Check-Host.cc

Domain

pay.google.com

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of pay.google.com

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
24
A/AAAA targets
Subdomains
CT + scan + body
Record Types
3
seen in DNS
Observed Certs
21
in our scans

DNS Records

A
108.177.15.92, 142.250.102.92, 142.250.110.92, 142.250.27.92, 142.251.127.92, 142.251.168.92, 142.251.173.92, 172.253.154.92
AAAA
2a00:1450:4001:c21::5c, 2a00:1450:400c:c06::5c, 2a00:1450:400c:c07::5c, 2a00:1450:400c:c09::5c, 2a00:1450:400c:c0b::5c, 2a00:1450:400c:c0c::5c, 2a00:1450:400c:c0d::5c, 2a00:1450:400c:c1d::5c
MX
NS
TXT
facebook-domain-verification=1tz70lttak6evr3u7rhji02lbtms0t
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

89.125.33.222:443 href · ×6
3.76.224.33:443 href · ×6
45.76.163.194:443 href · ×6
188.40.231.165:443 href · ×4
129.80.54.222:443 href · ×4
132.226.52.174:443 href · ×4
129.80.67.123:443 href · ×4
129.80.77.44:443 href · ×4
129.80.97.34:443 href · ×4
129.80.125.210:443 href · ×4
157.151.236.228:443 href · ×4
129.80.158.162:443 href · ×4
3.130.114.242:443 href · ×3
34.160.126.50:443 href · ×3
34.117.180.209:80 href · ×3
34.49.60.19:80 href · ×3
165.232.121.56:80 href · ×3
162.55.191.234:443 href · ×3
5.135.117.142:80 href · ×2
54.164.20.162:80 href · ×2
23.251.142.88:80 href · ×2
104.248.141.67:443 href · ×2
64.226.91.220:443 href · ×2
62.156.143.133:443 href · ×2
18.226.121.54:443 href · ×2
34.61.139.82:8080 href · ×2
195.187.63.42:443 href · ×2
54.164.20.162:443 href · ×2
34.150.119.90:443 href · ×2
3.250.140.132:443 href · ×2
64.62.202.145:443 href · ×2
51.222.28.242:8000 href · ×2
3.36.83.0:443 href · ×2
176.223.133.6:443 href · ×2
63.184.251.47:443 href · ×2
193.46.187.146:443 href · ×1
159.65.221.14:443 href · ×1
99.83.159.216:443 href · ×1
34.140.39.191:80 href · ×1
188.166.219.14:443 href · ×1
3.219.254.173:443 href · ×1
192.118.64.211:443 href · ×1
104.155.13.63:80 href · ×1
192.155.92.111:80 href · ×1
31.70.80.10:443 href · ×1
3.11.14.76:80 href · ×1
18.170.68.144:443 href · ×1
13.134.102.59:443 href · ×1
18.135.71.36:443 href · ×1
18.218.129.129:443 href · ×1

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
A 142.251.173.92 2026-05-25 21:56:50.553 2026-05-27 10:57:29.374
AAAA 2a00:1450:400c:c0c::5c 2026-05-25 21:56:50.553 2026-06-23 10:33:21.736
A 142.251.127.92 2026-05-26 02:22:42.939 2026-07-25 02:35:06.089
TXT facebook-domain-verification=1tz70lttak6evr3u7rhji02lbtms0t 2026-05-26 02:22:42.939 2026-07-31 19:07:11.830
AAAA 2a00:1450:4001:c21::5c 2026-05-26 02:22:42.939 2026-07-25 02:35:06.089
A 108.177.15.92 2026-05-26 03:19:32.089 2026-06-19 14:57:31.732
AAAA 2a00:1450:400c:c06::5c 2026-05-26 03:50:49.068 2026-07-16 13:49:12.895
AAAA 2a00:1450:400c:c09::5c 2026-05-26 06:05:24.294 2026-07-25 15:35:26.647
A 64.233.184.92 2026-05-26 07:20:33.209 2026-07-28 16:46:46.383
AAAA 2a00:1450:400c:c1f::5c 2026-05-26 07:20:33.209 2026-07-27 14:49:39.372
AAAA 2a00:1450:400c:c0b::5c 2026-05-26 07:37:40.512 2026-07-25 15:44:47.162
A 64.233.167.92 2026-05-26 09:11:18.736 2026-06-23 16:27:42.962
AAAA 2a00:1450:400c:c0d::5c 2026-05-26 11:43:25.524 2026-05-26 14:34:58.230
A 64.233.166.92 2026-05-26 12:10:36.757 2026-06-23 16:31:00.285
A 66.102.1.92 2026-05-26 17:18:28.359 2026-06-21 17:34:14.787
A 74.125.206.92 2026-05-26 22:37:39.926 2026-06-19 13:51:59.137
A 142.250.110.92 2026-05-27 13:13:58.833 2026-05-27 13:13:58.833
A 142.251.168.92 2026-05-27 14:15:03.762 2026-06-22 10:35:09.289
AAAA 2a00:1450:4025:401::5c 2026-06-03 05:34:14.106 2026-07-31 19:07:11.830
A 142.250.27.92 2026-06-03 05:34:14.106 2026-07-31 19:07:11.830
AAAA 2a00:1450:400c:c1d::5c 2026-06-03 08:06:01.953 2026-06-22 10:35:09.289
AAAA 2a00:1450:4025:402::5c 2026-06-14 22:36:55.780 2026-07-24 08:51:20.706
A 142.250.102.92 2026-06-14 22:52:09.672 2026-07-24 12:01:21.797
AAAA 2a00:1450:400c:c07::5c 2026-06-23 16:24:24.574 2026-06-23 16:27:42.962
A 172.253.154.92 2026-07-15 18:55:07.621 2026-07-15 18:55:07.621