Check-Host.cc

Domain

api.w.org

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of api.w.org

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
4
A/AAAA targets
Subdomains
CT + scan + body
Record Types
6
seen in DNS
Observed Certs
in our scans

DNS Records

A
198.143.164.252, 66.6.42.252
AAAA
2607:f978:5:8002::c68f:a4fc, 2620:109:b00a::4206:2afc
MX
10 smtp1-dca.wordpress.org, 10 smtp1-ord.wordpress.org, 10 smtp2-dca.wordpress.org, 10 smtp2-ord.wordpress.org
NS
ns1.wordpress.org, ns2.wordpress.org, ns3.wordpress.org, ns4.wordpress.org
TXT
google-site-verification=UL0sGJ1dZbCT4J7pGrLW3hqM_I1LJ8pUi2WBEI_98kI, google-site-verification=t8FjG1vzC4OFZJ8qL4SkR8xxtLyKldXKbswyeemQS5w, v=spf1 ip4:66.6.42.0/24 ip4:66.155.40.0/24 include:helpscoutemail.com -all, v=spf1 ip4:66.6.42.0/24 ip4:66.155.40.0/24 ip4:198.143.164.0/24 include:helpscoutemail.com -all
CNAME
CAA
0 iodef "mailto:caa@wordpress.org", 0 issue "letsencrypt.org;validationmethods=dns-01;accounturi=https://acme-v02.api.letsencrypt.org/acme/acct/53691143"

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

139.59.113.91:443 href · ×72
18.133.91.110:80 href · ×25
188.34.202.164:443 href · ×22
192.36.171.160:80 href · ×21
192.36.171.160:443 href · ×21
34.248.110.32:443 href · ×21
52.204.236.224:443 href · ×16
54.253.51.238:443 href · ×14
35.200.255.86:443 href · ×12
100.56.66.145:443 href · ×9
34.226.31.65:443 href · ×9
34.14.52.175:443 href · ×5
35.205.87.125:443 href · ×5
193.136.43.14:443 href · ×4
101.32.204.98:80 href · ×4
193.170.124.228:80 href · ×4
43.165.167.248:443 href · ×4
161.34.4.28:80 href · ×4
64.210.133.132:80 href · ×4
210.129.88.45:443 href · ×4
60.43.197.23:443 href · ×4
185.209.223.35:443 href · ×4
69.172.211.73:443 href · ×4
206.189.140.182:80 href · ×4
45.146.48.66:80 href · ×3
15.204.135.110:443 href · ×3
157.245.216.217:443 href · ×3
185.110.188.169:8080 href · ×3
138.219.252.8:443 href · ×3
61.112.36.21:80 href · ×3
140.227.21.106:80 href · ×3
216.213.30.223:443 href · ×3
172.234.16.123:443 href · ×3
162.14.76.190:443 href · ×3
148.178.149.224:443 href · ×3
66.39.154.38:80 href · ×3
68.178.193.134:443 href · ×3
45.55.136.112:443 href · ×3
13.247.39.115:443 href · ×3
5.133.198.147:443 href · ×3
101.42.90.12:443 href · ×3
192.185.56.156:443 href · ×3
93.158.68.181:80 href · ×3
143.110.159.137:443 href · ×3
162.240.230.144:80 href · ×3
95.163.236.246:443 href · ×3
103.27.179.38:80 href · ×3
2.9.183.126:443 href · ×3
3.209.82.233:80 href · ×3
24.144.68.99:443 href · ×3

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
AAAA 2607:f978:5:8002::c68f:a4fc 2026-05-25 21:54:50.392 2026-06-24 01:05:03.339
A 198.143.164.252 2026-05-25 21:54:50.392 2026-06-24 01:05:03.339
TXT google-site-verification=UL0sGJ1dZbCT4J7pGrLW3hqM_I1LJ8pUi2WBEI_98kI 2026-05-25 22:05:29.416 2026-07-28 20:58:16.328
MX 10 smtp2-ord.wordpress.org 2026-05-25 22:05:29.416 2026-05-31 15:36:31.869
NS ns4.wordpress.org 2026-05-25 22:05:29.416 2026-07-28 20:58:16.328
TXT google-site-verification=t8FjG1vzC4OFZJ8qL4SkR8xxtLyKldXKbswyeemQS5w 2026-05-25 22:05:29.416 2026-07-28 20:58:16.328
NS ns2.wordpress.org 2026-05-25 22:05:29.416 2026-07-28 20:58:16.328
NS ns3.wordpress.org 2026-05-25 22:05:29.416 2026-07-28 20:58:16.328
TXT v=spf1 ip4:66.6.42.0/24 ip4:66.155.40.0/24 ip4:198.143.164.0/24 include:helpscoutemail.com -all 2026-05-25 22:05:29.416 2026-06-24 01:05:03.339
NS ns1.wordpress.org 2026-05-25 22:05:29.416 2026-07-28 20:58:16.328
MX 10 smtp1-ord.wordpress.org 2026-05-25 22:05:29.416 2026-05-31 15:36:31.869
CAA 0 issue "letsencrypt.org;validationmethods=dns-01;accounturi=https://acme-v02.api.letsencrypt.org/acme/acct/53691143" 2026-05-25 23:59:40.866 2026-07-28 20:58:16.328
CAA 0 iodef "mailto:caa@wordpress.org" 2026-05-25 23:59:40.866 2026-07-28 20:58:16.328
MX 10 smtp2-dca.wordpress.org 2026-06-06 04:02:20.898 2026-07-28 20:58:16.328
MX 10 smtp1-dca.wordpress.org 2026-06-06 04:02:20.898 2026-07-28 20:58:16.328
TXT v=spf1 ip4:66.6.42.0/24 ip4:66.155.40.0/24 include:helpscoutemail.com -all 2026-07-14 20:14:55.325 2026-07-28 20:58:16.328
A 66.6.42.252 2026-07-15 19:13:20.615 2026-07-28 20:58:16.328
AAAA 2620:109:b00a::4206:2afc 2026-07-15 19:13:20.615 2026-07-28 20:58:16.328