fraudulent.link - robtex.com

fraudulent.link

DNSSEC⚠️ Not signed
A2a01:4ff:f0:b2ea::1πŸ‡ΊπŸ‡Έ HETZNER-CLOUD2-AS2a01:4ff::/40 HETZNER-IPv6-BLK
PTRazumanga.gay
A5.161.195.229πŸ‡ΊπŸ‡Έ HETZNER-CLOUD2-AS5.161.195.0/24
NSkarsyn.ns.cloudflare.com ⭐
A2606:4700:50::a29f:26c2πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRkarsyn.ns.cloudflare.com
A2803:f800:50::6ca2:c2c2πŸ‡¨πŸ‡· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRkarsyn.ns.cloudflare.com
A2a06:98c1:50::ac40:22c2πŸ‡ΊπŸ‡Έ Cloudflare2a06:98c1:50::/45
PTRkarsyn.ns.cloudflare.com
A108.162.194.194πŸ‡ΊπŸ‡Έ Cloudflare108.162.194.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRkarsyn.ns.cloudflare.com
A162.159.38.194Cloudflare162.159.32.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRkarsyn.ns.cloudflare.com
A172.64.34.194πŸ‡ΊπŸ‡Έ Cloudflare172.64.34.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRkarsyn.ns.cloudflare.com
NSsonny.ns.cloudflare.com
A2606:4700:58::a29f:2c42πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRsonny.ns.cloudflare.com
A2803:f800:50::6ca2:c342πŸ‡¨πŸ‡· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRsonny.ns.cloudflare.com
A2a06:98c1:50::ac40:2342πŸ‡ΊπŸ‡Έ Cloudflare2a06:98c1:50::/45
PTRsonny.ns.cloudflare.com
A108.162.195.66πŸ‡ΊπŸ‡Έ Cloudflare108.162.195.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRsonny.ns.cloudflare.com
A162.159.44.66Cloudflare162.159.32.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRsonny.ns.cloudflare.com
A172.64.35.66πŸ‡ΊπŸ‡Έ Cloudflare172.64.35.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRsonny.ns.cloudflare.com
MXazumanga.gay ⭐
A2a01:4ff:f0:b2ea::1πŸ‡ΊπŸ‡Έ HETZNER-CLOUD2-AS2a01:4ff::/40 HETZNER-IPv6-BLK
PTRazumanga.gay
A5.161.195.229πŸ‡ΊπŸ‡Έ HETZNER-CLOUD2-AS5.161.195.0/24
PTRazumanga.gay
TXTv=spf1 mx -all
SOAkarsyn.ns.cloudflare.comdns@cloudflare.com serial=2399447032

link

DNSSECπŸ”’ Signed (DS record present)
NSns01.trs-dns.com ⭐
NSns.trs-dns.com
NSns01.trs-dns.net
NSns10.trs-dns.info
NSns10.trs-dns.org
SOAns.trs-dns.comtrs-ops@tucows.com serial=1774149869

Same first word

Similar names

DNS History

5 records (5 active, 0 former)

NSkarsyn.ns.cloudflare.comsonny.ns.cloudflare.comMXazumanga.gayA2a01:4ff:f0:b2ea::15.161.195.229
●NSkarsyn.ns.cloudflare.com2026-03-10 β†’ 2026-03-22 Β· 2 obs
● 2026-03-10 07:12:36
● 2026-03-22 15:03:02
●NSsonny.ns.cloudflare.com2026-03-10 β†’ 2026-03-22 Β· 2 obs
● 2026-03-10 07:12:36
● 2026-03-22 15:03:02
●MXazumanga.gay2026-03-10 β†’ 2026-03-22 Β· 2 obs
● 2026-03-10 07:12:36
● 2026-03-22 15:03:02
●A2a01:4ff:f0:b2ea::12026-03-10 β†’ 2026-03-22 Β· 2 obs
● 2026-03-10 07:12:36
● 2026-03-22 15:03:02
●A5.161.195.2292026-03-10 β†’ 2026-03-22 Β· 2 obs
● 2026-03-10 07:12:36
● 2026-03-22 15:03:02

πŸ” DNS Trace

πŸ“‹ Delegation Chain

ZoneNameserversGlue
linkns10.trs-dns.org, ns01.trs-dns.com, ns01.trs-dns.net, ns10.trs-dns.info8 records
fraudulent.linksonny.ns.cloudflare.com, karsyn.ns.cloudflare.com-

βœ… Authoritative Response

Server: 108.162.195.66

NS records: sonny.ns.cloudflare.com, karsyn.ns.cloudflare.com

πŸ”’ DNSSEC Status

⚠️ Insecure (no DNSSEC)

No DS record for fraudulent.link (unsigned zone)

⏱️ Timing

Total: 431ms | Queries: -

πŸ“„ Records

TypeCountSample Data
A15.161.195.229
AAAA12a01:4ff:f0:b2ea::1
NS2karsyn.ns.cloudflare.com, sonny.ns.cloudflare.com
MX1azumanga.gay (pri: 0)
TXT1v=spf1 mx -all
SOA1karsyn.ns.cloudflare.com dns.cloudflare.

πŸ“Œ Glue Records Collected

Total: 8

Out-of-bailiwick: 8 (ns10.trs-dns.info, ns10.trs-dns.org, ns01.trs-dns.net...)

Analysis

IP Addresses

fraudulent.link has two IP numbers: 2a01:4ff:f0:b2ea::1 and 5.161.195.229.

Name Servers

fraudulent.link's delegation uses two name servers: karsyn.ns.cloudflare.com and sonny.ns.cloudflare.com.

fraudulent.link uses the same name server setup as other domains, such as diproimports.com, pingsup.com, shlawimi.com, laurrenscloset.com and letudiantautonome.fr.

fraudulent.link at least partially shares name servers with other domains, including americanlighting.com, yiikede.com, casinosyz.online, kemab.nu and hq368.com.

these name servers are commonly used alongside the name servers grannbo.ns.cloudflare.com, sean.ns.cloudflare.com, kallie.ns.cloudflare.com, desiree.ns.cloudflare.com and kianchau.ns.cloudflare.com.

Host names with six IP numbers:

karsyn.ns.cloudflare.com points to 2606:4700:50::a29f:26c2, 2803:f800:50::6ca2:c2c2, 2a06:98c1:50::ac40:22c2, 108.162.194.194, 162.159.38.194 and 172.64.34.194.

sonny.ns.cloudflare.com points to 2606:4700:58::a29f:2c42, 2803:f800:50::6ca2:c342, 2a06:98c1:50::ac40:2342, 108.162.195.66, 162.159.44.66 and 172.64.35.66.

Mail Servers

A single mail server handles fraudulent.link, azumanga.gay.

The host name azumanga.gay resolves to two IP numbers: 2a01:4ff:f0:b2ea::1 and 5.161.195.229.