phishofficial.com - robtex.com

phishofficial.com

DNSSEC⚠️ Not signed
A2606:4700:3032::ac43:b5e2πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:3032::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A2606:4700:3035::6815:1ffeπŸ‡ΊπŸ‡Έ Cloudflare2606:4700:3035::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A104.21.31.254Cloudflare104.21.16.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A172.67.181.226πŸ‡ΊπŸ‡Έ Cloudflare172.67.176.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
NSemily.ns.cloudflare.com ⭐
A2606:4700:50::adf5:3a9bπŸ‡ΊπŸ‡Έ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRemily.ns.cloudflare.com
A2803:f800:50::6ca2:c09bπŸ‡¨πŸ‡· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRemily.ns.cloudflare.com
A2a06:98c1:50::ac40:209bπŸ‡ΊπŸ‡Έ Cloudflare2a06:98c1:50::/45
PTRemily.ns.cloudflare.com
A108.162.192.155πŸ‡ΊπŸ‡Έ Cloudflare108.162.192.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRemily.ns.cloudflare.com
A172.64.32.155πŸ‡ΊπŸ‡Έ Cloudflare172.64.32.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRemily.ns.cloudflare.com
A173.245.58.155πŸ‡ΊπŸ‡Έ Cloudflare173.245.58.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRemily.ns.cloudflare.com
NSmitchell.ns.cloudflare.com
A2606:4700:58::a29f:2ce7πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRmitchell.ns.cloudflare.com
A2803:f800:50::6ca2:c3e7πŸ‡¨πŸ‡· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRmitchell.ns.cloudflare.com
A2a06:98c1:50::ac40:23e7πŸ‡ΊπŸ‡Έ Cloudflare2a06:98c1:50::/45
PTRmitchell.ns.cloudflare.com
A108.162.195.231πŸ‡ΊπŸ‡Έ Cloudflare108.162.195.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRmitchell.ns.cloudflare.com
A162.159.44.231Cloudflare162.159.32.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRmitchell.ns.cloudflare.com
A172.64.35.231πŸ‡ΊπŸ‡Έ Cloudflare172.64.35.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRmitchell.ns.cloudflare.com
MXmail.phishofficial.com ⭐
A91.214.78.215πŸ‡·πŸ‡Ί AS21582691.214.78.0/24
TXTv=spf1 ip4:91.214.78.215 ip4:89.167.5.211 a:mail.phishofficial.com -all
HTTPSHTTP/3, HTTP/2 βœ“ hints match
IPv4 hints104.21.31.254, 172.67.181.226
IPv6 hints2606:4700:3032::ac43:b5e2, 2606:4700:3035::6815:1ffe
ECHX25519, HKDF-SHA256 + AES-128-GCM draft, id=209, name=cloudflare-ech.com
SOAemily.ns.cloudflare.comdns@cloudflare.com serial=2401151359

com

⚠️ On DNS blocklist: tif

Same first word

DNS History

7 records (7 active, 0 former)

NSemily.ns.cloudflare.commitchell.ns.cloudflare.comMXmail.phishofficial.comA104.21.31.254172.67.181.2262606:4700:3032::ac43:b5e22606:4700:3035::6815:1ffe
●NSemily.ns.cloudflare.com2026-03-26 β†’ 2026-04-13 Β· 2 obs
● 2026-03-26 12:57:54
● 2026-04-13 09:13:04
●NSmitchell.ns.cloudflare.com2026-03-26 β†’ 2026-04-13 Β· 2 obs
● 2026-03-26 12:57:54
● 2026-04-13 09:13:04
●MXmail.phishofficial.com2026-03-26 β†’ 2026-04-13 Β· 2 obs
● 2026-03-26 12:57:54
● 2026-04-13 09:13:04
●A104.21.31.2542026-03-26 β†’ 2026-04-13 Β· 2 obs
● 2026-03-26 12:57:54
● 2026-04-13 09:13:04
●A172.67.181.2262026-03-26 β†’ 2026-04-13 Β· 2 obs
● 2026-03-26 12:57:54
● 2026-04-13 09:13:04
●A2606:4700:3032::ac43:b5e22026-03-26 β†’ 2026-04-13 Β· 2 obs
● 2026-03-26 12:57:54
● 2026-04-13 09:13:04
●A2606:4700:3035::6815:1ffe2026-03-26 β†’ 2026-04-13 Β· 2 obs
● 2026-03-26 12:57:54
● 2026-04-13 09:13:04

πŸ” DNS Trace

πŸ“‹ Delegation Chain

ZoneNameserversGlue
coml.gtld-servers.net, j.gtld-servers.net, h.gtld-servers.net, d.gtld-servers.net...-
phishofficial.comemily.ns.cloudflare.com, mitchell.ns.cloudflare.com12 records

βœ… Authoritative Response

Server:108.162.192.155

NS records: emily.ns.cloudflare.com, mitchell.ns.cloudflare.com

πŸ”’ DNSSEC Status

⚠️ Insecure (no DNSSEC)

No DS record for phishofficial.com (unsigned zone)

⏱️ Timing

Total: 269ms | Queries: -

πŸ“„ Records

TypeCountSample Data
A2104.21.31.254, 172.67.181.226
AAAA22606:4700:3035::6815:1ffe, 2606:4700:3032::ac43:b5e2
NS2emily.ns.cloudflare.com, mitchell.ns.cloudflare.com
MX1mail.phishofficial.com (pri: 10)
TXT1v=spf1 ip4:91.214.78.215 ip4:89.167.5.21
HTTPS1{"priority":1,"target":".","alpn":["h3",
SOA1emily.ns.cloudflare.com dns.cloudflare.c

πŸ“Œ Glue Records Collected

Total: 12

Out-of-bailiwick: 12 (emily.ns.cloudflare.com, emily.ns.cloudflare.com, emily.ns.cloudflare.com...)

Analysis

IP Addresses

phishofficial.com maps to four IP numbers: 2606:4700:3032::ac43:b5e2, 2606:4700:3035::6815:1ffe, 104.21.31.254 and 172.67.181.226.

Other host names, for instance novibetcasino.org, mixfun365.com, superlambbanana.com, www.partidopirata.org and wdjh.net share IP numbers with phishofficial.com.

Name Servers

Two name servers emily.ns.cloudflare.com and mitchell.ns.cloudflare.com are delegated to phishofficial.com.

phishofficial.com uses the same name server configuration as other domains, such as jehefesuotxtcom.pages.dev, jojoel.com, gearamigo.com, coachela-official.com and fuzzrd.com.

phishofficial.com at least partially shares name servers with other domains such as ruay365.com, dianadegraaf.nl, keponetworks.com, redebrasileiradetransdisciplinaridade.net and investmama.ru.

These name servers are commonly used with nelly.ns.cloudflare.com and kate.ns.cloudflare.com.

Host names with six IP numbers: Host name emily.ns.cloudflare.com points to 2606:4700:50::adf5:3a9b, 2803:f800:50::6ca2:c09b, 2a06:98c1:50::ac40:209b, 108.162.192.155, 172.64.32.155 and 173.245.58.155; host name mitchell.ns.cloudflare.com points to 2606:4700:58::a29f:2ce7, 2803:f800:50::6ca2:c3e7, 2a06:98c1:50::ac40:23e7, 108.162.195.231, 162.159.44.231 and 172.64.35.231.

Mail Servers

phishofficial.com is handled by a single mail server, mail.phishofficial.com.

mail.phishofficial.com points to one IP number: 91.214.78.215.