Executive Summary

Attack Surface Mapping & Passive Reconnaissance Toolkit • Domain: google.com • Date: March 20, 2026 at 05:47 UTC • Version: 1.0.0

17
/ 100

LOW EXPOSURE

  • SSL Issues: 2/20
  • Missing Headers: 11/20
  • DNS Issues: 3/15
  • Admin Exposure: 0/15

Scope & Methodology

Assessment method: passive, non-destructive reconnaissance only. No brute force, payload injection, or exploitation techniques were used.

Subdomains

NameStatusIPCDN
accounts.flexpack.google.comUNRESOLVABLE--
accounts.freezone.google.comUNRESOLVABLE--
accounts.google.comREDIRECT192.178.211.84-
ads-compare.eem.corp.google.comUNRESOLVABLE--
adwords.google.comUNRESOLVABLE192.178.211.101-
alt1.aspmx.l.google.comLIVE172.217.221.27-
alt1.gmail-smtp-in.l.google.comLIVE172.217.221.27-
alt1.gmr-smtp-in.l.google.comLIVE172.217.221.14-
alt2.aspmx.l.google.comLIVE192.178.163.26-
alt2.gmail-smtp-in.l.google.comLIVE192.178.163.27-
alt2.gmr-smtp-in.l.google.comLIVE192.178.163.14-
alt3.aspmx.l.google.comLIVE172.217.78.26-
alt3.gmail-smtp-in.l.google.comLIVE172.217.78.27-
alt3.gmr-smtp-in.l.google.comLIVE172.217.78.14-
alt4.aspmx.l.google.comLIVE142.250.101.26-
alt4.gmail-smtp-in.l.google.comLIVE142.250.101.27-
alt4.gmr-smtp-in.l.google.comLIVE142.250.101.14-
answers.google.comREDIRECT142.250.206.14-
apis.corp.google.comUNRESOLVABLE--
appengine.google.comREDIRECT142.250.206.14-
apps-secure-data-connector.google.comUNRESOLVABLE--
aspmx.l.google.comLIVE142.250.4.26-
audioads.google.comUNRESOLVABLE142.251.220.110-
auth.corp.google.comUNRESOLVABLE--
bigstore-test.corp.google.comUNRESOLVABLE--
bigstore.corp.google.comREDIRECT172.253.118.129-
blogger.corp.google.comUNRESOLVABLE--
blogspot.corp.google.comUNRESOLVABLE--
c.docs.google.comUNRESOLVABLE--
c.pack.google.comUNRESOLVABLE--
c.play.google.comUNRESOLVABLE--
c.video.google.comUNRESOLVABLE--
cache1.c.docs.google.comUNRESOLVABLE--
cache1.c.play.google.comUNRESOLVABLE--
cache1.c.video.google.comUNRESOLVABLE--
cache2.c.docs.google.comUNRESOLVABLE--
cache2.c.play.google.comUNRESOLVABLE--
cache2.c.video.google.comUNRESOLVABLE--
cache3.c.docs.google.comUNRESOLVABLE--
cache3.c.play.google.comUNRESOLVABLE--
cache3.c.video.google.comUNRESOLVABLE--
cache4.c.docs.google.comUNRESOLVABLE--
cache4.c.play.google.comUNRESOLVABLE--
cache4.c.video.google.comUNRESOLVABLE--
cache5.c.docs.google.comUNRESOLVABLE--
cache5.c.play.google.comUNRESOLVABLE--
cache5.c.video.google.comUNRESOLVABLE--
cache6.c.docs.google.comUNRESOLVABLE--
cache6.c.play.google.comUNRESOLVABLE--
cache6.c.video.google.comUNRESOLVABLE--
cache7.c.docs.google.comUNRESOLVABLE--
cache7.c.play.google.comUNRESOLVABLE--
cache7.c.video.google.comUNRESOLVABLE--
cache8.c.docs.google.comUNRESOLVABLE--
cache8.c.play.google.comUNRESOLVABLE--
cache8.c.video.google.comUNRESOLVABLE--
cag.ext.google.comUNRESOLVABLE--
cert-test.sandbox.google.comLIVE74.125.68.90-
checkout.google.comUNRESOLVABLE--
chrome.google.comREDIRECT142.250.206.14-
client-channel.google.comUNRESOLVABLE142.251.43.46-
clients.google.comUNRESOLVABLE--
cloud.google.comLIVE142.251.221.174-
cod.ext.google.comLIVE216.239.44.73-
code.google.comLIVE142.251.222.174-
corp-backups.corp.google.comUNRESOLVABLE--
corp.google.comUNRESOLVABLE142.250.4.129-
da.ext.corp.google.comUNRESOLVABLE--
da.ext.google.comUNRESOLVABLE--
dasher-qa.corp.google.comUNRESOLVABLE172.253.118.129-
dasher.corp.google.comREDIRECT172.253.118.129-
demetrius-codespot.corp.google.comUNRESOLVABLE--
demetrius-googlecode.corp.google.comUNRESOLVABLE--
demetrius.corp.google.comUNRESOLVABLE--
desktop.l.google.comUNRESOLVABLE142.250.77.100-
devconsole-testers.sandbox.google.comUNRESOLVABLE172.217.194.81-
developer.google.comREDIRECT142.251.43.238-
developers.google.comLIVE142.250.205.142-
dfa7.corp.google.comUNRESOLVABLE--
dg.video.google.comUNRESOLVABLE172.217.194.176-
docs-dev.corp.google.comUNRESOLVABLE172.253.118.129-
docs-nightly.corp.google.comUNRESOLVABLE--
docs-platinum.corp.google.comUNRESOLVABLE--
docs-qa.corp.google.comREDIRECT172.253.118.129-
docs.google.comREDIRECT142.251.220.110-
docs.sandbox.google.comREDIRECT142.250.4.81-
drive-test.corp.google.comUNRESOLVABLE--
drive.google.comREDIRECT172.217.24.14-
drive.sandbox.google.comREDIRECT172.253.118.81-
dthree.corp.google.comUNRESOLVABLE--
ecc-test.sandbox.google.comLIVE142.251.12.81-
eggroll.ext.google.comLIVE216.239.44.90-
ext.google.comUNRESOLVABLE--
flexpack.google.comUNRESOLVABLE--
focus.corp.google.comUNRESOLVABLE--
fra-da.ext.google.comUNRESOLVABLE--
freezone.accounts.google.comUNRESOLVABLE--
freezone.google.comUNRESOLVABLE--
freezone.m.google.comUNRESOLVABLE--
freezone.mail.google.comUNRESOLVABLE--
friendconnect.google.comUNRESOLVABLE142.250.206.14-
gaiastaging.flexpack.google.comUNRESOLVABLE--
gaiastaging.freezone.google.comUNRESOLVABLE--
games.corp.google.comUNRESOLVABLE--
ghs.google.comLIVE142.250.67.51-
git.corp.google.comREDIRECT172.253.118.129-
glass-eur.ext.google.comUNRESOLVABLE--
glass-mtv.ext.google.comUNRESOLVABLE--
glass-twd.ext.google.comUNRESOLVABLE--
glass.ext.google.comUNRESOLVABLE--
gmail-smtp-in.l.google.comLIVE74.125.24.27-
gmail.google.comREDIRECT142.250.206.14-
gmr-smtp-in.l.google.comLIVE74.125.200.14-
google-proxy-74-125-212-167.google.comLIVE74.125.212.167-
google.comREDIRECT142.251.222.206-
googlesource.corp.google.comUNRESOLVABLE--
groups.google.comREDIRECT64.233.170.113-
hosted-id.google.comUNRESOLVABLE--
hot-da.ext.google.comUNRESOLVABLE--
hyd-da.ext.google.comUNRESOLVABLE--
ice.ext.google.comUNRESOLVABLE--
ics.prod.google.comUNRESOLVABLE--
images.google.comLIVE142.250.206.14-
images.l.google.comUNRESOLVABLE142.250.206.14-
jaiku.l.google.comUNRESOLVABLE142.250.77.113-
jmt0.google.comUNRESOLVABLE142.250.206.14-
jotspot-qa08.corp.google.comUNRESOLVABLE--
login.corp.google.comLIVE172.253.118.129-
loop.corp.google.comUNRESOLVABLE--
m.google.comREDIRECT142.251.43.235-
m.guts.corp.google.comREDIRECT172.253.118.129-
m.gutsdev.corp.google.comREDIRECT172.253.118.129-
mail-ua1-f9.google.comLIVE209.85.222.9-
mail-vk1-f251.google.comLIVE209.85.221.251-
mail.flexpack.google.comUNRESOLVABLE--
mail.freezone.google.comUNRESOLVABLE--
mail.google.comREDIRECT142.250.205.69-
meeting.ext.google.comUNRESOLVABLE--
misc-sni.google.comUNRESOLVABLE--
misc.google.comUNRESOLVABLE--
mtalk.google.comLIVE172.253.118.188-
mtv-da-1.ad.corp.google.comUNRESOLVABLE--
mtv-da.corp.google.comUNRESOLVABLE--
mtv-da.ext.google.comLIVE216.239.45.170-
mx.google.comUNRESOLVABLE--
mygeist.corp.google.comUNRESOLVABLE--
mygeist2010.corp.google.comUNRESOLVABLE--
news-cctld.l.google.comUNRESOLVABLE142.251.222.131-
news.freezone.google.comUNRESOLVABLE--
onex.wifi.google.comUNRESOLVABLE--
orkut-fixprod.corp.google.comUNRESOLVABLE--
orkut-impersonation.corp.google.comUNRESOLVABLE--
orkut-ocdemo.corp.google.comUNRESOLVABLE--
orkut-qa.corp.google.comUNRESOLVABLE--
orkut-staging.corp.google.comUNRESOLVABLE--
orkut-uberproxy.corp.google.comUNRESOLVABLE--
orkut-vctask0.corp.google.comUNRESOLVABLE--
orkut-vcvrfy.corp.google.comUNRESOLVABLE--
orkut-yhtask0.corp.google.comUNRESOLVABLE--
orkut-yhvrfy.corp.google.comUNRESOLVABLE--
orkut-yqtask0.corp.google.comUNRESOLVABLE--
orkut-yqvrfy.corp.google.comUNRESOLVABLE--
oz-gmail.corp.google.comUNRESOLVABLE--
oz-s2.corp.google.comUNRESOLVABLE--
oz-www.corp.google.comUNRESOLVABLE--
photos.google.comREDIRECT142.250.206.14-
plus.corp.google.comUNRESOLVABLE--
plus.flexpack.google.comUNRESOLVABLE--
plus.freezone.google.comUNRESOLVABLE--
plus.google.comREDIRECT142.251.223.14-
plusone.corp.google.comUNRESOLVABLE--
postini.corp.google.comUNRESOLVABLE--
profiles.corp.google.comUNRESOLVABLE--
prom-qa.corp.google.comUNRESOLVABLE--
prom-qa.sandbox.google.comUNRESOLVABLE--
prom-test.corp.google.comUNRESOLVABLE--
prom-test.sandbox.google.comUNRESOLVABLE74.125.24.81-
prom.corp.google.comREDIRECT172.253.118.129-
proxyconfig.corp.google.comREDIRECT172.253.118.129-
pub-5701735781782373.afd.ghs.google.comLIVE142.250.205.115-
qa.adz.google.comUNRESOLVABLE--
rate-limited-proxy-74-125-149-19.google.comLIVE74.125.149.19-
rate-limited-proxy-74-125-151-227.google.comLIVE74.125.151.227-
rate-limited-proxy-74-125-218-131.google.comLIVE74.125.218.131-
reseed.corp.google.comUNRESOLVABLE--
sandbox.google.comUNRESOLVABLE172.253.118.81-
script.sandbox.google.comREDIRECT142.250.4.81-
search.corp.google.comREDIRECT172.253.118.129-
search.flexpack.google.comUNRESOLVABLE--
search.freezone.google.comUNRESOLVABLE--
services.google.comREDIRECT142.250.206.14-
sites-googlegroups-nightly.corp.google.comUNRESOLVABLE--
sites-googlegroups-qa01.corp.google.comUNRESOLVABLE--
sites-googlegroups-qa02.corp.google.comUNRESOLVABLE--
sites-googlegroups-qa03.corp.google.comUNRESOLVABLE--
sites-googlegroups-qa04.corp.google.comUNRESOLVABLE--
sites-googlegroups-qa05.corp.google.comUNRESOLVABLE--
sites-googlegroups-qa06.corp.google.comUNRESOLVABLE--
sites-googlegroups-qa07.corp.google.comUNRESOLVABLE--
sites-googlegroups-qa08.corp.google.comUNRESOLVABLE--
sites-googlegroups-tctest.corp.google.comUNRESOLVABLE--
sites.google.comREDIRECT142.250.207.78-
sites.sandbox.google.comREDIRECT74.125.130.81-
soaproxyprod01.ext.google.comLIVE72.14.225.70-
soaproxytest01.ext.google.comLIVE216.239.44.94-
spdy-proxy-debug.ext.google.comUNRESOLVABLE--
spdy-proxy.ext.google.comUNRESOLVABLE--
staging-a.blogger.corp.google.comUNRESOLVABLE--
staging-b.blogger.corp.google.comUNRESOLVABLE--
staging-c.blogger.corp.google.comUNRESOLVABLE--
staging-d.blogger.corp.google.comUNRESOLVABLE--
staging-daily.blogger.corp.google.comUNRESOLVABLE--
staging-daily.blogspot.corp.google.comUNRESOLVABLE--
staging-gaia.blogger.corp.google.comUNRESOLVABLE--
staging-git.corp.google.comREDIRECT172.253.118.129-
staging-googlesource.corp.google.comUNRESOLVABLE--
staging-prod.blogger.corp.google.comUNRESOLVABLE--
staging-weekly.blogger.corp.google.comUNRESOLVABLE--
staging-weekly.blogspot.corp.google.comUNRESOLVABLE--
talk.google.comUNRESOLVABLE--
talkgadget.google.comUNRESOLVABLE142.250.182.78-
test.postini.corp.google.comUNRESOLVABLE--
toolbarqueries.google.comUNRESOLVABLE192.178.211.99-
toolbarqueries.l.google.comUNRESOLVABLE192.178.211.147-
trends.google.comREDIRECT172.217.24.132-
twd-da.ext.google.comLIVE72.14.229.178-
twdsalesgsa.twd.corp.google.comUNRESOLVABLE--
uberproxy-nocert.corp.google.comUNRESOLVABLE--
uberproxy-san.corp.google.comUNRESOLVABLE--
uberproxy.corp.google.comREDIRECT172.253.118.129-
upload.google.comUNRESOLVABLE142.250.77.143-
upload.video.google.comUNRESOLVABLE142.251.43.143-
urchin.corp.google.comUNRESOLVABLE--
url.google.comUNRESOLVABLE--
vp.video.l.google.comUNRESOLVABLE--
webdrive-test-canary.corp.google.comREDIRECT172.253.118.129-
webdrive-test-prod.corp.google.comREDIRECT172.253.118.129-
wide-blogspot.l.google.comUNRESOLVABLE192.178.211.197-
wifi.google.comUNRESOLVABLE192.178.211.123-
www.flexpack.google.comUNRESOLVABLE--
www.freezone.google.comUNRESOLVABLE--
www.google.comLIVE142.251.155.119-
www2.l.google.comUNRESOLVABLE172.217.24.132-
www3.l.google.comUNRESOLVABLE142.250.206.14-

DNS Analysis

Records

TypeValues
A142.251.222.206
AAAA2404:6800:4007:833::200e
MX10 smtp.google.com.
NSns4.google.com., ns2.google.com., ns3.google.com., ns1.google.com.
TXT
CNAME

Flags

SSL/TLS

Issuer: CN=WR2,O=Google Trust Services,C=US

Expiry: 2026-05-18T18:19:43+00:00 (59 days)

TLS Version: TLSv1.3

Wildcard: Yes

Risk Flags

Technology Stack

gws

Security Headers

HeaderValue
content-security-policy-report-onlyobject-src 'none';base-uri 'self';script-src 'nonce-0QXxUpOZgilLaGYS3tvoKA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp
x-xss-protection0
x-frame-optionsSAMEORIGIN

Findings

Attack Surface Map

Internal links: 8 | External links: 1

Forms: 1 | Scripts: 1

API-like routes: None detected

Admin paths: None detected

Wayback Findings

Historical URLRisk

Risk Summary

IDCategoryRiskFindingImpact
SSL-SAN-001 SSL/TLS MEDIUM SAN entries reveal internal/dev naming conventions. 5
HDR-001 Security Headers HIGH Content-Security-Policy header is missing 8
HDR-003 Security Headers HIGH Strict-Transport-Security header is missing 8
HDR-102 Security Headers LOW x-content-type-options header is missing 2
HDR-103 Security Headers LOW referrer-policy header is missing 2
HDR-104 Security Headers LOW permissions-policy header is missing 2
DNS-SPF-001 DNS MEDIUM SPF record missing or malformed. 5
DNS-DKIM-001 DNS LOW No DKIM hints discovered in queried TXT records. 2

Recommendations

  1. SSL-SAN-001 — Avoid exposing non-production hostnames in public certificates.
  2. HDR-001 — Implement a strict CSP policy tailored to required assets.
  3. HDR-003 — Enable HSTS with an adequate max-age.
  4. HDR-102 — Set a secure default for x-content-type-options.
  5. HDR-103 — Set a secure default for referrer-policy.
  6. HDR-104 — Set a secure default for permissions-policy.
  7. DNS-SPF-001 — Publish a valid SPF record to reduce spoofing risks.
  8. DNS-DKIM-001 — Ensure DKIM selectors are configured for active mail domains.

Appendix

Raw Subdomains: 244

Raw DNS A Records: 142.251.222.206

Historical Subdomains:

Non-Security Headers

HeaderValue
dateFri, 20 Mar 2026 05:48:55 GMT
expires-1
cache-controlprivate, max-age=0
content-typetext/html; charset=ISO-8859-1
reporting-endpointsdefault="//www.google.com/httpservice/retry/jserror?ei=x9-8ad77LIf2seMP8-yxuQI&cad=crash&error=Page%20Crash&jsel=1&bver=2405&dpf=IyEo2Kat1ZmqnVAO15MkhmK9ZswHwWUDSK_1H6OL7uA"
accept-chSec-CH-Prefers-Color-Scheme
p3pCP="This is not a P3P policy! See g.co/p3phelp for more info."
content-encodinggzip
servergws
set-cookie__Secure-BUCKET=CLkF; expires=Wed, 16-Sep-2026 05:48:55 GMT; path=/; domain=.google.com; Secure; HttpOnly
alt-svch3=":443"; ma=2592000,h3-29=":443"; ma=2592000
transfer-encodingchunked