Check-Host.cc
Domain

2016-66.com

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of 2016-66.com

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
5
A/AAAA targets
Subdomains
5
CT + scan + body
Record Types
5
seen in DNS
Observed Certs
2
in our scans

DNS Records

A
104.21.31.18, 172.67.174.165
AAAA
2606:4700:3030::ac43:aea5, 2606:4700:3031::ac43:aea5, 2606:4700:3037::6815:1f12
MX
10 mx1.emailsrvr.com, 20 mx2.emailsrvr.com
NS
elly.ns.cloudflare.com, toby.ns.cloudflare.com
TXT
0rb64fbt0h58n7rbc8plqw5wj0tz9c9r, v=spf1 a:cuda.gscadmin.com include:emailsrvr.com include:amazonses.com ~all
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Every subdomain we know about — harvested from CT-log SANs, scan-observed certs and HTML body references — paired with its current A/AAAA target.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Subject: www.2016-66.com
Issuer: RapidSSL TLS RSA CA G1
SANs: 2016-66.com, www.2016-66.com

IPs Citing This Domain

No citing IPs found yet

As the world-sweep progresses, hosts referencing this domain in their HTML will surface here.

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

Origin IP Origin ASN CDN ASN Confidence Reasoning
67.192.43.218 AS33070 AS13335 80% cert cfac650b… served by 67.192.43.218 (AS33070) carries SAN 2016-66.com which currently resolves through Cloudflare (AS13335) at 172.67.174.165, 104.21.31.18, 2606:4700:3030::ac43:aea5, 2606:4700:3037::6815:1f12

CT-Log Evidence

Certificates from public Certificate Transparency logs whose subject or SAN names this domain — including historic certs we never observed live.

6c4818311d9cc058… google · xenon2026h2
Subject: 2016-66.com
Issuer: WE1
SANs: 2016-66.com, *.2016-66.com
Valid: 2026-08-05 12:07:57 → 2026-11-03 13:07:37
f70387683445d3f6… digicert · wyvern2026h2
Subject: 2016-66.com
Issuer: YE2
SANs: *.2016-66.com, 2016-66.com
Valid: 2026-07-30 23:27:47 → 2026-10-28 23:27:46

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
AAAA 2606:4700:3031::ac43:aea5 2026-06-21 00:19:06.625 2026-06-21 00:19:06.625
MX 20 mx2.emailsrvr.com 2026-06-21 00:19:06.625 2026-08-28 18:58:16.007
TXT v=spf1 a:cuda.gscadmin.com include:emailsrvr.com include:amazonses.com ~all 2026-06-21 00:19:06.625 2026-08-28 18:58:16.007
TXT 0rb64fbt0h58n7rbc8plqw5wj0tz9c9r 2026-06-21 00:19:06.625 2026-08-28 18:58:16.007
AAAA 2606:4700:3037::6815:1f12 2026-06-21 00:19:06.625 2026-08-28 18:58:16.007
NS toby.ns.cloudflare.com 2026-06-21 00:19:06.625 2026-08-28 18:58:16.007
NS elly.ns.cloudflare.com 2026-06-21 00:19:06.625 2026-08-28 18:58:16.007
A 172.67.174.165 2026-06-21 00:19:06.625 2026-08-28 18:58:16.007
A 104.21.31.18 2026-06-21 00:19:06.625 2026-08-28 18:58:16.007
MX 10 mx1.emailsrvr.com 2026-06-21 00:19:06.625 2026-08-28 18:58:16.007
AAAA 2606:4700:3030::ac43:aea5 2026-07-28 17:13:52.071 2026-08-28 18:58:16.007