Check-Host.cc

Domain

ping.keff.org

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of ping.keff.org

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
1
A/AAAA targets
Subdomains
CT + scan + body
Record Types
5
seen in DNS
Observed Certs
4
in our scans

DNS Records

A
45.154.255.52
AAAA
MX
1 mail.keff.org
NS
ns1.he.net, ns2.he.net, ns3.he.net, ns4.he.net, ns5.he.net
TXT
oa1:btc recipient_address=bc1qnq72x5cwpncjv7y2d9fz70yfk6v0wrynfcpzc7; recipient_name=KeFF;, oa1:xmr recipient_address=4APuGQgR1C7C3n4AhNkUXXXF1upLxrSb5Rj9t8FoRs1dBM4UecQqp75LneKJ4dV5v9jJEgEA3J1CKLkH5KyYbLp5SSg6FK6; recipient_name=KeFF;, v=spf1 mx -all
CNAME
CAA
0 issue "letsencrypt.org"

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Subject: keff.org
Issuer: R12
SANs: as41281.net, gre.keff.org, keff.org, ping.keff.org, vps.keff.org

IPs Citing This Domain

No citing IPs found yet

As the world-sweep progresses, hosts referencing this domain in their HTML will surface here.

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
TXT oa1:xmr recipient_address=4APuGQgR1C7C3n4AhNkUXXXF1upLxrSb5Rj9t8FoRs1dBM4UecQqp75LneKJ4dV5v9jJEgEA3J1CKLkH5KyYbLp5SSg6FK6; recipient_name=KeFF; 2026-05-26 05:56:33.758 2026-07-23 06:30:51.162
NS ns3.he.net 2026-05-26 05:56:33.758 2026-07-23 06:30:51.162
NS ns1.he.net 2026-05-26 05:56:33.758 2026-07-23 06:30:51.162
MX 1 mail.keff.org 2026-05-26 05:56:33.758 2026-07-23 06:30:51.162
A 45.154.255.52 2026-05-26 05:56:33.758 2026-07-23 06:30:51.162
NS ns4.he.net 2026-05-26 05:56:33.758 2026-07-23 06:30:51.162
NS ns5.he.net 2026-05-26 05:56:33.758 2026-07-23 06:30:51.162
TXT v=spf1 mx -all 2026-05-26 05:56:33.758 2026-07-23 06:30:51.162
NS ns2.he.net 2026-05-26 05:56:33.758 2026-07-23 06:30:51.162
TXT oa1:btc recipient_address=bc1qnq72x5cwpncjv7y2d9fz70yfk6v0wrynfcpzc7; recipient_name=KeFF; 2026-05-26 05:56:33.758 2026-07-23 06:30:51.162
CAA 0 issue "letsencrypt.org" 2026-07-23 06:30:51.162 2026-07-23 06:30:51.162