Field notes
A DNS change is an observation, not an installation date
What a new MX, TXT or CNAME observation tells you, and how to separate first observations, confirmed changes and temporary lookup failures.
DNS can show that a domain routes mail through a provider, authorizes a sending service, or points a website at a platform. Repeating those observations makes a change visible. That is useful evidence, provided the claim stays as precise as the record.
Start with a baseline
The first scan tells us what we can see now. It cannot tell us when that configuration was introduced. A domain that has used the same mail provider for years will still produce a first observation when it enters our watchlist.
Domain Signals stores that first state as a baseline. Later, successful observations can show a new feature, a confirmed disappearance, a return, or a changed record value. Baselines stay separate from change counts.
Read the record type
MX points to the domain’s incoming mail infrastructure. A mail gateway may sit in front of another provider, so the record identifies visible routing rather than every service behind it.
SPF within TXT authorizes a service to send email. It does not show whether the service is currently sending, whether the company pays for it, or which features are enabled.
Verification TXT is a marker left by a verification workflow. It can persist long after the original integration is gone.
CNAME shows routing toward a host, platform or network. An apex and a www hostname can have different records, so both observations are retained separately.
Errors should not become disappearance stories
A timeout means the query failed. It does not mean the record was removed. We retain failed query outcomes for inspection and preserve the last confirmed state until a successful observation can support a comparison.
A return is also different from a first appearance. A feature seen before a confirmed absence can reappear later; that history is part of the signal.
State the coverage
A daily zone snapshot and a daily DNS watchlist serve different purposes. The zone can show changes in domain delegation. The bounded watchlist provides deeper DNS history for selected domains. An observed count from that watchlist should never be presented as a total for all of .com.
Public research on this site uses aggregates. See the methodology and observed technology pages for the current collection scope.