Blog
DomainDriftalertsdomainsverificationrelease

DomainDrift 1.86: alerts reach your channel, and a parked domain is a reading too

Change alerts now verify and deliver to Slack, Discord and Teams. A watched domain that does not resolve yet gets a real signed reading, so the record starts before an attacker flips the switch. Counts state their coverage, pages open in half a second, and the whole archive traces to one on-chain commitment.

Robert ChristianJuly 31, 20263 min read

DomainDrift watches domains and keeps a signed record of every change it sees. Versions 1.59 through 1.86 shipped across three weeks; this post covers what a reader, a subscriber, or a machine on the API can now do that they could not before.

Alerts that reach the channel you actually use

A change alert can now verify and deliver to Slack, Discord and Microsoft Teams. Those services accept incoming webhooks but can never answer a challenge handshake, so before this release a subscription pointed at any of them sat unverified and never fired. They now verify by delivering a clearly labeled notice to the channel itself, which the channel's own members can see, and existing subscriptions that were stuck revive on their own.

Every delivery is signed with a per-subscription secret, shown once when you create it, so a receiver can check that a payload really came from DomainDrift. The alerts page also says plainly what a pending subscription is waiting for, instead of showing active over a destination that will never answer.

A watched domain counts before it resolves

The pre-attack state of a lookalike domain is parked: registered, resolving to nothing, waiting. A scan of a domain with no DNS records used to produce no record at all, which meant no baseline, which meant the moment it switched on there was no before to diff against and nothing to alert on.

Now, when a domain a customer has named is scanned and the resolver gives a definitive answer that nothing is there, that absence becomes a real, signed, dated reading. A resolver timeout is our failure to observe and is never recorded as an absence. With the baseline in the record, the switch-on is a scored change like any other, and a watched domain going dark is a reading too. On two real adds, the first signed reading landed within seconds.

The scope is stated honestly: this covers the domains a customer names and watches, never every possible lookalike of a brand, and a reading says what the domain resolved to, never whether a site is malicious.

Counts that state their coverage

The 24 hour change count is measured by a ledger that walks the whole tracked catalog and accumulates what it has covered. While it is still walking, the number is presented as a floor: at least this many, with the walked window stated beside it. A count scoped to watched domains says watched. A source that has not been measured renders as unmeasured, never as zero, and a comparison against yesterday appears only when both sides measure the same thing.

On one measured day the headline moved from 238 to over 2,000 material changes as the ledger reached the rest of the catalog. The old number was not invented; it was a count of a smaller set printed under a bigger header. The fix is the label, and the labels are now part of the product.

Pages that open in half a second

Public pages are now actually served from the edge cache. Measured on the live site: the landing page went from 2.4 seconds to 0.40, pricing from 3.8 to 0.51, and the infrastructure map from 4.7 to 0.09. Navigation stopped flickering, because the shell styles and scripts now ship once as long-lived assets instead of riding every page, and loading placeholders appear only where they honestly match the page being loaded.

The whole archive, provable from your browser

Every reading DomainDrift takes is signed, and the record now traces end to end: 9,129 window roots covering more than 18 million signed readings were committed on Base in a single transaction, and the commitment page publishes the full set, the root, the on-chain entry, and the steps to rebuild the root yourself. The in-browser verifier checks both hops, a lone receipt pasted into the verify page is now accepted as a first-class artifact, and the raw leaf set for any window is public.

A signature proves who produced a reading and that it has not changed since; the on-chain commitment adds an independent timestamp. Those are added layers of trust on the record, and the verify page says exactly which checks ran and what each one showed.

Plans that say what each rung adds

The pricing page was rebuilt around three capability bands: watch, operate, and prove. Every number on it is read live from the catalog and from the same functions the product enforces with, so the page cannot drift from the gates. No rung carries a recommended badge, because six different buyers have six different right answers. Metered allowances are stated as numbers, and the signed evidence bundle now honors each plan's history window, so a Pro export covers 90 days instead of the 24 hours every tier was silently getting.

For machines, a paid per-call read on the agent lane now returns its settlement receipt in the response: the payment settles on Base and the transaction hash comes back in a standard header, so the calling agent can trace its own cent on chain.

Where to start

Look up any domain free at domaindrift.io, open the commitment page at domaindrift.io/verify, or put one domain on watch and point the alert at your channel.

Published by

Robert Christian

Founder and CEO, DRM3 Labs Corp.

2026 DRM3 Labs Corp. All rights reserved. DRM3 Labs builds infrastructure for open protocols.

This article is for informational purposes only. Nothing here is financial, investment, or legal advice. Tokens, staking, NFTs, and blockchain protocols are described as technical mechanisms, not investment recommendations. Digital assets carry risk. Do your own research.

Many DRM3 products mentioned are in early alpha. Features, availability, and economics are subject to change. References to the Morpheus network describe the public protocol as documented at mor.org.