Check-Host.cc

Domain

l.facebook.com

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of l.facebook.com

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
A/AAAA targets
Subdomains
CT + scan + body
Record Types
seen in DNS
Observed Certs
in our scans

DNS Records

A
AAAA
MX
NS
TXT
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

57.182.186.61:80 href · ×30
94.130.27.231:443 href · ×15
54.207.90.1:80 href · ×10
34.248.248.77:443 href · ×9
72.167.87.216:80 href · ×6
80.76.206.245:443 href · ×6
149.28.135.23:443 href · ×5
34.56.144.176:443 href · ×5
178.216.201.3:443 href · ×4
184.169.160.217:443 href · ×4
139.179.39.6:80 href · ×4
89.160.80.35:443 href · ×3
78.47.130.124:80 href · ×3
200.49.226.33:443 href · ×3
16.170.173.23:80 href · ×2
45.137.213.56:443 href · ×2
139.59.228.9:80 href · ×2
35.208.84.230:443 href · ×2
5.45.114.25:80 href · ×2
128.226.8.22:443 href · ×2
61.64.52.156:443 href · ×2
173.231.216.109:443 href · ×2
193.6.202.20:80 href · ×2
66.39.8.181:80 href · ×2
135.181.221.248:443 href · ×2
18.142.58.203:443 href · ×2
87.229.32.91:443 href · ×2
43.230.208.12:443 href · ×2
138.199.231.171:443 href · ×2
15.235.157.76:80 href · ×2
47.88.32.117:80 href · ×2
34.145.89.125:80 href · ×2
89.238.89.154:443 href · ×2
180.222.185.140:443 href · ×2
216.146.222.46:80 href · ×2
208.109.37.15:443 href · ×2
159.203.2.244:443 href · ×1
218.40.197.86:443 href · ×1
3.238.203.72:80 href · ×1
52.74.218.209:80 href · ×1
3.87.86.144:80 href · ×1
122.116.205.115:443 href · ×1
109.122.218.229:443 href · ×1
196.189.149.141:80 href · ×1
161.34.14.237:443 href · ×1
5.135.6.129:443 href · ×1
16.170.232.243:80 href · ×1
56.228.2.231:80 href · ×1
142.93.176.238:80 href · ×1
3.36.50.48:80 href · ×1

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Domain timeline pending

Passive-DNS history accumulates as our forward-DNS crawler observes A/AAAA/MX/NS/TXT records over time.