Check-Host.cc

Domain

web.facebook.com

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of web.facebook.com

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
A/AAAA targets
Subdomains
CT + scan + body
Record Types
seen in DNS
Observed Certs
in our scans

DNS Records

A
157.240.0.13, 157.240.17.17, 157.240.202.14, 157.240.253.13, 157.240.27.18, 157.240.9.18, 31.13.72.8, 31.13.84.8
AAAA
2a03:2880:f007:1:face:b00c:0:1, 2a03:2880:f028:11:face:b00c:0:2, 2a03:2880:f03f:12:face:b00c:0:2, 2a03:2880:f042:112:face:b00c:0:2, 2a03:2880:f083:10e:face:b00c:0:2, 2a03:2880:f084:10d:face:b00c:0:2, 2a03:2880:f36f:8d:face:b00c:0:2, 2a03:2880:f37a:8d:face:b00c:0:2
MX
10 smtpin.vvv.facebook.com
NS
TXT
v=spf1 a ~all
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

8.211.28.253:443 href · ×16
103.68.40.110:443 href · ×10
188.166.148.98:80 href · ×8
13.216.150.35:443 href · ×8
108.59.45.76:443 href · ×8
102.220.29.242:443 href · ×7
160.153.251.116:443 href · ×7
3.83.203.39:443 href · ×7
139.99.123.122:443 href · ×6
206.189.80.172:443 href · ×6
13.36.248.141:443 href · ×6
5.255.100.144:443 href · ×6
41.203.191.37:443 href · ×6
165.22.3.21:443 href · ×6
103.253.20.53:443 href · ×6
103.157.96.166:443 href · ×5
91.220.85.85:80 href · ×5
197.243.16.202:443 href · ×5
197.243.26.218:443 href · ×5
193.34.69.126:443 href · ×5
138.197.188.232:5000 href · ×4
213.252.245.246:443 href · ×4
44.217.76.215:443 href · ×4
43.240.82.124:443 href · ×4
173.249.45.244:443 href · ×4
41.185.14.221:443 href · ×4
159.223.38.243:80 href · ×4
164.90.199.201:443 href · ×4
103.229.53.114:443 href · ×4
206.223.241.145:443 href · ×4
103.41.207.211:443 href · ×4
51.79.159.105:443 href · ×4
194.32.140.162:443 href · ×4
160.22.161.21:80 href · ×4
148.113.12.31:443 href · ×4
23.23.100.150:80 href · ×4
64.181.170.81:443 href · ×4
46.250.229.61:443 href · ×4
34.128.107.14:80 href · ×4
50.6.229.231:443 href · ×4
167.71.205.125:443 href · ×4
164.68.112.158:443 href · ×4
146.190.61.142:80 href · ×4
103.253.146.36:80 href · ×4
64.227.110.108:443 href · ×4
34.63.55.199:443 href · ×4
41.203.191.112:443 href · ×4
164.151.129.55:443 href · ×4
34.128.107.14:443 href · ×4
95.217.40.184:443 href · ×3

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
A 157.240.27.18 2026-05-25 22:02:50.525 2026-06-23 16:35:22.862
AAAA 2a03:2880:f084:10d:face:b00c:0:2 2026-05-25 22:02:50.525 2026-07-24 03:54:40.750
AAAA 2a03:2880:f03f:12:face:b00c:0:2 2026-05-25 22:05:29.416 2026-07-28 14:28:46.692
A 157.240.0.13 2026-05-25 22:05:29.416 2026-07-27 07:54:05.840
TXT v=spf1 a ~all 2026-05-25 22:05:29.416 2026-07-31 01:03:43.234
MX 10 smtpin.vvv.facebook.com 2026-05-25 22:05:29.416 2026-07-31 01:03:43.234
A 57.144.244.141 2026-05-26 00:12:34.719 2026-07-26 05:01:06.184
AAAA 2a03:2880:f37c:8d:face:b00c:0:2 2026-05-26 00:28:48.843 2026-07-27 23:12:42.147
A 57.144.248.141 2026-05-26 02:43:02.200 2026-07-25 15:44:47.162
AAAA 2a03:2880:f37a:8d:face:b00c:0:2 2026-05-26 03:50:49.068 2026-07-28 04:09:46.054
AAAA 2a03:2880:f083:10e:face:b00c:0:2 2026-05-26 04:02:49.330 2026-06-23 22:19:38.022
A 157.240.253.13 2026-05-26 04:02:49.330 2026-07-26 23:53:41.507
AAAA 2a03:2880:f36f:8d:face:b00c:0:2 2026-06-02 16:54:40.408 2026-07-31 01:03:43.234
A 57.144.222.141 2026-06-02 16:54:40.408 2026-07-31 01:03:43.234
AAAA 2a03:2880:f042:112:face:b00c:0:2 2026-06-17 01:38:42.868 2026-06-17 01:38:42.868
A 157.240.202.14 2026-06-19 00:37:19.174 2026-06-19 00:37:19.174
A 157.240.17.17 2026-06-23 04:11:14.285 2026-06-23 04:11:14.285
A 31.13.72.8 2026-06-23 12:22:00.579 2026-06-23 12:22:00.579
A 157.240.9.18 2026-07-16 11:08:25.783 2026-07-31 01:02:37.406
AAAA 2a03:2880:f028:11:face:b00c:0:2 2026-07-17 02:03:19.494 2026-07-31 01:02:37.406
A 31.13.84.8 2026-07-21 19:30:18.681 2026-07-24 13:56:53.925
AAAA 2a03:2880:f007:1:face:b00c:0:1 2026-07-24 04:03:48.161 2026-07-24 13:56:53.925