Check-Host.cc

Domain

learn.wordpress.org

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of learn.wordpress.org

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
4
A/AAAA targets
Subdomains
CT + scan + body
Record Types
6
seen in DNS
Observed Certs
in our scans

DNS Records

A
198.143.164.252, 66.6.42.252
AAAA
2607:f978:5:8002::c68f:a4fc, 2620:109:b00a::4206:2afc
MX
10 smtp1-dca.wordpress.org, 10 smtp1-ord.wordpress.org, 10 smtp2-dca.wordpress.org, 10 smtp2-ord.wordpress.org
NS
ns1.wordpress.org, ns2.wordpress.org, ns3.wordpress.org, ns4.wordpress.org
TXT
google-site-verification=UL0sGJ1dZbCT4J7pGrLW3hqM_I1LJ8pUi2WBEI_98kI, google-site-verification=t8FjG1vzC4OFZJ8qL4SkR8xxtLyKldXKbswyeemQS5w, v=spf1 ip4:66.6.42.0/24 ip4:66.155.40.0/24 include:helpscoutemail.com -all, v=spf1 ip4:66.6.42.0/24 ip4:66.155.40.0/24 ip4:198.143.164.0/24 include:helpscoutemail.com -all
CNAME
CAA
0 iodef "mailto:caa@wordpress.org", 0 issue "letsencrypt.org;validationmethods=dns-01;accounturi=https://acme-v02.api.letsencrypt.org/acme/acct/53691143"

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

51.75.64.145:80 href · ×3
162.241.13.108:443 href · ×1
157.245.95.213:80 href · ×1
178.63.148.132:80 href · ×1
35.178.140.164:80 href · ×1
150.158.114.109:80 href · ×1
201.216.239.96:80 href · ×1
47.107.117.39:80 href · ×1
51.195.152.21:443 href · ×1
34.197.62.183:443 href · ×1
194.116.76.31:443 href · ×1
54.199.189.203:443 href · ×1
152.42.236.125:80 href · ×1
70.34.207.52:80 href · ×1
52.207.63.190:443 href · ×1
146.190.27.105:443 href · ×1
217.79.248.18:443 href · ×1
108.175.5.23:80 href · ×1
100.20.80.97:80 href · ×1
143.233.247.62:80 href · ×1
3.215.14.19:80 href · ×1
158.247.209.4:443 href · ×1
208.109.73.100:443 href · ×1
39.97.241.224:80 href · ×1
98.83.109.132:443 href · ×1
35.210.206.35:80 href · ×1
213.32.54.173:443 href · ×1
20.29.113.60:443 href · ×1
201.158.38.250:80 href · ×1
3.37.233.4:80 href · ×1
161.33.218.171:80 href · ×1
8.159.156.152:443 href · ×1
13.250.123.121:80 href · ×1
3.22.42.14:80 href · ×1
65.28.109.255:443 href · ×1
15.236.140.133:80 href · ×1
185.55.225.161:443 href · ×1
13.57.148.86:80 href · ×1
152.42.236.125:443 href · ×1
98.83.109.132:80 href · ×1
15.206.10.45:80 href · ×1
3.237.101.7:80 href · ×1
54.199.189.203:80 href · ×1
71.205.147.203:80 href · ×1
106.15.93.149:80 href · ×1
35.172.102.152:80 href · ×1
161.33.218.171:443 href · ×1
23.254.231.147:443 href · ×1
132.226.132.96:443 href · ×1
159.89.6.105:80 href · ×1

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
TXT google-site-verification=UL0sGJ1dZbCT4J7pGrLW3hqM_I1LJ8pUi2WBEI_98kI 2026-05-26 04:07:00.841 2026-07-26 22:22:22.975
MX 10 smtp2-ord.wordpress.org 2026-05-26 04:07:00.841 2026-05-27 17:29:58.988
NS ns4.wordpress.org 2026-05-26 04:07:00.841 2026-07-26 22:22:22.975
AAAA 2607:f978:5:8002::c68f:a4fc 2026-05-26 04:07:00.841 2026-06-23 02:50:28.761
TXT google-site-verification=t8FjG1vzC4OFZJ8qL4SkR8xxtLyKldXKbswyeemQS5w 2026-05-26 04:07:00.841 2026-07-26 22:22:22.975
NS ns2.wordpress.org 2026-05-26 04:07:00.841 2026-07-26 22:22:22.975
CAA 0 issue "letsencrypt.org;validationmethods=dns-01;accounturi=https://acme-v02.api.letsencrypt.org/acme/acct/53691143" 2026-05-26 04:07:00.841 2026-07-26 22:22:22.975
NS ns3.wordpress.org 2026-05-26 04:07:00.841 2026-07-26 22:22:22.975
CAA 0 iodef "mailto:caa@wordpress.org" 2026-05-26 04:07:00.841 2026-07-26 22:22:22.975
TXT v=spf1 ip4:66.6.42.0/24 ip4:66.155.40.0/24 ip4:198.143.164.0/24 include:helpscoutemail.com -all 2026-05-26 04:07:00.841 2026-06-23 02:50:28.761
NS ns1.wordpress.org 2026-05-26 04:07:00.841 2026-07-26 22:22:22.975
A 198.143.164.252 2026-05-26 04:07:00.841 2026-06-23 02:50:28.761
MX 10 smtp1-ord.wordpress.org 2026-05-26 04:07:00.841 2026-05-27 17:29:58.988
MX 10 smtp2-dca.wordpress.org 2026-06-14 22:23:29.853 2026-07-26 22:22:22.975
MX 10 smtp1-dca.wordpress.org 2026-06-14 22:23:29.853 2026-07-26 22:22:22.975
A 66.6.42.252 2026-07-18 05:35:39.131 2026-07-26 22:22:22.975
AAAA 2620:109:b00a::4206:2afc 2026-07-18 05:35:39.131 2026-07-26 22:22:22.975
TXT v=spf1 ip4:66.6.42.0/24 ip4:66.155.40.0/24 include:helpscoutemail.com -all 2026-07-18 05:35:39.131 2026-07-26 22:22:22.975