Check-Host.cc

Domain

boxwatch.app

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of boxwatch.app

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
A/AAAA targets
Subdomains
CT + scan + body
Record Types
seen in DNS
Observed Certs
in our scans

DNS Records

A
188.114.96.0, 188.114.97.0
AAAA
2a06:98c1:3120::, 2a06:98c1:3121::
MX
10 morganelli-com.p10.spamhero.com, 20 morganelli-com.p20.spamhero.net, 30 morganelli-com.p30.spamhero.net, 40 morganelli-com.p40.spamhero.net
NS
jill.ns.cloudflare.com, luke.ns.cloudflare.com
TXT
google-site-verification=aMkpc07LqlO2Vdbk1HaHY3KtI_0zxp4tU0w6k4902Yo
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Every subdomain we know about — harvested from CT-log SANs, scan-observed certs and HTML body references — paired with its current A/AAAA target.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Subject: boxwatch.app
Issuer: YE1
SANs: api.boxwatch.app, boxwatch.app, status.boxwatch.app, tv.boxwatch.app, www.boxwatch.app

IPs Citing This Domain

No citing IPs found yet

As the world-sweep progresses, hosts referencing this domain in their HTML will surface here.

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

Origin IP Origin ASN CDN ASN Confidence Reasoning
46.225.230.210 AS24940 AS13335 95% cert 70ecb9f4… served by 46.225.230.210 (AS24940) carries SAN api.boxwatch.app which currently resolves through Cloudflare (AS13335) at 188.114.96.0, 2a06:98c1:3121::, 2a06:98c1:3120::, 188.114.97.0

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
NS jill.ns.cloudflare.com 2026-07-19 02:49:31.525 2026-07-19 02:49:31.525
MX 20 morganelli-com.p20.spamhero.net 2026-07-19 02:49:31.525 2026-07-19 02:49:31.525
TXT google-site-verification=aMkpc07LqlO2Vdbk1HaHY3KtI_0zxp4tU0w6k4902Yo 2026-07-19 02:49:31.525 2026-07-19 02:49:31.525
AAAA 2a06:98c1:3120:: 2026-07-19 02:49:31.525 2026-07-19 02:49:31.525
A 188.114.96.0 2026-07-19 02:49:31.525 2026-07-19 02:49:31.525
MX 10 morganelli-com.p10.spamhero.com 2026-07-19 02:49:31.525 2026-07-19 02:49:31.525
NS luke.ns.cloudflare.com 2026-07-19 02:49:31.525 2026-07-19 02:49:31.525
MX 30 morganelli-com.p30.spamhero.net 2026-07-19 02:49:31.525 2026-07-19 02:49:31.525
A 188.114.97.0 2026-07-19 02:49:31.525 2026-07-19 02:49:31.525
AAAA 2a06:98c1:3121:: 2026-07-19 02:49:31.525 2026-07-19 02:49:31.525
MX 40 morganelli-com.p40.spamhero.net 2026-07-19 02:49:31.525 2026-07-19 02:49:31.525