DomainDrift for security operations
Mail posture drifts quietly. The record should not.
A DMARC slide to p=none passes every checkbox audit while enforcing nothing. A registrar change nobody ordered is the first symptom of a domain changing hands. DomainDrift watches the control planes: email authentication, certificates, registration, registry status, and lands each material change as a signed, timestamped event with the value before and the value after. A certificate issuer that changes, or an expiry drawing close, is estate posture the same as a mail record. Lookalikes you name go under the same watch, from before they resolve.
Email authentication drift, last 24 hours
DMARC, SPF, DKIM and MTA-STS transitions observed on watched domains, each with its stored summary.
DNSSEC, measured rather than assumed
A zone signing itself is a control-plane fact, and it is only worth anything if the record knows the difference between "off" and "never looked".
DomainDrift asks a domain's nameservers for its DNSKEY records directly, and writes the answer down only when the lookup actually succeeded. Turning DNSSEC on, or off, then lands as a dated event with the value before and the value after, the same as an email-authentication move, and the reading behind it is signed like every other.
Scope, plainly: that lookup runs on a slower pass across the whole catalog, not on the five-minute lane a name you add gets for DNS and reachability, so DomainDrift does not publish a DNSSEC posture for an entire estate on demand. A domain the pass has not reached carries no DNSSEC state at all, and the record says so instead of reporting it as unsigned. An absence nobody measured is not an absence.
Lookalike domains, watched from before they resolve
Brand impersonation and typosquats start as a name that answers nothing. A name that answers nothing is still a reading.
- Name it. Add a lookalike to a watch group. Registered or not, resolving or not. The first signed reading lands in seconds; the five-minute watch lane runs under it from there.
- The reading before. A resolver answering NXDOMAIN has answered. That answer is signed and dated like any other reading, and it is the baseline.
- The reading after. The day the name starts answering, the change lands as a dated event: the empty side before, the nameservers, mail exchangers and certificate after. The alert carries the same event.
Takedown work wants an exhibit, not a screenshot. Both readings export as a dated evidence report, and the registrar or host who receives it re-checks every signature in the public verifier, offline, with no account. A signature proves who took a reading and that it has not been altered since. It does not make the reading correct.
Scope, plainly: DomainDrift reads a curated catalog plus the domains you name. It does not enumerate every lookalike of a brand, and it does not judge whether a site is phishing. It records what each name published, and when.
Two steps in
curl https://domaindrift.io/v1/domains/example.com
One keyless request every 15 seconds per IP, for any domain in the catalog. It returns a reduced preview record with a receipt pointer you can resolve right away.
Opens the complete signed record and every list in full, and puts one of your own domains under watch. 20 API requests a day, refreshed at midnight UTC.
Pro puts your estate and your watchlist under the same signed watch, with webhook alerts your SOC can route.
Create an account →