Check-Host.cc

Domain

embed.tawk.to

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of embed.tawk.to

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
A/AAAA targets
Subdomains
CT + scan + body
Record Types
seen in DNS
Observed Certs
in our scans

DNS Records

A
104.20.42.169, 172.66.161.212
AAAA
2606:4700:10::6814:2aa9, 2606:4700:10::ac42:a1d4
MX
NS
TXT
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

79.137.76.179:8080 href · ×8
207.58.153.28:8080 href · ×8
213.199.38.0:443 href · ×6
95.40.133.197:80 href · ×6
34.100.254.62:80 href · ×6
66.39.84.42:443 href · ×6
129.154.231.226:443 href · ×5
194.163.182.196:80 href · ×5
50.6.251.7:443 href · ×4
91.229.239.43:7001 href · ×4
209.38.125.118:443 href · ×4
13.202.245.2:80 href · ×4
170.106.67.73:80 href · ×4
167.71.172.29:80 href · ×4
167.71.172.29:443 href · ×4
209.38.125.118:80 href · ×4
103.153.149.180:80 href · ×3
43.164.196.146:80 href · ×3
216.92.248.51:443 href · ×3
103.234.195.115:443 href · ×3
136.243.40.216:443 href · ×3
119.92.172.188:443 href · ×3
34.21.143.144:443 href · ×3
159.89.138.84:80 href · ×3
209.38.187.218:80 href · ×3
172.204.216.34:80 href · ×3
119.92.172.188:80 href · ×3
103.234.195.119:443 href · ×3
3.86.21.66:80 href · ×3
103.245.39.231:443 href · ×3
152.44.42.46:443 href · ×3
170.64.209.36:443 href · ×3
144.126.255.73:443 href · ×3
174.138.82.7:443 href · ×3
63.250.40.111:443 href · ×2
5.199.143.126:443 href · ×2
46.62.218.147:443 href · ×2
154.205.145.196:80 href · ×2
103.65.21.173:443 href · ×2
116.203.60.88:443 href · ×2
184.168.120.140:443 href · ×2
185.241.125.204:80 href · ×2
5.223.62.187:80 href · ×2
102.240.3.25:443 href · ×2
103.245.225.201:443 href · ×2
103.14.0.72:80 href · ×2
78.159.112.234:80 href · ×2
115.85.80.22:80 href · ×2
156.244.12.180:80 href · ×2
159.65.254.40:443 href · ×2

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
A 104.20.42.169 2026-05-25 21:54:50.392 2026-07-28 20:31:39.973
A 172.66.161.212 2026-05-25 21:54:50.392 2026-07-28 20:31:39.973
AAAA 2606:4700:10::6814:2aa9 2026-05-25 21:54:50.392 2026-07-28 20:31:39.973
AAAA 2606:4700:10::ac42:a1d4 2026-05-25 21:54:50.392 2026-07-28 20:31:39.973