phishingprevention.com - robtex.com

phishingprevention.com

DNSSEC⚠️ Not signed
A2606:4700:3030::ac43:83b6πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:3030::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A2606:4700:3031::6815:ac6πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:3031::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A104.21.10.198Cloudflare104.21.0.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A172.67.131.182πŸ‡ΊπŸ‡Έ Cloudflare172.67.128.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
NSdavid.ns.cloudflare.com ⭐
A2606:4700:58::adf5:3b98πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRdavid.ns.cloudflare.com
A2803:f800:50::6ca2:c198πŸ‡¨πŸ‡· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRdavid.ns.cloudflare.com
A2a06:98c1:50::ac40:2198πŸ‡ΊπŸ‡Έ Cloudflare2a06:98c1:50::/45
PTRdavid.ns.cloudflare.com
A108.162.193.152πŸ‡ΊπŸ‡Έ Cloudflare108.162.193.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRdavid.ns.cloudflare.com
A172.64.33.152πŸ‡ΊπŸ‡Έ Cloudflare172.64.33.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRdavid.ns.cloudflare.com
A173.245.59.152πŸ‡ΊπŸ‡Έ Cloudflare173.245.59.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRdavid.ns.cloudflare.com
NSmelissa.ns.cloudflare.com
A2606:4700:50::adf5:3ac7πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRmelissa.ns.cloudflare.com
A2803:f800:50::6ca2:c0c7πŸ‡¨πŸ‡· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRmelissa.ns.cloudflare.com
A2a06:98c1:50::ac40:20c7πŸ‡ΊπŸ‡Έ Cloudflare2a06:98c1:50::/45
PTRmelissa.ns.cloudflare.com
A108.162.192.199πŸ‡ΊπŸ‡Έ Cloudflare108.162.192.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRmelissa.ns.cloudflare.com
A172.64.32.199πŸ‡ΊπŸ‡Έ Cloudflare172.64.32.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRmelissa.ns.cloudflare.com
A173.245.58.199πŸ‡ΊπŸ‡Έ Cloudflare173.245.58.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRmelissa.ns.cloudflare.com
MXmxa.eu.mailgun.org ⭐
A34.111.130.244πŸ‡ΊπŸ‡Έ Google34.108.0.0/14
PTR244.130.111.34.bc.googleusercontent.com
MXmxb.eu.mailgun.org ⭐
A34.111.130.244πŸ‡ΊπŸ‡Έ Google34.108.0.0/14
PTR244.130.111.34.bc.googleusercontent.com
TXTgoogle-site-verification=TG73l4nCxbpgIycGDcS3PsiPXzFl21VRvkrKx7RAIqc
TXTv=spf1 ip4:143.55.236.227 ip4:143.55.236.228 ip4:143.55.236.247 ip4:34.140.69...
HTTPSHTTP/3, HTTP/2 βœ“ hints match
IPv4 hints104.21.10.198, 172.67.131.182
IPv6 hints2606:4700:3030::ac43:83b6, 2606:4700:3031::6815:ac6
ECHX25519, HKDF-SHA256 + AES-128-GCM draft, id=66, name=cloudflare-ech.com
SOAdavid.ns.cloudflare.comdns@cloudflare.com serial=2401139714

com

Same first word

DNS History

8 records (8 active, 0 former)

NSdavid.ns.cloudflare.commelissa.ns.cloudflare.comMXmxa.eu.mailgun.orgmxb.eu.mailgun.orgA104.21.10.198172.67.131.1822606:4700:3030::ac43:83b62606:4700:3031::6815:ac6
●NSdavid.ns.cloudflare.com2026-04-13 β†’ 2026-04-26 Β· 2 obs
● 2026-04-13 04:52:22
● 2026-04-26 06:58:48
●NSmelissa.ns.cloudflare.com2026-04-13 β†’ 2026-04-26 Β· 2 obs
● 2026-04-13 04:52:22
● 2026-04-26 06:58:48
●MXmxa.eu.mailgun.org2026-04-13 β†’ 2026-04-26 Β· 2 obs
● 2026-04-13 04:52:22
● 2026-04-26 06:58:48
●MXmxb.eu.mailgun.org2026-04-13 β†’ 2026-04-26 Β· 2 obs
● 2026-04-13 04:52:22
● 2026-04-26 06:58:48
●A104.21.10.1982026-04-13 β†’ 2026-04-26 Β· 2 obs
● 2026-04-13 04:52:22
● 2026-04-26 06:58:48
●A172.67.131.1822026-04-13 β†’ 2026-04-26 Β· 2 obs
● 2026-04-13 04:52:22
● 2026-04-26 06:58:48
●A2606:4700:3030::ac43:83b62026-04-13 β†’ 2026-04-26 Β· 2 obs
● 2026-04-13 04:52:22
● 2026-04-26 06:58:48
●A2606:4700:3031::6815:ac62026-04-13 β†’ 2026-04-26 Β· 2 obs
● 2026-04-13 04:52:22
● 2026-04-26 06:58:48

πŸ” DNS Trace

πŸ“‹ Delegation Chain

ZoneNameserversGlue
comm.gtld-servers.net, e.gtld-servers.net, a.gtld-servers.net, i.gtld-servers.net...-
phishingprevention.comdavid.ns.cloudflare.com, melissa.ns.cloudflare.com12 records

βœ… Authoritative Response

Server:108.162.192.199

NS records: david.ns.cloudflare.com, melissa.ns.cloudflare.com

πŸ”’ DNSSEC Status

⚠️ Insecure (no DNSSEC)

No DS record for phishingprevention.com (unsigned zone)

⏱️ Timing

Total: 220ms | Queries: -

πŸ“„ Records

TypeCountSample Data
A2172.67.131.182, 104.21.10.198
AAAA22606:4700:3030::ac43:83b6, 2606:4700:3031::6815:ac6
NS2david.ns.cloudflare.com, melissa.ns.cloudflare.com
MX2mxa.eu.mailgun.org (pri: 10), mxb.eu.mailgun.org (pri: 10)
TXT2google-site-verification=TG73l4nCxbpgIyc, v=spf1 ip4:143.55.236.227 ip4:143.55.236
HTTPS1{"priority":1,"target":".","alpn":["h3",
SOA1david.ns.cloudflare.com dns.cloudflare.c

πŸ“Œ Glue Records Collected

Total: 12

Out-of-bailiwick: 12 (david.ns.cloudflare.com, david.ns.cloudflare.com, david.ns.cloudflare.com...)

Analysis

IP Addresses

phishingprevention.com resolves to four IP numbers: 2606:4700:3030::ac43:83b6, 2606:4700:3031::6815:ac6, 104.21.10.198 and 172.67.131.182.

Other host names such as mail.vxg.co, avtoremont48.ru, o84i9.bestsalonandspa.com, hrbdhwy.com and twinahead.cn share IPs with phishingprevention.com.

Name Servers

phishingprevention.com is delegated to two name servers: david.ns.cloudflare.com and melissa.ns.cloudflare.com.

phishingprevention.com shares the same name server setup as 0ffice365.be, colruytgroup.com.co, phished.be, mleczko.pro and corona-alerts.be.

phishingprevention.com at least partially shares name servers with other domains, for instance rentautos.org, 552079.com, plantesports.com, clcromania.ro and siabinversiones.com.

These name servers are commonly used together with marty.ns.cloudflare.com, teagan.ns.cloudflare.com and keira.ns.cloudflare.com.

Host names with six IP numbers:

david.ns.cloudflare.com points to 2606:4700:58::adf5:3b98, 2803:f800:50::6ca2:c198, 2a06:98c1:50::ac40:2198, 108.162.193.152, 172.64.33.152 and 173.245.59.152.

melissa.ns.cloudflare.com points to 2606:4700:50::adf5:3ac7, 2803:f800:50::6ca2:c0c7, 2a06:98c1:50::ac40:20c7, 108.162.192.199, 172.64.32.199 and 173.245.58.199.

Mail Servers

phishingprevention.com is handled by two mail servers: mxa.eu.mailgun.org and mxb.eu.mailgun.org.

The mail server setup for phishingprevention.com matches that of other domains, for instance mail.julius-k9.co.uk, oikarinen.org, notify.bettercallclaude.ch, verlff.com and mail.parc-naturel-avesnois.fr.

phishingprevention.com shares at least partially some mail servers with other domains, including mazctf.fr, autofixa.com, therussiantimes.com, royalcraft.fr and watchmemore.com.

these mail servers are often used with aspmx.l.google.com, alt1.aspmx.l.google.com, alt2.aspmx.l.google.com, alt3.aspmx.l.google.com and alt4.aspmx.l.google.com.

Host names sharing one IP: mxa.eu.mailgun.org and mxb.eu.mailgun.org point to 34.111.130.244.