Check-Host.cc

Domain

sync.mn

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of sync.mn

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
A/AAAA targets
Subdomains
CT + scan + body
Record Types
seen in DNS
Observed Certs
in our scans

DNS Records

A
185.199.108.153, 185.199.109.153, 185.199.110.153, 185.199.111.153
AAAA
MX
10 mx2.mail.mn, 5 mx.mail.mn
NS
ns1.dns.mn, ns2.dns.mn, ns3.dns.mn, ns4.dns.mn
TXT
amazonses:JCoybABRoEU0gJwfoloeR4z1XJJ8SLKK0kntoovks6M=, v=spf1 include:spf.mail.mn ~all
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Subject: *.sync.mn
Issuer: Sectigo Public Server Authentication CA DV R36
SANs: *.sync.mn, sync.mn

IPs Citing This Domain

No citing IPs found yet

As the world-sweep progresses, hosts referencing this domain in their HTML will surface here.

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

Origin IP Origin ASN CDN ASN Confidence Reasoning
103.229.177.14 AS133453 AS54113 95% cert 6877bb70… served by 103.229.177.14 (AS133453) carries SAN sync.mn which currently resolves through Fastly (AS54113) at 185.199.110.153, 185.199.111.153, 185.199.109.153, 185.199.108.153

CT-Log Evidence

Certificates from public Certificate Transparency logs whose subject or SAN names this domain — including historic certs we never observed live.

6877bb7052870006… google · xenon2026h2
Subject: *.sync.mn
Issuer: Sectigo Public Server Authentication CA DV R36
SANs: *.sync.mn, sync.mn
Valid: 2025-09-10 00:00:00 → 2026-09-09 23:59:59
b435d6a834360cde… google · argon2026h2
Subject: *.sync.mn
Issuer: Sectigo Public Server Authentication CA DV R36
SANs: *.sync.mn, sync.mn
Valid: 2025-09-10 00:00:00 → 2026-09-09 23:59:59
1f9ea5cfdf8a3a09… google · argon2026h2
Subject: *.sync.mn
Issuer: Sectigo Public Server Authentication CA DV R36
SANs: *.sync.mn, sync.mn
Valid: 2025-09-08 00:00:00 → 2026-09-09 23:59:59
ff04b781a47872fe… google · xenon2026h2
Subject: *.sync.mn
Issuer: Sectigo Public Server Authentication CA DV R36
SANs: *.sync.mn, sync.mn
Valid: 2025-09-08 00:00:00 → 2026-09-09 23:59:59

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
A 185.199.109.153 2026-06-20 14:02:52.402 2026-06-23 22:56:36.868
NS ns2.dns.mn 2026-06-20 14:02:52.402 2026-06-23 22:56:36.868
TXT amazonses:JCoybABRoEU0gJwfoloeR4z1XJJ8SLKK0kntoovks6M= 2026-06-20 14:02:52.402 2026-06-23 22:56:36.868
A 185.199.108.153 2026-06-20 14:02:52.402 2026-06-23 22:56:36.868
MX 10 mx2.mail.mn 2026-06-20 14:02:52.402 2026-06-23 22:56:36.868
MX 5 mx.mail.mn 2026-06-20 14:02:52.402 2026-06-23 22:56:36.868
NS ns4.dns.mn 2026-06-20 14:02:52.402 2026-06-23 22:56:36.868
NS ns1.dns.mn 2026-06-20 14:02:52.402 2026-06-23 22:56:36.868
TXT v=spf1 include:spf.mail.mn ~all 2026-06-20 14:02:52.402 2026-06-23 22:56:36.868
A 185.199.111.153 2026-06-20 14:02:52.402 2026-06-23 22:56:36.868
NS ns3.dns.mn 2026-06-20 14:02:52.402 2026-06-23 22:56:36.868
A 185.199.110.153 2026-06-20 14:02:52.402 2026-06-23 22:56:36.868