DomainDrift for security operations

Mail posture drifts quietly. The record should not.

A DMARC slide to p=none passes every checkbox audit while enforcing nothing. A registrar change nobody ordered is the first symptom of a domain changing hands. DomainDrift watches the control planes: email authentication, certificates, registration, registry status, and lands each material change as a signed, timestamped event with the value before and the value after. A certificate issuer that changes, or an expiry drawing close, is estate posture the same as a mail record. Lookalikes you name go under the same watch, from before they resolve.

For security and brand protection2 minA parked lookalike gets a signed baseline. The day it arms, the change lands as a dated event.Transcript

Email authentication drift, last 24 hours

DMARC, SPF, DKIM and MTA-STS transitions observed on watched domains, each with its stored summary.

asuprep.org
DMARC enforcement downgraded (p=quarantine to p=none)
email.auth.dmarc.downgraded· 2h ago
sharcsoftware.com
DMARC enforcement downgraded (p=quarantine to p=none)
email.auth.dmarc.downgraded· 4h ago
hapi.trade
DMARC enforcement raised to p=reject
email.auth.dmarc.upgraded· 8h ago

DNSSEC, measured rather than assumed

A zone signing itself is a control-plane fact, and it is only worth anything if the record knows the difference between "off" and "never looked".

DomainDrift asks a domain's nameservers for its DNSKEY records directly, and writes the answer down only when the lookup actually succeeded. Turning DNSSEC on, or off, then lands as a dated event with the value before and the value after, the same as an email-authentication move, and the reading behind it is signed like every other.

Scope, plainly: that lookup runs on a slower pass across the whole catalog, not on the five-minute lane a name you add gets for DNS and reachability, so DomainDrift does not publish a DNSSEC posture for an entire estate on demand. A domain the pass has not reached carries no DNSSEC state at all, and the record says so instead of reporting it as unsigned. An absence nobody measured is not an absence.

Lookalike domains, watched from before they resolve

Brand impersonation and typosquats start as a name that answers nothing. A name that answers nothing is still a reading.

  1. Name it. Add a lookalike to a watch group. Registered or not, resolving or not. The first signed reading lands in seconds; the five-minute watch lane runs under it from there.
  2. The reading before. A resolver answering NXDOMAIN has answered. That answer is signed and dated like any other reading, and it is the baseline.
  3. The reading after. The day the name starts answering, the change lands as a dated event: the empty side before, the nameservers, mail exchangers and certificate after. The alert carries the same event.

Takedown work wants an exhibit, not a screenshot. Both readings export as a dated evidence report, and the registrar or host who receives it re-checks every signature in the public verifier, offline, with no account. A signature proves who took a reading and that it has not been altered since. It does not make the reading correct.

Scope, plainly: DomainDrift reads a curated catalog plus the domains you name. It does not enumerate every lookalike of a brand, and it does not judge whether a site is phishing. It records what each name published, and when.

Two steps in

1 · Try it, no account
curl https://domaindrift.io/v1/domains/example.com

One keyless request every 15 seconds per IP, for any domain in the catalog. It returns a reduced preview record with a receipt pointer you can resolve right away.

2 · Register

Opens the complete signed record and every list in full, and puts one of your own domains under watch. 20 API requests a day, refreshed at midnight UTC.

Pro puts your estate and your watchlist under the same signed watch, with webhook alerts your SOC can route.

Create an account →

What it costs →

CONTINUOUS INTERNET TELEMETRY24H DRIFT5,157 material changesacross 2,622 domains · 24h to ~3h ago · -22,775 vs yesterdayROTATION59 domains moved DNS from magpiedns.com to koaladns.com, 59 moved backa rotation loop, not a migration · 24hNOW646 curated domains not reachablelast probe, steadySITE ERRORS17,707 sites serving errorslast probe · 5xx / 404 / TLSBOT DEFENSEbot defense observed on 79,463 sites429 rate-limit / 403 bot-block, a posture signal