519 Receipt
- Receipt ID
rcpt_5c28918adba9c15d- Output Hash
2fe623d9b37a2007bb26071557e2ddad706e3689bdc2e674bdc4be0e32d46021- Signature
ed25519:d93b7c2c539a715e955da96db4ad030ac660f51e18174c567f6ec08cdb7a386aed802aae2fb220125666d5e20eeb4c22cc39214f09b9ae9ea1e68a0aa0525608- Public Key
ed25519:4859bb613d650e12dd7478cc307c73a8712fabc115a9dc59f65534ed3c09a8f9- Parent
(genesis)- Plane
- fast