August 4, 2026

A Parking Lot Grows, and an Expired Domain Comes Back as a Ghost

Out of roughly 12,900 DNS changes spotted in the last 24 hours (against 12.7M tracked domains), one pattern stood out: a handful of unrelated domains all landing on the same parking infrastructure within hours of each other.

Everybody's moving to the same parking lot

Three domains switched their nameservers to ns1.lander.d.parity.domains / ns2.lander.d.parity.domains and dropped onto AS30058 in quick succession:

  • hikeguru.store — was sitting behind Cloudflare's CDN, now reclassified as "unknown" hosting on AS30058.
  • waseeb.com — used to be a Shopify store (shops.myshopify.com CNAME, Shopify's AS13335); that CNAME and its CAA records are gone, and it's parked now.
  • medreader.com — previously on parkingcrew.net nameservers via AS206834, its Let's Encrypt CAA record and SPF (-all) both vanished as it hopped to the same parity.domains setup.

Different starting points — a CDN, an e-commerce host, another parking service — but they all end up in the same place. Worth watching if it keeps showing up: could be a monetization network scooping up expiring or abandoned domains.

A Whois-lookup ghost story: berwickagent.xyz

berwickagent.xyz (and its www twin) dropped Afternic's parked-domain nameservers (ns5/ns6.afternic.com) for dns1.onamae-expired.com / dns2.onamae-expired.com — a registrar's literal "expired" holding pattern — while its network hop moved from AS16509 to AS7506. It also lost its v=spf1 -all TXT record on the way out. It's the DNS equivalent of a "for lease" sign going up right as the old tenant's mail gets shut off.

A tidier migration: kinan.biz

Not every change is messy. kinan.biz moved off ns1/ns2.muumuu-domain.com onto dns0.heteml.jp / dns1.heteml.jp (AS206834 → AS7506) and picked up real mail routing (mx-proxy501/502.heteml.jp) plus a working SPF record — v=spf1 include:_spf.heteml.jp ~all — replacing a dead-end v=spf1 -all. It also shed a stray CAA record with empty issue values. A rare case where a migration leaves DNS hygiene better than it found it.

Locking down the front door

www.hellohi.in added a full slate of CAA records — Comodo, DigiCert, GlobalSign, Let's Encrypt, Google's pki.goog, and Sectigo, both for regular and wildcard issuance — while adding Hostinger mail (mx1/mx2.hostinger.com) and SPF (include:_spf.mail.hostinger.com). That's a domain owner explicitly telling every major CA "these are the only six who can issue certs for me," which is more diligence than most domains bother with.