🌐 mail.com
DOMAIN
· host
mail.com
· threat 0.50 (HIGH)
· Ransomware Actors First seen 2026-08-06 13:13:01 · last seen 2026-08-06 13:13:01
🔄 Pivot:📁 Ransomware Actors
Threat score
0.50
MEDIUM
Sightings
1
1 sources
Subdomains (local)
1
from indicators
Related IPs
1
A/AAAA records
DNS records (local)
0
0 types
Reporting sources
1
0 enrichments
📡 Reporting-source breakdown
1
1 total source links on this indicator.
🏷 Tag breakdown (domain family)
2
2
1
1
📈 DNS record-type counts
No data.
📅 First-seen timeline (family)
2
🏷 WHOIS / Registration (local cache)
No cached WHOIS for mail.com. Resolve & cache.
📡 DNS Records
Live (DNS-over-HTTPS · optional augmentation)
| Type | Value | TTL |
|---|---|---|
| A | 217.72.199.4 |
22 |
| MX | 10 mx01.mail.com. |
471 |
| MX | 10 mx00.mail.com. |
471 |
| NS | ns-gmx.ui-dns.org. |
20733 |
| NS | ns-gmx.ui-dns.biz. |
20733 |
| NS | ns-gmx.ui-dns.com. |
20733 |
| NS | ns-gmx.ui-dns.de. |
20733 |
| TXT | tpverification20190725 |
261 |
| TXT | v=spf1 redirect=_spf.mail.com |
261 |
| TXT | facebook-domain-verification=1tfo5yk9c82lmx9liuspqxjs4pflqh |
261 |
| TXT | google-site-verification=YymMa2Q1A1HdQ6ZSXlCEjvK-0cm9pYYHyK9jLlaZO_Q |
261 |
| TXT | 6l6jlm3slqmj6p36q5ml3klr3y26fdf8 |
261 |
| TXT | google-site-verification=uKluyr2DCMEw-x6xj83XKnu0IKR3AqUJ1qZcWyAZRDk |
261 |
| TXT | plnw801jhnynl9yjq06byqmfhjw58vh2 |
261 |
| TXT | google-site-verification=q1HG15Gz1NxldgaHm8L0IMUI1rx-lcr7b3GdhzQD38M |
261 |
| TXT | google-site-verification=Kf3yXNbla6wH4iBd4VLGWn_8tSmFpAVTsDakfLRx5fI |
261 |
🖥 Related IPs (1)
Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.
🌐 Subdomains — local intel (1)
Domains/URLs in the local DB ending in .mail.com (bounded to 200). Each links to its own dossier.
📡 Reporting Sources (1)
MISP Galaxy Ransomware | Ransomware Actors |
🌐 Same-ASN domains (0)
No ASN linkage in local intel.
🔍 OSINT pivots — external lookups
🔗 Internal pivots & actions
📁 Case Management
Every panel resolves local-first: threat, category, first-seen & sightings from
indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Audit DNS to build passive history
- Pivot resolved IPs to their dossiers
- Report phishing to registrar/host