Check-Host.cc

Domain

sphinx-doc.org

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of sphinx-doc.org

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
6
A/AAAA targets
Subdomains
19
CT + scan + body
Record Types
3
seen in DNS
Observed Certs
6
in our scans

DNS Records

A
104.21.11.126, 172.67.166.9
AAAA
2606:4700:3031::ac43:a609, 2606:4700:3032::6815:b7e, 2606:4700:3034::6815:b7e, 2606:4700:3037::ac43:a609
MX
NS
aurora.ns.cloudflare.com, terin.ns.cloudflare.com
TXT
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Every subdomain we know about — harvested from CT-log SANs, scan-observed certs and HTML body references — paired with its current A/AAAA target.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

85.214.243.19:80 href · ×2
100.27.83.229:443 href · ×2
18.138.89.98:443 href · ×1
185.117.82.36:443 href · ×1
34.102.139.107:443 href · ×1
104.36.110.15:80 href · ×1
45.33.199.176:443 href · ×1
117.50.15.14:80 href · ×1
54.153.28.208:80 href · ×1
45.63.56.137:443 href · ×1
47.108.146.13:80 href · ×1
137.74.28.212:443 href · ×1
107.170.47.141:80 href · ×1
34.238.230.185:443 href · ×1
104.131.21.103:80 href · ×1
39.98.164.63:443 href · ×1
44.195.71.147:443 href · ×1
173.249.220.47:80 href · ×1
89.58.12.181:80 href · ×1
154.21.94.170:443 href · ×1
91.225.115.19:443 href · ×1
75.119.156.255:8081 href · ×1
170.106.108.162:80 href · ×1
130.255.76.54:443 href · ×1
78.47.78.120:80 href · ×1
44.208.254.124:443 href · ×1
51.178.48.145:80 href · ×1
193.69.239.202:80 href · ×1
206.189.240.82:8080 href · ×1
185.117.82.50:443 href · ×1
193.70.74.220:8000 href · ×1
18.162.154.98:443 href · ×1
46.235.225.72:443 href · ×1
49.212.160.40:443 href · ×1
185.117.82.45:80 href · ×1
54.72.166.204:443 href · ×1
72.18.215.172:80 href · ×1

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Domain timeline pending

Passive-DNS history accumulates as our forward-DNS crawler observes A/AAAA/MX/NS/TXT records over time.