Opens the print dialog of your browser. Choose "Save as PDF" as the printer there to get a file: the browser writes it, nothing is uploaded.
Share a snapshot of this report
A live report changes with every lookup, so a shared link to it would not show what you see now. A snapshot stores this report as our server observed it and gives it its own link for 30 days. It holds public lookup data only. Anyone with the link can open it; search engines are asked not to index it.
A domain is not one thing. It is a registration held at a registry, a set of DNS records served by nameservers, one or more servers that answer on the IP addresses those records point to, and usually a mail setup that lives somewhere else entirely. Problems tend to appear in the gaps between those layers, so the report looks at all of them in a single pass.
The registration section comes from RDAP, the structured successor to WHOIS: registrar, creation, update and expiry dates, status codes, nameservers and DNSSEC state. The DNS section queries public recursive resolvers for A, AAAA, NS, MX, TXT, CAA and SOA records. The mail section reads MX, SPF and DMARC. The hosting section maps each IP address to its network owner. The web section makes one HTTPS request and records redirects, the response status and the certificate the server presented.
DKIM keys are published under a selector chosen by the sender, so they cannot be discovered from the domain alone. Find the selector in the s= tag of a DKIM-Signature header.
Findings
SPF uses softfail (~all)
Unlisted senders are marked as a soft failure. This is a common setting when DMARC is enforced; "-all" is the stricter form.
DMARC policy is reject
An enforcing DMARC policy is published (inherited from github.com). Its pct, alignment and reporting tags were not evaluated.
MX, SPF and enforcing DMARC are published
The basic DNS records for mail authentication are present. DKIM could not be checked without a selector, and this says nothing about message delivery.
LiveSource: DNS · public resolvers 1.1.1.1, 8.8.8.8Observed:
This address belongs to a CDN or proxy network. It is not the origin server, and the allocation country is not the server's physical location.
LiveSource: Team Cymru IP-to-ASN (DNS) · IP RDAP · PTRObserved:
Web and TLS
HTTP status
200
Final URL
https://gist.github.com/starred
Redirects
302 → https://gist.github.com/starred
Server header
github.com
Response time
184 ms
Page title
Discover gists · GitHub
HSTS
HSTS
TLS
Chain validated
Chain validated
Issuer
Sectigo Limited · Sectigo Public Server Authentication CA DV E36
Subject
*.github.com
Valid from
Valid to
47 days left
Protocol
TLSv1.3
Alternative names
*.github.com, github.com
LiveSource: Direct HTTPS request (headers + first 64 KB of HTML)Observed:
Change history
What this service recorded for this name on earlier checks. A check happens only when someone opens a report or calls the API: nothing is scheduled, so gaps between checks are normal.
39 checks since Sep 25, 2026, the latest on Oct 11, 2026.
Changes observed
IPv4 addresses (A) changed on Oct 11, 2026 ()Before: 140.82.113.3After: 140.82.114.3Source: DNS · public resolvers 1.1.1.1, 8.8.8.8
IPv4 addresses (A) changed on Oct 11, 2026 ()Before: 140.82.114.4After: 140.82.113.3Source: DNS · public resolvers 1.1.1.1, 8.8.8.8
IPv4 addresses (A) changed on Oct 11, 2026 ()Before: 140.82.113.3After: 140.82.114.4Source: DNS · public resolvers 1.1.1.1, 8.8.8.8
IPv4 addresses (A) changed on Oct 11, 2026 ()Before: 140.82.113.4After: 140.82.113.3Source: DNS · public resolvers 1.1.1.1, 8.8.8.8
IPv4 addresses (A) changed on Oct 11, 2026 ()Before: 140.82.114.4After: 140.82.113.4Source: DNS · public resolvers 1.1.1.1, 8.8.8.8
IPv4 addresses (A) changed on Oct 10, 2026 ()Before: 140.82.114.3After: 140.82.114.4Source: DNS · public resolvers 1.1.1.1, 8.8.8.8
IPv4 addresses (A) changed on Oct 10, 2026 ()Before: 140.82.112.4After: 140.82.114.3Source: DNS · public resolvers 1.1.1.1, 8.8.8.8
IPv4 addresses (A) changed on Oct 10, 2026 ()Before: 140.82.114.4After: 140.82.112.4Source: DNS · public resolvers 1.1.1.1, 8.8.8.8
IPv4 addresses (A) changed on Oct 9, 2026 ()Before: 140.82.112.4After: 140.82.114.4Source: DNS · public resolvers 1.1.1.1, 8.8.8.8
IPv4 addresses (A) changed on Oct 5, 2026 ()Before: 140.82.113.4After: 140.82.112.4Source: DNS · public resolvers 1.1.1.1, 8.8.8.8
Showing the 10 most recent changes.
Values on record
Registrar
MarkMonitor Inc. (IANA 292)
unchanged since Sep 25, 2026, seen in 14 checks · Source: RDAP · rdap.verisign.com + rdap.markmonitor.com · Observed:
Expiry date
2028-10-09
unchanged since Sep 25, 2026, seen in 14 checks · Source: RDAP · rdap.verisign.com + rdap.markmonitor.com · Observed:
unchanged since Sep 25, 2026, seen in 23 checks · Source: DNS · public resolvers 1.1.1.1, 8.8.8.8 · Observed:
IPv4 addresses (A)
140.82.114.3
12 distinct values so far · unchanged since Oct 11, 2026, seen in 1 check · Source: DNS · public resolvers 1.1.1.1, 8.8.8.8 · Observed:
Mail servers (MX)
0 github-com.mail.protection.outlook.com
unchanged since Sep 25, 2026, seen in 12 checks · Source: DNS · public resolvers 1.1.1.1, 8.8.8.8 · Observed:
Certificate issuer
Sectigo Limited · Sectigo Public Server Authentication CA DV E36
unchanged since Sep 25, 2026, seen in 13 checks · Source: Direct HTTPS request (headers + first 64 KB of HTML) · Observed:
Certificate expiry
2026-11-27
unchanged since Sep 25, 2026, seen in 13 checks · Source: Direct HTTPS request (headers + first 64 KB of HTML) · Observed:
The history is kept for the domain name only; nothing about who looked it up is stored. Entries not seen again for 400 days are deleted. Changing A, AAAA and hosting values are normal for sites behind load balancers or content delivery networks.
How this domain compares
Fixed points of reference, not rankings. Each line says what the value is compared with and where it came from.
8 nameservers in the registry record. RFC 1034 asks for at least two; two to four is the usual range, and more is common for large operators.Source: RDAP · rdap.verisign.com + rdap.markmonitor.com · Observed:
DNSSEC: the registry record carries no DS data. Enabling it needs a DNS provider that signs the zone and a registrar that accepts DS records.Source: RDAP · rdap.verisign.com + rdap.markmonitor.com · Observed:
Registrar: MarkMonitor (IANA ID 292), a corporate and brand-protection registrar, headquartered in United States. MarkMonitorSource: IANA Registrar IDs registry, read on 2026-09-21
.com is operated by Verisign; open to anyone. Registration data: RDAP (rdap.verisign.com). .comSource: IANA RDAP bootstrap file and root zone database, read on 2026-09-16
729 days to the expiry date recorded at the registry. A gTLD registration can be renewed up to ten years ahead.Source: RDAP · rdap.verisign.com + rdap.markmonitor.com · Observed:
IPv4 only: 1 A record and no AAAA record at this name.Source: DNS · public resolvers 1.1.1.1, 8.8.8.8 · Observed:
Hosting networks
AS36459 GITHUB - GitHub, Inc. (US)
unchanged since Sep 25, 2026, seen in 9 checks · Source: Team Cymru IP-to-ASN (DNS) · IP RDAP · PTR · Observed:
Announced by 1 network: AS36459. Allocation country: United States (where the address block is registered, not where the server stands).Source: Team Cymru IP-to-ASN (DNS) · IP RDAP · PTR · Observed:
1 MX host; SPF present; DMARC present (p=quarantine). DKIM needs a selector to be checked.Source: DNS · public resolvers 1.1.1.1, 8.8.8.8 · Observed:
Certificate lifetime 89 days, 47 days remaining. Publicly trusted certificates issued on this date may be valid for at most 200 days (CA/Browser Forum Baseline Requirements).Source: Direct HTTPS request (headers + first 64 KB of HTML) · Observed: