Domain Intelligence

chatgpt.org

Low-risk posture with minor configuration gaps.

Low Risk NAMECHEAP INC 3.5 years old
spf_not_strict dmarc_monitor_only dnssec_not_validated no_caa_records

Threat Score

12 /100

Low Risk

Domain appears safe

Risk score

12/100

low risk

Server IPs

1

resolved address records

Mail posture

DMARC present

mail provider not classified

DNS controls

No DNSSEC

CAA missing

Server Infrastructure

Resolved IPs with ASN, country, and provider data

1 server
IP Address Location ASN / Org Provider Reverse DNS
176.125.242.237 A RU
AS200019

AlexHost - ALEXHOST SRL, MD

Not classified server.chatgpt.org

DNS Records

Address, mail, text, and certificate records from public DNS

8 records
A (1) MX (2) NS (2) TXT (2) SOA (1)
A 1 record
Name Value TTL
chatgpt.org 176.125.242.237 3362s
MX 2 records
Name Value TTL
chatgpt.org 20 mail.chatgpt.org. 3600s
chatgpt.org 10 mail.chatgpt.org. 3600s
NS 2 records
Name Value TTL
chatgpt.org ns1.chatgpt.org. 3600s
chatgpt.org ns2.chatgpt.org. 3600s
TXT 2 records
Name Value TTL
_dmarc.chatgpt.org "v=DMARC1; p=none; aspf=r; sp=none" 3600s
chatgpt.org "v=spf1 ip4:176.125.242.237 a mx ~all" 3600s
SOA 1 record
Name Value TTL
chatgpt.org server.chatgpt.org. root.chatgpt.org. 2026040704 10800 3600 604800 86400 3600s

Email & DNS Security

Mail authentication posture and DNS security controls

Mail Provider

Not classified

Authentication

MX Records
Present
SPF Record
Present
DMARC Policy
none

Policy is set to none โ€” monitoring only, no enforcement action taken.

Authentication Flow

flowchart LR
  A["Email\nfrom chatgpt.org"] --> B["SPF\nPermissive ~all / +all"]
  B --> C["DMARC\np=none"]
  C --> D["Domain can\nbe spoofed"]:::warn

DNS Security

DNSSEC
Not enabled
CAA Records
Missing

Nameservers

ns1.chatgpt.orgns2.chatgpt.org

WHOIS & Registrar

Registration details via RDAP

RDAP

Registrar

NAMECHEAP INC

NAMECHEAP INC

Abuse: support@namecheap.com

Registration Dates

Domain age

3.5 years

Created

Dec 1, 2022

Updated

Mar 18, 2025

Expires

Dec 1, 2026

Registrant

Organization Privacy service provided by Withheld for Privacy ehf
Email c2715579b26d4a2d998ed55b101a6f93.protect@withheldforprivacy.com
Phone +354.4212434
Location Reykjavik, Capital Region, IS

Status

client transfer prohibited

Similar Domains

Typosquat and adjacent-domain candidates resolved with public DNS

5 active
resolves

missing last character

76.223.54.146, 13.248.169.48

repeated last character

76.223.54.146, 13.248.169.48

app suffix

app suffix without separator

login suffix

resolves

.com TLD swap

104.18.32.47, 172.64.155.209 +2 more

resolves

.net TLD swap

76.223.54.146, 13.248.169.48

resolves

.io TLD swap

172.67.172.43, 104.21.39.244 +2 more

Self-hostable Threat Feeds

Free feed candidates for VPS import โ€” no paid DNSBLs queried at runtime

HaGeZi Threat Intelligence Feed

recommended plain domain list

Malware, phishing, scam, and high-confidence threat domains for local DNS filtering.

License
GPL-3.0
Source
https://raw.githubusercontent.com/hagezi/dns-blocklists/main/domains/tif.txt

HaGeZi Newly Registered Domains

optional plain domain list

Freshly observed domains often abused in short-lived campaigns.

License
GPL-3.0
Source
https://raw.githubusercontent.com/hagezi/dns-blocklists/main/domains/nrd.txt

URLhaus hostfile

recommended hosts file

Active malware distribution hosts that can be mirrored into a local resolver or VPS matcher.

License
abuse.ch community API fair use
Source
https://urlhaus.abuse.ch/downloads/hostfile/

URLhaus RPZ

optional DNS RPZ

Response Policy Zone feed for VPS-hosted DNS enforcement.

License
abuse.ch community API fair use
Source
https://urlhaus.abuse.ch/downloads/rpz/

Queried 6/4/2026, 6:31:31 PM ยท 1380ms