copyleaks.com
Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.
Run a live full scan of copyleaks.com
On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.
DNS Records
WHOIS / Registration
Registration data planned
Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.
Subdomains
Every subdomain we know about — harvested from CT-log SANs, scan-observed certs and HTML body references — paired with its current A/AAAA target.
| Subdomain | Resolves to | Last seen |
|---|---|---|
| image.mail.copyleaks.com | 2026-07-25 17:23:34.977 | |
| auth.copyleaks.com | 2026-06-22 15:06:35.832 | |
| copyleaks.com | 2026-07-27 07:19:40.268 | |
| img.emails1.copyleaks.com | 2026-06-22 20:01:25.494 | |
| docs-old.copyleaks.com | 2026-06-17 00:09:49.655 | |
| help.copyleaks.com | 2026-06-15 08:14:01.046 | |
| click.mail.copyleaks.com | 2026-06-20 18:41:24.149 | |
| r.email2.copyleaks.com | 2026-06-19 14:03:59.798 | |
| r.emails1.copyleaks.com | 1970-01-01 00:00:00.000 | |
| salesloft.copyleaks.com | 1970-01-01 00:00:00.000 |
Tech Stack
Tech detection pending
Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.
TLS Certificates
Certificate observations pending
TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.
IPs Citing This Domain
Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.
Origin / IP-Leak
When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.
No origin-IP leaks detected (yet)
Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.
Threat Intelligence
Domain threat-intel pending
Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.
History
Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.
| Type | Value | First seen | Last seen |
|---|---|---|---|
| AAAA | 2606:4700:20::6818:ae14 | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | vwo-validation-k3t9sj8v | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| NS | coco.ns.cloudflare.com | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | brevo-code:aa8b0dc8c25e976ab16f207dd077e3d1 | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | 00DKj00000Bo189=1TBQU0000000D3h | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| AAAA | 2606:4700:20::6818:af14 | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | anthropic-domain-verification-8kwkyy=mtyt2ZX5pvzWV0CTV65hiyGRq | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | brevo-code:53801532a84af569b02b55cf590747aa | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | docusign=52b42afa-182e-4a8d-9b2f-50997c6e8fc7 | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| A | 104.24.175.20 | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | mixpanel-domain-verify=29e2fc83-fb51-42d7-a507-fc3fe9442b87 | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | google-site-verification=R5tP6cehvJ0TGrZbfdiRrFJGfnUrwx-55CJoVPh6jkc | 2026-05-26 00:12:34.719 | 2026-05-26 04:11:07.627 |
| TXT | google-site-verification=GMPVo2tRsaD-hJnwJNaIUOlNl6sat10atVywnZ0wtys | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | v=spf1 include:spf.sendinblue.com include:_spf.google.com include:_spf.salesforce.com ~all | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | MS=ms67576820 | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | atlassian-domain-verification=bZkoDbI6RQim1aBJmSBfIeqH4uxEj/XInsjHyIJSeNHJjcCcAnXILaZm8sk0vKWt | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | stripe-verification=11EBC111CAA046D2A16AB2F13C2DFF6EB9BC56FA9D4AEBF37FD5FDF569F42B7E | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | google-site-verification=FWs2CNnnEHScaEm7mwRjwuueVZWoVXPauktYT4nJlx8 | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | stripe-verification=4254c75e64bc540ee2ed22eff6f734e791ff0fa23992e85b7fa4f4ea5360aea5 | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| AAAA | 2606:4700:20::ac43:60a6 | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | apple-domain-verification=fRPFvUfkWWR7jJZr | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | google-site-verification=fYFNQiSTTWxd1edDpTQy_W9i6VK6kFUtU4cEumhyQZ8 | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | postman-domain-verification=844a4d27661d183cd68a294f7ce23c8c25f1e72361ff345a110afcd30b77410e7b6fc80d22db3be483b2ffc93c4085a5a2ff887031cc71aa589731a87413e678 | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| CAA | 0 issue "ssl.com" | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | cloudflare_dashboard_sso=7df8aafae7fb0922a863cf682ad43516 | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| NS | dan.ns.cloudflare.com | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | mixpanel-domain-verify=8e5a1dd9-85cf-4534-b2d6-fe03131975d1 | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| CAA | 0 issuewild "digicert.com; cansignhttpexchanges=yes" | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | OSSRH-64910 | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| CAA | 0 issuewild "ssl.com" | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| MX | 5 alt2.aspmx.l.google.com | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| MX | 10 alt4.aspmx.l.google.com | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| MX | 1 aspmx.l.google.com | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| A | 172.67.96.166 | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| CAA | 0 issue "digicert.com; cansignhttpexchanges=yes" | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| MX | 5 alt1.aspmx.l.google.com | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| CAA | 0 issue "pki.goog; cansignhttpexchanges=yes" | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| CAA | 0 issuewild "comodoca.com" | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | cursor-domain-verification-963rb6=fiRxGhfZakGQ8S0HM6kETey2X | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| CAA | 0 issuewild "letsencrypt.org" | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| A | 104.24.174.20 | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| CAA | 0 issuewild "pki.goog; cansignhttpexchanges=yes" | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| CAA | 0 issue "cloudflare.com" | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| MX | 10 alt3.aspmx.l.google.com | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| CAA | 0 issue "letsencrypt.org" | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| CAA | 0 issue "comodoca.com" | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |
| TXT | sinch-domain-verification=b37ce13a-aa6e-42e9-bc45-1317e895350f | 2026-05-26 00:12:34.719 | 2026-07-27 07:19:40.268 |