Check-Host.cc

Domain

auth.openai.com

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of auth.openai.com

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
A/AAAA targets
Subdomains
CT + scan + body
Record Types
seen in DNS
Observed Certs
in our scans

DNS Records

A
104.18.41.241, 172.64.146.15
AAAA
2606:4700:4400::6812:29f1, 2606:4700:4406::6812:29f1, 2a06:98c1:3106::ac40:920f, 2a06:98c1:310c::ac40:920f
MX
NS
TXT
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

156.238.254.108:80 href · ×1
45.207.206.229:5000 href · ×1
186.244.210.209:80 href · ×1
43.164.190.95:80 href · ×1
77.42.41.40:80 href · ×1
47.129.221.20:443 href · ×1
43.128.132.210:80 href · ×1
64.110.81.255:8080 href · ×1

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

CT-Log Evidence

Certificates from public Certificate Transparency logs whose subject or SAN names this domain — including historic certs we never observed live.

f58cd6544f43ed81… sectigo · elephant2026h1
Subject: auth.openai.com
Issuer: WE1
SANs: auth.openai.com, *.auth.openai.com
Valid: 2026-01-25 21:11:47 → 2026-04-25 22:11:42
9dbf93b42e171d26… sectigo · elephant2026h1
Subject: auth.openai.com
Issuer: E7
SANs: *.auth.openai.com, auth.openai.com
Valid: 2026-01-25 14:27:46 → 2026-04-25 14:27:45
91d0a19dcad40ba8… sectigo · elephant2026h1
Subject: auth.openai.com
Issuer: R12
SANs: *.auth.openai.com, auth.openai.com
Valid: 2026-01-25 14:27:42 → 2026-04-25 14:27:41
d2639fdba8e2f096… sectigo · elephant2026h1
Subject: auth.openai.com
Issuer: WE1
SANs: auth.openai.com
Valid: 2026-01-23 04:08:51 → 2026-04-23 05:08:49
bc0270600149df5c… cloudflare · nimbus2026
Subject: auth.openai.com
Issuer: WE1
SANs: auth.openai.com, *.auth.openai.com
Valid: 2025-11-27 20:55:40 → 2026-02-25 21:55:38
f4d445bc1f61b2f0… cloudflare · nimbus2026
Subject: auth.openai.com
Issuer: WE1
SANs: auth.openai.com, *.auth.openai.com
Valid: 2025-11-27 20:55:40 → 2026-02-25 21:55:38
f4d445bc1f61b2f0… sectigo · elephant2026h1
Subject: auth.openai.com
Issuer: WE1
SANs: auth.openai.com, *.auth.openai.com
Valid: 2025-11-27 20:55:40 → 2026-02-25 21:55:38
09274f30abb7f11d… cloudflare · nimbus2026
Subject: auth.openai.com
Issuer: E8
SANs: *.auth.openai.com, auth.openai.com
Valid: 2025-11-27 15:02:03 → 2026-02-25 15:02:02
09274f30abb7f11d… sectigo · elephant2026h1
Subject: auth.openai.com
Issuer: E8
SANs: *.auth.openai.com, auth.openai.com
Valid: 2025-11-27 15:02:03 → 2026-02-25 15:02:02
4fe333566895d210… cloudflare · nimbus2026
Subject: auth.openai.com
Issuer: R13
SANs: *.auth.openai.com, auth.openai.com
Valid: 2025-11-27 15:01:59 → 2026-02-25 15:01:58
4fe333566895d210… sectigo · elephant2026h1
Subject: auth.openai.com
Issuer: R13
SANs: *.auth.openai.com, auth.openai.com
Valid: 2025-11-27 15:01:59 → 2026-02-25 15:01:58

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
AAAA 2a06:98c1:3106::ac40:920f 2026-05-26 15:29:36.699 2026-06-21 03:33:31.470
AAAA 2606:4700:4406::6812:29f1 2026-05-26 15:29:36.699 2026-06-21 03:33:31.470
A 104.18.41.241 2026-05-26 15:29:36.699 2026-07-24 15:12:08.939
A 172.64.146.15 2026-05-26 15:29:36.699 2026-07-24 15:12:08.939
AAAA 2606:4700:4400::6812:29f1 2026-07-21 16:21:30.235 2026-07-24 15:12:08.939
AAAA 2a06:98c1:310c::ac40:920f 2026-07-21 16:21:30.235 2026-07-24 15:12:08.939