CONTINUOUS INTERNET TELEMETRY24H DRIFT219 material changesacross 144 domains · +73 vs yesterdayEMAIL DRIFT1 domain switched email providertop destination xn----8sbafg9clhjcp.bgNOW4,691 curated domains not answering+357 vs yesterdayERRORS30,432 responded with an errorlast probe · 5xx / 404 / TLSTHROTTLED88,598 throttled or blocked our scanner429 rate-limit / 403 bot-blockMOVERgov.brAll nameservers removed (domain is dark)24H DRIFT219 material changesacross 144 domains · +73 vs yesterdayEMAIL DRIFT1 domain switched email providertop destination xn----8sbafg9clhjcp.bgNOW4,691 curated domains not answering+357 vs yesterdayERRORS30,432 responded with an errorlast probe · 5xx / 404 / TLSTHROTTLED88,598 throttled or blocked our scanner429 rate-limit / 403 bot-blockMOVERgov.brAll nameservers removed (domain is dark)

thg.com

Observed Jul 18, 2026, 13:16 UTC (3d ago). Every field below was attested with an Ed25519 signature at scan time.

Up right now
Runs onCloudflare
Email byMimecast
Secured byLet's Encrypt
Registered withKey-Systems GmbH
Also usesGoogle Search ConsoleFacebook/MetaAtlassian1PasswordDocuSign
IPv6 · tranco_40k
Every line above is a signed observation. Check the math at the bottom of the page.
INFRASTRUCTURE MAPwhat thg.com actually stands on - every host below is a signed observation
thg.com
A / AAAA
146.75.37.912a04:4e42:95::347
Cloudflareserves the site
NS
dns1.p05.nsone.netdns2.p05.nsone.netdns3.p05.nsone.netdns4.p05.nsone.net+4 more
nsone.net + thg-ns.netanswers its DNS
MX
eu-smtp-inbound-1.mimecast.comeu-smtp-inbound-2.mimecast.com
Mimecastreceives its email
TLS
thg.com
Let's Encryptissued its certificate

DNS Records

A 1

  • 146.75.37.91

AAAA 1

  • 2a04:4e42:95::347

MX 2

  • 40eu-smtp-inbound-1.mimecast.com
  • 40eu-smtp-inbound-2.mimecast.com

TXT 26

  • 0ed1fe018a268a91c0e1a34f199cf23d88c0cd36e2
  • MS=ms27094714
  • MS=ms92159595
  • 3f7bd5ece62f487a80eed905c2779003
  • google-site-verification=NRpaYgjjJ4yw19Vbq9567DGFb1KURDSSpc2JWBOMiEM
  • v=spf1 include:eu._netblocks.mimecast.com -all
  • apple-domain-verification=kT3WOPyNaVxLlopf
  • 654tmcj71f8y2pgkm34x4gw6f1xhh7zv
  • facebook-domain-verification=0n2osltn0sqhtdyr1f2uhxbq24r37v
  • ca3-7f45acab88cc415eb6e0a3d056faa54d

NS 8

  • dns1.p05.nsone.net
  • dns2.p05.nsone.net
  • dns3.p05.nsone.net
  • dns4.p05.nsone.net
  • ns01.thg-ns.net
  • ns02.thg-ns.net
  • ns03.thg-ns.net
  • ns04.thg-ns.net

SOA 1

  • dns1.p05.nsone.net hostmaster.nsone.net

TLS Certificates (3)

Common NameIssuerExpires
thg.com C=US, O=Let's Encrypt, CN=YR2 Sun, 04 Oct 2026 21:53:02 +0000
YR2 C=US, O=ISRG, CN=Root YR Sat, 02 Sep 2028 23:59:59 +0000
Root YR C=US, O=Internet Security Research Group, CN=ISRG Root X1 Thu, 02 Sep 2032 23:59:59 +0000

Subdomains (0)

None observed.

The proof

Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; nothing leaves your machine.

Verify this receipt

Put the receipt on your own site. A live badge showing what DomainDrift observes and signs for thg.com. It updates itself. It attests a signed observation - not that the site is safe.

DomainDrift signed-observation badge for thg.com <a href="https://domaindrift.io/t/thg.com"> <img src="https://domaindrift.io/badge/thg.com.svg" width="300" height="64" alt="DomainDrift signed observations for thg.com"> </a>

Ed25519 Receipt

Receipt ID
2e2d3f12-bf9f-45cb-9370-39789e5af37a
Output Hash
3a58b240b13afe4c8c82ab4cb510dbf31c058715203d9af514ce9770354cfb5d
Signature
ed25519:98cb68dcf21043b4354f753d53d7d32ea75316bf2a0ac6ea39d291c352a324887ea9dae262fc8fa823d1d13541e0435c1589ea164cd22450b8c0dbf3b2d39d0d
Public Key
ed25519:178c3bd0f57d9d64b83cc4630753381e1a465005a2bbba3d032371f24af0bfd8
Parent
(genesis)
Plane
fast
Verify this in your browser