Sensors on participating networks note the DNS answers that resolvers receive: the name, the answer, and when it was first and last seen. Nothing is asked of the domain itself, so the history shows what people were actually sent. It only covers names those networks' users looked up.
Reading the timeline.
Each step is a network (the company announcing the addresses) and the span its addresses were seen; a gap of over a year starts a new step.
The network is the one that announces the address today. For cloud and hosting ranges that rarely changes, but an address can move to a new owner over the years.
A very short period on an unexpected network is often a wrong answer from a filtering or hijacked resolver, not a real move.
"Seen" counts how many times the sensors recorded the answer; busy sites reach millions.
Questions people ask.
What is DNS history?
A record of the answers a domain's DNS gave in the past: the IP addresses it pointed to, its aliases, and when. It comes from passive DNS, where sensors on networks note the answers resolvers receive and when each was first and last seen.
Where does the data come from?
From mnemonic's public passive DNS: records marked TLP:WHITE, which mnemonic offers to the public and which may be shared freely. Today's records come from live DNS, and the network behind each address from Team Cymru's IP to ASN mapping.
Why is my domain missing?
Passive DNS only sees names that the users of its sensors' networks look up. Small, new or rarely visited sites are often not in it, and that says nothing about the domain.
Does it show old name servers and mail servers?
Only what passive DNS saw, which is mostly addresses and aliases. For the registration record use WHOIS, and for old versions of the website the domain history tool.
Why does the history list a network the site never used?
Passive DNS records what resolvers were told, and filtering or hijacked resolvers sometimes answer with their own address. A short, isolated period on an unexpected network is usually one of those.
Hivex index
Short names, still free to register.
Starting something new? Hivex keeps a live index of short, brandable .si names nobody has claimed yet, each checked with the registry.
Hivex's free JSON API and MCP server check domains, DNS and registration records from your own code or from AI assistants that speak MCP. No key needed.
By Hivex. Updated 11 October 2026. Past records come from mnemonic's public passive DNS and are kept up to a day; today's records are read live. The names you search are not stored.
github.com · DNS history
Checked 03:08:58 UTC · mnemonic passive DNS · live DNS
First seen
10 April 2013
Addresses seen
28
Networks
5
Now on
GitHub, Inc.
Good: Since 10 April 2013, github.com has pointed to 28 addresses on 5 networks; today it is on GitHub, Inc.
Hosting over time
Network of each IPv4 address
Note: Rackspace Hosting10 April 2013 to 3 September 2013 · 204.232.175.90
Note: GitHub, Inc.2 April 2016 to 10 October 2026 · 192.30.252.120, 192.30.252.121, 192.30.252.122 and 15 more
Note: Amazon.com, Inc.6 December 2017 to 15 February 2018 · 18.194.104.89, 18.195.85.27, 35.159.8.160
Note: Automattic, Inc8 July 2021 to 17 November 2022 · 192.0.78.24, 192.0.78.25
Note: Microsoft Corporation19 February 2024 to 10 October 2026 · 4.208.26.197, 20.26.156.215, 4.225.11.194 and 1 more
Good: Now: GitHub, Inc.140.82.112.4
Each network is the one that announces the address today; cloud and hosting ranges rarely change hands.