Check-Host.cc

Domain

deflock.org

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of deflock.org

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
5
A/AAAA targets
Subdomains
15
CT + scan + body
Record Types
5
seen in DNS
Observed Certs
10
in our scans

DNS Records

A
104.21.20.64, 172.67.191.214
AAAA
2606:4700:3031::ac43:bfd6, 2606:4700:3035::ac43:bfd6, 2606:4700:3036::6815:1440
MX
10 mx.zoho.com, 20 mx2.zoho.com, 50 mx3.zoho.com
NS
bill.ns.cloudflare.com, mia.ns.cloudflare.com
TXT
google-site-verification=-VCBHUq0i-X4Qh_UXMsv57T_hvmRMYXXZgYejj-wOVY, v=spf1 include:zohomail.com ~all, zoho-verification=zb65645166.zmverify.zoho.com
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

154.16.118.144:443 href · ×1

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

Origin IP Origin ASN CDN ASN Confidence Reasoning
204.13.88.6 AS40630 AS13335 95% cert ee106e9f… served by 204.13.88.6 (AS40630) carries SAN overpass.deflock.org which currently resolves through Cloudflare (AS13335) at 104.21.20.64, 172.67.191.214, 2606:4700:3035::ac43:bfd6, 2606:4700:3036::6815:1440

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
AAAA 2606:4700:3036::6815:1440 2026-05-27 09:24:40.778 2026-07-22 02:22:51.743
MX 20 mx2.zoho.com 2026-05-27 09:24:40.778 2026-07-22 02:22:51.743
TXT google-site-verification=-VCBHUq0i-X4Qh_UXMsv57T_hvmRMYXXZgYejj-wOVY 2026-05-27 09:24:40.778 2026-07-22 02:22:51.743
A 104.21.20.64 2026-05-27 09:24:40.778 2026-07-22 02:22:51.743
TXT v=spf1 include:zohomail.com ~all 2026-05-27 09:24:40.778 2026-07-22 02:22:51.743
MX 50 mx3.zoho.com 2026-05-27 09:24:40.778 2026-07-22 02:22:51.743
MX 10 mx.zoho.com 2026-05-27 09:24:40.778 2026-07-22 02:22:51.743
A 172.67.191.214 2026-05-27 09:24:40.778 2026-07-22 02:22:51.743
TXT zoho-verification=zb65645166.zmverify.zoho.com 2026-05-27 09:24:40.778 2026-07-22 02:22:51.743
NS mia.ns.cloudflare.com 2026-05-27 09:24:40.778 2026-07-22 02:22:51.743
NS bill.ns.cloudflare.com 2026-05-27 09:24:40.778 2026-07-22 02:22:51.743
AAAA 2606:4700:3035::ac43:bfd6 2026-05-27 09:24:40.778 2026-06-05 14:45:33.924
AAAA 2606:4700:3031::ac43:bfd6 2026-07-22 02:22:51.743 2026-07-22 02:22:51.743