toolkit

In Action · Before you touch a site

Where is this hosted?

“Where is this hosted?” Or: “Did the client move hosting on us?”

"Where is this actually hosted" and "did the client quietly move providers on us" are both answerable from the outside, without a single login — web host, nameservers, email provider, SSL certificate, registrar, and exactly when the domain last changed hands. This reads all of that in one pass and knows the fingerprints that trip up simpler lookup tools, including correctly reporting a site sitting behind a client's own Cloudflare account as hidden rather than mislabeling whatever's actually underneath it.

Watch it run

Watch OpenCode turn one hosting question into a complete, timestamped infrastructure snapshot without a login.

Where is this hosted?

Watch OpenCode turn one hosting question into a complete, timestamped infrastructure snapshot without a login.

Where is sherberandrad.com hosted? Return the hosting, DNS, edge, email, SSL, registrar, and last-change date. Read only.

0:11live read-onlyINFO

What to ask for

See it work

A real run of Hosting & DNS:

example.com
  hosting:    Cloudflare (origin hidden)
  platform:   —
  CDN/edge:   Cloudflare
  nameserver: Cloudflare
  IP:         <ip>  CLOUDFLARENET - Cloudflare, Inc., US
  email:
  SSL:        SSL Corporation
  registrar:  RESERVED-Internet Assigned Numbers Authority
  registered: <date>
  last change:<date>
  account:    active — SEO (Active)
  expects:    seo, analytics, content
  CS:         Jordan Casey
  specialist: Priya Nandan
  tech SEO:   Sam Okafor
  writer:     Morgan Reyes
  editor:     Alex Chen
  content dev:Jamie Park

HOSTING PLAYBOOK
  wiki disabled (--no-wiki)
wrote ./out/hosting-and-dns.json
report: ./out/hosting-and-dns-hosting-and-dns.html

The captured report, exactly as a run hands it to a client —open the full report ↗

Seen in the wild

The manual reply had one field. The lookup returned eight.

Ticket #12651closed

Nameserver and hosting details requested

DNS / hosting

This ticket was answered by a person opening a lookup tool, reading off the nameservers, and typing them into a reply. That is a completely reasonable way to answer it. It is also the whole answer, every time, for a question we get repeatedly.

What one command returned

HostingWP Engine
NameserversCloudflare
CDN / edgeCloudflare
MailGoogle Workspace
SSL issuerLet’s Encrypt
RegistrarSquarespace
Registered2022-06-14
Last changed2026-05-30

Everything above came back from a single lookup — including the two dates, which nobody thought to check by hand.

Nameservers onlyWhat the manual reply contained
Eight fieldsWhat the same question returns automatically

The infrastructure fingerprint: web host, nameservers, CDN/edge, email provider, SSL issuer, registrar, and when the domain last changed hands — read entirely from the outside, no login. It also knows the fingerprints generic whois-style tools miss, and correctly reports a site sitting behind the client’s own Cloudflare as “origin hidden” rather than mislabelling the host underneath.

  1. Run the hosting and DNS snapshot for the domain and save the timestamped result — this is the only record of “where it was” once anything changes.
  2. Read the DNS, TLS, response and registration evidence together; each answers a different part of the question, and a domain can be proxied through one provider while actually hosted on another.
  3. Compare the snapshot against the client’s expected host or an in-flight cutover plan, and route any disagreement to whoever owns infrastructure for that client.
  4. For a migration specifically, capture a snapshot before the change and verify again after — one run gives you a point in time, never a history.

One snapshot, never a history

The check answers “where is this, right now.” Whether it moved, when, or from where is only answerable if a snapshot already exists from before — which is exactly why step 4 matters more on a migration than it looks like it should.

What this does not cover

Whether the records are *correct* for this client, and what they were last week. It reports what DNS, TLS and RDAP say right now; it does not crawl pages, audit content, or track history between runs — a single snapshot, not a monitor.

← All jobs