July 19, 2026
Flipkart's TXT Cleanup and a Nameserver Flip-Flopper Named Yougiz
Out of roughly 3.19 million domains under watch, we caught 2,361 changes and 819,129 brand-new domains in the last 24 hours. Most of it is routine housekeeping, but a few records stood out.
Flipkart does some serious spring cleaning
www.flipkart.com (fronted by Akamai) had one of the busier records in the window. It dropped its Mimecast inbound mail routes (eu-smtp-inbound-1.mimecast.com, eu-smtp-inbound-2.mimecast.com), added a fresh CAA policy scoped to digicert.com, globalsign.com, and letsencrypt.org, and got a new SOA. The TXT record ballooned with verification strings for the usual enterprise SaaS suspects — Atlassian, Adobe, OneTrust, SuccessFactors, Google, Docker — plus a newer entry: anthropic-domain-verification. Big companies verifying a growing stack of vendor tools is basically a DNS rite of passage now.
A clean CDN-to-CDN jump
www.bullets.gg moved off Vercel and onto Cloudflare — CNAME to cname.vercel-dns.com gone, replaced by Cloudflare's edge network (AS13335), with the old CAA and SOA records swept away in the same change. Textbook migration: new host, new authoritative records, done in one pass.
The flappers
A few names couldn't sit still. middlewaylogic.com racked up 15 changes and yougiz.com (plus its www variant) logged 13 and 10 respectively, bouncing back and forth between nameservers ns1.kirklanddc.com/ns2.kirklanddc.com, ns1.brainydns.com/ns2.brainydns.com, and ns1.magpiedns.com/ns2.magpiedns.com — with the underlying network hopping between AS43350, AS55286, and AS395954 multiple times within hours. That kind of rapid, repeated NS/ASN cycling usually points to load-balanced or churn-prone DNS infrastructure rather than a deliberate migration.
Elsewhere, www.co.cc quietly lost its CloudFront setup — the CNAME to d1jze2t1odcdhs.cloudfront.net and its AWS Route 53 nameservers (ns-1216.awsdns-24.org and friends) were all removed, leaving it without a clear CDN classification for now.
Small but notable security tweaks
visa.com refreshed its Cloudflare SOA and swapped out a long list of legacy verification TXT records (Atlassian, MongoDB, Palo Alto Networks, Postman, and more) for a single new one: miro-verification. Meanwhile tohidtamin.ir and its www subdomain flip-flopped a certum.eu CAA policy on and off twice within a day, alongside a TXT verification token that appeared and disappeared in sync — a sign someone was mid-configuration rather than anything malicious.