Check-Host.cc

Domain

api.example.com

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of api.example.com

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
A/AAAA targets
Subdomains
CT + scan + body
Record Types
seen in DNS
Observed Certs
in our scans

DNS Records

A
AAAA
MX
NS
TXT
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Subject: demo-api.example.com
Issuer: demo-api.example.com
SANs: demo-api.example.com
Subject: demo-api.example.com
Issuer: demo-api.example.com
SANs: demo-api.example.com
Subject: dev-idpf-api.example.com
Issuer: dev-idpf Root CA
SANs: dev-idpf-api.example.com
Subject: lb.example.com
Issuer: lb.example.com
SANs: api.example.com, lb.example.com
Subject: api.example.com
Issuer: api.example.com
SANs: api.example.com
Subject: math-api.example.com
Issuer: math-api.example.com
SANs: *.elb.amazonaws.com, *.us-west-2.elb.amazonaws.com, math-api.example.com
Subject: C=US, ST=CA
Issuer: C=US, ST=California, O=Example CA
SANs: api.example.com, app.example.com, www.example.com
Subject: cloud-api.example.com
Issuer: cloud-api.example.com
SANs: cloud-api.example.com

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

120.48.123.240:8080 href · ×6
124.221.237.84:443 href · ×4
120.48.37.230:5000 href · ×4
158.180.75.4:443 href · ×4
138.124.86.144:8443 href · ×4
136.112.88.222:443 href · ×4
43.134.49.184:80 href · ×4
2.26.83.249:8888 href · ×3
130.83.128.193:443 href · ×3
20.254.68.27:443 href · ×3
91.195.56.52:443 href · ×3
5.188.78.139:443 href · ×3
47.92.192.255:80 href · ×3
91.218.112.180:443 href · ×3
20.188.29.163:443 href · ×3
5.78.63.97:443 href · ×3
64.227.171.249:443 href · ×3
85.214.96.104:443 href · ×3
185.57.66.97:443 href · ×2
170.64.221.122:443 href · ×2
178.254.35.240:443 href · ×2
91.134.135.148:443 href · ×2
82.177.57.36:443 href · ×2
46.224.128.122:443 href · ×2
154.37.218.139:443 href · ×2
185.26.104.171:443 href · ×2
151.80.147.200:443 href · ×2
212.98.56.147:443 href · ×2
5.182.21.4:443 href · ×2
89.167.106.13:443 href · ×2
213.221.24.145:443 href · ×2
185.226.117.23:443 href · ×2
163.227.224.27:443 href · ×2
195.93.253.97:443 href · ×2
144.91.67.25:443 href · ×2
2.27.86.253:443 href · ×2
185.147.81.11:443 href · ×2
82.196.120.74:443 href · ×2
46.10.160.252:443 href · ×2
144.126.232.204:443 href · ×2
5.75.233.249:443 href · ×2
32.194.232.17:443 href · ×2
87.99.143.145:443 href · ×2
193.138.81.77:443 href · ×2
176.9.211.196:443 href · ×2
109.123.242.39:443 href · ×2
132.226.199.53:443 href · ×2
145.255.5.90:443 href · ×2
129.28.95.17:80 href · ×2
90.158.121.56:443 href · ×2

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Domain timeline pending

Passive-DNS history accumulates as our forward-DNS crawler observes A/AAAA/MX/NS/TXT records over time.