Check-Host.cc

Domain

htmlcodex.com

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of htmlcodex.com

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
6
A/AAAA targets
Subdomains
23
CT + scan + body
Record Types
6
seen in DNS
Observed Certs
11
in our scans

DNS Records

A
104.21.23.168, 172.67.212.89
AAAA
2606:4700:3033::6815:17a8, 2606:4700:3034::6815:17a8, 2606:4700:3034::ac43:d459, 2606:4700:3037::ac43:d459
MX
1 aspmx.l.google.com, 10 alt3.aspmx.l.google.com, 10 alt4.aspmx.l.google.com, 5 alt1.aspmx.l.google.com, 5 alt2.aspmx.l.google.com
NS
jule.ns.cloudflare.com, skip.ns.cloudflare.com
TXT
google-site-verification=xApK4mBZ9ni9TPE4ZigCp9WI1UeLzenPfBKfp7zF8Ew, v=spf1 a mx include:websitewelcome.com include:_spf.google.com ~all
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Every subdomain we know about — harvested from CT-log SANs, scan-observed certs and HTML body references — paired with its current A/AAAA target.

Subdomain Resolves to Last seen
htmlcodex.com 2026-07-28 20:23:38.809
download.htmlcodex.com 2026-05-31 01:19:40.742
autodiscover.htmlcodex.com
1970-01-01 00:00:00.000
cpanel.htmlcodex.com
1970-01-01 00:00:00.000
cpcalendars.htmlcodex.com
1970-01-01 00:00:00.000
cpcontacts.htmlcodex.com
1970-01-01 00:00:00.000
mail.htmlcodex.com
1970-01-01 00:00:00.000
webdisk.htmlcodex.com
1970-01-01 00:00:00.000
webmail.htmlcodex.com
1970-01-01 00:00:00.000
www.htmlcodex.com
1970-01-01 00:00:00.000

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

5.161.101.61:443 href · ×12
20.66.121.51:443 href · ×8
165.22.218.49:443 href · ×6
138.0.60.19:443 href · ×6
206.42.10.37:80 href · ×6
193.8.172.148:80 href · ×4
46.224.223.187:80 href · ×4
177.11.15.134:80 href · ×4
45.6.1.195:8081 href · ×4
45.166.222.205:80 href · ×4
200.125.173.243:80 href · ×4
138.36.240.223:443 href · ×4
45.4.144.204:443 href · ×4
103.188.175.6:443 href · ×4
163.172.168.28:80 href · ×4
203.125.60.69:443 href · ×4
206.85.13.152:80 href · ×4
187.63.123.255:80 href · ×4
170.231.91.236:443 href · ×4
38.60.194.180:80 href · ×4
206.85.13.174:80 href · ×4
187.93.64.132:80 href · ×4
158.69.178.134:443 href · ×4
185.21.10.174:80 href · ×4
190.11.208.194:443 href · ×4
189.76.210.83:443 href · ×4
190.12.132.13:443 href · ×4
206.85.13.108:80 href · ×4
177.11.55.241:443 href · ×4
189.113.180.46:443 href · ×4
172.96.193.68:443 href · ×4
210.184.49.200:8443 href · ×4
201.13.0.36:443 href · ×4
177.87.84.250:443 href · ×4
5.78.221.180:80 href · ×4
212.47.237.146:80 href · ×4
200.125.173.243:443 href · ×4
45.6.1.233:8081 href · ×4
183.178.148.131:8443 href · ×4
179.61.154.36:80 href · ×4
179.61.154.39:80 href · ×4
177.11.15.136:443 href · ×4
144.217.207.65:443 href · ×4
20.247.51.178:993 href · ×4
138.204.186.74:443 href · ×4
20.212.43.49:8443 href · ×4
206.85.13.14:443 href · ×4
206.85.13.116:443 href · ×4
13.114.127.210:80 href · ×4
66.112.212.227:443 href · ×4

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
AAAA 2606:4700:3033::6815:17a8 2026-05-25 21:56:50.553 2026-06-23 23:35:49.207
A 104.21.23.168 2026-05-25 21:56:50.553 2026-07-28 20:23:38.809
A 172.67.212.89 2026-05-25 21:56:50.553 2026-07-28 20:23:38.809
AAAA 2606:4700:3034::ac43:d459 2026-05-25 21:56:50.553 2026-06-23 23:35:49.207
NS jule.ns.cloudflare.com 2026-05-25 22:13:29.500 2026-07-28 20:23:38.809
NS skip.ns.cloudflare.com 2026-05-25 22:13:29.500 2026-07-28 20:23:38.809
TXT v=spf1 a mx include:websitewelcome.com include:_spf.google.com ~all 2026-05-25 22:13:29.500 2026-07-28 20:23:38.809
MX 5 alt2.aspmx.l.google.com 2026-05-25 22:13:29.500 2026-07-28 20:23:38.809
MX 10 alt4.aspmx.l.google.com 2026-05-25 22:13:29.500 2026-07-28 20:23:38.809
MX 1 aspmx.l.google.com 2026-05-25 22:13:29.500 2026-07-28 20:23:38.809
TXT google-site-verification=xApK4mBZ9ni9TPE4ZigCp9WI1UeLzenPfBKfp7zF8Ew 2026-05-25 22:13:29.500 2026-07-28 20:23:38.809
MX 5 alt1.aspmx.l.google.com 2026-05-25 22:13:29.500 2026-07-28 20:23:38.809
MX 10 alt3.aspmx.l.google.com 2026-05-25 22:13:29.500 2026-07-28 20:23:38.809
SRV _autodiscover._tcp 0 0 443 cpanelemaildiscovery.cpanel.net 2026-05-25 23:59:40.866 2026-07-28 20:23:38.809
SRV _carddav._tcp 0 0 2079 gator4127.hostgator.com 2026-05-25 23:59:40.866 2026-07-28 20:23:38.809
SRV _caldav._tcp 0 0 2079 gator4127.hostgator.com 2026-05-25 23:59:40.866 2026-07-28 20:23:38.809
AAAA 2606:4700:3037::ac43:d459 2026-07-15 20:04:13.980 2026-07-28 20:23:38.809
AAAA 2606:4700:3034::6815:17a8 2026-07-15 20:04:13.980 2026-07-28 20:23:38.809