URL / Domain Profile

🌐 mail.com

DOMAIN · host mail.com · threat 0.50 (HIGH) · Ransomware Actors
First seen 2026-08-06 13:13:01 · last seen 2026-08-06 13:13:01

Threat score

0.50
MEDIUM

Sightings

1
1 sources

Subdomains (local)

1
from indicators

Related IPs

1
A/AAAA records

DNS records (local)

0
0 types

Reporting sources

1
0 enrichments

📡 Reporting-source breakdown

Ransomware Actors
1
1 total source links on this indicator.

🏷 Tag breakdown (domain family)

medium-severity
2
auto-tagged
2
ransomware
1
url
1

📈 DNS record-type counts

No data.

📅 First-seen timeline (family)

2026-08
2

🏷 WHOIS / Registration (local cache)

No cached WHOIS for mail.com. Resolve & cache.

🏷 Tags

ransomware medium-severity auto-tagged
CategoryRansomware Actors
SeverityMEDIUM

📡 DNS Records

Live (DNS-over-HTTPS · optional augmentation)

TypeValueTTL
A 217.72.199.4 22
MX 10 mx01.mail.com. 471
MX 10 mx00.mail.com. 471
NS ns-gmx.ui-dns.org. 20733
NS ns-gmx.ui-dns.biz. 20733
NS ns-gmx.ui-dns.com. 20733
NS ns-gmx.ui-dns.de. 20733
TXT tpverification20190725 261
TXT v=spf1 redirect=_spf.mail.com 261
TXT facebook-domain-verification=1tfo5yk9c82lmx9liuspqxjs4pflqh 261
TXT google-site-verification=YymMa2Q1A1HdQ6ZSXlCEjvK-0cm9pYYHyK9jLlaZO_Q 261
TXT 6l6jlm3slqmj6p36q5ml3klr3y26fdf8 261
TXT google-site-verification=uKluyr2DCMEw-x6xj83XKnu0IKR3AqUJ1qZcWyAZRDk 261
TXT plnw801jhnynl9yjq06byqmfhjw58vh2 261
TXT google-site-verification=q1HG15Gz1NxldgaHm8L0IMUI1rx-lcr7b3GdhzQD38M 261
TXT google-site-verification=Kf3yXNbla6wH4iBd4VLGWn_8tSmFpAVTsDakfLRx5fI 261

🖥 Related IPs (1)

Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.

217.72.199.4

🌐 Subdomains — local intel (1)

Domains/URLs in the local DB ending in .mail.com (bounded to 200). Each links to its own dossier.

http://www.securityfocus.com/templates/archive.pike?list=1&msg=383085010.956159226625.JavaMail.root%40web305-mc.mail.com

📡 Reporting Sources (1)

MISP Galaxy RansomwareRansomware Actors

🌐 Same-ASN domains (0)

No ASN linkage in local intel.

📁 Case Management

+ New case from this
Every panel resolves local-first: threat, category, first-seen & sightings from indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php

🔗 Related Tools