CONTINUOUS INTERNET TELEMETRY24H DRIFT167 material changesacross 120 domains · +21 vs yesterdayEMAIL DRIFT1 domain switched email providertop destination xn----8sbafg9clhjcp.bgCERT DRIFT1 domains switched issuing CA24hNOW4,498 curated domains not answering+164 vs yesterdayERRORS29,606 responded with an errorlast probe · 5xx / 404 / TLSTHROTTLED87,620 throttled or blocked our scanner429 rate-limit / 403 bot-blockMOVERgov.brAll nameservers removed (domain is dark)24H DRIFT167 material changesacross 120 domains · +21 vs yesterdayEMAIL DRIFT1 domain switched email providertop destination xn----8sbafg9clhjcp.bgCERT DRIFT1 domains switched issuing CA24hNOW4,498 curated domains not answering+164 vs yesterdayERRORS29,606 responded with an errorlast probe · 5xx / 404 / TLSTHROTTLED87,620 throttled or blocked our scanner429 rate-limit / 403 bot-blockMOVERgov.brAll nameservers removed (domain is dark)

golf.com

Observed Jul 18, 2026, 13:22 UTC (3d ago). Every field below was attested with an Ed25519 signature at scan time.

Up right now
Runs onFastly
Email byMimecast
Secured byLet's Encrypt
Registered withNetwork Solutions, LLC
Also usesFacebook/MetaGoogle Search Console
IPv6 · 1 subdomain · tranco_40k
Every line above is a signed observation. Check the math at the bottom of the page.
INFRASTRUCTURE MAPwhat golf.com actually stands on - every host below is a signed observation
golf.com
A / AAAA
23.185.0.42620:12a:8001::42620:12a:8000::4
Fastlyserves the site
NS
quincy.ns.cloudflare.comsreeni.ns.cloudflare.com
cloudflare.comanswers its DNS
MX
us-smtp-inbound-1.mimecast.comus-smtp-inbound-2.mimecast.com
Mimecastreceives its email
TLS
golf.com
Let's Encryptissued its certificate

DNS Records

A 1

  • 23.185.0.4

AAAA 2

  • 2620:12a:8001::4
  • 2620:12a:8000::4

MX 2

  • 10us-smtp-inbound-1.mimecast.com
  • 10us-smtp-inbound-2.mimecast.com

TXT 15

  • /n/4X+Rqg4iU4sybJatBVfPyVBmqBJljwuWcKL92ucuhDy/kqOj3yaZldvfqVk0aj0Xph2Rusg/6h2NIDjXAgw==
  • MS=ms81406623
  • _globalsign-domain-verification=klUJkI4MZw-0elRtIBbVGs7d-e1CPM16mbnrVrKORw
  • amazonses:Ss6+MweaoG+qKERvyTSeaDOjM8wxfBGAf30Zm3tNiGU=
  • dqinv0plz05kh.cloudfront.net
  • facebook-domain-verification=kmkfy3p8y6rhsrex2pa8hv33rw9acw
  • globalsign-domain-verification=dvjFIatJrlYDGxFlwxd-fHmRGsYpRlED33VwLUgXli
  • google-site-verification=7Ly2DLc2WeBOutgUU6z2tkp0vfR_VrmocTnQFtt1dXo
  • google-site-verification=XLEB2CQRR6xhSfptwDminlSiH2jFQSjr0gpYsxb6sQY
  • google-site-verification=lKt12J5RD7yKQzsCjPjo0bZZNdjOeEAeN4A76XdO48k

NS 2

  • quincy.ns.cloudflare.com
  • sreeni.ns.cloudflare.com

SOA 1

  • quincy.ns.cloudflare.com dns.cloudflare.com

TLS Certificates (3)

Common NameIssuerExpires
golf.com C=US, O=Let's Encrypt, CN=YR2 Wed, 16 Sep 2026 20:55:32 +0000
YR2 C=US, O=ISRG, CN=Root YR Sat, 02 Sep 2028 23:59:59 +0000
Root YR C=US, O=Internet Security Research Group, CN=ISRG Root X1 Thu, 02 Sep 2032 23:59:59 +0000

Subdomains (1)

The proof

Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; nothing leaves your machine.

Verify this receipt

Put the receipt on your own site. A live badge showing what DomainDrift observes and signs for golf.com. It updates itself. It attests a signed observation - not that the site is safe.

DomainDrift signed-observation badge for golf.com <a href="https://domaindrift.io/t/golf.com"> <img src="https://domaindrift.io/badge/golf.com.svg" width="300" height="64" alt="DomainDrift signed observations for golf.com"> </a>

Ed25519 Receipt

Receipt ID
5cb06d55-0821-4e27-813c-0e478ad16e51
Output Hash
15b31b4b430014f47a1202a43c2d62fe21054b4b981046df94f7de9d6628d296
Signature
ed25519:8937a1c96564bf77e737f7837752f9aceba34bb5965a5e509f9d25fc6537f56a54a3f3ed8a3806d036e3ea1c2b26714e7440b16bbb4506d0b1b9bac913d36705
Public Key
ed25519:178c3bd0f57d9d64b83cc4630753381e1a465005a2bbba3d032371f24af0bfd8
Parent
(genesis)
Plane
fast
Verify this in your browser