CONTINUOUS INTERNET TELEMETRY24H DRIFT154 material changesacross 106 domains · +8 vs yesterdayEMAIL DRIFT1 domain switched email providertop destination xn----8sbafg9clhjcp.bgCERT DRIFT1 domains switched issuing CA24hNOW4,351 curated domains not answeringlast probe, steadyERRORS28,433 responded with an errorlast probe · 5xx / 404 / TLSTHROTTLED85,471 throttled or blocked our scanner429 rate-limit / 403 bot-blockMOVERgov.brAll nameservers removed (domain is dark)24H DRIFT154 material changesacross 106 domains · +8 vs yesterdayEMAIL DRIFT1 domain switched email providertop destination xn----8sbafg9clhjcp.bgCERT DRIFT1 domains switched issuing CA24hNOW4,351 curated domains not answeringlast probe, steadyERRORS28,433 responded with an errorlast probe · 5xx / 404 / TLSTHROTTLED85,471 throttled or blocked our scanner429 rate-limit / 403 bot-blockMOVERgov.brAll nameservers removed (domain is dark)

tfi.com

Observed Jul 18, 2026, 12:07 UTC (3d ago). Every field below was attested with an Ed25519 signature at scan time.

Up right now
Runs onIONOS SE
Secured bySectigo
logistics_expanded
Every line above is a signed observation. Check the math at the bottom of the page.
INFRASTRUCTURE MAPwhat tfi.com actually stands on - every host below is a signed observation
tfi.com
A / AAAA
74.208.236.198
IONOS SEserves the site
NS
ns51.1and1.comns52.1and1.com
1and1.comanswers its DNS
MX
mx01.1and1.commx00.1and1.com
1and1.comreceives its email
TLS
*.tfi.com
Sectigo Limitedissued its certificate

DNS Records

A 1

  • 74.208.236.198

MX 2

  • 10mx01.1and1.com
  • 10mx00.1and1.com

TXT 2

  • v=spf1 include:_spf.perfora.net include:_spf.kundenserver.de -all
  • v=DMARC1; p=none

NS 2

  • ns51.1and1.com
  • ns52.1and1.com

SOA 1

  • ns51.1and1.com hostmaster.1and1.com

TLS Certificates (4)

Common NameIssuerExpires
*.tfi.com C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA DV R36 Wed, 18 Nov 2026 23:59:59 +0000
Sectigo Public Server Authentication CA DV R36 C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication Root R46 Fri, 21 Mar 2036 23:59:59 +0000
Sectigo Public Server Authentication Root R46 C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority Mon, 18 Jan 2038 23:59:59 +0000
USERTrust RSA Certification Authority C=GB, ST=Greater Manchester, L=Salford, O=Comodo CA Limited, CN=AAA Certificate Services Sun, 31 Dec 2028 23:59:59 +0000

Subdomains (0)

None observed.

The proof

Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; nothing leaves your machine.

Verify this receipt

Put the receipt on your own site. A live badge showing what DomainDrift observes and signs for tfi.com. It updates itself. It attests a signed observation - not that the site is safe.

DomainDrift signed-observation badge for tfi.com <a href="https://domaindrift.io/t/tfi.com"> <img src="https://domaindrift.io/badge/tfi.com.svg" width="300" height="64" alt="DomainDrift signed observations for tfi.com"> </a>

Ed25519 Receipt

Receipt ID
6e14af9a-2c65-4817-ae5b-5cad301353f4
Output Hash
089e6abbf08579c53f8decfbf4cc02cd556a7b919435d0d72f03f15cf0eaa9af
Signature
ed25519:03bb2b8e26ddbf62a49f50d29294966444174e5c3d733d50957c0dfac64d4de5ca85a206a2df25ea96b07445c3fa53c6895767404aad08c66936a5b34301c604
Public Key
ed25519:178c3bd0f57d9d64b83cc4630753381e1a465005a2bbba3d032371f24af0bfd8
Parent
(genesis)
Plane
fast
Verify this in your browser