Domain Intelligence

chat.io

Low-risk posture with minor configuration gaps.

Low Risk
spf_not_strict dmarc_monitor_only dnssec_not_validated no_caa_records

Threat Score

12 /100

Low Risk

Domain appears safe

Risk score

12/100

low risk

Server IPs

1

resolved address records

Mail posture

DMARC present

Google Workspace

DNS controls

No DNSSEC

CAA missing

Server Infrastructure

Resolved IPs with ASN, country, and provider data

1 server
IP Address Location ASN / Org Provider Reverse DNS
104.198.14.52 A US
AS396982

GOOGLE-CLOUD-PLATFORM - Google LLC, US

Google Cloud 52.14.198.104.bc.googleusercontent.com

DNS Records

Address, mail, text, and certificate records from public DNS

23 records
A (1) MX (5) NS (12) TXT (4) SOA (1)
A 1 record
Name Value TTL
chat.io 104.198.14.52 288s
MX 5 records
Name Value TTL
chat.io 10 aspmx.l.google.com. 300s
chat.io 20 alt1.aspmx.l.google.com. 300s
chat.io 20 alt2.aspmx.l.google.com. 300s
chat.io 30 aspmx2.googlemail.com. 300s
chat.io 30 aspmx3.googlemail.com. 300s
NS 12 records
Name Value TTL
chat.io vin.ns.cloudflare.com. 86400s
chat.io ns1.p29.dynect.net. 86400s
chat.io a3-67.akam.net. 86400s
chat.io a26-66.akam.net. 86400s
chat.io a12-67.akam.net. 86400s
chat.io a1-64.akam.net. 86400s
chat.io ns2.p29.dynect.net. 86400s
chat.io ns3.p29.dynect.net. 86400s
chat.io ns4.p29.dynect.net. 86400s
chat.io a13-64.akam.net. 86400s
chat.io a2-65.akam.net. 86400s
chat.io ruth.ns.cloudflare.com. 86400s
TXT 4 records
Name Value TTL
_dmarc.chat.io "v=DMARC1; p=none; pct=100; rua=mailto:re+vhaty78zuze@dmarc.postmarkapp.com; sp=none; aspf=r;" 300s
chat.io "google-site-verification=yG1XvA_Morn2FDf6vJeUIAE11qYoQd7wJNgjKMy-Iy0" 300s
chat.io "status-page-domain-verification=nrl1s0lpfcmz" 300s
chat.io "v=spf1 a mx include:spf.mtasv.net include:_spf.google.com include:servers.mcsv.net include:stspg-customer.com include:spf.autopilothq.com include:sendgrid.net ~all" 300s
SOA 1 record
Name Value TTL
chat.io ruth.ns.cloudflare.com. dns.cloudflare.com. 2402352390 3600 600 604800 1800 1800s

Email & DNS Security

Mail authentication posture and DNS security controls

Mail Provider

Google Workspace

Authentication

MX Records
Present
SPF Record
Present
DMARC Policy
none

Policy is set to none β€” monitoring only, no enforcement action taken.

Authentication Flow

flowchart LR
  A["Email\nfrom chat.io"] --> B["SPF\nPermissive ~all / +all"]
  B --> C["DMARC\np=none"]
  C --> D["Domain can\nbe spoofed"]:::warn
Cloudflare

DNS Security Β· Cloudflare

DNSSEC
Not enabled
CAA Records
Missing

Nameservers

vin.ns.cloudflare.comns1.p29.dynect.neta3-67.akam.neta26-66.akam.neta12-67.akam.neta1-64.akam.netns2.p29.dynect.netns3.p29.dynect.netns4.p29.dynect.neta13-64.akam.neta2-65.akam.netruth.ns.cloudflare.com

WHOIS & Registrar

Registration details via RDAP

RDAP

Registrar

Unknown

Registration Dates

Created

β€”

Updated

β€”

Expires

β€”

WHOIS server: 2562047h47m16.854775807s.

Similar Domains

Typosquat and adjacent-domain candidates resolved with public DNS

7 active
resolves

app suffix

18.208.88.157, 98.84.224.111 +2 more

resolves

app suffix without separator

216.150.16.193, 216.150.1.1

login suffix

resolves

.com TLD swap

172.64.146.196, 104.18.41.60 +2 more

resolves

.net TLD swap

199.36.158.100

resolves

.org TLD swap

51.81.16.13

resolves

.ai TLD swap

18.238.25.33, 18.238.25.4 +2 more

resolves

.co TLD swap

216.150.1.1

Self-hostable Threat Feeds

Free feed candidates for VPS import β€” no paid DNSBLs queried at runtime

HaGeZi Threat Intelligence Feed

recommended plain domain list

Malware, phishing, scam, and high-confidence threat domains for local DNS filtering.

License
GPL-3.0
Source
https://raw.githubusercontent.com/hagezi/dns-blocklists/main/domains/tif.txt

HaGeZi Newly Registered Domains

optional plain domain list

Freshly observed domains often abused in short-lived campaigns.

License
GPL-3.0
Source
https://raw.githubusercontent.com/hagezi/dns-blocklists/main/domains/nrd.txt

URLhaus hostfile

recommended hosts file

Active malware distribution hosts that can be mirrored into a local resolver or VPS matcher.

License
abuse.ch community API fair use
Source
https://urlhaus.abuse.ch/downloads/hostfile/

URLhaus RPZ

optional DNS RPZ

Response Policy Zone feed for VPS-hosted DNS enforcement.

License
abuse.ch community API fair use
Source
https://urlhaus.abuse.ch/downloads/rpz/

Queried 6/4/2026, 11:21:03 PM Β· 781ms