Check-Host.cc

Domain

nginx.net

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of nginx.net

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
A/AAAA targets
Subdomains
CT + scan + body
Record Types
seen in DNS
Observed Certs
in our scans

DNS Records

A
3.125.197.172, 52.58.199.22
AAAA
MX
10 mail.nginx.net
NS
ns1.f5clouddns.com, ns2.f5clouddns.com
TXT
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Every subdomain we know about — harvested from CT-log SANs, scan-observed certs and HTML body references — paired with its current A/AAAA target.

Subdomain Resolves to Last seen
nginx.net 2026-07-28 20:47:52.650

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

89.106.215.18:443 href · ×116
91.238.103.12:80 href · ×4
147.161.239.131:443 href · ×3
103.82.196.139:80 href · ×3
81.71.65.220:80 href · ×3
114.116.126.74:443 href · ×3
159.93.166.173:443 href · ×3
47.97.156.34:80 href · ×3
198.96.86.183:443 href · ×3
109.167.200.229:80 href · ×3
190.131.241.143:80 href · ×3
74.205.13.182:80 href · ×3
8.131.87.248:80 href · ×3
153.125.147.77:8443 href · ×3
1.12.75.56:80 href · ×3
61.132.73.60:80 href · ×3
153.127.218.233:8443 href · ×3
161.97.89.115:80 href · ×3
101.53.133.27:80 href · ×3
45.76.119.201:80 href · ×3
168.119.99.50:80 href · ×3
176.9.127.77:80 href · ×3
45.136.56.83:80 href · ×3
38.165.17.181:80 href · ×3
155.138.255.116:443 href · ×3
188.226.246.56:80 href · ×3
67.215.237.172:80 href · ×3
133.242.236.10:8443 href · ×3
130.125.112.33:80 href · ×3
212.112.108.70:443 href · ×3
87.51.88.100:80 href · ×3
101.32.19.222:443 href · ×3
114.55.250.204:80 href · ×3
223.109.7.164:80 href · ×3
133.242.70.104:80 href · ×3
129.153.12.39:80 href · ×3
185.228.27.228:80 href · ×3
153.127.201.202:8443 href · ×3
116.124.128.119:80 href · ×3
140.238.32.115:80 href · ×3
159.203.144.5:80 href · ×3
120.48.82.100:80 href · ×3
114.55.111.38:80 href · ×3
188.213.48.125:80 href · ×3
38.165.17.250:80 href · ×3
175.45.201.117:443 href · ×3
198.199.91.213:443 href · ×3
46.250.168.100:80 href · ×3
105.242.192.25:80 href · ×3
153.120.167.210:8443 href · ×3

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Domain timeline pending

Passive-DNS history accumulates as our forward-DNS crawler observes A/AAAA/MX/NS/TXT records over time.