In Action · Before you touch a site
Where is this hosted?
“Where is this hosted?” Or: “Did the client move hosting on us?”
"Where is this actually hosted" and "did the client quietly move providers on us" are both answerable from the outside, without a single login — web host, nameservers, email provider, SSL certificate, registrar, and exactly when the domain last changed hands. This reads all of that in one pass and knows the fingerprints that trip up simpler lookup tools, including correctly reporting a site sitting behind a client's own Cloudflare account as hidden rather than mislabeling whatever's actually underneath it.
Watch it run
What to ask for
See it work
A real run of Hosting & DNS:
example.com
hosting: Cloudflare (origin hidden)
platform: —
CDN/edge: Cloudflare
nameserver: Cloudflare
IP: <ip> CLOUDFLARENET - Cloudflare, Inc., US
email:
SSL: SSL Corporation
registrar: RESERVED-Internet Assigned Numbers Authority
registered: <date>
last change:<date>
account: active — SEO (Active)
expects: seo, analytics, content
CS: Jordan Casey
specialist: Priya Nandan
tech SEO: Sam Okafor
writer: Morgan Reyes
editor: Alex Chen
content dev:Jamie Park
HOSTING PLAYBOOK
wiki disabled (--no-wiki)
wrote ./out/hosting-and-dns.json
report: ./out/hosting-and-dns-hosting-and-dns.htmlThe captured report, exactly as a run hands it to a client —open the full report ↗
Seen in the wild
The manual reply had one field. The lookup returned eight.
Ticket #12651closed
Nameserver and hosting details requested
This ticket was answered by a person opening a lookup tool, reading off the nameservers, and typing them into a reply. That is a completely reasonable way to answer it. It is also the whole answer, every time, for a question we get repeatedly.
What one command returned
| Hosting | WP Engine |
|---|---|
| Nameservers | Cloudflare |
| CDN / edge | Cloudflare |
| Google Workspace | |
| SSL issuer | Let’s Encrypt |
| Registrar | Squarespace |
| Registered | 2022-06-14 |
| Last changed | 2026-05-30 |
Everything above came back from a single lookup — including the two dates, which nobody thought to check by hand.
The infrastructure fingerprint: web host, nameservers, CDN/edge, email provider, SSL issuer, registrar, and when the domain last changed hands — read entirely from the outside, no login. It also knows the fingerprints generic whois-style tools miss, and correctly reports a site sitting behind the client’s own Cloudflare as “origin hidden” rather than mislabelling the host underneath.
- Run the hosting and DNS snapshot for the domain and save the timestamped result — this is the only record of “where it was” once anything changes.
- Read the DNS, TLS, response and registration evidence together; each answers a different part of the question, and a domain can be proxied through one provider while actually hosted on another.
- Compare the snapshot against the client’s expected host or an in-flight cutover plan, and route any disagreement to whoever owns infrastructure for that client.
- For a migration specifically, capture a snapshot before the change and verify again after — one run gives you a point in time, never a history.
One snapshot, never a history
The check answers “where is this, right now.” Whether it moved, when, or from where is only answerable if a snapshot already exists from before — which is exactly why step 4 matters more on a migration than it looks like it should.
What this does not cover
Whether the records are *correct* for this client, and what they were last week. It reports what DNS, TLS and RDAP say right now; it does not crawl pages, audit content, or track history between runs — a single snapshot, not a monitor.
