Check-Host.cc

Domain

html5up.net

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of html5up.net

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
22
A/AAAA targets
Subdomains
11
CT + scan + body
Record Types
4
seen in DNS
Observed Certs
in our scans

DNS Records

A
104.21.76.136, 172.67.195.190, 188.114.96.0, 188.114.96.10, 188.114.96.11, 188.114.96.3, 188.114.96.5, 188.114.97.0
AAAA
2606:4700:3030::6815:4c88, 2606:4700:3036::ac43:c3be, 2a06:98c1:3120::, 2a06:98c1:3120::3, 2a06:98c1:3120::5, 2a06:98c1:3120::b, 2a06:98c1:3121::, 2a06:98c1:3121::3
MX
10 alt1.gmr-smtp-in.l.google.com, 20 alt2.gmr-smtp-in.l.google.com, 30 alt3.gmr-smtp-in.l.google.com, 40 alt4.gmr-smtp-in.l.google.com, 5 gmr-smtp-in.l.google.com
NS
aragorn.ns.cloudflare.com, tori.ns.cloudflare.com
TXT
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Every subdomain we know about — harvested from CT-log SANs, scan-observed certs and HTML body references — paired with its current A/AAAA target.

Subdomain Resolves to Last seen
html5up.net 2026-07-22 08:29:57.545

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

44.211.189.238:80 href · ×35
62.68.221.215:443 href · ×20
62.68.221.215:80 href · ×10
83.81.234.68:443 href · ×8
162.218.217.197:80 href · ×7
67.209.182.6:443 href · ×6
8.138.101.95:80 href · ×6
93.93.205.242:443 href · ×6
144.24.47.157:80 href · ×6
34.182.9.30:80 href · ×6
119.28.158.180:80 href · ×6
188.128.203.194:443 href · ×6
147.182.131.207:443 href · ×5
104.248.114.250:443 href · ×5
199.247.2.215:443 href · ×5
120.26.47.168:80 href · ×4
98.28.64.79:443 href · ×4
108.12.23.198:80 href · ×4
134.122.105.6:443 href · ×4
89.39.121.43:443 href · ×4
108.12.23.198:8888 href · ×4
51.68.127.184:80 href · ×4
62.234.223.96:80 href · ×4
66.94.109.127:443 href · ×4
85.214.24.80:443 href · ×4
93.153.15.56:443 href · ×4
141.147.153.102:80 href · ×3
85.215.133.100:443 href · ×3
170.10.162.69:443 href · ×3
3.145.106.67:80 href · ×3
35.212.177.62:8443 href · ×3
47.79.144.136:443 href · ×3
129.148.40.173:80 href · ×3
212.224.88.63:443 href · ×3
140.245.50.216:80 href · ×3
43.218.247.120:443 href · ×3
188.68.59.175:443 href · ×3
72.56.22.4:443 href · ×3
192.227.214.211:80 href · ×3
43.135.132.179:80 href · ×3
154.27.210.5:80 href · ×3
201.51.24.161:80 href · ×3
34.209.22.29:80 href · ×3
162.55.190.180:443 href · ×3
31.57.28.133:443 href · ×3
92.118.206.180:80 href · ×3
219.117.219.115:80 href · ×3
31.48.76.5:443 href · ×3
103.85.115.67:443 href · ×3
31.172.77.191:443 href · ×3

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

CT-Log Evidence

Certificates from public Certificate Transparency logs whose subject or SAN names this domain — including historic certs we never observed live.

27b69ecdc5f792b6… sectigo · elephant2026h1
Subject: html5up.net
Issuer: WE1
SANs: html5up.net, *.html5up.net
Valid: 2026-01-13 08:50:27 → 2026-04-13 09:46:45
04fbfc4259790111… sectigo · elephant2026h1
Subject: html5up.net
Issuer: Sectigo Public Server Authentication CA DV E36
SANs: html5up.net, *.html5up.net
Valid: 2025-12-05 00:00:00 → 2026-03-05 04:33:05
7d4b7716fa97091b… sectigo · elephant2026h1
Subject: html5up.net
Issuer: Sectigo Public Server Authentication CA DV E36
SANs: html5up.net, *.html5up.net
Valid: 2025-12-05 00:00:00 → 2026-03-05 04:33:05
714dd8d41328d8c4… sectigo · elephant2026h1
Subject: html5up.net
Issuer: WE1
SANs: html5up.net, *.html5up.net
Valid: 2025-11-15 05:36:06 → 2026-02-13 06:34:47
48cf6541444839a9… sectigo · elephant2026h1
Subject: html5up.net
Issuer: Sectigo Public Server Authentication CA DV E36
SANs: html5up.net, *.html5up.net
Valid: 2025-10-14 00:00:00 → 2026-01-05 02:47:22
f2323b9453664609… sectigo · elephant2026h1
Subject: html5up.net
Issuer: Sectigo Public Server Authentication CA DV E36
SANs: html5up.net, *.html5up.net
Valid: 2025-10-14 00:00:00 → 2026-01-05 02:47:22

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
AAAA 2606:4700:3036::ac43:c3be 2026-05-25 21:56:50.553 2026-06-23 23:17:28.969
A 172.67.195.190 2026-05-25 21:56:50.553 2026-06-23 23:17:28.969
AAAA 2606:4700:3030::6815:4c88 2026-05-25 21:56:50.553 2026-06-23 23:17:28.969
A 104.21.76.136 2026-05-25 21:56:50.553 2026-06-23 23:17:28.969
A 188.114.96.3 2026-05-25 21:58:50.500 2026-07-22 00:22:46.464
AAAA 2a06:98c1:3120::3 2026-05-25 21:58:50.500 2026-07-22 04:30:05.081
AAAA 2a06:98c1:3121::3 2026-05-25 21:58:50.500 2026-07-22 04:30:05.081
A 188.114.97.3 2026-05-25 21:58:50.500 2026-07-22 00:22:46.464
MX 30 alt3.gmr-smtp-in.l.google.com 2026-05-25 22:13:29.500 2026-07-22 08:29:57.545
MX 40 alt4.gmr-smtp-in.l.google.com 2026-05-25 22:13:29.500 2026-07-22 08:29:57.545
MX 20 alt2.gmr-smtp-in.l.google.com 2026-05-25 22:13:29.500 2026-07-22 08:29:57.545
MX 5 gmr-smtp-in.l.google.com 2026-05-25 22:13:29.500 2026-07-22 08:29:57.545
NS aragorn.ns.cloudflare.com 2026-05-25 22:13:29.500 2026-07-22 08:29:57.545
MX 10 alt1.gmr-smtp-in.l.google.com 2026-05-25 22:13:29.500 2026-07-22 08:29:57.545
NS tori.ns.cloudflare.com 2026-05-25 22:13:29.500 2026-07-22 08:29:57.545
AAAA 2a06:98c1:3120:: 2026-06-02 02:46:39.720 2026-07-22 08:29:57.545
A 188.114.96.0 2026-06-02 02:46:39.720 2026-07-22 08:29:57.545
AAAA 2a06:98c1:3121:: 2026-06-02 02:46:39.720 2026-07-22 08:29:57.545
A 188.114.97.0 2026-06-02 02:46:39.720 2026-07-22 08:29:57.545
A 188.114.96.5 2026-06-14 23:22:00.742 2026-06-16 17:00:24.159
A 188.114.97.5 2026-06-14 23:22:00.742 2026-06-16 17:00:24.159
AAAA 2a06:98c1:3121::5 2026-06-15 01:22:55.677 2026-06-15 03:02:54.402
AAAA 2a06:98c1:3120::5 2026-06-15 01:22:55.677 2026-06-15 03:02:54.402
A 188.114.97.11 2026-06-18 01:37:17.884 2026-06-23 20:13:35.709
A 188.114.96.11 2026-06-18 01:37:17.884 2026-06-23 20:13:35.709
AAAA 2a06:98c1:3120::b 2026-06-18 06:27:11.807 2026-06-20 17:36:17.084
AAAA 2a06:98c1:3121::b 2026-06-18 06:27:11.807 2026-06-20 17:36:17.084
A 188.114.97.10 2026-07-19 19:31:49.732 2026-07-19 19:31:49.732
A 188.114.96.10 2026-07-19 19:31:49.732 2026-07-19 19:31:49.732