Domain Intelligence

chat.ai

Low-risk posture with minor configuration gaps.

Low Risk Zenaida.cate.ai 8.5 years old
spf_not_strict dmarc_monitor_only dnssec_not_validated no_caa_records

Threat Score

12 /100

Low Risk

Domain appears safe

Risk score

12/100

low risk

Server IPs

4

resolved address records

Mail posture

DMARC present

Google Workspace

DNS controls

No DNSSEC

CAA missing

Server Infrastructure

Resolved IPs with ASN, country, and provider data

4 servers
IP Address Location ASN / Org Provider Reverse DNS
18.238.25.91 A US
AS16509

AMAZON-02 - Amazon.com, Inc., US

AWS AWS server-18-238-25-91.cmh68.r.cloudfront.net
18.238.25.33 A US
AS16509

AMAZON-02 - Amazon.com, Inc., US

AWS AWS server-18-238-25-33.cmh68.r.cloudfront.net
18.238.25.4 A US
AS16509

AMAZON-02 - Amazon.com, Inc., US

AWS AWS server-18-238-25-4.cmh68.r.cloudfront.net
18.238.25.74 A US
AS16509

AMAZON-02 - Amazon.com, Inc., US

AWS AWS server-18-238-25-74.cmh68.r.cloudfront.net

DNS Records

Address, mail, text, and certificate records from public DNS

18 records
A (4) MX (5) NS (4) TXT (4) SOA (1)
A 4 records
Name Value TTL
chat.ai 18.238.25.91 60s
chat.ai 18.238.25.33 60s
chat.ai 18.238.25.4 60s
chat.ai 18.238.25.74 60s
MX 5 records
Name Value TTL
chat.ai 1 aspmx.l.google.com. 300s
chat.ai 10 alt3.aspmx.l.google.com. 300s
chat.ai 10 alt4.aspmx.l.google.com. 300s
chat.ai 5 alt1.aspmx.l.google.com. 300s
chat.ai 5 alt2.aspmx.l.google.com. 300s
NS 4 records
Name Value TTL
chat.ai ns-1398.awsdns-46.org. 172800s
chat.ai ns-146.awsdns-18.com. 172800s
chat.ai ns-1752.awsdns-27.co.uk. 172800s
chat.ai ns-763.awsdns-31.net. 172800s
TXT 4 records
Name Value TTL
_dmarc.chat.ai "v=DMARC1; p=none; rua=mailto:mailauth-reports@chat.ai" 300s
chat.ai "google-site-verification=DIp7s6BOyTzQF0w3cXpvvh9boLctYTL_Y9RlngeOeds" 300s
chat.ai "openai-domain-verification=dv-3wBD5Aj3HFPvjO9CHLEwJr1S" 300s
chat.ai "v=spf1 include:_spf.google.com ~all" 300s
SOA 1 record
Name Value TTL
chat.ai ns-1752.awsdns-27.co.uk. awsdns-hostmaster.amazon.com. 1 7200 900 1209600 86400 900s

Email & DNS Security

Mail authentication posture and DNS security controls

Mail Provider

Google Workspace

Authentication

MX Records
Present
SPF Record
Present
DMARC Policy
none

Policy is set to none β€” monitoring only, no enforcement action taken.

Authentication Flow

flowchart LR
  A["Email\nfrom chat.ai"] --> B["SPF\nPermissive ~all / +all"]
  B --> C["DMARC\np=none"]
  C --> D["Domain can\nbe spoofed"]:::warn

DNS Security Β· AWS Route 53

DNSSEC
Not enabled
CAA Records
Missing

Nameservers

ns-1398.awsdns-46.orgns-146.awsdns-18.comns-1752.awsdns-27.co.ukns-763.awsdns-31.net

WHOIS & Registrar

Registration details via RDAP

RDAP

Registrar

Zenaida.cate.ai

Registration Dates

Domain age

8.5 years

Created

Dec 16, 2017

Updated

Jun 4, 2026

Expires

Jan 18, 2028

Registrant

Name Marc Hadfield
Organization Vital AI
Email marc@hadfield.org
Phone +111.1111111111
Location Brooklyn, NY, US

Status

client transfer prohibited

Similar Domains

Typosquat and adjacent-domain candidates resolved with public DNS

7 active
resolves

app suffix

172.67.209.57, 104.21.23.56

resolves

app suffix without separator

52.33.207.86, 44.224.247.228

login suffix

resolves

.com TLD swap

104.18.41.60, 172.64.146.196 +2 more

resolves

.net TLD swap

199.36.158.100

resolves

.org TLD swap

51.81.16.13

resolves

.io TLD swap

104.198.14.52

resolves

.co TLD swap

216.150.1.1

Self-hostable Threat Feeds

Free feed candidates for VPS import β€” no paid DNSBLs queried at runtime

HaGeZi Threat Intelligence Feed

recommended plain domain list

Malware, phishing, scam, and high-confidence threat domains for local DNS filtering.

License
GPL-3.0
Source
https://raw.githubusercontent.com/hagezi/dns-blocklists/main/domains/tif.txt

HaGeZi Newly Registered Domains

optional plain domain list

Freshly observed domains often abused in short-lived campaigns.

License
GPL-3.0
Source
https://raw.githubusercontent.com/hagezi/dns-blocklists/main/domains/nrd.txt

URLhaus hostfile

recommended hosts file

Active malware distribution hosts that can be mirrored into a local resolver or VPS matcher.

License
abuse.ch community API fair use
Source
https://urlhaus.abuse.ch/downloads/hostfile/

URLhaus RPZ

optional DNS RPZ

Response Policy Zone feed for VPS-hosted DNS enforcement.

License
abuse.ch community API fair use
Source
https://urlhaus.abuse.ch/downloads/rpz/

Queried 6/4/2026, 11:20:50 PM Β· 767ms