All Products
ScannerPublic Alpha

DomainDrift

The state of the internet, notarized on-chain. Continuous DNS, TLS, WHOIS, and HTTPS, signed per observation and notarized on Base within about 15 minutes.

Who it's for
Security researchers, due-diligence and compliance teams, auditors and underwriters, and infrastructure analysts who need internet telemetry they can verify.
Get started
Search a domain, download a signed evidence bundle you can verify offline, and trace any reading to its on-chain root on Base.

A continuous record of the internet's surface: who hosts a domain, who handles its mail, who issues its certificate, whether it is up and why. A 2,050,978 domain catalog under continuous scan across every plane: DNS across nine record types, TLS from certificate transparency, WHOIS, subdomains, DNSSEC, ASN, and robots.txt.

Every observation is Ed25519-signed the moment it is made and chained to the one before it. The data is not just collected. It is attested at the time of collection, so a downstream consumer can verify what was observed, when, and by whom, and hand a signed evidence bundle to an auditor, an underwriter, or a court, verifiable offline against DomainDrift's published keys.

Each new observation is also notarized on Base mainnet within about 15 minutes. Every signed receipt in a 15-minute window is rolled into one Merkle root, and that root is written to a public contract, so the block's own timestamp is an independent record of when the reading already existed and it cannot be backdated afterward. Anyone can trace a single receipt to that on-chain root in their browser, from the receipt to its 15-minute window to the root to the transaction on Base.

That check runs end to end, on published inputs, with nothing to take on faith beyond the signature itself. The leaf set behind any published window is served openly at domaindrift.io/anchor/leafset/PERIOD, so you can rebuild the window's root from the receipts and confirm your receipt is one of the leaves, then compare that root against the transaction on Base.

The record from before that lane opened is committed too, in one transaction rather than backdated one window at a time. On 2026-07-29, 9,129 window roots covering 18,183,009 signed readings taken between 2026-04-14 and 2026-07-28 were written to Base as a single commitment, and the full set of window roots is published openly at domaindrift.io/anchor/commitment/archive-2026-04-14-2026-07-28 so anyone can rebuild the commitment root and check it against the chain. A reading from that archive proves itself in two hops, into its window's root and that root into the commitment; a reading from the going-forward lane takes one. The commitment is dated the day it was made, because a block timestamp records when we committed, never when the reading was taken.

Change is scored in-stream and published as a daily feed you can read or pull as RSS or JSON. A universal search answers the reverse questions: who sits on this IP, who uses this certificate authority, who this registrar holds. Agents reach the same signed data over REST, a live stream, MCP discovery, or per-call x402 payment.

Paired with RunsWith for deeper infrastructure fingerprinting across 80+ provider categories. Together they form the scanner tier of DRM3 intelligence.

Plans, limits, and prices live on DomainDrift's own pricing page at domaindrift.io/pricing, which reads them from the billing ledger. There is a free tier, and anything beyond the published plans goes through inquiries@drm3.io.

Capabilities

2,050,978-domain catalog under continuous scan across every plane

DNS, TLS, WHOIS, DNSSEC, ASN, robots.txt observation

Certificate + email-auth posture (SPF/DMARC/DKIM/MTA-STS) and dangling-delegation flags

Ed25519 provenance on every observation + offline evidence bundles

Notarized on Base: one Merkle root per 15-minute window in a public contract, with the pre-lane archive committed in a single transaction, and any receipt's inclusion traceable by you

Signed daily change feed (RSS / JSON) and webhook alerts, material-vs-noise scored

Universal reverse search (IP, provider, certificate authority, registrar)

Agent-native access: REST, live stream, MCP discovery, x402 pay-per-call

Scanning Methodology

DomainDrift is not a web crawler. It is a DNS and infrastructure-metadata scanner. DomainDrift does not crawl websites, index page content, follow links, or traverse URL paths.

DomainDrift collects publicly available infrastructure metadata: DNS records, TLS certificate data, domain registration information, and the HTTP response status from a single lightweight probe to a domain's root. Every observation is Ed25519-signed at the moment of collection, producing a tamper-evident provenance receipt.

HTTP requests to target domains

HEAD /Single liveness probe recording HTTP status and response headers. Falls back to GET only if the server returns 405 Method Not Allowed.
GET /robots.txtCollected as a data point for AI crawler policy analysis. DomainDrift reads this file to report which AI user-agents a domain blocks. This is observational. DomainDrift records the contents but does not use robots.txt as a crawl gate, because DomainDrift does not crawl.

DomainDrift does not

Crawl, index, or store page content
Follow links or traverse site paths
Access any URL path beyond / and /robots.txt
Send POST, PUT, or any state-modifying request
Use authentication, cookies, or sessions
Store or reproduce page content from target domains

External metadata APIs

These requests go to third-party public APIs, not to the target domain.

Certificate transparencyPublic CT log queries via crt.sh and CertSpotter
RDAP serversPublic domain registration metadata
cloudflare-dns.comDNSSEC validation via DNS-over-HTTPS (dns.google as fallback)
Team Cymru IP-to-ASNASN and network ownership for IP addresses found in DNS records, over DNS

Identification

User-AgentDomainDrift-DNS-Intelligence/0.5 (+https://domaindrift.io)
ProtocolHTTPS only. Maximum 3 redirect hops. 3 to 5 second timeouts per request.

Opt-out

Domain operators can request exclusion from DomainDrift scanning by emailing inquiries@drm3.io with the domain name. Opt-out requests are processed within 7 business days.

Request domain exclusion

Provide your domain name. We verify ownership, then process within 7 business days.

+

Don't see your domain?

Submit your domain for inclusion in the DomainDrift scanning catalog. We review every submission and follow up within 7 business days.

Add my domain

Share your domain name. We review and follow up within 7 business days.

Live Provenance

github.comprovenance receipts from a live scan

Every scan produces Ed25519-signed receipts across five observation planes. Each receipt is independently verifiable against the published keys, on your own machine.

Every observation is Ed25519-signed
Verify them offline. Nothing leaves your machine.
Verify github.com
Provenance by Plane5/5 scanned
DRM3 Provenance Receipt - DNS & TLS
Public Key
connor-fast-v0.1.0
Status
Locally Signed
Observed
6/3/2026, 12:02:39 PM
Observations
74 total
Receipt ID
cd96deef-d4a7-4aea-b864-96aadcaaafc2
Output Hash (SHA-256)
95629854bd483d6fb10cdf182b5ea78222f4053815433e01992edd25864bd188
Derivation Path
connor/fast

Live from the DomainDrift scanning network