Check-Host.cc

Domain

linux.do

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of linux.do

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
4
A/AAAA targets
Subdomains
34
CT + scan + body
Record Types
7
seen in DNS
Observed Certs
21
in our scans

DNS Records

A
104.20.16.234, 172.66.166.61
AAAA
2606:4700:10::6814:10ea, 2606:4700:10::ac42:a63d
MX
10 mail.linuxdo.org, 5 mail.linux.do
NS
dahlia.ns.cloudflare.com, marek.ns.cloudflare.com
TXT
google-site-verification=dXFnJHavazXf0Czwwn70iSIW1U26O7ZrGWiuPFY5RL4, stripe-verification=d86ad55b4aeb3926892d8b9bbd8f89af18cc0a5d2aaaa45c4a931a644c047d07, v=spf1 include:_spf.smtp.do a:mail.linux.do -all
CNAME
CAA
0 issue "comodoca.com", 0 issue "digicert.com; cansignhttpexchanges=yes", 0 issue "letsencrypt.org", 0 issue "pki.goog; cansignhttpexchanges=yes", 0 issue "ssl.com", 0 issuewild "comodoca.com", 0 issuewild "digicert.com; cansignhttpexchanges=yes", 0 issuewild "letsencrypt.org"

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

57.183.6.226:80 href · ×10
110.42.176.144:443 href · ×8
205.189.160.131:443 href · ×8
140.245.59.16:443 href · ×6
48.210.24.54:8000 href · ×4
18.221.62.25:80 href · ×4
140.245.127.9:8008 href · ×4
150.230.6.159:8000 href · ×4
156.235.28.44:80 href · ×4
107.174.78.154:8000 href · ×2
66.85.45.205:8000 href · ×2
138.2.108.219:8000 href · ×2
198.144.176.100:80 href · ×2
107.174.52.150:8000 href · ×2
47.79.121.49:8000 href · ×2
43.130.57.204:8000 href · ×2
43.159.48.102:8000 href · ×2
172.245.118.209:8081 href · ×2
94.177.17.102:8000 href · ×2
156.239.252.67:8000 href · ×2
204.152.198.252:8000 href · ×2
124.221.161.98:80 href · ×2
199.7.140.102:443 href · ×2
141.147.108.65:8000 href · ×2
165.1.66.49:8000 href · ×2
35.212.167.242:8000 href · ×2
172.237.21.12:8000 href · ×2
23.94.204.215:80 href · ×2
192.227.133.149:8000 href · ×2
74.211.104.77:8000 href · ×2
156.235.28.44:8000 href · ×2
206.237.12.115:8000 href · ×2
192.9.249.238:8000 href · ×2
113.20.9.89:8000 href · ×2
58.87.104.65:8000 href · ×2
60.205.246.14:8000 href · ×2
159.65.108.76:8000 href · ×2
54.253.3.129:8000 href · ×2
144.24.71.135:443 href · ×2
45.43.59.92:8000 href · ×2
43.156.123.182:8000 href · ×2
108.174.49.143:80 href · ×2
103.124.105.157:8000 href · ×2
152.67.220.57:8000 href · ×2
172.245.45.248:8000 href · ×2
138.2.224.254:443 href · ×2
152.42.233.9:8000 href · ×2
43.134.113.101:8000 href · ×2
89.233.104.135:8000 href · ×2
158.101.151.66:8000 href · ×2

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Domain timeline pending

Passive-DNS history accumulates as our forward-DNS crawler observes A/AAAA/MX/NS/TXT records over time.