Check-Host.cc

Domain

docs.openclaw.ai

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of docs.openclaw.ai

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
6
A/AAAA targets
Subdomains
CT + scan + body
Record Types
2
seen in DNS
Observed Certs
1
in our scans

DNS Records

A
104.21.13.122, 172.67.167.244
AAAA
2606:4700:3030::6815:d7a, 2606:4700:3032::ac43:a7f4, 2606:4700:3034::ac43:a7f4, 2606:4700:3037::6815:d7a
MX
NS
TXT
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

47.101.193.240:8080 href · ×9
39.97.33.55:443 href · ×8
47.128.90.85:443 href · ×8
120.25.191.240:80 href · ×4
52.203.20.136:443 href · ×4
136.183.56.193:80 href · ×4
39.106.166.155:80 href · ×4
13.228.164.241:443 href · ×3
175.178.243.192:443 href · ×3
129.204.157.15:80 href · ×2
47.94.169.93:80 href · ×2
35.247.10.96:8000 href · ×2
43.139.213.244:8080 href · ×2
106.54.206.154:80 href · ×2
47.253.113.252:80 href · ×2
8.147.59.215:80 href · ×2
120.76.141.44:443 href · ×1
74.91.136.116:443 href · ×1
158.160.231.33:443 href · ×1
44.218.109.91:443 href · ×1
201.51.8.126:443 href · ×1
155.212.220.135:443 href · ×1
209.38.107.15:443 href · ×1
103.195.238.75:443 href · ×1
139.155.129.15:443 href · ×1
34.165.34.140:443 href · ×1
161.97.66.48:443 href · ×1
154.36.179.135:8443 href · ×1
81.70.166.16:8443 href · ×1
110.42.48.226:443 href · ×1
32.199.125.26:80 href · ×1
206.189.27.65:443 href · ×1
122.51.229.98:443 href · ×1
39.104.13.44:443 href · ×1
167.233.101.27:443 href · ×1
85.214.91.110:443 href · ×1
185.197.31.49:443 href · ×1
178.105.144.110:443 href · ×1
167.99.236.88:443 href · ×1
64.23.157.48:443 href · ×1
208.113.213.235:80 href · ×1
156.236.75.76:443 href · ×1
118.145.234.89:443 href · ×1
139.155.134.199:8080 href · ×1
206.189.105.37:443 href · ×1
82.157.113.104:443 href · ×1
154.222.31.188:443 href · ×1
159.75.210.155:443 href · ×1
167.233.48.251:443 href · ×1
47.243.157.247:443 href · ×1

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
A 104.21.13.122 2026-05-25 22:11:29.484 2026-07-28 20:31:39.973
A 172.67.167.244 2026-05-25 22:11:29.484 2026-07-28 20:31:39.973
AAAA 2606:4700:3037::6815:d7a 2026-05-25 22:11:29.484 2026-06-23 17:22:53.461
AAAA 2606:4700:3034::ac43:a7f4 2026-05-25 22:11:29.484 2026-06-23 17:22:53.461
AAAA 2606:4700:3030::6815:d7a 2026-07-16 10:56:09.141 2026-07-28 20:31:39.973
AAAA 2606:4700:3032::ac43:a7f4 2026-07-16 10:56:09.141 2026-07-28 20:31:39.973