Check-Host.cc

Domain

x.gd

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of x.gd

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
A/AAAA targets
Subdomains
CT + scan + body
Record Types
seen in DNS
Observed Certs
in our scans

DNS Records

A
104.21.46.170, 172.67.140.193
AAAA
MX
NS
alan.ns.cloudflare.com, poppy.ns.cloudflare.com
TXT
google-site-verification=R2iLnkWqFjSQjNqCWkr10HVjSl3vJJYteJ10oHGZWmo
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Every subdomain we know about — harvested from CT-log SANs, scan-observed certs and HTML body references — paired with its current A/AAAA target.

Subdomain Resolves to Last seen
x.gd 2026-07-25 11:37:35.289
v2x2.x.gd
1970-01-01 00:00:00.000

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

54.95.200.172:443 href · ×44
133.242.19.148:443 href · ×42
133.167.122.252:443 href · ×8
153.126.162.7:80 href · ×6
133.242.147.175:443 href · ×5
210.172.101.213:80 href · ×4
153.120.171.209:443 href · ×4
180.222.185.16:443 href · ×4
60.43.210.205:80 href · ×3
150.60.218.238:443 href · ×2
61.208.209.46:80 href · ×2
18.181.36.197:443 href · ×2
200.144.4.102:80 href · ×2
153.127.44.156:80 href · ×2
202.214.43.45:80 href · ×2
34.60.27.208:80 href · ×2
35.189.155.231:443 href · ×2
133.25.221.46:80 href · ×2
133.242.146.176:443 href · ×2
61.126.51.38:443 href · ×1
153.149.194.108:443 href · ×1
157.205.127.37:443 href · ×1
202.214.43.46:443 href · ×1
153.149.194.108:80 href · ×1
219.94.215.119:443 href · ×1
202.51.11.59:443 href · ×1
13.112.213.62:443 href · ×1
211.1.47.15:80 href · ×1
163.43.100.182:80 href · ×1
194.91.3.165:443 href · ×1
54.238.192.54:443 href · ×1
183.90.235.164:443 href · ×1
153.120.164.215:443 href · ×1
54.248.210.55:443 href · ×1
210.148.155.67:443 href · ×1
210.154.219.120:80 href · ×1
194.91.3.172:443 href · ×1
218.216.185.50:80 href · ×1
176.34.62.213:443 href · ×1
163.43.100.182:443 href · ×1
163.43.100.188:80 href · ×1
157.205.181.13:443 href · ×1
202.214.43.45:443 href · ×1
61.208.209.46:443 href · ×1
210.154.235.53:80 href · ×1
210.170.110.129:443 href · ×1
61.208.209.45:443 href · ×1
133.167.66.133:443 href · ×1
219.118.193.247:443 href · ×1
18.180.71.81:443 href · ×1

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Domain timeline pending

Passive-DNS history accumulates as our forward-DNS crawler observes A/AAAA/MX/NS/TXT records over time.