Hostname
return.st
Last fetched
return.st resolves to 104.21.61.254, announced in 104.21.48.0/20 by CLOUDFLARENET - Cloudflare, Inc. in CA. return.st is listed by 1 threat feed; reconciled level HIGH.
Threat posture
40threat score (procedure-native scale)
HIGHListed by 1 threat feed. At least one source recommends blocking.
Categories: Phishing
- Threat feeds listing this
- 1
- Verdict coverage
- malicious-evidenced
- First seen on a feed
- Wed, 26 Aug 2026 14:45:24 GMT
- Last seen on a feed
- Tue, 15 Sep 2026 00:18:35 GMT
Nutrition Label
Resolution chain
- 104.21.61.254
104.21.48.0/20 · CLOUDFLARENET - Cloudflare, Inc. · Toronto, CA
- 104.26.6.7
104.26.0.0/20 · CLOUDFLARENET - Cloudflare, Inc. · Toronto, CA
- 104.26.7.7
104.26.0.0/20 · CLOUDFLARENET - Cloudflare, Inc. · Toronto, CA
- 172.67.217.119
172.67.208.0/20 · CLOUDFLARENET - Cloudflare, Inc. · Toronto, CA
- 172.67.68.83
172.67.64.0/20 · CLOUDFLARENET - Cloudflare, Inc. · Toronto, CA
- 216.146.31.1
216.146.31.0/24 · DiamWall - DIAMWALL, LDA · Lisbon, PT
- 83.150.218.17
83.150.218.0/24 · YORKHOST - YORKHOST SAS · Vélizy-Villacoublay, FR
IPv6 resolution
Attribution
Cloudflare
cdn · ORIGIN_AS, CDN
WHOIS identity
WhisperGraph holds no WHOIS registrar, registrant organisation or contact email for return.st. WHOIS is recorded against the registrable domain, so a subdomain such as a www. host carries none of its own — check the registrable domain for this name.
Subdomains
Showing 3 of 4. View all subdomains →
Mail and authentication
Nameservers
- jen.ns.cloudflare.com
- johnny.ns.cloudflare.com
- lilith.ns.cloudflare.com
- rajeev.ns.cloudflare.com
- chip.diamwall.com
- runah.diamwall.com
- ns1.istanco.com
- ns2.istanco.com
MX records
- _dc-mx.843c2590cec0.return.st
- mail.return.st
SPF policy
- a: return.st
- mx: return.st
- ip: 66.94.97.77
Threat-feed evidence
History
Related pages
Pivot from return.st into the addresses, networks and registries it depends on.
Cypher and MCP
Reproduce this hostname's resolution chain against graph.whisper.security:
MATCH (h:HOSTNAME {name: "return.st"})-[:RESOLVES_TO]->(ip:IPV4)
-[:ANNOUNCED_BY]->(ap:ANNOUNCED_PREFIX)-[:ROUTES]->(a:ASN)
OPTIONAL MATCH (a)-[:HAS_NAME]->(n:ASN_NAME)
RETURN ip.name AS ip, ap.name AS prefix, a.name AS asn, n.name AS network
LIMIT 20Or query Whisper from your own LLM workflow via the Whisper MCP server.