Check-Host.cc

Domain

ip.sb

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of ip.sb

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
6
A/AAAA targets
Subdomains
27
CT + scan + body
Record Types
5
seen in DNS
Observed Certs
9
in our scans

DNS Records

A
104.26.12.31, 104.26.13.31, 172.67.75.172
AAAA
2606:4700:20::681a:c1f, 2606:4700:20::681a:d1f, 2606:4700:20::ac43:4bac
MX
10 in1-smtp.messagingengine.com, 10 in2-smtp.messagingengine.com
NS
a.dns.sb, b.dns.sb
TXT
google-site-verification=LUVThoTnxAFullzVYeUHgp_KGRF9APoWRbxvK6lFpB0, google-site-verification=iy8uEaEk2pUwhDpnk-8BIcdD7BLMT43F1v6afDzau9I, v=spf1 include:spf.messagingengine.com -all, v=spf1 include:spf.messagingengine.com ?all
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Every subdomain we know about — harvested from CT-log SANs, scan-observed certs and HTML body references — paired with its current A/AAAA target.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Subject: ip.sb
Issuer: ip.sb
SANs: ip.sb
Subject: ip.sb
Issuer: ip.sb
SANs: ip.sb
Subject: ip.sb
Issuer: ip.sb
SANs: ip.sb
Subject: ip.sb
Issuer: ip.sb
SANs: ip.sb
Subject: ip.sb
Issuer: ip.sb
SANs: ip.sb
Subject: *.ip.sb
Issuer: AlphaSSL CA - SHA256 - G2
SANs: *.ip.sb, ip.sb

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

103.88.47.131:443 href · ×5
103.201.128.16:443 href · ×5
140.245.59.16:443 href · ×3
154.197.254.197:443 href · ×1
154.197.252.205:443 href · ×1
13.83.127.162:443 href · ×1
140.238.22.128:443 href · ×1
154.197.174.14:443 href · ×1
154.197.252.195:443 href · ×1
154.197.253.211:443 href · ×1
47.96.147.167:443 href · ×1
154.197.173.81:443 href · ×1
39.105.186.182:80 href · ×1
104.223.43.183:443 href · ×1
154.197.253.213:443 href · ×1
154.197.175.87:443 href · ×1
154.197.252.201:443 href · ×1
8.210.93.220:443 href · ×1
47.242.4.30:443 href · ×1
154.197.255.211:443 href · ×1
154.197.174.17:443 href · ×1
154.197.174.23:443 href · ×1
154.197.255.200:443 href · ×1
193.112.95.186:443 href · ×1
154.197.255.221:443 href · ×1

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

Origin IP Origin ASN CDN ASN Confidence Reasoning
38.244.204.31 AS29802 AS13335 95% cert 8e10ec4b… served by 38.244.204.31 (AS29802) carries SAN ip.sb which currently resolves through Cloudflare (AS13335) at 104.26.12.31, 104.26.13.31, 172.67.75.172, 2606:4700:20::ac43:4bac
61.224.118.131 AS3462 AS13335 95% cert 4f0b6b55… served by 61.224.118.131 (AS3462) carries SAN ip.sb which currently resolves through Cloudflare (AS13335) at 104.26.12.31, 104.26.13.31, 172.67.75.172, 2606:4700:20::ac43:4bac
14.137.238.35 AS401339 AS13335 95% cert 64489b35… served by 14.137.238.35 (AS401339) carries SAN ip.sb which currently resolves through Cloudflare (AS13335) at 104.26.12.31, 104.26.13.31, 172.67.75.172, 2606:4700:20::ac43:4bac
38.180.89.99 AS29802 AS13335 95% cert 8e10ec4b… served by 38.180.89.99 (AS29802) carries SAN ip.sb which currently resolves through Cloudflare (AS13335) at 104.26.12.31, 104.26.13.31, 172.67.75.172, 2606:4700:20::ac43:4bac
176.97.64.125 AS9009 AS13335 95% cert 82e5742d… served by 176.97.64.125 (AS9009) carries SAN ip.sb which currently resolves through Cloudflare (AS13335) at 104.26.12.31, 104.26.13.31, 172.67.75.172, 2606:4700:20::ac43:4bac
103.201.128.16 AS3258 AS13335 95% cert cf333050… served by 103.201.128.16 (AS3258) carries SAN ip.sb which currently resolves through Cloudflare (AS13335) at 104.26.12.31, 104.26.13.31, 172.67.75.172, 2606:4700:20::ac43:4bac

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
A 104.26.12.31 2026-05-26 03:23:54.879 2026-07-28 15:43:39.508
MX 10 in2-smtp.messagingengine.com 2026-05-26 03:23:54.879 2026-07-28 15:43:39.508
NS a.dns.sb 2026-05-26 03:23:54.879 2026-07-28 15:43:39.508
AAAA 2606:4700:20::681a:c1f 2026-05-26 03:23:54.879 2026-07-28 15:43:39.508
AAAA 2606:4700:20::ac43:4bac 2026-05-26 03:23:54.879 2026-07-28 15:43:39.508
TXT v=spf1 include:spf.messagingengine.com ?all 2026-05-26 03:23:54.879 2026-07-15 20:04:13.980
MX 10 in1-smtp.messagingengine.com 2026-05-26 03:23:54.879 2026-07-28 15:43:39.508
TXT google-site-verification=LUVThoTnxAFullzVYeUHgp_KGRF9APoWRbxvK6lFpB0 2026-05-26 03:23:54.879 2026-07-28 15:43:39.508
AAAA 2606:4700:20::681a:d1f 2026-05-26 03:23:54.879 2026-07-28 15:43:39.508
NS b.dns.sb 2026-05-26 03:23:54.879 2026-07-28 15:43:39.508
TXT google-site-verification=iy8uEaEk2pUwhDpnk-8BIcdD7BLMT43F1v6afDzau9I 2026-05-26 03:23:54.879 2026-07-28 15:43:39.508
A 104.26.13.31 2026-05-26 03:23:54.879 2026-07-28 15:43:39.508
A 172.67.75.172 2026-05-26 03:23:54.879 2026-07-28 15:43:39.508
TXT v=spf1 include:spf.messagingengine.com -all 2026-07-22 14:15:47.566 2026-07-28 15:43:39.508