Check-Host.cc

Domain

facebook.com

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of facebook.com

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
A/AAAA targets
Subdomains
CT + scan + body
Record Types
seen in DNS
Observed Certs
in our scans

DNS Records

A
157.240.0.35, 157.240.17.35, 157.240.210.35, 157.240.253.35, 157.240.27.35, 157.240.30.35, 157.240.9.35, 163.70.128.35
AAAA
2a03:2880:f107:83:face:b00c:0:25de, 2a03:2880:f10a:83:face:b00c:0:25de, 2a03:2880:f128:83:face:b00c:0:25de, 2a03:2880:f136:83:face:b00c:0:25de, 2a03:2880:f13d:83:face:b00c:0:25de, 2a03:2880:f13f:83:face:b00c:0:25de, 2a03:2880:f150:82:face:b00c:0:25de, 2a03:2880:f15b:83:face:b00c:0:25de
MX
10 smtpin.vvv.facebook.com
NS
a.ns.facebook.com, b.ns.facebook.com, c.ns.facebook.com, d.ns.facebook.com
TXT
facebook-domain-verification=y7isfmi3kzyg1r4wophh9vyb6pgbda, google-site-verification=A2WZWCNQHrGV_TWwKh6KHY90tY0SHZo_RnyMJoDaG0s, google-site-verification=sK6uY9x7eaMoEMfn3OILqwTFYgaNp4llmguKI-C3_iA, google-site-verification=wdH5DTJTc9AYNwVunSVFeK0hYDGUIEOGb-RReU6pJlY, v=spf1 redirect=_spf.facebook.com, zoom-domain-verification=4b2ef4e1-6dee-4483-9869-9bef353fd147
CNAME
CAA
0 issue "digicert.com; account=271b0beda0771d006aa3a6c11b05187d456d6c239b46cb5241196095b09c92af"

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

159.203.0.127:443 href · ×212
165.245.171.132:443 href · ×76
52.194.133.103:80 href · ×66
199.188.205.209:80 href · ×50
167.71.140.109:80 href · ×48
185.197.75.9:443 href · ×42
13.230.200.109:80 href · ×33
13.115.94.26:80 href · ×33
35.79.12.255:80 href · ×33
34.149.87.18:443 href · ×33
3.11.86.88:80 href · ×32
8.211.28.253:443 href · ×28
46.231.30.102:443 href · ×20
97.231.192.218:443 href · ×20
101.0.113.187:443 href · ×20
80.241.209.138:443 href · ×18
44.198.171.177:80 href · ×18
44.198.171.177:443 href · ×18
103.212.211.243:80 href · ×18
159.203.37.85:443 href · ×17
154.205.47.230:443 href · ×17
168.76.15.158:443 href · ×17
168.76.14.147:443 href · ×17
15.237.246.245:443 href · ×16
45.145.100.73:443 href · ×16
103.27.207.159:443 href · ×16
5.78.40.8:443 href · ×16
167.99.46.42:443 href · ×15
146.148.47.87:443 href · ×15
89.10.209.118:443 href · ×14
104.248.90.114:80 href · ×14
58.137.125.72:443 href · ×14
185.56.238.73:443 href · ×14
38.194.255.23:443 href · ×14
13.43.37.59:443 href · ×14
18.130.94.48:80 href · ×13
52.20.7.6:443 href · ×13
69.55.238.244:80 href · ×13
3.141.213.167:80 href · ×12
34.234.176.24:443 href · ×12
192.210.143.106:443 href · ×12
15.188.72.98:443 href · ×12
3.101.86.33:80 href · ×12
23.111.165.51:443 href · ×12
34.225.134.84:80 href · ×12
82.223.65.192:443 href · ×12
23.111.165.51:80 href · ×12
135.181.45.132:443 href · ×12
45.63.9.228:443 href · ×12
54.84.205.125:80 href · ×11

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
A 157.240.0.35 2026-05-25 21:32:03.363 2026-07-28 01:47:12.379
AAAA 2a03:2880:f37a:1:face:b00c:0:25de 2026-05-25 21:32:03.363 2026-07-28 19:02:52.609
AAAA 2a03:2880:f13f:83:face:b00c:0:25de 2026-05-25 21:36:03.270 2026-07-28 20:39:29.599
A 157.240.253.35 2026-05-25 21:36:03.270 2026-07-28 19:02:52.609
A 157.240.27.35 2026-05-25 21:50:03.344 2026-07-27 12:12:08.125
AAAA 2a03:2880:f37c:1:face:b00c:0:25de 2026-05-25 22:00:50.546 2026-07-27 21:48:21.645
MX 10 smtpin.vvv.facebook.com 2026-05-25 22:05:29.416 2026-07-31 03:52:56.144
NS a.ns.facebook.com 2026-05-25 22:05:29.416 2026-07-31 03:52:56.144
TXT zoom-domain-verification=4b2ef4e1-6dee-4483-9869-9bef353fd147 2026-05-25 22:05:29.416 2026-07-31 03:52:56.144
TXT google-site-verification=A2WZWCNQHrGV_TWwKh6KHY90tY0SHZo_RnyMJoDaG0s 2026-05-25 22:05:29.416 2026-07-31 03:52:56.144
TXT google-site-verification=wdH5DTJTc9AYNwVunSVFeK0hYDGUIEOGb-RReU6pJlY 2026-05-25 22:05:29.416 2026-07-31 03:52:56.144
NS b.ns.facebook.com 2026-05-25 22:05:29.416 2026-07-31 03:52:56.144
AAAA 2a03:2880:f177:185:face:b00c:0:25de 2026-05-25 22:05:29.416 2026-07-28 13:42:19.007
TXT v=spf1 redirect=_spf.facebook.com 2026-05-25 22:05:29.416 2026-07-31 03:52:56.144
TXT google-site-verification=sK6uY9x7eaMoEMfn3OILqwTFYgaNp4llmguKI-C3_iA 2026-05-25 22:05:29.416 2026-07-31 03:52:56.144
TXT facebook-domain-verification=y7isfmi3kzyg1r4wophh9vyb6pgbda 2026-05-25 22:05:29.416 2026-07-31 03:52:56.144
NS c.ns.facebook.com 2026-05-25 22:05:29.416 2026-07-31 03:52:56.144
NS d.ns.facebook.com 2026-05-25 22:05:29.416 2026-07-31 03:52:56.144
CAA 0 issue "digicert.com; account=271b0beda0771d006aa3a6c11b05187d456d6c239b46cb5241196095b09c92af" 2026-05-25 23:59:40.866 2026-07-31 03:52:56.144
AAAA 2a03:2880:f176:181:face:b00c:0:25de 2026-05-26 00:32:50.780 2026-07-28 12:23:56.037
A 57.144.244.1 2026-05-26 02:59:13.593 2026-07-28 17:23:57.234
A 57.144.248.1 2026-05-26 03:15:29.400 2026-07-27 01:35:17.893
A 57.144.222.1 2026-05-27 21:33:40.775 2026-07-31 03:52:56.144
AAAA 2a03:2880:f36f:1:face:b00c:0:25de 2026-05-27 23:03:40.753 2026-07-31 03:52:56.144
AAAA 2a03:2880:f17b:88:face:b00c:0:25de 2026-05-27 23:09:40.760 2026-05-27 23:43:40.759
A 157.240.210.35 2026-05-31 05:53:40.817 2026-05-31 05:53:40.817
A 163.70.128.35 2026-06-17 23:15:41.834 2026-06-17 23:15:41.834
A 31.13.72.36 2026-06-18 19:25:12.328 2026-06-23 21:54:04.953
AAAA 2a03:2880:f10a:83:face:b00c:0:25de 2026-06-18 23:25:29.435 2026-06-21 11:52:57.962
AAAA 2a03:2880:f150:82:face:b00c:0:25de 2026-06-20 21:06:00.591 2026-06-20 21:06:00.591
AAAA 2a03:2880:f15b:83:face:b00c:0:25de 2026-06-22 08:03:20.158 2026-07-28 10:59:00.670
AAAA 2a03:2880:f17b:283:face:b00c:0:25de 2026-06-22 23:29:24.788 2026-06-22 23:29:24.788
A 157.240.17.35 2026-06-23 10:17:19.270 2026-07-27 00:19:18.651
AAAA 2a03:2880:f136:83:face:b00c:0:25de 2026-06-23 21:28:21.023 2026-06-23 21:28:21.023
A 157.240.30.35 2026-06-23 21:31:36.213 2026-06-23 21:31:36.213
AAAA 2a03:2880:f13d:83:face:b00c:0:25de 2026-06-23 21:31:36.213 2026-06-23 21:57:54.231
A 157.240.9.35 2026-07-15 20:04:13.980 2026-07-28 17:34:09.807
AAAA 2a03:2880:f128:83:face:b00c:0:25de 2026-07-15 20:04:13.980 2026-07-28 20:58:16.328
AAAA 2a03:2880:f382:1:face:b00c:0:25de 2026-07-17 19:41:30.447 2026-07-28 09:31:49.057
A 57.145.4.1 2026-07-17 19:41:30.447 2026-07-28 09:31:49.057
A 31.13.84.36 2026-07-20 08:35:22.092 2026-07-28 19:39:40.097
AAAA 2a03:2880:f107:83:face:b00c:0:25de 2026-07-23 04:38:53.059 2026-07-24 18:20:45.158