domaindrift

Retired — functionality merged into urlrecon.

retired 2026-05-31

This tool has moved

domaindrift was a Python CLI for historical subdomain inventory and subdomain-takeover detection. Both subcommands are now part of urlrecon as the domaindrift subcommand — with several improvements:

Migration

# Old (domaindrift)
curl -fsSL https://cli.johlem.net/install.sh | bash -s -- domaindrift
domaindrift enum cyberramen.com
domaindrift takeover cyberramen.com
domaindrift history cyberramen.com

# New (urlrecon domaindrift)
curl -fsSL https://cli.johlem.net/install.sh | bash -s -- urlrecon
urlrecon domaindrift history cyberramen.com --limit 200
urlrecon domaindrift history cyberramen.com --include-expired --format json
urlrecon domaindrift takeover cyberramen.com --concurrency 16
urlrecon domaindrift takeover cyberramen.com --format markdown

Why retired?

domaindrift duplicated urlrecon's DNS resolver, HTTP client, and crt.sh client. Folding the two subcommands into urlrecon means the certificate-transparency code path is shared with urlrecon certchain, and operators install one binary instead of two.

Deferred for a follow-up session: the old monitor subcommand (long-running daemon to alert on new CT issuances) was not ported — it fits a systemd timer / cron job better than a one-shot CLI. DNSSEC validation and zone-transfer (AXFR) attempts are also deferred; the new pipeline is OSINT-only, no authoritative-server probing.

→ Go to urlrecon