Who Is Hosting This Website

The addresses a site resolves to, the network that holds them, and what its headers give away about the CDN and the stack in front of it.

This tool needs JavaScript: the server makes the request, because a browser cannot read another site headers.

A domain or a URL. One request is made to the home page over https, the same request a browser would make.

Result

This is one of the few tools here that asks the server rather than your browser, because a browser cannot do it. Nothing you put in is stored; the request is rate limited by address and the answer is not cached.

Where a site actually lives: the addresses it resolves to, the network those addresses belong to, and what the response headers give away about what is in front of it.

The honest answer is often “Cloudflare”, and that is worth knowing too. A CDN is designed to be the thing you see, and no lookup from outside can see past a correctly configured one.

How to use

Put in a domain or a URL. One request is made to the home page over https, which is the same request a browser would make. Nothing else is probed.

Example

Host                                       wordpress.org

Addresses
  198.143.164.252                          no PTR record

Network holding 198.143.164.252
  name                                     AUTOMATTIC
  range                                    198.143.164.0 – 198.143.164.255
  country                                  US
  organisation                             Automattic Inc

What the site says about itself
  status                                   200
  final address                            https://wordpress.org/
  server                                   nginx
  in front                                 nothing that announces itself, so this is probably the origin
  looks like                               WordPress, from the headers it sends

Pitfalls

A CDN hides the host, deliberately. With Cloudflare, Fastly or CloudFront in front, the address and the network you see belong to the CDN. The origin is visible only when it is misconfigured, and building anything on that is building on somebody else’s mistake.

Shared hosting looks like the host, not the site. On shared infrastructure every site on the box has the same address and the same headers, which tells you the provider and nothing about the account.

Server and X-Powered-By are whatever the server chooses to say. They are often removed, sometimes wrong on purpose, and X-Powered-By: PHP/7.4 is a gift to anybody scanning for old versions. Removing it is one of the cheapest hardening steps there is.

Reverse DNS is a hint, not a fact. A PTR record says what the address owner chose to write there. Matching it against forward DNS is what makes it meaningful, and most addresses have no PTR at all.

Several addresses usually means a CDN or a load balancer, not several servers you could reach. The one your browser uses depends on where you are, which is the point.

This is passive. One GET to the home page, the same one a browser makes. It does not scan ports, probe paths or test for vulnerabilities, because doing any of that to a site you do not own is a different activity with a different legal status.

Hosting reviews built on this data are usually wrong. Response time from one server in one place says nothing about the experience of the people who actually visit the site.

Compatibility

Three lookups: DNS for the addresses, RDAP for the network that holds the first of them, and one HTTPS GET to the site. This is one of the few tools here that asks the server, because a browser cannot read another origin’s response headers and cannot make a DNS query at all.

The network lookup uses ARIN’s RDAP service, which redirects to the other regional registries for addresses outside its own region; the redirect is followed by the same guard as everything else.

That guard matters more here than anywhere: this tool takes an address from a stranger and asks the server to fetch it. Only http and https, only on the standard ports, the name resolved before use with every address checked against the private and reserved ranges, redirects followed by hand with the checks repeated on each hop, and the response capped in size and time. The request is rate limited to 20 a minute per address and nothing is stored.

CDN detection is by header, and the header that proved it is named: cf-ray for Cloudflare, x-vercel-id for Vercel, x-amz-cf-id for CloudFront, x-served-by for Fastly, and so on. Where nothing announces itself the tool says so rather than guessing.

Frequently asked questions

It says Cloudflare. Where is the site really?
Behind Cloudflare, and that is all anyone outside can say. Historical DNS records sometimes show an address from before the CDN was added, which may or may not still be the origin.
Can I find out which hosting company a competitor uses?
Often, from the network name, unless they are behind a CDN. It tells you the provider rather than the plan, and it is a weaker signal about their setup than it looks.
Why do I get a different address than the tool does?
DNS answers vary by location. A CDN deliberately returns the address nearest to whoever asked, so a server in another country legitimately sees a different one.
Does this check whether a site is up?
Only incidentally: it reports the status code of one request. A monitoring service checks repeatedly from several places, which is a different question.
Why not show more about the stack?
Because anything further would mean probing paths on somebody else’s site, and a tool that does that to any address a stranger types is a tool for attacking sites rather than for understanding them.
Weekly drops

New tools, when there are new tools

One email when something worth using ships. No schedule to fill, so no filler.

Your address goes nowhere else, and one click unsubscribes.