Blog
DomainDriftConnorDNSdriftprovenanceinfrastructure

DomainDrift: verifiable internet telemetry

2,050,978 domains on a loop, watched domains re-checked every 5 minutes. Every DNS, host, email, and certificate change recorded with a signed receipt the moment we see it.

Robert ChristianJuly 12, 20263 min read

Editor's note, 2026-08-02: the scale figures below were accurate when this was published on 2026-07-12 and are left as written. DomainDrift has since grown by roughly 40x. The current line is 2,050,978 domains cataloged, 1,971,849 with at least one signed reading, watched domains re-checked every 5 minutes, every observation Ed25519-signed and notarized on Base in 15-minute windows.

DomainDrift watches around 50,000 domains on a loop and signs every observation. When a domain's DNS, host, email posture, or certificate moves, the change is the event: what it was, what it became, and when we saw it.

The internet's configuration moves constantly, and it moves silently. DomainDrift turns those silent moves into a record you can search, watch, and hand to someone else as evidence.

DomainDrift: around 50,000 domains on a loop, every change signed.
DomainDrift, live at domaindrift.io

The change is the event

A nameserver that moved is how a hijack starts. A certificate that reissued off schedule is how impersonation starts. A mail record that weakened is how spoofed invoices start. A host that went dark is how an outage announcement starts, and you want to be the one making it, not receiving it.

DomainDrift records each of these as a first-class event with a before, an after, and a timestamp. You never have to wonder whether something changed: the record says what changed, and when. If you run a portfolio, watch your vendors, track competitors, or answer to clients for infrastructure you do not control, this is the feed you check in the morning.

What a scan sees

Each pass sweeps the full catalog roughly every 21 hours and records every plane that matters operationally: DNS across nine record types, TLS from certificate transparency, WHOIS over RDAP, ASN, DNSSEC, and robots.txt. The methodology documents exactly what it touches and what it never does. It is not a crawler, and it never reads page content.

Evidence, not screenshots

Every observation carries an Ed25519 receipt written the moment it is made, and receipts verify in your browser against published keys. When you need to show a registrar, a client, or an auditor that a record changed on a specific day, you are not sending a screenshot. You are sending a signed observation they can check themselves.

Take a look

Search a domain at domaindrift.io, open its page, and see what is steady and what has moved.

Formerly Connor. Old links redirect, and every receipt ever issued still verifies.

Published by

Robert Christian

Founder and CEO, DRM3 Labs Corp.

2026 DRM3 Labs Corp. All rights reserved. DRM3 Labs builds infrastructure for open protocols.

This article is for informational purposes only. Nothing here is financial, investment, or legal advice. Tokens, staking, NFTs, and blockchain protocols are described as technical mechanisms, not investment recommendations. Digital assets carry risk. Do your own research.

Many DRM3 products mentioned are in early alpha. Features, availability, and economics are subject to change. References to the Morpheus network describe the public protocol as documented at mor.org.