Check-Host.cc

Domain

deepseek.com

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of deepseek.com

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
A/AAAA targets
Subdomains
CT + scan + body
Record Types
seen in DNS
Observed Certs
in our scans

DNS Records

A
3.173.21.63
AAAA
MX
10 hzmx02.mxmail.netease.com, 5 hzmx01.mxmail.netease.com
NS
ns-1318.awsdns-36.org, ns-1748.awsdns-26.co.uk, ns-250.awsdns-31.com, ns-735.awsdns-27.net, ns3.dnsv4.com, ns4.dnsv4.com
TXT
v=spf1 include:spf.163.com -all
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Subject: *.deepseek.com
Issuer: RapidSSL Global TLS RSA4096 SHA256 2022 CA1
SANs: *.deepseek.com, deepseek.com
Subject: clawdeepseek.com
Issuer: E8
SANs: clawdeepseek.com
Subject: difypengyou.lanhaideepseek.com
Issuer: R10
SANs: difypengyou.lanhaideepseek.com
Subject: api.deepseek.com
Issuer: api.deepseek.com
SANs: api.deepseek.com

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

47.121.27.98:443 href · ×5
39.104.92.106:443 href · ×4
23.95.34.170:443 href · ×3
118.195.131.106:443 href · ×2
203.195.240.165:443 href · ×2
124.222.71.213:443 href · ×1
67.180.236.50:443 href · ×1
8.217.6.27:80 href · ×1
118.25.15.75:443 href · ×1
59.110.30.84:80 href · ×1
43.167.176.207:443 href · ×1
140.143.182.49:443 href · ×1
8.152.3.227:443 href · ×1
47.105.38.163:80 href · ×1
123.56.125.238:80 href · ×1
47.121.199.96:443 href · ×1
118.25.15.75:80 href · ×1
47.121.199.250:80 href · ×1

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

Origin IP Origin ASN CDN ASN Confidence Reasoning
43.240.12.160 AS133731 AS16509 95% cert 9d88ac26… served by 43.240.12.160 (AS133731) carries SAN api.deepseek.com which currently resolves through Amazon (AS16509) at 3.173.21.63

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
NS ns3.dnsv4.com 2026-05-26 04:15:48.898 2026-07-27 22:28:57.726
A 3.173.21.63 2026-05-26 04:15:48.898 2026-07-27 22:28:57.726
NS ns4.dnsv4.com 2026-05-26 04:15:48.898 2026-07-27 22:28:57.726
TXT v=spf1 include:spf.163.com -all 2026-05-26 04:15:48.898 2026-07-27 22:28:57.726
MX 5 hzmx01.mxmail.netease.com 2026-05-26 04:15:48.898 2026-07-27 22:28:57.726
MX 10 hzmx02.mxmail.netease.com 2026-05-26 04:15:48.898 2026-07-27 22:28:57.726
NS ns-735.awsdns-27.net 2026-06-15 09:50:59.476 2026-06-15 09:50:59.476
NS ns-1318.awsdns-36.org 2026-06-15 09:50:59.476 2026-06-15 09:50:59.476
NS ns-1748.awsdns-26.co.uk 2026-06-15 09:50:59.476 2026-06-15 09:50:59.476
NS ns-250.awsdns-31.com 2026-06-15 09:50:59.476 2026-06-15 09:50:59.476