Check-Host.cc

Domain

substackcdn.com

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of substackcdn.com

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
133
A/AAAA targets
Subdomains
11
CT + scan + body
Record Types
4
seen in DNS
Observed Certs
2
in our scans

DNS Records

A
18.64.211.101, 18.64.211.2, 18.64.211.30, 18.64.211.57, 3.173.161.11, 3.173.161.14, 3.173.161.73, 3.173.161.96
AAAA
2600:9000:20a2:0:4:b4b9:d3c0:93a1, 2600:9000:20a2:1000:4:b4b9:d3c0:93a1, 2600:9000:20a2:1200:4:b4b9:d3c0:93a1, 2600:9000:20a2:1400:4:b4b9:d3c0:93a1, 2600:9000:20a2:1600:4:b4b9:d3c0:93a1, 2600:9000:20a2:1a00:4:b4b9:d3c0:93a1, 2600:9000:20a2:1c00:4:b4b9:d3c0:93a1, 2600:9000:20a2:1e00:4:b4b9:d3c0:93a1
MX
NS
TXT
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Every subdomain we know about — harvested from CT-log SANs, scan-observed certs and HTML body references — paired with its current A/AAAA target.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

18.225.70.231:443 href · ×35
159.65.92.34:80 href · ×24
35.202.203.147:443 href · ×16
160.153.173.174:443 href · ×12
194.195.211.90:8000 href · ×11
91.107.210.214:443 href · ×4
64.119.8.21:443 href · ×3
51.210.151.164:80 href · ×3
144.76.163.157:443 href · ×2
5.78.186.213:80 href · ×1
89.58.53.54:443 href · ×1
3.66.144.108:443 href · ×1
35.232.44.129:443 href · ×1
63.181.102.111:443 href · ×1
44.238.91.251:443 href · ×1
87.99.156.195:8080 href · ×1

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Domain timeline pending

Passive-DNS history accumulates as our forward-DNS crawler observes A/AAAA/MX/NS/TXT records over time.