Check-Host.cc

Domain

global.oup.com

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of global.oup.com

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
A/AAAA targets
Subdomains
CT + scan + body
Record Types
seen in DNS
Observed Certs
in our scans

DNS Records

A
108.132.120.164, 108.133.116.13, 18.202.5.118, 3.248.60.231, 52.16.68.251, 52.17.101.2, 52.17.251.2, 52.51.218.47
AAAA
MX
NS
TXT
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Subject: *.oup.com
Issuer: DigiCert TLS RSA SHA256 2020 CA1
SANs: *.oup.com, global.oup.com, learninglink.oup.com, oup.com

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

159.203.216.192:80 href · ×1
220.68.249.14:443 href · ×1
217.69.8.21:443 href · ×1
52.9.170.73:80 href · ×1
167.179.100.217:443 href · ×1
103.74.84.31:443 href · ×1
35.172.112.60:443 href · ×1
82.223.52.41:443 href · ×1
44.222.52.118:443 href · ×1

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
A 52.16.68.251 2026-05-26 20:28:03.075 2026-05-27 13:29:41.935
A 54.170.4.222 2026-05-26 20:28:03.075 2026-05-27 13:29:41.935
A 18.202.5.118 2026-06-14 22:52:09.672 2026-06-15 01:22:55.677
A 108.132.120.164 2026-06-14 22:52:09.672 2026-06-21 06:03:37.319
A 3.248.60.231 2026-06-21 06:03:37.319 2026-06-21 06:03:37.319
A 52.51.218.47 2026-06-23 20:00:26.071 2026-06-23 20:04:18.632
A 52.17.101.2 2026-06-23 20:00:26.071 2026-06-23 20:04:18.632
A 52.17.251.2 2026-07-26 08:54:07.116 2026-07-26 09:02:45.579
A 108.133.116.13 2026-07-26 08:54:07.116 2026-07-26 09:02:45.579