Check-Host.cc

Domain

br.wordpress.org

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of br.wordpress.org

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
A/AAAA targets
Subdomains
CT + scan + body
Record Types
seen in DNS
Observed Certs
in our scans

DNS Records

A
198.143.164.252, 66.6.42.252
AAAA
2607:f978:5:8002::c68f:a4fc, 2620:109:b00a::4206:2afc
MX
10 smtp1-dca.wordpress.org, 10 smtp1-ord.wordpress.org, 10 smtp2-dca.wordpress.org, 10 smtp2-ord.wordpress.org
NS
ns1.wordpress.org, ns2.wordpress.org, ns3.wordpress.org, ns4.wordpress.org
TXT
google-site-verification=UL0sGJ1dZbCT4J7pGrLW3hqM_I1LJ8pUi2WBEI_98kI, google-site-verification=t8FjG1vzC4OFZJ8qL4SkR8xxtLyKldXKbswyeemQS5w, v=spf1 ip4:66.6.42.0/24 ip4:66.155.40.0/24 include:helpscoutemail.com -all, v=spf1 ip4:66.6.42.0/24 ip4:66.155.40.0/24 ip4:198.143.164.0/24 include:helpscoutemail.com -all
CNAME
CAA
0 iodef "mailto:caa@wordpress.org", 0 issue "letsencrypt.org;validationmethods=dns-01;accounturi=https://acme-v02.api.letsencrypt.org/acme/acct/53691143"

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

45.77.116.12:80 href · ×2
200.17.100.109:80 href · ×2
129.148.20.166:443 href · ×2
186.202.161.193:443 href · ×2
159.65.183.115:443 href · ×2
67.205.182.161:443 href · ×2
168.138.255.138:80 href · ×2
100.51.93.49:443 href · ×2
44.195.214.199:443 href · ×2
69.6.215.17:443 href · ×2
186.202.161.193:80 href · ×2
144.22.151.108:443 href · ×2
168.138.156.164:80 href · ×2
134.122.113.137:8000 href · ×2
129.148.55.122:443 href · ×2
187.72.141.157:443 href · ×2
162.241.2.48:80 href · ×2
64.23.233.7:80 href · ×2
44.195.214.199:80 href · ×2
129.213.115.205:80 href · ×2
159.203.124.6:80 href · ×2
162.215.217.239:443 href · ×1
35.243.143.12:80 href · ×1
46.51.170.129:443 href · ×1
129.148.56.77:80 href · ×1
193.122.191.140:443 href · ×1
67.159.252.170:443 href · ×1
144.22.182.251:443 href · ×1
100.31.229.249:443 href · ×1
167.99.106.109:80 href · ×1
137.184.145.199:443 href · ×1
157.230.172.245:443 href · ×1
3.22.66.156:443 href · ×1
144.22.221.86:443 href · ×1
167.233.26.105:80 href · ×1
191.235.88.175:443 href · ×1
131.72.220.231:443 href · ×1
159.89.237.187:80 href · ×1
212.56.41.237:443 href · ×1
159.65.186.59:8080 href · ×1
137.184.101.80:80 href · ×1
137.184.101.80:443 href · ×1
44.215.179.218:443 href · ×1
54.158.235.35:80 href · ×1
177.153.60.215:443 href · ×1
57.129.68.164:443 href · ×1
132.145.167.130:443 href · ×1
162.214.78.54:443 href · ×1
34.210.52.249:443 href · ×1
35.199.101.80:80 href · ×1

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
AAAA 2607:f978:5:8002::c68f:a4fc 2026-05-25 21:54:50.392 2026-06-23 23:49:26.837
A 198.143.164.252 2026-05-25 21:54:50.392 2026-06-23 23:49:26.837
TXT google-site-verification=UL0sGJ1dZbCT4J7pGrLW3hqM_I1LJ8pUi2WBEI_98kI 2026-05-26 00:32:50.780 2026-07-28 01:03:27.292
MX 10 smtp2-ord.wordpress.org 2026-05-26 00:32:50.780 2026-05-31 11:15:40.719
NS ns4.wordpress.org 2026-05-26 00:32:50.780 2026-07-28 01:03:27.292
TXT google-site-verification=t8FjG1vzC4OFZJ8qL4SkR8xxtLyKldXKbswyeemQS5w 2026-05-26 00:32:50.780 2026-07-28 01:03:27.292
NS ns2.wordpress.org 2026-05-26 00:32:50.780 2026-07-28 01:03:27.292
CAA 0 issue "letsencrypt.org;validationmethods=dns-01;accounturi=https://acme-v02.api.letsencrypt.org/acme/acct/53691143" 2026-05-26 00:32:50.780 2026-07-28 01:03:27.292
NS ns3.wordpress.org 2026-05-26 00:32:50.780 2026-07-28 01:03:27.292
CAA 0 iodef "mailto:caa@wordpress.org" 2026-05-26 00:32:50.780 2026-07-28 01:03:27.292
TXT v=spf1 ip4:66.6.42.0/24 ip4:66.155.40.0/24 ip4:198.143.164.0/24 include:helpscoutemail.com -all 2026-05-26 00:32:50.780 2026-06-23 23:49:26.837
NS ns1.wordpress.org 2026-05-26 00:32:50.780 2026-07-28 01:03:27.292
MX 10 smtp1-ord.wordpress.org 2026-05-26 00:32:50.780 2026-05-31 11:15:40.719
MX 10 smtp2-dca.wordpress.org 2026-06-14 22:08:58.337 2026-07-28 01:03:27.292
MX 10 smtp1-dca.wordpress.org 2026-06-14 22:08:58.337 2026-07-28 01:03:27.292
A 66.6.42.252 2026-07-15 22:52:35.591 2026-07-28 01:03:27.292
AAAA 2620:109:b00a::4206:2afc 2026-07-15 22:52:35.591 2026-07-28 01:03:27.292
TXT v=spf1 ip4:66.6.42.0/24 ip4:66.155.40.0/24 include:helpscoutemail.com -all 2026-07-15 22:52:35.591 2026-07-28 01:03:27.292