Check-Host.cc

Domain

steem.com

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of steem.com

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
8
A/AAAA targets
Subdomains
13
CT + scan + body
Record Types
5
seen in DNS
Observed Certs
2
in our scans

DNS Records

A
185.199.108.153, 185.199.109.153, 185.199.110.153, 185.199.111.153
AAAA
2606:50c0:8000::153, 2606:50c0:8001::153, 2606:50c0:8002::153, 2606:50c0:8003::153
MX
1 aspmx.l.google.com, 10 aspmx2.googlemail.com, 10 aspmx3.googlemail.com, 5 alt1.aspmx.l.google.com, 5 alt2.aspmx.l.google.com
NS
ns-1184.awsdns-20.org, ns-1998.awsdns-57.co.uk, ns-205.awsdns-25.com, ns-686.awsdns-21.net
TXT
v=spf1 include:_spf.google.com ~all
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Subject: vps102668.esteem.com.my
Issuer: YR1
SANs: vps102668.esteem.com.my
Subject: kv-03.aristeem.com
Issuer: YE1
SANs: kv-03.aristeem.com
Subject: api.riseselfesteem.com
Issuer: E8
SANs: api.riseselfesteem.com
Subject: xplore.safe-esteem.com
Issuer: Amazon RSA 2048 M01
SANs: xplore.safe-esteem.com
Subject: *.dristeem.com
Issuer: Starfield Secure Certificate Authority - G2
SANs: *.dristeem.com, dristeem.com
Subject: api.trysteem.com
Issuer: Amazon RSA 2048 M04
SANs: api.trysteem.com
Subject: api.riseselfesteem.com
Issuer: E8
SANs: api.riseselfesteem.com
Subject: vps102668.esteem.com.my
Issuer: R13
SANs: vps102668.esteem.com.my

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

188.68.55.39:8080 href · ×1
13.223.21.223:443 href · ×1
34.201.227.126:443 href · ×1

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

CT-Log Evidence

Certificates from public Certificate Transparency logs whose subject or SAN names this domain — including historic certs we never observed live.

b534139266b42a63… google · argon2026h2
Subject: steem.com
Issuer: Amazon RSA 2048 M04
SANs: steem.com, *.steem.io, *.steem.com, steem.io
Valid: 2025-09-18 00:00:00 → 2026-10-16 23:59:59
b55e9458b1a1a37c… google · argon2026h2
Subject: steem.com
Issuer: Amazon RSA 2048 M04
SANs: steem.com, *.steem.io, *.steem.com, steem.io
Valid: 2025-09-18 00:00:00 → 2026-10-16 23:59:59

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Domain timeline pending

Passive-DNS history accumulates as our forward-DNS crawler observes A/AAAA/MX/NS/TXT records over time.