Check-Host.cc

Domain

spring.io

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of spring.io

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
A/AAAA targets
Subdomains
CT + scan + body
Record Types
seen in DNS
Observed Certs
in our scans

DNS Records

A
104.18.42.155, 172.64.145.101
AAAA
2606:4700:4406::ac40:9165, 2606:4700:4409::ac40:9165, 2a06:98c1:3100::6812:2a9b, 2a06:98c1:3106::6812:2a9b
MX
13 isaac.mx.cloudflare.net, 80 amir.mx.cloudflare.net, 90 linda.mx.cloudflare.net
NS
mary.ns.cloudflare.com, theo.ns.cloudflare.com
TXT
CFE5-A8BB-39C8-811C-275E-359B-7D50-A9A2, MS=ms74802145, _8bf4m05zgllzh6kpmbdw29k8s51faur, _ng92d6yb9n8jfhfjkgaixcyflt73g28, atlassian-domain-verification=axGNi8XOxPg2qasalLkg8DO6ODN7aQn9/aoDhzplZ/9Z4Oxkyei72gvYJu6HR6yn, e601f6cfb729414088b22175584eb026, google-site-verification=YSdDbpdDobwxE01DfU6-38UABqxNWafTc6vk-Df_mnk, google-site-verification=Z9wK7ueF-FuImFwV628x5gnY-FfL7jNaIVnGcMobeyY
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

223.109.141.134:8080 href · ×41
52.9.170.206:443 href · ×37
66.98.116.160:443 href · ×33
43.180.150.53:80 href · ×10
39.104.75.149:443 href · ×8
1.94.131.16:80 href · ×5
101.132.61.156:80 href · ×5
83.229.123.238:443 href · ×4
101.200.241.65:443 href · ×3
137.184.128.101:443 href · ×3
129.211.164.192:443 href · ×3
117.72.65.229:80 href · ×2
101.34.255.22:8000 href · ×2
111.231.21.38:80 href · ×2
8.135.2.63:80 href · ×2
157.245.116.172:443 href · ×2
23.236.68.174:5000 href · ×2
89.36.211.12:80 href · ×1
8.155.160.98:443 href · ×1
67.205.176.76:443 href · ×1
146.200.103.96:443 href · ×1
40.78.87.14:80 href · ×1
23.238.39.229:443 href · ×1
13.49.234.1:80 href · ×1
84.247.160.102:8081 href · ×1
16.145.10.107:80 href · ×1
106.53.6.136:80 href · ×1
94.130.128.238:8080 href · ×1
52.15.154.178:443 href · ×1
51.68.191.250:80 href · ×1
47.113.220.125:80 href · ×1
212.132.65.114:9443 href · ×1
37.123.193.59:80 href · ×1
40.78.87.14:443 href · ×1
43.202.1.236:80 href · ×1
129.27.202.78:443 href · ×1
139.162.143.173:443 href · ×1
135.134.190.111:443 href · ×1

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

CT-Log Evidence

Certificates from public Certificate Transparency logs whose subject or SAN names this domain — including historic certs we never observed live.

3e641004573110cc… google · xenon2026h2
Subject: *.sc2.itcna.vmware.com
Issuer: DigiCert Global G2 TLS RSA SHA256 2020 CA1
SANs: *.sc2.itcna.vmware.com, sc2.itcna.vmware.com, *.panorama.vmware.com, panorama.vmware.com, *.apps.sc2.itcna.vmware.com, apps.sc2.itcna.vmware.com, *.network.pivotal.io, network.pivotal.io, *.pvtl.spring.io, pvtl.spring.io, *.pvtl.cfapps.io, pvtl.cfapps.io, *.apps.itcna.vmware.com, apps.itcna.vmware.com, *.sc2-04-pcf1-system.oc.vmware.com, *.uaa.sc2-04-pcf1-system.oc.vmware.com, *.sc2-04-pcf1-apps.oc.vmware.com, *.panaroma.vmware.com, panaroma.vmware.com, *.tas.vmware.com, tas.vmware.com, *.cfk8s.vmware.com, cfk8s.vmware.com, *.pvtl.tas.vmware.com, pvtl.tas.vmware.com, docs.pivotal.io, *.docs.pivotal.io, docs-test.pivotal.io, *.docs-test.pivotal.io, *.pivotal.io, pivotal.io, *.spring.io, *.cfapps.io, cfapps.io, *.itcna.vmware.com, spring.io, oc.vmware.com, *.oc.vmware.com, *.whiteboard.vmware.com, whiteboard.vmware.com, *.postfacto.vmware.com, postfacto.vmware.com, *.postfacto-api.vmware.com, postfacto-api.vmware.com, *.toolsmiths.cf-app.com, *.isvci.sc2.itcna.vmware.com, api.panorama.vmware.com, sandbox.panorama.vmware.com, api.sandbox.panorama.vmware.com, pano.vmware.com, api.pano.vmware.com, sandbox.pano.vmware.com, api.sandbox.pano.vmware.com, exploremobileappsgai.vmware.com
Valid: 2026-03-20 00:00:00 → 2026-09-12 23:59:59

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Domain timeline pending

Passive-DNS history accumulates as our forward-DNS crawler observes A/AAAA/MX/NS/TXT records over time.