All Products
ScannerPublic Alpha

DomainDrift

Verifiable internet telemetry. Continuous DNS, TLS, WHOIS, and HTTPS, signed per observation.

Who it's for
Security researchers, due-diligence and compliance teams, auditors and underwriters, and infrastructure analysts who need internet telemetry they can verify.
Get started
Search a domain and download a signed evidence bundle you can verify offline.

A continuous record of the internet's surface: who hosts a domain, who handles its mail, who issues its certificate, whether it is up and why. DNS across nine record types, TLS from certificate transparency, WHOIS, subdomains, DNSSEC, ASN, and robots.txt, across 74,639 curated domains, refreshed continuously.

Every observation is Ed25519-signed the moment it is made and chained to the one before it. The data is not just collected. It is attested at the time of collection, so a downstream consumer can verify what was observed, when, and by whom, and hand a signed evidence bundle to an auditor, an underwriter, or a court, verifiable offline against DomainDrift's published keys.

Change is scored in-stream and published as a daily feed you can read or pull as RSS or JSON. A universal search answers the reverse questions: who sits on this IP, who uses this certificate authority, who this registrar holds. Agents reach the same signed data over REST, a live stream, MCP discovery, or per-call x402 payment.

Paired with RunsWith for deeper infrastructure fingerprinting across 80+ provider categories. Together they form the scanner tier of DRM3 intelligence.

Capabilities

74,639-domain catalog under continuous scan

DNS, TLS, WHOIS, DNSSEC, ASN, robots.txt observation

Certificate + email-auth posture (SPF/DMARC/DKIM/MTA-STS) and dangling-delegation flags

Ed25519 provenance on every observation + offline evidence bundles

Signed daily change feed (RSS / JSON) and webhook alerts, material-vs-noise scored

Universal reverse search (IP, provider, certificate authority, registrar)

Agent-native access: REST, live stream, MCP discovery, x402 pay-per-call

Scanning Methodology

DomainDrift is not a web crawler. It is a DNS and infrastructure-metadata scanner. DomainDrift does not crawl websites, index page content, follow links, or traverse URL paths.

DomainDrift collects publicly available infrastructure metadata: DNS records, TLS certificate data, domain registration information, and the HTTP response status from a single lightweight probe to a domain's root. Every observation is Ed25519-signed at the moment of collection, producing a tamper-evident provenance receipt.

HTTP requests to target domains

HEAD /Single liveness probe recording HTTP status and response headers. Falls back to GET only if the server returns 405 Method Not Allowed.
GET /robots.txtCollected as a data point for AI crawler policy analysis. DomainDrift reads this file to report which AI user-agents a domain blocks. This is observational. DomainDrift records the contents but does not use robots.txt as a crawl gate, because DomainDrift does not crawl.

DomainDrift does not

Crawl, index, or store page content
Follow links or traverse site paths
Access any URL path beyond / and /robots.txt
Send POST, PUT, or any state-modifying request
Use authentication, cookies, or sessions
Store or reproduce page content from target domains

External metadata APIs

These requests go to third-party public APIs, not to the target domain.

Certificate transparencyPublic CT log queries via crt.sh and CertSpotter
RDAP serversPublic domain registration metadata
cloudflare-dns.comDNSSEC validation via DNS-over-HTTPS (dns.google as fallback)
Team Cymru IP-to-ASNASN and network ownership for IP addresses found in DNS records, over DNS

Identification

User-AgentDomainDrift-DNS-Intelligence/0.5 (+https://domaindrift.io)
ProtocolHTTPS only. Maximum 3 redirect hops. 3 to 5 second timeouts per request.

Opt-out

Domain operators can request exclusion from DomainDrift scanning by emailing inquiries@drm3.io with the domain name. Opt-out requests are processed within 7 business days.

Request domain exclusion

Provide your domain name. We verify ownership, then process within 7 business days.

+

Don't see your domain?

Submit your domain for inclusion in the DomainDrift scanning catalog. We review every submission and follow up within 7 business days.

Add my domain

Share your domain name. We review and follow up within 7 business days.

Live Provenance

github.comprovenance receipts from a live scan

Every scan produces Ed25519-signed receipts across five observation planes. Each receipt is independently verifiable against the published keys, on your own machine.

Every observation is Ed25519-signed
Verify them offline. Nothing leaves your machine.
Verify github.com
Provenance by Plane5/5 scanned
DRM3 Provenance Receipt - DNS & TLS
Public Key
connor-fast-v0.1.0
Status
Locally Signed
Observed
6/3/2026, 12:02:39 PM
Observations
74 total
Receipt ID
cd96deef-d4a7-4aea-b864-96aadcaaafc2
Output Hash (SHA-256)
95629854bd483d6fb10cdf182b5ea78222f4053815433e01992edd25864bd188
Derivation Path
connor/fast

Live from the DomainDrift scanning network