CONTINUOUS INTERNET TELEMETRY24H DRIFT8,763 material changesacross 8,372 domains · 24h to ~2h ago · -32,097 vs yesterdayNOW563 curated domains not reachablelast probe, steadySITE ERRORS34,264 sites serving errorslast probe · 5xx / 404 / TLSBOT DEFENSEbot defense observed on 156,299 sites429 rate-limit / 403 bot-block, a posture signalMOVERokta.comNo mail routes in the latest observation

zelmer.pl

Observed Aug 2, 2026, 09:58 UTC (14h ago). Every field below was attested with an Ed25519 signature at scan time. Catalog observation, re-checked on rotation - watch it for 5-minute checks.

Up right now
Runs onCloudflare
Email byMicrosoft 365
Secured byGoogle Trust Services
Also usesFacebook/Meta
IPv6 · tranco
Every line above is a signed observation. Check the math at the bottom of the page.
EVIDENCE OF WILDCARD DNSobserved 2026-08-02 09:58 UTC

DomainDrift asked this domain for a TXT record at a name nobody registers, and got an answer back. A domain that answers a name that was never created is answering names in general, and that is wildcard DNS.

Wildcard DNS clusters around domain parking, dynamic DNS and catch-all hosting. It is also a real attack surface: if every invented hostname resolves, then a hostname an attacker invents resolves too, which is the ground state for subdomain takeover and for phishing hosted under a name that looks legitimate.

This is evidence of wildcard behaviour, not a proven fact. It rests on one control name: a domain could legitimately serve a TXT record at exactly that name for an unrelated reason, and a wildcard that answers address records but not TXT records would not be caught here at all. What this reading is and is not.

INFRASTRUCTURE MAPwhat zelmer.pl actually stands on - every host below is a signed observation
zelmer.pl
A / AAAA
172.67.68.84104.26.7.49104.26.6.492606:4700:20::681a:631+2 more
Cloudflareserves the site
NS
johnathan.ns.cloudflare.commolly.ns.cloudflare.com
cloudflare.comanswers its DNS
MX
zelmer-pl.mail.protection.outlook.com
Microsoft 365receives its email
TLS
zelmer.pl
Google Trust Servicesissued its certificate

DNS Records

A 3

  • 172.67.68.84
  • 104.26.7.49
  • 104.26.6.49

AAAA 3

  • 2606:4700:20::681a:631
  • 2606:4700:20::681a:731
  • 2606:4700:20::ac43:4454

MX 1

  • 0zelmer-pl.mail.protection.outlook.com

TXT 3

  • MS=ms47195113
  • facebook-domain-verification=ifs7pd8zxgok3opkwp0gg4x62qg9os
  • v=spf1 mx a a:out.zelmer.pl a:red.zelmer.pl include:spf.protection.outlook.com include:_spf.getresponse.com ~all

NS 2

  • johnathan.ns.cloudflare.com
  • molly.ns.cloudflare.com

SOA 1

  • johnathan.ns.cloudflare.com dns.cloudflare.com

MCP_RECORDS 1

  • BSH Hausgeraete GmbH

DMARC_RECORDS 1

  • v=DMARC1; p=none;

BIMI_RECORDS 1

  • BSH Hausgeraete GmbH

MTA_STS_RECORDS 1

  • BSH Hausgeraete GmbH

TLS Certificates (3)

Common NameIssuerExpires
zelmer.pl C=US, O=Google Trust Services, CN=WE1 Tue, 29 Sep 2026 11:21:30 +0000
WE1 C=US, O=Google Trust Services LLC, CN=GTS Root R4 Tue, 20 Feb 2029 14:00:00 +0000
GTS Root R4 C=BE, O=GlobalSign nv-sa, 2.5.4.11=Root CA, CN=GlobalSign Root CA Fri, 28 Jan 2028 00:00:42 +0000

Subdomains (0)

None observed.

The proof

Signed at scan time. Check the math yourself. Every line above is part of one signed observation. Re-hash it and check the Ed25519 signature in your own browser; nothing leaves your machine.

Verify this receipt

Ed25519 Receipt

Receipt ID
rcpt_1ed077b8bb806b17
Output Hash
575bcee97e5938241966a4ce3514089e1894cebe114b07ddd5cf6a66ec9b0d0c
Signature
ed25519:fdeb19340e7478b47024aba2936fbb04aab6aaea1d637a4fd910e3b03315dddc1b69259d61768c71d9abb90a24f9911dc4a581a73bea7ed865391133e822f50b
Public Key
ed25519:4859bb613d650e12dd7478cc307c73a8712fabc115a9dc59f65534ed3c09a8f9
Parent
(genesis)
Plane
fast
Verify this in your browser