DomainDrift 1.86: alerts reach your channel, and a parked domain is a reading too
Change alerts now verify and deliver to Slack, Discord and Teams. A watched domain that does not resolve yet gets a real signed reading, so the record starts before an attacker flips the switch. Counts state their coverage, pages open in half a second, and the whole archive traces to one on-chain commitment.
DomainDrift watches domains and keeps a signed record of every change it sees. Versions 1.59 through 1.86 shipped across three weeks; this post covers what a reader, a subscriber, or a machine on the API can now do that they could not before.
Alerts that reach the channel you actually use
A change alert verifies and delivers to Slack, Discord and Microsoft Teams. Chat services accept incoming webhooks but do not answer a challenge handshake, so verification happens the way those channels work: DomainDrift delivers a clearly labeled notice to the channel itself, visible to its own members, and the destination is confirmed once it lands.
Every delivery is signed with a per-subscription secret, shown once when you create it, so a receiver can check that a payload really came from DomainDrift. The alerts page also says plainly what a pending subscription is waiting for, instead of showing active over a destination that will never answer.
A watched domain counts before it resolves
The pre-attack state of a lookalike domain is parked: registered, resolving to nothing, waiting. That is the moment worth watching, and it is the moment most monitoring has nothing to say about, because there is nothing there yet to describe.
DomainDrift records it anyway. When a watched domain is scanned and the resolver answers definitively that nothing is there, that absence becomes a signed, dated reading in the record. A resolver timeout is a failure to observe, and is never written as an absence. So the domain carries a baseline before it ever switches on, the switch-on is a scored change like any other, and a watched domain going dark is a reading too. On two real adds, the first signed reading landed within seconds.
The scope is stated honestly: this covers the domains a customer names and watches, never every possible lookalike of a brand, and a reading says what the domain resolved to, never whether a site is malicious.
Counts that state their coverage
The 24 hour change count is measured by a ledger that walks the whole tracked catalog and accumulates what it has covered. While it is still walking, the number is presented as a floor: at least this many, with the walked window stated beside it. A count scoped to watched domains says watched. A source that has not been measured renders as unmeasured, never as zero, and a comparison against yesterday appears only when both sides measure the same thing.
On one measured day the headline moved from 238 to over 2,000 material changes as the ledger reached the rest of the catalog. The old number was not invented; it was a count of a smaller set printed under a bigger header. The fix is the label, and the labels are now part of the product.
Pages that open in half a second
Public pages are now actually served from the edge cache. Measured on the live site: the landing page went from 2.4 seconds to 0.40, pricing from 3.8 to 0.51, and the infrastructure map from 4.7 to 0.09. Navigation stopped flickering, because the shell styles and scripts now ship once as long-lived assets instead of riding every page, and loading placeholders appear only where they honestly match the page being loaded.
The whole archive, provable from your browser
Every reading DomainDrift takes is signed, and the record now traces end to end: 9,129 window roots covering more than 18 million signed readings were committed on Base in a single transaction, and the commitment page publishes the full set, the root, the on-chain entry, and the steps to rebuild the root yourself. The in-browser verifier checks both hops, a lone receipt pasted into the verify page is now accepted as a first-class artifact, and the raw leaf set for any window is public.
A signature proves who produced a reading and that it has not changed since; the on-chain commitment adds an independent timestamp. Those are added layers of trust on the record, and the verify page says exactly which checks ran and what each one showed.
Plans that say what each rung adds
The pricing page was rebuilt around three capability bands: watch, operate, and prove. Every number on it is read live from the catalog and from the same functions the product enforces with, so the page cannot drift from the gates. No rung carries a recommended badge, because six different buyers have six different right answers. Metered allowances are stated as numbers, and the signed evidence bundle now honors each plan's history window, so a Pro export covers the full 90 days of history that plan carries.
For machines, a paid per-call read on the agent lane now returns its settlement receipt in the response: the payment settles on Base and the transaction hash comes back in a standard header, so the calling agent can trace its own cent on chain.
Where to start
Look up any domain free at domaindrift.io, open the commitment page at domaindrift.io/verify, or put one domain on watch and point the alert at your channel.
Published by
Robert Christian
Founder and CEO, DRM3 Labs Corp.
More from DRM3 Labs
TruthFoundry 1.36: a public dataset becomes a section, and every story that runs is kept
Robert Christian · 5 min read
DomainDrift 1.97: look up any of two million domains and read its signed history
Robert Christian · 2 min read
TruthFoundry 1.12: see what carries a claim and what cuts against it
Robert Christian · 2 min read
2026 DRM3 Labs Corp. All rights reserved. DRM3 Labs builds infrastructure for open protocols.
This article is for informational purposes only. Nothing here is financial, investment, or legal advice. Tokens, staking, NFTs, and blockchain protocols are described as technical mechanisms, not investment recommendations. Digital assets carry risk. Do your own research.
Many DRM3 products mentioned are in early alpha. Features, availability, and economics are subject to change. References to the Morpheus network describe the public protocol as documented at mor.org.
