DNSIGHT Device Intelligence ◎ Operating picture → ← Back to fleet connecting…

Device

DNS activity profile
Reading the airwaves…
best guess from live DNS patterns
15 min agonow
Range Bucket

Action log — specific things the apps did, newest first

Live feed — connecting…

Interaction threads — one thread is one sitting

A notification, an app opened, what happened next. A new thread starts when the device goes five minutes with no app activity, and a stretch that runs past about 45 minutes is split again at its own quietest moment. That second rule exists because social apps refresh every couple of minutes on their own, so a phone in a pocket never actually falls silent.

History — every day on record; click a day to inspect it

Activity timeline

Sessions
⛔ Blocked

The story

Auto-generated narrative of what this device was doing

Daily rhythm — every day on record; when the phone is awake, asleep, or off the network

00:0006:0012:0018:0024:00

Habits — what follows what

Most common app-to-app moves across every session

Typical day & binges

Which app usually dominates each part of the day
00040812162024

Security & anomaly watch — what's new and what never stops talking

Newly-seen domains — first appearance in 24 h

Always-on / beaconing connections

Notifications & attention — what pulls vs. what's chosen

Digital wellbeing — sleep, screen & focus

New apps & services — first-ever appearances, newest first

Registered domains this device had never contacted before, grouped and de-noised, each classified by kind. Stays listed for the whole window, so a one-time open never scrolls away. The strip highlights sensitive and app-like arrivals (dating, finance, health, AI…); the table below classifies everything, background infra included.

Unidentified services — what the knowledge base cannot name yet

Domains this device uses regularly that match no rule, ranked by how much traffic we are failing to explain. This is the coverage gap, stated plainly: the work-list for the next intelligence ingest rather than a hole we hide. Names arrive as the catalogue grows, or you can train one yourself from the app row.

Attempted — tried to reach something a pack blocks

Every lookup this device made that was refused. On the phone a block just looks like a page that failed to load, so this is the only place it is visible. One caveat kept in view throughout: a blocked lookup does not prove a person typed the address. An embedded ad frame, a preloaded link or a background SDK all produce them. Attempts that look like someone actually opening something are counted separately from background noise.

Most recent attempts

Phoning home to China — who is on the other end

Two different questions, kept apart on purpose. Where it landed is measured: the resolver records the network each answer geolocated to. Who operates it is ownership: the service belongs to a company headquartered in China even when a US or European cloud serves it. TikTok is the reason both matter — it resolves inside the United States and is run by ByteDance. DNS shows which services are contacted and where they resolve. It cannot see what was sent, and nothing here claims otherwise.

Places — which network this device is attached to, and for how long

DNS reveals a network fingerprint, never a coordinate. A place becomes an address when you name it. Open map →

Association intelligence — which selectors cross over on the same network, and when

Two devices on one fixed network at the same time is a link. Cellular is excluded — a shared carrier gateway is not a place. Open the operating picture →

Forensics & change — installs, clockwork beacons, buying, mobility

App install / removal timeline

Clockwork beacons — steadiest callbacks

Recent shopping / purchase signals

Apps & services

Everything the device talked to in this window

Top domains, explained

What each endpoint actually is