Check-Host.cc

Domain

api.ipdata.co

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of api.ipdata.co

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
A/AAAA targets
Subdomains
CT + scan + body
Record Types
seen in DNS
Observed Certs
in our scans

DNS Records

A
AAAA
MX
NS
TXT
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

194.28.68.9:443 href · ×1
136.114.110.136:80 href · ×1
191.232.252.1:443 href · ×1
192.34.59.224:443 href · ×1
18.159.193.216:7001 href · ×1
110.227.217.7:80 href · ×1
35.170.15.156:80 href · ×1
136.114.110.136:443 href · ×1
104.131.83.100:80 href · ×1
66.246.10.23:443 href · ×1
202.61.197.36:8000 href · ×1
14.63.163.225:8080 href · ×1
43.247.134.165:443 href · ×1

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
A 3.67.217.132 2026-05-26 04:07:00.841 2026-05-26 22:33:29.497
NS ns-1947.awsdns-51.co.uk 2026-05-26 04:07:00.841 2026-07-28 01:29:26.112
NS ns-1193.awsdns-21.org 2026-05-26 04:07:00.841 2026-07-28 01:29:26.112
A 18.185.196.10 2026-05-26 04:07:00.841 2026-05-26 22:33:29.497
NS ns-205.awsdns-25.com 2026-05-26 04:07:00.841 2026-07-28 01:29:26.112
NS ns-594.awsdns-10.net 2026-05-26 04:07:00.841 2026-07-28 01:29:26.112
A 3.65.6.27 2026-05-26 08:41:11.770 2026-05-26 08:56:48.112
A 51.102.174.126 2026-05-26 08:41:11.770 2026-05-26 08:56:48.112
A 3.67.50.161 2026-06-18 02:12:26.927 2026-06-18 02:15:39.079
A 52.58.173.191 2026-06-18 02:12:26.927 2026-06-18 02:15:39.079
A 3.76.52.3 2026-06-19 09:25:22.114 2026-06-19 09:25:22.114
A 3.124.178.252 2026-06-19 09:25:22.114 2026-06-19 09:25:22.114
A 18.198.221.233 2026-06-21 14:08:53.794 2026-06-21 14:08:53.794
A 3.122.211.130 2026-06-21 14:08:53.794 2026-06-21 14:08:53.794
A 18.157.68.14 2026-07-16 12:53:45.120 2026-07-16 12:53:45.120
A 52.59.154.183 2026-07-16 12:53:45.120 2026-07-16 12:53:45.120
A 3.127.41.131 2026-07-18 05:35:39.131 2026-07-18 19:52:20.432
A 3.120.232.51 2026-07-18 05:35:39.131 2026-07-18 19:52:20.432
A 18.197.183.57 2026-07-19 08:30:01.554 2026-07-19 08:30:01.554
A 18.185.51.78 2026-07-19 08:30:01.554 2026-07-19 08:30:01.554
A 18.184.111.96 2026-07-28 01:29:26.112 2026-07-28 01:29:26.112
A 18.159.86.225 2026-07-28 01:29:26.112 2026-07-28 01:29:26.112