user.show
Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.
Run a live full scan of user.show
On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.
DNS Records
WHOIS / Registration
Registration data planned
Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.
Subdomains
Every subdomain we know about — harvested from CT-log SANs, scan-observed certs and HTML body references — paired with its current A/AAAA target.
| Subdomain | Resolves to | Last seen |
|---|---|---|
| 0d4.user.show | 1970-01-01 00:00:00.000 | |
| 7cn.user.show | 1970-01-01 00:00:00.000 | |
| account.user.show | 1970-01-01 00:00:00.000 | |
| admin.user.show | 1970-01-01 00:00:00.000 | |
| apply.user.show | 1970-01-01 00:00:00.000 | |
| auth.user.show | 1970-01-01 00:00:00.000 | |
| cn.user.show | 1970-01-01 00:00:00.000 | |
| com.user.show | 1970-01-01 00:00:00.000 | |
| dashboard.user.show | 1970-01-01 00:00:00.000 | |
| de.user.show | 1970-01-01 00:00:00.000 | |
| deleted.user.show | 1970-01-01 00:00:00.000 | |
| department.user.show | 1970-01-01 00:00:00.000 | |
| dev.user.show | 1970-01-01 00:00:00.000 | |
| dk.user.show | 1970-01-01 00:00:00.000 | |
| ee.user.show | 1970-01-01 00:00:00.000 | |
| eu.user.show | 1970-01-01 00:00:00.000 | |
| events.user.show | 1970-01-01 00:00:00.000 | |
| fi.user.show | 1970-01-01 00:00:00.000 | |
| gui.user.show | 1970-01-01 00:00:00.000 | |
| hjc.user.show | 1970-01-01 00:00:00.000 | |
| html.user.show | 1970-01-01 00:00:00.000 | |
| ie.user.show | 1970-01-01 00:00:00.000 | |
| int.user.show | 1970-01-01 00:00:00.000 | |
| lt.user.show | 1970-01-01 00:00:00.000 | |
| lu.user.show | 1970-01-01 00:00:00.000 | |
| lv.user.show | 1970-01-01 00:00:00.000 | |
| master.user.show | 1970-01-01 00:00:00.000 | |
| modal.user.show | 1970-01-01 00:00:00.000 | |
| net.user.show | 1970-01-01 00:00:00.000 | |
| no.user.show | 1970-01-01 00:00:00.000 | |
| nu.user.show | 1970-01-01 00:00:00.000 | |
| org.user.show | 1970-01-01 00:00:00.000 | |
| panels.user.show | 1970-01-01 00:00:00.000 | |
| profile.user.show | 1970-01-01 00:00:00.000 | |
| properties.user.show | 1970-01-01 00:00:00.000 | |
| qj.user.show | 1970-01-01 00:00:00.000 | |
| qj3.user.show | 1970-01-01 00:00:00.000 | |
| quantile.user.show | 1970-01-01 00:00:00.000 | |
| se.user.show | 1970-01-01 00:00:00.000 | |
| structures.user.show | 1970-01-01 00:00:00.000 | |
| switch.user.show | 1970-01-01 00:00:00.000 | |
| tenant.user.show | 1970-01-01 00:00:00.000 | |
| tickets.user.show | 1970-01-01 00:00:00.000 | |
| user.show | 1970-01-01 00:00:00.000 | |
| v1.user.show | 1970-01-01 00:00:00.000 | |
| ww38.apply.user.show | 1970-01-01 00:00:00.000 | |
| ww38.com.user.show | 1970-01-01 00:00:00.000 | |
| ww38.de.user.show | 1970-01-01 00:00:00.000 | |
| ww38.dk.user.show | 1970-01-01 00:00:00.000 | |
| ww38.e.user.show | 1970-01-01 00:00:00.000 | |
| ww38.net.user.show | 1970-01-01 00:00:00.000 | |
| ww38.x3i.user.show | 1970-01-01 00:00:00.000 | |
| x3i.user.show | 1970-01-01 00:00:00.000 | |
| xn--p1ai.user.show | 1970-01-01 00:00:00.000 |
Tech Stack
Tech detection pending
Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.
TLS Certificates
Certificate observations pending
TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.
IPs Citing This Domain
No citing IPs found yet
As the world-sweep progresses, hosts referencing this domain in their HTML will surface here.
Origin / IP-Leak
When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.
No origin-IP leaks detected (yet)
Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.
Threat Intelligence
Domain threat-intel pending
Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.
History
Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.
| Type | Value | First seen | Last seen |
|---|---|---|---|
| NS | cloth.dnspod.net | 2026-06-19 10:19:24.494 | 2026-06-21 00:59:18.447 |
| NS | coral.dnspod.net | 2026-06-19 10:19:24.494 | 2026-06-21 00:59:18.447 |