August 4, 2026
A Parking Lot Grows, and an Expired Domain Comes Back as a Ghost
Out of roughly 12,900 DNS changes spotted in the last 24 hours (against 12.7M tracked domains), one pattern stood out: a handful of unrelated domains all landing on the same parking infrastructure within hours of each other.
Everybody's moving to the same parking lot
Three domains switched their nameservers to ns1.lander.d.parity.domains / ns2.lander.d.parity.domains and dropped onto AS30058 in quick succession:
hikeguru.store— was sitting behind Cloudflare's CDN, now reclassified as "unknown" hosting on AS30058.waseeb.com— used to be a Shopify store (shops.myshopify.comCNAME, Shopify's AS13335); that CNAME and its CAA records are gone, and it's parked now.medreader.com— previously onparkingcrew.netnameservers via AS206834, its Let's Encrypt CAA record and SPF (-all) both vanished as it hopped to the same parity.domains setup.
Different starting points — a CDN, an e-commerce host, another parking service — but they all end up in the same place. Worth watching if it keeps showing up: could be a monetization network scooping up expiring or abandoned domains.
A Whois-lookup ghost story: berwickagent.xyz
berwickagent.xyz (and its www twin) dropped Afternic's parked-domain nameservers (ns5/ns6.afternic.com) for dns1.onamae-expired.com / dns2.onamae-expired.com — a registrar's literal "expired" holding pattern — while its network hop moved from AS16509 to AS7506. It also lost its v=spf1 -all TXT record on the way out. It's the DNS equivalent of a "for lease" sign going up right as the old tenant's mail gets shut off.
A tidier migration: kinan.biz
Not every change is messy. kinan.biz moved off ns1/ns2.muumuu-domain.com onto dns0.heteml.jp / dns1.heteml.jp (AS206834 → AS7506) and picked up real mail routing (mx-proxy501/502.heteml.jp) plus a working SPF record — v=spf1 include:_spf.heteml.jp ~all — replacing a dead-end v=spf1 -all. It also shed a stray CAA record with empty issue values. A rare case where a migration leaves DNS hygiene better than it found it.
Locking down the front door
www.hellohi.in added a full slate of CAA records — Comodo, DigiCert, GlobalSign, Let's Encrypt, Google's pki.goog, and Sectigo, both for regular and wildcard issuance — while adding Hostinger mail (mx1/mx2.hostinger.com) and SPF (include:_spf.mail.hostinger.com). That's a domain owner explicitly telling every major CA "these are the only six who can issue certs for me," which is more diligence than most domains bother with.