47 comments

  • pimterry1 day ago
    For the desperate people whose tests all just broke, I have a page on my public endpoint testing server that exactly reproduces the classic design: <a href="https:&#x2F;&#x2F;example.testserver.host&#x2F;" rel="nofollow">https:&#x2F;&#x2F;example.testserver.host&#x2F;</a>. You can just use update the URL and go back to blissful ignorance.<p>Also open-source and self-hostable: <a href="https:&#x2F;&#x2F;github.com&#x2F;httptoolkit&#x2F;testserver" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;httptoolkit&#x2F;testserver</a>. Lots of other endpoints too, full docs here: <a href="https:&#x2F;&#x2F;testserver.host&#x2F;" rel="nofollow">https:&#x2F;&#x2F;testserver.host&#x2F;</a>
    • Cthulhu_1 day ago
      If you do have tests relying on it... stop it:<p>&gt; This is not a service; avoid relying on it for testing and monitoring purposes.
      • zahlman20 hours ago
        Before this submission, it genuinely never occurred to me that people would actually have tests that rely on example.com being up, let alone depend on its content.
        • n8m817 hours ago
          Same, and now I’m grinning ear to ear!
      • smashed1 day ago
        Opus 5.5 in Claude code added a unit test checking DNS and internet access using example.com as the target on a project I&#x27;m building yesterday. It&#x27;s an agent sandbox (I know, yet another), so the call was expected to fail, but still... It should have at least targeted a captive portal endpoint or a project owned domain.<p>I caught it in review but thousands of others won&#x27;t.<p>That ship has sailed I would say.
        • nemomarx1 day ago
          If it breaks in those thousands of projects, that will be an important lesson to review your agents more carefully. So a net win?
          • vikramkr23 hours ago
            More likely the agents will fix it as fast as they made it and people will continue not caring so much about reviewing what agents are doing for cases where they don&#x27;t care so much (which is a lot of cases)
      • SamuelAdams1 day ago
        So is wrong to use captive.apple.com for tests as well? It&#x27;s nice to know your network can reach the internet and these pages are generally fairly reliable.<p>[1]: <a href="https:&#x2F;&#x2F;captive.apple.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;captive.apple.com&#x2F;</a>
        • TowerTall23 hours ago
          A HTTP request for <a href="http:&#x2F;&#x2F;www.msftncsi.com&#x2F;ncsi.txt" rel="nofollow">http:&#x2F;&#x2F;www.msftncsi.com&#x2F;ncsi.txt</a> returning 200 OK and the text Microsoft NCSI. This is the url windows has been using for decades to determine if the device is online. It is highly reliable.
        • lxgr22 hours ago
          These pages are unfortunately getting special treatment from quite a few networks these days, among other things to avoid iOS users getting stuck in a loop of trying to connect, and getting disconnected by the OS due to a &quot;non-working connection&quot; for local-only networks like in-flight entertainment systems.<p>It&#x27;s a shame that we don&#x27;t have any standards for the concerns of canonically testing Internet reachability and for authoritatively redirecting network users to a captive payment portal (without having to resort to ugly hacks that often break with TLS).
          • Ajedi3222 hours ago
            RFC8910, from 2020: <a href="https:&#x2F;&#x2F;www.rfc-editor.org&#x2F;rfc&#x2F;rfc8910.html" rel="nofollow">https:&#x2F;&#x2F;www.rfc-editor.org&#x2F;rfc&#x2F;rfc8910.html</a>
            • lxgr21 hours ago
              Woah, amazing! Do you know if any popular network stacks actually support it?<p>But even just having an RFC to yell about is great, thank you :)
        • nemomarx1 day ago
          If they say that it&#x27;s not intended as a reliable service for testing purposes it can&#x27;t be that reliable, and they might take it down or change the structure arbitrarily at any time, etc.<p>So yeah I would pick something simpler for a network access test probably?
        • patmorgan231 day ago
          Why not ping 8.8.8.8 or 1.1.1.1 or time.windows.com? Things that are actually designed to be highly available services
          • ceejayoz1 day ago
            Is there any reason to believe captive.apple.com is any less &quot;designed to be highly available&quot; than time.windows.com?<p>It&#x27;s a static page that every Apple device relies on saying only:<p><pre><code> &lt;HTML&gt;&lt;HEAD&gt;&lt;TITLE&gt;Success&lt;&#x2F;TITLE&gt;&lt;&#x2F;HEAD&gt;&lt;BODY&gt;Success&lt;&#x2F;BODY&gt;&lt;&#x2F;HTML&gt;</code></pre>
            • mixdup23 hours ago
              The only risk is that Apple hasn&#x27;t announced it as being reliable or promised to keep it up or the format the same in any way. They could 100% pull it out from under everyone, with modifications in their OSes prepared for the change
              • simondotau16 hours ago
                Also some captive portals fake&#x2F;emulate responses from this service.
          • encom22 hours ago
            1.1 is enough.<p><pre><code> ~$ ping -c1 1.1 PING 1.1 (1.0.0.1) 56(84) bytes of data. 64 bytes from 1.0.0.1: icmp_seq=1 ttl=56 time=7.89 ms --- 1.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min&#x2F;avg&#x2F;max&#x2F;mdev = 7.888&#x2F;7.888&#x2F;7.888&#x2F;0.000 ms</code></pre>
            • nhecker19 hours ago
              Thanks! I&#x27;d forgotten that 1.1 and 1.1.1 resolve. I&#x27;ll not infrequently ping 1.1.1.1.1 with overzealous typing. That will, alas, not resolve.
            • stavros16 hours ago
              When did this start working? Did they backport IPv6-style addressing, or did I just never know this?
        • 98codes19 hours ago
          Just don&#x27;t blame the user and&#x2F;or their internet service when the service you&#x27;re relying on inevitably goes down.
      • bevr133721 hours ago
        I have been naively using example.com in the browser. WHATWG URL throws if there is no origin when constructing the URL. Web apps that need to construct _just_ the pathname must go through this song and dance. `new URL(&quot;&#x2F;blah&quot;, &quot;<a href="https:&#x2F;&#x2F;example.com&quot;).pathname" rel="nofollow">https:&#x2F;&#x2F;example.com&quot;).pathname</a>` This isn&#x27;t relying on any external example.com service but I&#x27;m learning the lesson.
        • pseudohadamard13 hours ago
          I use amazon.com. Being able to ping some near-universally-available responder address doesn&#x27;t mean you&#x27;ve got general internet connectivity, which connecting to amazon.com is a good proxy for.
          • bevr133713 hours ago
            Interesting. I&#x27;m intending not to reach out it in my case. The goal was to find a safeISH default parameter when constructing a WHATWG URL only for its pathname.<p>I&#x27;ve seen google STUN servers used in production. Folks probably rely on unpkg too much to deliver their JS. Good to consider these failure modes.<p>If your service runs on AWS, reaching amazon dot com seems somewhat more reasonable an internal health check.
    • oneeyedpigeon1 day ago
      What kind of tests would this break? Aside from the advice on the page itself (which, iirc, is new anyway), i&#x27;m wondering why any testing would actually involve the contents of design of the page. Just a weird &#x27;sanity&#x27; check?
      • voidUpdate1 day ago
        People depend on all sorts of weird stuff working exactly as expected. <a href="https:&#x2F;&#x2F;www.hyrumslaw.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.hyrumslaw.com&#x2F;</a><p>As an example, depending on &quot;man -w&quot; not outputting anything to stderr: <a href="https:&#x2F;&#x2F;unix.stackexchange.com&#x2F;questions&#x2F;405783&#x2F;why-does-man-print-gimme-gimme-gimme-at-0030" rel="nofollow">https:&#x2F;&#x2F;unix.stackexchange.com&#x2F;questions&#x2F;405783&#x2F;why-does-man...</a>
        • madeofpalk1 day ago
          Our saas had an internal-use, undocumented, publicly accessibly but not publicly used (by us) health endpoint that included an internal version number.<p>We removed the version and a few customers complained we broke their stuff.
          • bonesss1 day ago
            I landed a massive database upgrade on a payroll system years ago, end-to-end standardization, cleanup, and improvement with a seamless rollout.<p>Our back clapping was interrupted by an angry customer phone call. One of our customers had gotten access to our internal schema and had a massive reporting setup in Access solving most of his needs.<p>I ended up converting his reports using some internal tools we had. Customers will grab anything to give them.<p>[<i>The caliber and depth of his reports were such I wish we would have bought them instead of making me spend months building out our own reports.</i>]
            • eru1 day ago
              &gt; [The caliber and depth of his reports were such I wish we would have bought them instead of making me spend months building out our own reports.]<p>Learning from customers is some of the best learning you can do. :)
            • sumtechguy19 hours ago
              I had one customer that managed to figure out which stored procs were tied to which reports we were using. Then he would deliberately break it in weird subtle ways them and call tech support &#x27;just to see how we would react&#x27;.
          • The API surface is what’s exposed, not just what’s documented.<p>This is probably an even more important principle in the age of LLMs.
      • BoxOfRain23 hours ago
        While not the same thing, I was once stung by a test failing because a dependency of a dependency decided on a minor version bump that foo@example.com wasn&#x27;t a valid email address.
        • ButlerianJihad13 hours ago
          &gt; foo@example.com wasn&#x27;t a valid email address<p>That&#x27;s an interesting case. Did you consider this a correct result?<p>On one hand, &lt;foo@example.com&gt; is a valid <i>hypothetical address</i> that can be used strictly in documentation. It is also syntactically valid, which is the best kind of valid. However, &lt;foo@example.com&gt; (and all its permutations) is an obviously <i>invalid actual address</i> if you&#x27;re trying to send email to it, or manipulate it in any real way on the Internet.<p>It&#x27;s a good sanity check, but quite pedantic. I can understand if you are validating some public input form, where people are likely to put fake email addresses, and you don&#x27;t want someone knowingly filling in &lt;blah@example.com&gt; because you also know, <i>a priori</i> it&#x27;s a fake, and it will waste your time validating or trying to send to it.
          • BoxOfRain6 hours ago
            Yeah it&#x27;s an interesting one, I guess at some point a previous dev had chosen it on the fly and thought nothing of it - I didn&#x27;t think anything of it either until it suddenly failed! I would agree in hindsight the newer behaviour in the library is the correct one, it was just a surprise.
      • Topfi1 day ago
        Probably akin to: <a href="https:&#x2F;&#x2F;xkcd.com&#x2F;1172&#x2F;" rel="nofollow">https:&#x2F;&#x2F;xkcd.com&#x2F;1172&#x2F;</a>
        • cbm-vic-201 day ago
          I knew what this was before clicking on the link, but for a lot of people, it may be a 1053.
    • wildzzz23 hours ago
      One of the critical things I use example.com for is triggering wifi login portals as it doesn&#x27;t not use SSL. Certificate pinning and all that fancy stuff has made it so the browser has an absolutely awful time figuring out what to do when <a href="https:&#x2F;&#x2F;google.com" rel="nofollow">https:&#x2F;&#x2F;google.com</a> does not present itself as the same host it was earlier.
      • pimterry23 hours ago
        Same server also has an endpoint for that: <a href="http:&#x2F;&#x2F;no-tls.testserver.host" rel="nofollow">http:&#x2F;&#x2F;no-tls.testserver.host</a>. Sends RST for any attempted TLS connections, so clients always fall back to plain HTTP.<p>Also as a _long_ list of other specialist TLS endpoint configurations if you&#x27;re interested, which can be arbitrarily combined, see <a href="https:&#x2F;&#x2F;testserver.host&#x2F;#tls-endpoints" rel="nofollow">https:&#x2F;&#x2F;testserver.host&#x2F;#tls-endpoints</a>.<p>That gives neat tricks like <a href="https:&#x2F;&#x2F;tls-v1-2--expired--incomplete-chain--http2.testserver.host&#x2F;" rel="nofollow">https:&#x2F;&#x2F;tls-v1-2--expired--incomplete-chain--http2.testserve...</a>: only accepts TLS 1.2, then sends an expired certificate but fails to send the intermediate cert for the chain (so the client must infer it) and then negotiates HTTP&#x2F;2 for the connection on top. Fun!
      • willismonroe23 hours ago
        I like using <a href="http:&#x2F;&#x2F;neverssl.com&#x2F;" rel="nofollow">http:&#x2F;&#x2F;neverssl.com&#x2F;</a> for that... easy to remember (although I guess example.com was as well).
    • skrtskrt19 hours ago
      Do you do any sort of rate-limiting to stop people&#x2F;bots from hammering it (accidentally or otherwise)? Or do you just let it fall over under load.
      • pimterry6 hours ago
        Currently no rate limiting, I might if I have issues in future, but right now it&#x27;s vastly overpowered for the traffic and extremely cheap to run.<p>If you want to hit it hard, or you just want to avoid any risk of limits in future, it&#x27;s a one-liner to host it yourself with Docker: `docker run --rm -it -p 3000:3000 httptoolkit&#x2F;testserver`, then open <a href="http:&#x2F;&#x2F;example.localhost:3000&#x2F;" rel="nofollow">http:&#x2F;&#x2F;example.localhost:3000&#x2F;</a>. Advanced config options for CAs etc are in the GitHub README.
    • simoncion1 day ago
      &gt; For the desperate people whose tests all just broke...<p>The web page at example.com is maintained as a courtesy by IANA in order to explain the purpose of the example.com domain to wayward humans.<p>In the nomenclature of RFC 2119, one MUST NOT design computer systems that rely on the correct operation of an HTTP server at that domain. [0] Plus, it&#x27;s <i>_really_</i> rude to pound on a small-scale service being provided as a courtesy... go hit the home page of a tech megacorp (such as Microsoft or Google) or the status page for a major CDN (such as Cloudflare or Akamai) instead!<p>[0] I expect that <i>someone</i> here will want to pop up with a &quot;gotcha&quot; where they say something like &quot;Oh, but IANA&#x27;s email says that automated use is strongly recommended against, rather than <i>prohibited</i> and besides, they can&#x27;t actually stop me from doing it!&quot;. To that, I reply &quot;Sure, and standards-writers can&#x27;t <i>actually</i> stop implementers that do the profoundly antisocial thing and do the things they MUST NOT. As any adult who&#x27;s been paying attention to the world around them throughout their lives knows, there&#x27;s only <i>so</i> much you can do to stop people who are <i>very</i> determined to be enormous assholes.&quot;.
      • Nnnes1 day ago
        &gt; the status page for a major CDN (such as Cloudflare or Akamai)<p>Would you settle for any old static page served by Cloudflare? For instance, example.com? <a href="https:&#x2F;&#x2F;bgp.tools&#x2F;dns&#x2F;example.com" rel="nofollow">https:&#x2F;&#x2F;bgp.tools&#x2F;dns&#x2F;example.com</a>
        • mixdup23 hours ago
          That they&#x27;ve put it behind Cloudflare doesn&#x27;t mean it&#x27;s &quot;served by Cloudflare&quot;<p>Maybe Cloudflare gives them a good rate, or is donating service, but it&#x27;s also possible or even likely that IANA is just using Cloudflare as a vendor, and therefore is paying for all the traffic, which is why they don&#x27;t want people relying on it or hammering it all the time
        • simoncion1 day ago
          <p><pre><code> In the nomenclature of RFC 2119, one MUST NOT design computer systems that rely on the correct operation of an HTTP server at [example.com.] Plus, it&#x27;s *_really_* rude to pound on a small-scale service being provided as a courtesy.</code></pre>
      • lxgr22 hours ago
        &gt; go hit the home page of a tech megacorp (such as Microsoft or Google)<p>Much too big for metered data, full of ads, and importantly they all mandate HTTPS these days, which breaks my use case of forcing a captive portal on paid&#x2F;login-gated Wi-Fi to render.<p>example.com is (unfortunately for the IATA) the almost perfect &quot;can I reach the Internet&quot; service: It&#x27;s unlikely to go away, supports HTTP, is fairly small, easy to remember, and I don&#x27;t care if a captive portal poisons my DNS cache with a fake response temporarily.
        • simoncion7 hours ago
          &gt; Much too big for metered data, full of ads, and importantly they all mandate HTTPS...<p>You&#x27;ll be pleased to learn that nearly (actually?) all major sites that mandate HTTPS provide an HTTP redirect response when hit on port 80. You can&#x27;t help but agree that a 30X with no body is <i>way</i> less data than pulling down even just the HTML parts of example.com.<p><pre><code> curl -v http:&#x2F;&#x2F;cloudflarestatus.com * Trying [2600:1901:0:4a3b::]:80... * Host cloudflarestatus.com:80 was resolved. * IPv6: 2600:1901:0:4a3b:: * IPv4: 35.201.124.30 * Established connection to cloudflarestatus.com (2600:1901:0:4a3b:: port 80) from [REDACTED] port [REDACTED] * using HTTP&#x2F;1.x &gt; GET &#x2F; HTTP&#x2F;1.1 &gt; Host: cloudflarestatus.com &gt; User-Agent: curl&#x2F;8.22.0 &gt; Accept: *&#x2F;* &gt; * Request completely sent off &lt; HTTP&#x2F;1.1 301 Moved Permanently &lt; Cache-Control: private &lt; Location: https:&#x2F;&#x2F;www.cloudflarestatus.com:443&#x2F; &lt; Content-Length: 0 &lt; Date: Wed, 07 Oct 2026 08:07:34 GMT &lt; Content-Type: text&#x2F;html; charset=UTF-8 &lt; * Connection #0 to host cloudflarestatus.com:80 left intact </code></pre> And in regards to &quot;DNS cache poisoning&quot;, approximately no one cares about hitting the status page of a major CDN. ;)<p>&gt; ...which breaks my use case of forcing a captive portal on paid&#x2F;login-gated Wi-Fi to render.<p>Huh? Captive portals -especially ones that redirect to payment collection systems- are served up by infrastructure that either you control or that you&#x27;ve arranged with someone else to operate. If you&#x27;re paying IANA to operate your captive portal, and they&#x27;ve made the choice to hit example.com:443, then that&#x27;s <i>their</i> -odd- choice... but I bet that&#x27;s not who&#x27;s operating your captive portal.<p>If you&#x27;ve designed a captive portal system that <i>depends</i> on a functioning HTTPS server at example.com, you <i>desperately</i> need to go back and redesign it... if for no <i>other</i> reason than to -given your concern about metered data- massively reduce your own bandwidth bills.
          • lxgr4 hours ago
            &gt; You&#x27;ll be pleased to learn that nearly (actually?) all major sites that mandate HTTPS provide an HTTP redirect response when hit on port 80. You can&#x27;t help but agree that a 30X with no body is way less data than pulling down even just the HTML parts of example.com.<p>My browser (in which I do these ad hoc connectivity tests) does in the end pull down the redirection target including all resources. Not fun on a slow and metered network such as in-flight Wi-Fi.<p>On top of that, sites like google.com just haven&#x27;t worked as well for me in the past in these situations. Not sure why, but I suspect they just use all the latest security extensions like HSTS etc., making it hard to access the non-secure version once that&#x27;s cached. Could also be some heuristics in my browser.<p>&gt; And in regards to &quot;DNS cache poisoning&quot;, approximately no one cares about hitting the status page of a major CDN. ;)<p>What I mean is the captive portal poisoning <i>my</i> DNS cache, and thereby rendering e.g. google.com unusable for me even after authenticating&#x2F;purchasing access. I don&#x27;t really care if example.com redirects me to the in-flight Wi-Fi portal; in fact, that&#x27;s usually what I want it to do when losing connectivity.<p>&gt; Huh? Captive portals -especially ones that redirect to payment collection systems- are served up by infrastructure that either you control or that you&#x27;ve arranged with someone else to operate.<p>I (unfortunately?) don&#x27;t control the payment systems or captive portal implementation of the airlines I fly with. I&#x27;m just sharing my experience in practically mitigating their various deficiencies as a user.
    • egorfine1 day ago
      I think we&#x27;re on the verge of a big disruption coming for the example.com&#x27;s business. I can see a SaaS opportunity. We can use AI to speed up time to market.<p>&#x2F;s
      • Cthulhu_1 day ago
        example.com-as-a-service, although XaaS is no longer hip so now it&#x27;ll be example.ai, an AI that will generate an example.com style landing page using frontier AI models. $20 &#x2F; month for the beginner plan (100 requests&#x2F;month), contact us for pricing.
      • aghuang1 day ago
        Enterprise ready. Coming soon in Q4.
  • selcuka1 day ago
    I&#x27;m wondering how many automated tests this change broke.<p>Yes, I know it&#x27;s not the example.com&#x27;s fault, and it&#x27;s a side effect of Hyrum&#x27;s Law:<p>&gt; This is not a service, avoid relying on it for testing and monitoring purposes.<p>Don&#x27;t we all have a few fragile tests?
    • teraflop1 day ago
      That&#x27;s an excellent reason to change the page design occasionally, so that people learn not to rely on it (the hard way if necessary).
      • hanibrel1 day ago
        Go a step further and randomize it. Different page at every request.
        • eru1 day ago
          But then people will rely on the randomness to pick their quicksort pivots or something like that.
          • dilap1 day ago
            Maybe, but in any case far fewer than will rely on a fixed page. I think very clearly it&#x27;d be a net-pain lowering move for example.com to randomize the results a bit, if they felt like it.
            • danielmeskin17 hours ago
              ~~I feel like that would probably meaningfully increase the amount of compute necessary to serve the website. As it were it’s likely static html, but any randomness would have to rely on a server side operation for each request and couldn’t be cached.~~<p>I went and checked and in fact it is already serving a script s.js so I guess you’re right!
    • brookst1 day ago
      If 1.1.1.1 ever stops responding to pings…
      • JdeBP1 day ago
        … then you&#x27;ll be back in the world before CloudFlare set up its public DNS service, which is also the world where taking over 1.1.1.1 in the first place came at the price of having to measure how many people had ignorantly or lazily put four ones into somewhere that they had to fill in an IP address, and how much bogus and positively risky (to them) traffic there was being caused by people just thinking &#x27;I will just use 1.1.1.1, which is not a real IP address.&#x27;.<p>Just before COVID, a random unidentifiable person reported that 1.1.1.1 saw 60Mb&#x2F;s of ICMP echo traffic. When APNIC first experimented with making it a valid network almost a decade before that, it was being sent 50Mb&#x2F;s of general IP traffic. Amusingly, a side-effect of what CloudFlare has done is that it has stopped all of that traffic leaving the edges of the Internet, and funnelling in to one big central place.<p>There are those who remember the risks of &#x27;just use 1.1.1.1&#x27; and how the people who did that used be characterized as &#x27;bad Internet citizens&#x27;. The ServerFault answer (q.v.) is from 2011.<p>* <a href="https:&#x2F;&#x2F;labs.ripe.net&#x2F;author&#x2F;franz&#x2F;pollution-in-18&#x2F;" rel="nofollow">https:&#x2F;&#x2F;labs.ripe.net&#x2F;author&#x2F;franz&#x2F;pollution-in-18&#x2F;</a><p>* <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=19335833">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=19335833</a><p>* <a href="https:&#x2F;&#x2F;serverfault.com&#x2F;a&#x2F;339782" rel="nofollow">https:&#x2F;&#x2F;serverfault.com&#x2F;a&#x2F;339782</a>
        • mitxela23 hours ago
          That was part of Cloudflare&#x27;s pitch to take over the 1.1.1.1 address block - that Cloudflare had the relatively unique ability to handle all the junk traffic as anycast nearby to any source, not overloading the wider internet.
      • anyfoo1 day ago
        I don’t use this one, because I remember when long, long ago it was in some random IP address block belonging to someone, and this particular address didn’t reply to ping.<p>Likely for good reason, even back then there would have bound to be lots of misconfigured endpoints trying to access 1.1.1.1, so just blocking it at the earliest point possible kept at lot of the annoyance away. Nowadays, it’s an anycast address, so it’s slightly less bad.<p>But for me, old habits die hard.
      • folmar1 day ago
        I&#x27;ve already seen a couple of train hotspots respond locally to pings directed at 1.1.1.1 and 8.8.8.8, apparently in effort to convince devices that they are on a good network event if the internet itself is broken due to being in the tunnel.
      • tesnorindian1 day ago
        If 1.1.1.1 fails, I will try 8.8.8.8
      • Toslink10 hours ago
        [dead]
      • &gt; 1.1.1.1<p>Pinging such an address is inherently a troublesome practice. This address, like many public DNS servers (resolvers as well as root and authoritative ones), uses &quot;anycast&quot; routing methodology.<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Anycast" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Anycast</a><p>Pinging an anycast address will yield a cornucopia of different results. Of course, people who naïvely &quot;ping&quot; a recognizable or easy-to-type IPv4 address get what they deserve, especially when they enshrine it into software, unit tests, or the LLM coughs up such tokens on their behalf.<p>Fundamentally, the question is &quot;what do you really want to test?&quot; by pinging a particular IPv4? Do you want to test Layer 3 connectivity? Test your ISP&#x27;s backbone and connectivity? Test only your upstream router? Test the existence of ICMP in your stack and theirs?<p>... the possibilities are endless. Your router can do anything. Ping zombo.com.
        • zettabomb1 day ago
          Why is pinging an anycast address an issue? Most people, myself included, ping addresses like 1.1.1.1 to check for internet connectivity. It&#x27;s a perfectly valid check, you don&#x27;t need a fine grained test all the time. If it fails, then I go looking in detail. Most of the time it will pass.<p>Pinging a domain name could fail for a variety of other reasons, particularly if it&#x27;s not a reliable site. Cloudflare&#x27;s business is being reliable; few sites would be a better choice.
          • The problem is pinging 1.1.1.1 can end up hitting a really really close-by server. You could be having ISP issues and 1.1.1.1 could end up being closer to you than the issue is, so you get okay ping results but still unable to access resources on the other side of the issue
            • zettabomb1 day ago
              You&#x27;re thinking far too hard. If I can ping 1.1.1.1, it means traffic is flowing from inside my network, to outside my network. I&#x27;m not going to diagnose my ISP&#x27;s issues, that&#x27;s their job, I just need to know that it&#x27;s not <i>my</i> problem.
            • mcapodici1 day ago
              Most of my connection issues are between the street and my computer, I don&#x27;t think Cloudflare got there. Yet.
            • account421 day ago
              You can have routing issues that alow some IP addresses to work and others not, anycast or not. It&#x27;s not supposed to be a comprehensive connectivity report, just a sanity check that the intertubes are connected at all.
            • brookst1 day ago
              Of course. Ping 1.1.1.1 is not a test that everything is working great. DNS could be dead. IPv6 could be black holed.<p>But it’s a good “is traffic making it past my router with some semblance of connectivity” sanity check, and easier than finding the provider-side next hop address.
          • The corollary is that when it fails, you&#x27;ve no idea what failed, or how it failed, or if the &quot;fail&quot; is even valid or relevant, because you&#x27;re abusing a service that isn&#x27;t designed for you and isn&#x27;t fit for use. So if it succeeds, you really don&#x27;t know, because perhaps your train&#x27;s WiFi router is responding with a spoofed IPv4 address while it goes through the Chunnel. And if it fails, you really don&#x27;t know, because you DGAF about learning formal troubleshooting methods and couldn&#x27;t be arsed to find out your upstream router&#x27;s address in order to simply isolate your PING to a singular link, rather than relying on complex routing rules, especially those introduced by &quot;anycast&quot;. And perhaps you can manually dig in when your manual checks fail, but your AI agent or automated script DGAF about your nuanced knowledge that 1.1.1.1 isn&#x27;t your upstream router; in fact it&#x27;s not yours at all and has nothing to do with your network topology. But at least it looks elegant.
            • brookst2 hours ago
              Is there any single ping test that correctly diagnoses all of the possible issues you raise?
        • QuantumNomad_1 day ago
          I ping 1.1.1.1 to see if my internet is working or not after a couple of websites don’t load. I reboot the router. I keep the terminal where I’m pinging 1.1.1.1 open until I start seeing responses and then I know my internet is back. Then I continue my web browsing and other online activities.
          • M4v3R1 day ago
            I’m so lazy I just type `ping 1.1` and it still works (apparently 1.0.0.1 is also always up).
            • justinator1 day ago
              It&#x27;s much faster just pinging 127.0.0.1 for such purposes. Try it!
              • JdeBP1 day ago
                In the spirit of M4v3R&#x27;s post, that should be 127.1 . (-:
                • jasongill19 hours ago
                  ping 0 would save you 3 bytes!
          • frizlab1 day ago
            Same
        • ffaccount21 day ago
          Fun fact, ping is the standard windows way to wait a given number of seconds[0]. You&#x27;re supposed to ping 127.0.0.1, but I saw a lot of scripts pinging 1.1.1.1 or 8.8.8.8<p>[0]: <a href="https:&#x2F;&#x2F;stackoverflow.com&#x2F;questions&#x2F;1672338&#x2F;how-to-sleep-for-five-seconds-in-a-batch-file-cmd#1672375" rel="nofollow">https:&#x2F;&#x2F;stackoverflow.com&#x2F;questions&#x2F;1672338&#x2F;how-to-sleep-for...</a>
          • itintheory1 day ago
            &gt; standard windows way<p>The thread you linked to suggests &#x27;timeout&#x27;[0]<p>[0] <a href="https:&#x2F;&#x2F;learn.microsoft.com&#x2F;en-us&#x2F;windows-server&#x2F;administration&#x2F;windows-commands&#x2F;timeout" rel="nofollow">https:&#x2F;&#x2F;learn.microsoft.com&#x2F;en-us&#x2F;windows-server&#x2F;administrat...</a>
            • fingerlocks19 hours ago
              Scroll down. Ping is preferred because timeout is buggy
        • alibarber1 day ago
          Any IP address could one day change where it is being announced from, or become anycast, or change the number of hops between you and it.<p>I don&#x27;t think people are using `ping 1.1.1.1` as a stable API, rather as a yes&#x2F;no test of the network segment that they control.
        • vlyan1 day ago
          &gt;Of course, people who naïvely &quot;ping&quot; a recognizable or easy-to-type IPv4 address get what they deserve<p>Look what happened because of what you did, what it led to! Two microservices are in critical condition and you&#x27;re laughing. You&#x27;re laughing.
        • Hikikomori1 day ago
          Why would it matter?
          • <a href="https:&#x2F;&#x2F;utcc.utoronto.ca&#x2F;~cks&#x2F;space&#x2F;blog&#x2F;tech&#x2F;InternetPathsMayVaryByPort" rel="nofollow">https:&#x2F;&#x2F;utcc.utoronto.ca&#x2F;~cks&#x2F;space&#x2F;blog&#x2F;tech&#x2F;InternetPathsM...</a>
            • Hikikomori1 day ago
              Don&#x27;t see why this is relevant, ping is not traceroute or http. If you just want to test if packets can leave your network then its a good enough test and anycast doesn&#x27;t affect that.
        • lirolero1 day ago
          [dead]
    • chews1 day ago
      that&#x27;s a really good point I&#x27;d not considered but if you just hash the response and the followups remain consistent (they do in this case)... you&#x27;re gonna do just fine.
  • jamdav161 day ago
    &gt; there&#x27;s a gradual opacity transition<p>Looks like they removed this and instead just show all languages with no CSS animation now.
    • kijeda1 day ago
      Yes, the revised version that alternated through the translations was posted a week ago on Monday. It was revised to no longer do that on Friday based on reasonable feedback that it wasn&#x27;t the best idea for accessibility. Now all the translations are presented together, but your preferred language will be bumped to the top based on your browser language preference.
    • ChrisRR1 day ago
      Oh that&#x27;s good, I had that complaint when it first changed. It was difficult to read the entire chunk of text before it transitioned to a different language. And then who knows how long it took to loop back round to english
    • johnnyanmac1 day ago
      Aww, I was wondering if I was just looking at an older version. How disappointing. But I suppose, unsurprising given the conversation here. I&#x27;m sure such transitions would be bringing a surprising amount of instrumentation down.<p>It still probably is as it is now. But there&#x27;s better arguments to support localization than transitions.
      • p-t1 day ago
        For some reason the localization still requires javascript... (I&#x27;m pretty sure the transition could have been done in just CSS as well)
        • thaumasiotes1 day ago
          &gt; For some reason the localization still requires javascript<p>Well, no. The purpose of the redesign is to move as much of the page content as possible into an external javascript file. There&#x27;s no question of what parts of the page <i>require</i> javascript; the question is what parts of the page can be moved into javascript.
  • sea-gold1 day ago
    Discussed here a few days ago: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49915060">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49915060</a>
    • dang1 day ago
      Thanks! Macroexpanded:<p><i>IANA&#x27;s email about why example.com changed</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49915060">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49915060</a> - Sept 2026 (20 comments)
    • frogulis1 day ago
      And the &quot;statement&quot; in this article is the text from that email, disingenuously edited. I&#x27;m not sure why, but it rubs me the wrong way.
      • creatonez1 day ago
        What makes you think it&#x27;s edited?
        • frogulis1 day ago
          Yeah apologies, bad wording on my part. I really just meant the removal of the opening line which made it clear that it was a correspondence: &quot;I am happy to try and answer any questions you have.&quot;
      • The hilariously ironic thing is that Dunk, a Google Engineer, went out of their way to make a hyperlink of &quot;example dot com&quot; so that people could tap and visit the site, even where Davies&#x27; email specifically reiterates that the domain is for <i>documentation purposes only</i> and nobody should ever be actually visiting the site!<p>McCarthy of DebugBear clearly noticed this admonition and perhaps the mistake as well, because they have carefully highlighted &quot;example.com&quot; without linking to it, although they apparently have <i>visited the site</i> in order to copy and cite screenshots and unpack the CSS, and describe an extensive history of it.
  • The page mentions example.com 14 times and not a single one is a link
    • ndriscoll1 day ago
      You also failed to make it a link. In order to automatically create links, you should use the format <a href="https:&#x2F;&#x2F;example.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;example.com&#x2F;</a> with scheme included. So in your case you&#x27;d do <a href="https:&#x2F;&#x2F;example.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;example.com&#x2F;</a>
      • Guess I am part of the problem. Thank you for the link kind stranger.
      • mitxela23 hours ago
        Thanks. But you also forgot to include the link. You used the example domain <a href="https:&#x2F;&#x2F;example.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;example.com&#x2F;</a> but forgot to substitute the correct address of the website. In this case that would be <a href="https:&#x2F;&#x2F;example.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;example.com&#x2F;</a>
    • Outrageous. How will people ever find it?!
      • oneeyedpigeon1 day ago
        By typing it or copy+pasting it, which is much more time consuming and much less convenient.<p>(I actually tried the select, share [sic], open in browser route, but for some reason I only saw opera as an option, not chrome, the browser I actually use for everything. Links still rule.)
        • user1928222 hours ago
          For me, it&#x27;s double click and cmd-U which launches the Search with Google service on macOS.
        • lirolero1 day ago
          [dead]
    • kccqzy1 day ago
      That’s because they are in code blocks. Oh I hate people who abuse code blocks for things that aren’t code. Domain names are not code. Your browser doesn’t display URLs in a monospace coding font. Stop this abuse.
  • VVilhelmsen1 day ago
    This has rendered my usecase for example.org worthless. I used this website several times per week to clean my glasses as it provided a nearly completely white website - optimal for allowing me to spot smudges on my glasses. It is now black by default for me, or grey.<p>I am devastated.
    • Do the kids not know about about:blank?
      • pwython22 hours ago
        Wouldn&#x27;t help OC if their system is dark mode.
        • kbolino18 hours ago
          It&#x27;s not as easy to remember, but you can also do:<p><pre><code> data:text&#x2F;html,&lt;body%20bgcolor=&quot;white&quot;&gt;</code></pre>
        • bigstrat200318 hours ago
          The elites don&#x27;t want you to know this, but you can disable dark mode in your settings. I actually use light mode every day, but keep that between us.
    • PurpleRamen1 day ago
      whitedisplay.com can be your new friend. Just select the preferred color.
      • ceejayoz1 day ago
        &gt; Just select the preferred color.<p>I kinda expected this to be Ford Model T &quot;Any color the customer wants, as long as it’s black&quot; joke.
    • jmaw1 day ago
      Good old Hyrum&#x27;s Law
    • skipants1 day ago
      Relevant xkcd: <a href="https:&#x2F;&#x2F;xkcd.com&#x2F;1172&#x2F;" rel="nofollow">https:&#x2F;&#x2F;xkcd.com&#x2F;1172&#x2F;</a>
    • anigbrowl15 hours ago
      Just expand the HN comment box. Some of my greatest bangers started out with a large blank canvas that I then felt compelled to fill.
  • zahrevsky1 day ago
    &gt; There is no requirement there is a HTTP service present on the host in order to fulfill its purpose, we just operate it as a courtesy.<p>I guess this is also done to prevent bad actors from abusing the fact that this domain is hit by people who might not know what they&#x27;re doing (the ones copy-pasting code without reading it)
    • zamadatix1 day ago
      More the DNS and DNSSEC and the like. Whether or not there is actually an HTTP server responding is irrelevant to whether or not those securely point anywhere but a malicious system.
    • jgx01 day ago
      Yeah there’s definitely a lot of sensitive data that gets sent to the domain just because of people not changing configs
    • krackers1 day ago
      I don&#x27;t understand, what risk would there be if they chose _not_ to serve a site?
      • dylan6041 day ago
        Someone else could
        • altermetax1 day ago
          No, because they can&#x27;t register the domain, it&#x27;s already taken, no matter if a web service is running behind it or not
          • dylan6041 day ago
            It&#x27;s just part and parcel of owning the domain. It&#x27;s one thing to have the domain, but the next step is offering an active website so that people that actually put that domain in a browser can see it&#x27;s a placeholder.
            • notpushkin1 day ago
              This is not the point discussed here.<p>&gt; Someone else could<p>When you own a domain, you can choose not to serve anything on HTTP&#x2F;S, and still nobody can come and serve some other website on your domain, because they don’t control the DNS records.
            • valleyer1 day ago
              Why HTTP? Why not SSH? When I try to connect to it that way, I get no response. How will I know it&#x27;s a placeholder?
              • pests1 day ago
                HTTP is used by billions of people while SSH is not. It should be pretty apparent. Why do people answer my phone calls and texts but everyone is ignoring my smoke signals?
                • dofm1 day ago
                  What <i>is</i> the smoke signal for “we’ve been trying to reach you about your car’s extended warranty“?
  • philo231 day ago
    I appreciate that there must be a lot of traffic hitting this web server so maybe every little bit of savings counts, but I kinda wish the HTML wasn&#x27;t so heavily compressed.<p>I remember getting my start with web development by simply reading the source code of sites I found interesting and trying to recreate them. example.com isn&#x27;t exactly very interesting but it feels like compressing the HTML isn&#x27;t in the spirit of things either.<p>On a side note I&#x27;d love to see how complicated (or maybe simple) the hosting setup for this site actually is behind the scenes.
    • itintheory1 day ago
      It&#x27;s static content in Cloudflare CDN. Seems unlikely that many requests actually hit any kind of origin server. If I were building something like this the origin would be Cloudflare R2 (or similar) object storage, with a very long cache lifetime. Nothing to update, nothing to maintain.<p>But beyond that, what are you referring to as compression? When I look at the source I see a VERY short easily human-readable HTML page. It doesn&#x27;t have newlines, but I wouldn&#x27;t consider that compression. It also references a short, but non-obfuscated javascript file at <a href="https:&#x2F;&#x2F;example.com&#x2F;s.js" rel="nofollow">https:&#x2F;&#x2F;example.com&#x2F;s.js</a> .<p>Maybe I misunderstood what you&#x27;re referring to...
  • slipfold1 day ago
    Here is some context: <a href="https:&#x2F;&#x2F;kimdavies.com&#x2F;being-exemplary" rel="nofollow">https:&#x2F;&#x2F;kimdavies.com&#x2F;being-exemplary</a>
  • kjellsbells1 day ago
    I&#x27;m not sure I believe that IANA&#x27;s goal of reducing serving costs is met by a site where each letter is wrapped in a &lt;span&gt;...<p>separate shower thought: Microsoft have used contoso.com as the example domain in their docs for 25+ years. I bet the logs for that domain are absolutely wild.
  • skrtskrt16 hours ago
    &gt; Conclusion<p>&gt; Looking at the visual timeline, we can see that changes to example.com happen sporadically.<p>I am glad to see someone else struggling to write a non-awkward conclusion to a technical blog. I always feel like I am just restating the obvious to the point that it is borderline insulting to the reader. But I don&#x27;t have much more to say and removing the conclusion makes it seem like the whole thing just fell off a cliff.
  • hannob19 hours ago
    Kinda interesting that this is getting so much attention.<p>Ultimately, the example.com domain is just there so you can use it in documentation or code examples. Your expectation about the actual example.com domain should basically be none at all, maybe with the exception that it&#x27;s hopefully not doing actively malicious things like serving malware or running a catchall mailbox feeding spammers.<p>Whatever HTML they server or if they serve anything at all... shouldn&#x27;t matter.
  • This is mine now! &lt;link rel=icon href=data:,&gt;
    • xigoi1 day ago
      I put this on all my websites that don’t have a favicon. I hate the default browser behavior of making a request to &#x2F;favicon.ico without being asked.
  • Lightbody1 day ago
    I’m curious… who hosts and controls this content? IANA? Never really considered this question until now…
    • jonah-archive1 day ago
      see <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=42705284">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=42705284</a> for some historic detail on this
    • notatoad1 day ago
      the &#x27;about&#x27; link on example.com sends you here <a href="https:&#x2F;&#x2F;www.iana.org&#x2F;help&#x2F;example-domains" rel="nofollow">https:&#x2F;&#x2F;www.iana.org&#x2F;help&#x2F;example-domains</a><p>which does appear to say that yes, IANA hosts this
  • danhite1 day ago
    So they made a prior tweak to reduce fetches of favicon.ico ( by link rel=&quot;icon&quot; href=&quot;data:,&quot; ) but why do they still serve the overlarge meaningless html page to requests for robots.txt ?!<p>Given that they have gotten spiked by automated requests lately, aka agents, wouldn&#x27;t this at least be respected by the big players?<p>Also, as they are using Cloudflare, wouldn&#x27;t a discussion (or a note from IANA or CF) about how they configured CF request rejection and how one should love CF&#x27;s flat rate static serving be appropriate?<p>Am I missing something?
    • etatester1 day ago
      It&#x27;s quite sad to see incompetence at these levels. This is a static page that loads JS. They even inject styles via JS...
      • bmarch1 day ago
        It’s not incompetence they are intentionally doing as much as possible via javascript to reduce their bandwidth costs. This is because most access to the domain is automated (not using a browser, using curl etc) and doesn’t load javascript
        • explain1 day ago
          They use Cloudflare, which does not charge for bandwidth.
          • mitxela23 hours ago
            For free users. But cloudflare picks and chooses its free users.
  • certyfreak16 hours ago
    Looking at the timeline and UI changes, it seems that web interfaces are strongly shaped by the cultural tastes, conventions, and technological assumptions of their era.
  • gavino1 day ago
    Really funny coincidence, I noticed amazon wasn&#x27;t loading a couple hours ago. Thought it was my internet so went to example.com to check and noticed the redesign. Figured it was a while ago though.
  • tty4561 day ago
    It&#x27;s been about 10 years since I last saw this site and accidentally visited it a few days ago and thought &quot;I don&#x27;t remember it looking like this&quot;
  • Gualdrapo1 day ago
    &gt; Along with introducing multi-language support, the JavaScript code also inserts an SVG book icon.<p>Wait - using JS for dynamic content is understandable, but why using it for inserting a static SVG?
    • worg1 day ago
      Reducing egress bandwidth, if you have automated clients that don&#x27;t support JS you save precious bytes from being served by not embedding the SVG, which at example.com scale may be worth it
      • autoexec1 day ago
        Wouldn&#x27;t removing the pointless SVG image entirely save the most precious bytes from being served no matter if JS (or SVG) is supported or not?
        • schiffern1 day ago
          <p><pre><code> &gt;pointless SVG image </code></pre> Why aren&#x27;t we all eating inexpensive gruel instead of &quot;pointless&quot; food? Same reason.<p>It&#x27;s good to have a little color&#x2F;flavor&#x2F;spice in life.
          • account421 day ago
            Ah yes because bog standard corporate design is how you add color&#x2F;flavor&#x2F;spice in life.
            • schiffern1 day ago
              Judging by the reaction to one SVG, it&#x27;s the most they could do! Can you imagine if it was some <i>art nouveau</i> project instead?<p>Good for them, and it&#x27;s still better than nothing. Without it the page would almost looked broken it&#x27;s so bare.
              • account427 hours ago
                They could have left it as before. That design at least had the character of old infrastructure or an example website.
                • schiffern2 hours ago
                  They could have, and they did, for many years! But i18n is important, and including some tiny art was nice too. Life is short, so put some art in places where a Protestant wouldn&#x27;t. ;)<p>And if you visit with JS turned off, you get exactly what you&#x27;re asking for. This seems like a sensible compromise.<p>The SVG itself is pretty interesting, all of 355 bytes before compression! Prettified version below:<p><pre><code> &lt;svg viewBox=0,0,20,20 width=44 height=44 fill=currentColor aria- hidden=true&gt; &lt;path fill=none stroke=currentColor stroke-width=1.3 stroke-linejoin=round d=&quot;M6 4H3v12q 4 0 7 1.5-1-3.5-4-4.5V2q3.5 1 4 3v12.5q3-1.5 7-1.5V4q-4.5 0-7 1&quot;&#x2F;&gt; &lt;g transform=rotate(-6,13.6,8.3)&gt; &lt;path id=q d=&quot;M11.5 6.6h1.8v1.8l-1 1.6-.6-.3.8-1.3h-1z&quot;&#x2F;&gt; &lt;use href=#q x=2.4 &#x2F;&gt; &lt;&#x2F;g&gt; &lt;&#x2F;svg&gt;</code></pre>
    • hiccuphippo19 hours ago
      I wonder if it&#x27;s injecting both through javascript to minimize breaking people&#x27;s tests. Trying to reduce dealing with non-ascii characters and svg tags.
    • domh1 day ago
      Why does this site need JS at all? It appears to inject all of the other languages via client side JS. Why can&#x27;t they all just be served from the server?
      • TheCoelacanth16 hours ago
        To minimize their hosting costs. They get a large amount of automated traffic that won&#x27;t actually render the content, so moving as much content as possible out of the initial HTML document is more efficient.
    • afavour1 day ago
      Simple answer is the article is wrong, I tried it with disabled JS and still see the SVG.<p>The whole article reads like something put together with AI, so maybe it’s not too surprising.
      • zamadatix1 day ago
        I get nothing but a gray page with the following with JS disabled <a href="https:&#x2F;&#x2F;i.imgur.com&#x2F;81aYPeB.png" rel="nofollow">https:&#x2F;&#x2F;i.imgur.com&#x2F;81aYPeB.png</a> in Firefox via javascript.enabled set to false.
      • ajcp1 day ago
        You may want to check your settings again or clear you cache as there is definitely a `s.js`[0] file that inserts the `&lt;svg&gt;` element into the HTML DOM[1], which you can see does not contain the element itself.<p>0<p>```<p>var B = document.body, P, p; B.children[0].insertAdjacentHTML(&quot;afterend&quot;, &quot;&lt;p lang=ar dir=rtl&gt;هذا النطاق مُخصص للاستخدام في أمثلة التوثيق دون الحاجة إلى إذن. هذه ليست خدمة، يُرجى تجنب الاعتماد عليها لأغراض الاختبار والمراقبة.&lt;&#x2F;p&gt;&lt;p lang=zh&gt;该域名仅用于文档示例,无需获得许可。这并非一项服务,请勿将其用于测试和监控目的。&lt;&#x2F;p&gt;&lt;p lang=fr&gt;L’usage de ce domaine est réservé à des exemples de documentation, sans autorisation préalable. Il ne s’agit pas d’un service ; son utilisation à des fins de test ou de surveillance est à éviter.&lt;&#x2F;p&gt;&lt;p lang=ru&gt;Данный домен предназначен для использования в примерах документации без необходимости получения предварительного разрешения. Это не сервис; не рекомендуется его использование для тестирования и мониторинга.&lt;&#x2F;p&gt;&lt;p lang=es&gt;Este dominio está destinado al uso en ejemplos de documentación sin necesidad de permiso. Esto no es un servicio; evitar utilizarlo para realizar pruebas o monitoreos.&lt;&#x2F;p&gt;&lt;a href=<a href="https:&#x2F;&#x2F;iana.org&#x2F;help&#x2F;example-domains" rel="nofollow">https:&#x2F;&#x2F;iana.org&#x2F;help&#x2F;example-domains</a>&gt;Learn more&lt;&#x2F;a&gt;&quot;); P = [...B.querySelectorAll(&quot;p&quot;)]; P[0].lang = &quot;en&quot;; navigator.languages.some(l =&gt; p = P.find(p =&gt; p.lang == l.split(&quot;-&quot;)[0])); p = p || P[0]; B.prepend(p); B.insertAdjacentHTML(&quot;afterbegin&quot;, &#x27;&lt;style&gt;svg{display:block;margin:-2.75em auto 0;opacity:.55}p+p{font-size:.875em;opacity:.6}&lt;&#x2F;style&gt;&lt;svg viewBox=0,0,20,20 width=44 height=44 fill=currentColor aria-hidden=true&gt;&lt;path fill=none stroke=currentColor stroke-width=1.3 stroke-linejoin=round d=&quot;M6 4H3v12q4 0 7 1.5-1-3.5-4-4.5V2q3.5 1 4 3v12.5q3-1.5 7-1.5V4q-4.5 0-7 1&quot;&#x2F;&gt;&lt;g transform=rotate(-6,13.6,8.3)&gt;&lt;path id=q d=&quot;M11.5 6.6h1.8v1.8l-1 1.6-.6-.3.8-1.3h-1z&quot;&#x2F;&gt;&lt;use href=#q x=2.4 &#x2F;&gt;&lt;&#x2F;g&gt;&lt;&#x2F;svg&gt;&#x27;)<p>```<p>1<p>```<p>&lt;!doctype html&gt; &lt;html lang=en&gt; &lt;head&gt; &lt;meta charset=utf-8&gt; &lt;link rel=icon href=data:,&gt; &lt;meta name=viewport content=&quot;width=device-width,initial-scale=1&quot;&gt; &lt;title&gt;Example Domain&lt;&#x2F;title&gt; &lt;style&gt; html { color-scheme: light dark; background: light-dark(#eee,#222) }<p><pre><code> body { font: 16px&#x2F;1.6 system-ui,sans-serif; max-width: 26em; margin: auto; padding: 25vh 2em 2em; text-align: center } &lt;&#x2F;style&gt; &lt;&#x2F;head&gt; &lt;body&gt; &lt;p&gt;This domain is for use in documentation examples without needing permission. This is not a service; avoid relying on it for testing and monitoring purposes.&lt;&#x2F;p&gt; &lt;script src=&#x2F;s.js&gt;&lt;&#x2F;script&gt; &lt;&#x2F;body&gt;</code></pre> &lt;&#x2F;html&gt;<p>```
        • notpushkin1 day ago
          ``` doesn’t work on HN, prepend two spaces to each line to get a code block.<p>Regardless, it’s a lot of code, so maybe better move it out to a pastebin&#x2F;gist?
  • lxgr22 hours ago
    &gt; Since most of the traffic to the site is automated it tends not to fetch the Javascript file, reducing overall data requirements.<p>Well, IATA – give me api.example.com or sniff my user agent and I&#x27;ll be out of your hair :)
  • soltanov1 day ago
    Maybe this is the most web-development thing possible: even example.com eventually became a frontend project.
  • dfox1 day ago
    It seems that they changed it again and now there is minified HTML with english message + simple script that injects the other languages and the icon, no animation. Which to me seems much more sensible.
  • pona-a1 day ago
    I actually noticed that! I was debugging some HTTP proxy and typed out an HTTP&#x2F;1.1 request by hand in netcat, and was wondering why I saw a giant blob of dynamic nonsense instead of a small bit of markup.<p>(This was when it had the language scroll though, I think moving the extras to JS should have resolved that issue; maybe I was misremembering the details too.)<p>example.com is not a user-facing service. I don&#x27;t want to disparage the designer, but it&#x27;s not meant to be pretty. It&#x27;s meant to be small so you can copy its response to an automated test or visually verify its correctness, or just out of the bandwidth consideration you&#x27;d still be serving it to billions of requestors, even if you insist it&#x27;s not meant to be used that way.
    • eugenekolo1 day ago
      I believe your use is what they&#x27;re trying to discourage.<p>example.com is meant to be legally allowed to be used in text such as &quot;You visit a website (example.com) to browse the internet&quot;<p>It is not meant to be queried by automated tests or used as a service.
      • pona-a1 day ago
        I never queried it _automatically_, but many projects do. They might not have set out to provide that use, but what happened has happened, and breaking this implicit contract for a silly redesign is an odd choice.
    • scubbo1 day ago
      &gt; It&#x27;s meant to be small [...], even if [...] it&#x27;s not meant to be used that way<p>It is not, in fact, _meant_ to be used that way.
    • creatonez1 day ago
      &gt; and was wondering why I saw a giant blob of dynamic nonsense instead of a small bit of markup.<p>It&#x27;s 4.5x the size of the original. Which sounds bad, until you notice this means it&#x27;s 2540 bytes and serves the explanatory text in 6x the number of languages. And it&#x27;s now served with brotli compression, for a total of 1713 bytes. Or 334 bytes if you only request the HTML (which still has a usable page with the full English version of the explanatory text), like a basic scraper or a health check would. So for the vast majority of traffic, it&#x27;s now half the size of the old version.<p>I notice it&#x27;s been through several revisions, the pre-2025 version of the site most people are familiar with is 1270 bytes because it didn&#x27;t make use of any minification, and it also triggered an unnecessary `&#x2F;favicon.ico` request because it didn&#x27;t use the trick to cancel the request.
  • monskov1 day ago
    who&#x27;s job was it to make incremental stylesheet changes on example.com in the 2010s?
    • failbuffer1 day ago
      The government. It was a top secret skunkworks project to see if centering a &lt;div&gt; was possible.
      • johnnyanmac1 day ago
        I see the government continues to try solving impossible problems in the shadows. A pity.
    • efilife1 day ago
      Whose. Who&#x27;s is a contraction of who + is
  • absynth1 day ago
    I just wonder how much unintended traffic they receive.<p>eg If they put DNS, NTP etc on it... Likely billions per hour or something equally ludicrous.<p>Deluge is likely an exponential understatement.
  • pipes1 day ago
    What should I use for example URLs in my testa.
    • hayleox1 day ago
      Google operates <a href="http:&#x2F;&#x2F;connectivitycheck.gstatic.com&#x2F;generate_204" rel="nofollow">http:&#x2F;&#x2F;connectivitycheck.gstatic.com&#x2F;generate_204</a> and <a href="http:&#x2F;&#x2F;www.gstatic.com&#x2F;generate_204" rel="nofollow">http:&#x2F;&#x2F;www.gstatic.com&#x2F;generate_204</a>, both of which return a 204 No Content response.<p>Apple operates <a href="http:&#x2F;&#x2F;captive.apple.com" rel="nofollow">http:&#x2F;&#x2F;captive.apple.com</a>, which returns `&lt;HTML&gt;&lt;HEAD&gt;&lt;TITLE&gt;Success&lt;&#x2F;TITLE&gt;&lt;&#x2F;HEAD&gt;&lt;BODY&gt;Success&lt;&#x2F;BODY&gt;&lt;&#x2F;HTML&gt;`.<p>Microsoft operates <a href="http:&#x2F;&#x2F;www.msftconnecttest.com&#x2F;connecttest.txt" rel="nofollow">http:&#x2F;&#x2F;www.msftconnecttest.com&#x2F;connecttest.txt</a>, which returns `Microsoft Connect Test`.<p>Mozilla operates <a href="http:&#x2F;&#x2F;detectportal.firefox.com" rel="nofollow">http:&#x2F;&#x2F;detectportal.firefox.com</a>, which returns `success`.<p>These are what these companies&#x27; respective browsers&#x2F;operating systems use to check if they have an internet connection and are not stuck behind a captive portal. Given the enormous quantity of devices out in the world that are relying on these URLs to stay up, you can probably feel comfortable using these in your tests. If they do go down, good chance you&#x27;ll see news articles about it before you notice your tests failing.
      • pipes3 hours ago
        Thank you :)
  • BrandoElFollito6 hours ago
    I had no idea that example.com is even <i>registered</i>. I thought that it was the official placeholder for, well, examples.<p>It would not occur to me that my examples may lead somewhere at all. I was actually glad they do not, to spontaneously break incorrect configurations.
  • 1vuio0pswjnm71 day ago
    I just don&#x27;t understand why the operator, IANA, has to use Cloudflare for example.com<p>It cannot manage a one page website. WTF<p>There are no page &quot;aseets&quot;, no need for images, CSS, etc. It was a text-only website to test connectivity<p>iana.org forwards to Cloudflare, too<p>Fortunately the FTP server service still works<p>Without assistance from a third party<p>If it&#x27;s been a sensible decision to use Cloudflare for some period of time then why did IANA wait until now<p>(Yes, I know they used Akamai in the past)
    • kijeda1 day ago
      Cloudflare is the latest in a number of different CDN providers we&#x27;ve used to serve this over many years. I guess the question is, why is it important not to use a CDN?
      • cheschire1 day ago
        HN is currently anti Cloudflare. The only thing worse probably would’ve been to serve the static files on GitHub.io
    • NavinF1 day ago
      Same reason everyone else uses CF. Static page CDN only became too cheap to meter ~16 years ago, but if CF was around in the 90s IANA would have used it in the 90s too
    • IANA has a history of hosting even more important services with third-parties [0] [1], so this doesn&#x27;t seem too problematic to me.<p>[0]: <a href="https:&#x2F;&#x2F;root-servers.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;root-servers.org&#x2F;</a><p>[1]: <a href="https:&#x2F;&#x2F;datatracker.ietf.org&#x2F;doc&#x2F;html&#x2F;rfc6305.html" rel="nofollow">https:&#x2F;&#x2F;datatracker.ietf.org&#x2F;doc&#x2F;html&#x2F;rfc6305.html</a>
    • 1vuio0pswjnm71 day ago
      NB. IANA isn&#x27;t responsible for &quot;root servers&quot;<p>It&#x27;s only responsible for root.zone, root.hints, .arpa and .int zones<p>AS112 is a volunteer project not a company
    • 1vuio0pswjnm71 day ago
      If it&#x27;s a name in com&#x2F;net&#x2F;org only meant for documentation then why serve a page there for decades. If traffic is a problem then take it offline<p>Years ago IANA started requiring a user-agent header<p>FTP access to root.zone remains
    • 1vuio0pswjnm71 day ago
      *assets
    • NicoJuicy1 day ago
      Well, it&#x27;s a popular website. By using Cloudflare I think they will save a lot of bandwidth and traffic because the page and assets can be cached.
  • lifeisloving1 day ago
    Ive been using example1.com recently for availability type testing for what its worth.
  • chews1 day ago
    it&#x27;s nice, and it surprised me when I saw the redesign.... I use it to navigate into captive wifi portals that always seem to be misconfigured.
    • justinpombrio1 day ago
      I&#x27;ve used <a href="http:&#x2F;&#x2F;www.com" rel="nofollow">http:&#x2F;&#x2F;www.com</a> for that.
    • Same here! Yes, I used it as the well-known site that supported unencrypted http and no HSTS. Yes, I was one of those guys using the site &quot;as a service&quot; rather than simply documentation. Admittedly, it was perhaps interchangeable with other sites, but since it reliably worked for that purpose, I couldn&#x27;t be arsed to find other ones.<p>Isn&#x27;t there a dedicated site called nohttps or something? NeverSSL? I just tried http NeverSSL, and it redirected me to an https page with a random hostname and an Amazon SSL certificate!<p>Does example.com still function this way, with http and no HSTS? I noticed that my Chrome browser was immediately redirected in the customary way.
      • drdeca1 day ago
        <a href="http:&#x2F;&#x2F;neverssl.com&#x2F;online&#x2F;" rel="nofollow">http:&#x2F;&#x2F;neverssl.com&#x2F;online&#x2F;</a> seems to work for me?<p>Are you perhaps on an untrusted network which is spoofing that url to make it redirect somewhere else?
        • Arainach1 day ago
          No, NeverSSL changed to have SSL a while back - around the time that Chrome&#x2F;Firefox started throwing big warning signs and&#x2F;or blocking non-https pages.
          • red3691 day ago
            Wait, are you saying neverssl.com now sometimes uses SSL?<p>If this is a joke, it&#x27;s over my head. If not, I&#x27;m not knowledgeable enough in this space to pass judgement, but that would seem crazy to me. Like the owner should consider a domain name change :)
            • notpushkin1 day ago
              It has SSL on the main domain, and some subdomains without SSL (wildcard perhaps?). The main domain (when accessed over SSL?) redirects to a subdomain with plain HTTP.<p>Kinda weird setup!<p>Edit: okay, the subdomains also have SSL. I guess the random subdomain thing is to make sure it hasn’t been cached in a “this site has HTTPS” list. The HTTPS is needed, of course, to please the browser makers, as the parent says.
        • bobbean1 day ago
          <a href="http:&#x2F;&#x2F;http.rip&#x2F;" rel="nofollow">http:&#x2F;&#x2F;http.rip&#x2F;</a> is one I use
          • DaSHacka1 day ago
            Wow finally, a &quot;no ssl&quot; site that <i>actually</i> doesn&#x27;t use SSL! I was so disappointed when &quot;NEVERssl&quot; added SSL, like you literally have ONE job. Some clients automatically upgrade http-&gt;https or prepend https if left unspecified, so it&#x27;s nice to have an explicitly HTTP-only (IE port 80-only) service for testing&#x2F;captive portals.<p>This is very useful, thanks for sharing!
        • what1 day ago
          My browser (iOS safari) just takes me to the ssl version from that link, so “never ssl” seems wrong?
          • onedognight1 day ago
            <a href="http:&#x2F;&#x2F;example.com&#x2F;" rel="nofollow">http:&#x2F;&#x2F;example.com&#x2F;</a> works for me in Safari, warning that the site is “not secure”, but only if I type it in by hand.
  • Andddd it broke all my EVALs... ;)
  • Previously:<p><i>IANA&#x27;s email about why example.com changed</i><p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49915060">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49915060</a>
  • ErroneousBosh19 hours ago
    I did not know about that empty favicon trick, and I will be adding it to all my base HTML templates for my Flask projects where I get annoyed at all the 404s scrolling past as my browser keeps requesting a favicon that will not exist in that form.
  • grugdev421 day ago
    And example.net!
    • ButlerianJihad21 hours ago
      <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Example.com" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Example.com</a><p>example.com, example.net, example.org, and example.edu, along with .example, are all classified as the same type of name, reserved for documentation purposes.<p>Furthermore, there are IPv4 and IPv6 addresses that are reserved for documentation purposes! You never need to write live addresses, or even private RFC 1918 addresses!<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;IPv4#Special-use_addresses" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;IPv4#Special-use_addresses</a>
  • dangoodmanUT1 day ago
    the copy on example.com looks llm-generated now...
  • nilslindemann1 day ago
    I find the text shown on this site passive agressive.<p>When a newbie learning programming sees this message, then this is a downer.<p>&quot;Hello World from example.com [more info]&quot;
    • notpushkin1 day ago
      I find it pretty neutral, if maybe a bit bureaucratic. It explains what this domain does, and what it’s not supposed to be used for – that’s it.
      • nilslindemann1 day ago
        BTW, a &quot;background:white;&quot; for the body improves things. But still, the versions from 2013 or 2019 are much better in my opinion.
        • notpushkin1 day ago
          I think the previous versions didn’t really have a goal to discourage people from relying on example.com as infrastructure? *shrug*
    • reddalo1 day ago
      &gt;When a newbie learning programming<p>A newbie shouldn&#x27;t test their programs using example.com
      • nilslindemann1 day ago
        Nonsense. One may very well explain to a newbie how to link to an external site using example.com as target. Though I would not do it, with that layout. I would link to Google probably.
  • gumby1 day ago
    Static test is still, IMHO best, but if they want that fancy transition they could at least have used a gif. All that js is terrible overkill.
    • Arainach1 day ago
      Overkill for a web of humans loading sites in browsers. Not overkill for a dead internet with swarms of agents DDoSing everything in sight.
    • Barbing1 day ago
      The language translation animation only lasted a few days. Now it’s static with English at the top and translations below.
      • bossyTeacher1 day ago
        It&#x27;s English at the top for you. The top language depends on your browser settings afaik.
    • notpushkin1 day ago
      You understand that the GIF would be larger than the JS, right? (Apart from other problems with this idea.)
  • It&#x27;s down?
  • reincoder1 day ago
    We (IPinfo) have a practice of adopting low-maintenance, high-utility services. Generally, we adopt websites that would have become defunct and run them as services.<p>Even though IANA says example.com is intended for documentation purposes and not as a service, I feel that it nonetheless serves as a service to the broader internet. I think there are some cornerstone services on the internet, regardless of the maintainers&#x27; intentions or their legal definitions.<p>For example, we ourselves sometimes have to recognize that we are not a standard API service. Considering that we expect to process 3 trillion requests this year, a major outage could take down a good chunk of IT systems everywhere. So, we invested in infrastructure to avoid outages. We then started adopting other cornerstone services and running them indefinitely because we might as well support the users who depend on them because we have infrastructure to support them and us.
    • sevg1 day ago
      For a moment I thought you were saying ipinfo runs example.com.<p>Instead it just seems to be an advert for ipinfo on a post about example.com?
      • reincoder1 day ago
        Not an advert. I wish we ran example.com. However, we run a few other services.<p>The issue with example.com is this statement:<p>&gt; This domain is for use in documentation examples without needing permission. This is not a service; avoid relying on it for testing and monitoring purposes.<p>The problem is that, disclaimer or not, if a website provides a useful utility, people will use it as a service.<p>If example.com breaks, IANA can reasonably say it was never intended to be stable. But that does not change the fact that people will use it for testing and monitoring.<p>What we do is adopt legacy services whose maintainers can no longer afford, want, or have the resources to maintain them, and invest in keeping them running reliably.
        • sevg1 day ago
          My question was rhetorical ;)
    • gblargg1 day ago
      Example.com is one of the sites I visit most often for troubleshooting my connection on the go. It&#x27;s great for tickling a captive Wi-Fi login that didn&#x27;t trigger properly.
      • LeoPanthera1 day ago
        neverssl.com is slightly better for that, since it resists caching.
    • kijeda1 day ago
      I think what you describe is exactly right, it has organically become a service and it is maintained with that in mind. That doesn&#x27;t mean you shouldn&#x27;t be clear about what its for and what should be avoided. Otherwise it is setting up an implicit contract that it will service those needs without limitation which turns it into an even bigger dependency.
      • judge20201 day ago
        Not to mention indefinitely. Any decommission, even decades in the future, will be messy. Or imagine if ipinfo got bought up by private equity and they turned off the free service, or maybe attached some sort of agent-pay token to the response[0] so that they collect revenue from running it when possible.<p>0: <a href="https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;monetization-gateway-beta&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;monetization-gateway-beta&#x2F;</a>
  • matthewroop1 day ago
    [flagged]
  • cute_boi1 day ago
    IANA, a natural monopoly, can&#x27;t even host simple html page is kinda funny.
  • tesnorindian1 day ago
    IANA and ICANN should be moved under UN ITU from a non profit, so that they don&#x27;t make breaking changes without approval.
  • sajithdilshan1 day ago
    What would have been nice is that depending on the visitors IP address’s region, showing a localised message instead of fixed number of languages
    • Waterluvian1 day ago
      This feels like a “falsehood developers think about localization.”<p>It’s always funny when I get French YouTube ads. As if YouTube is desperately trying to offload the adbuys anywhere they can by pretending that Canada must mean French.
      • lxgr22 hours ago
        I hate this with a passion. Google is very guilty of this. Their AI summary very often insists on replying in the (IP) local language, nevermind the language of my HTTP headers, Google profile, or the actual natural language request...
      • what1 day ago
        Do you have ca-fr (or whatever) in your accept language header?
        • ffaccount21 day ago
          I want to read content only in a specific language. This is different language than the language of the country I live in. I have my operating system, my keyboard layout, my browser, my accept languages header, everything configured to the language I want.<p>And get I often get websites and ads in the language of the country my IP points to
        • account421 day ago
          Google famously think they know better than you what languages you want.
    • Cidan1 day ago
      I think the whole point is for it to be a static site that is easily distributed with little-to-no overhead, as it probably receives a non-trivial amount of traffic.
      • zahrevsky1 day ago
        Yep, that&#x27;s exactly their reasoning:<p>&gt; As it tends to be heavily trafficked, the overall bandwidth is a key consideration
      • account421 day ago
        Then they should have just kept it english only without any script.
    • justinpombrio1 day ago
      That assumes that (i) every region has a primary language, and (ii) everyone in that region speaks that language, both of which are false.<p>(And false often enough that guessing language based on IP address works badly in practice, I hear.)
    • int0x291 day ago
      Just check the Accept-Language header
    • erhuve1 day ago
      I believe it&#x27;s just using the official languages of the UN
      • sajithdilshan1 day ago
        Interesting, didn’t know that. Also I would have expected German and Hindi to be official UN languages given the number of native speakers in the world
        • gunalx1 day ago
          Guess most of German speaking and Hindi speaking also know English.