Rendered at 09:41:40 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
pimterry 2 hours ago [-]
For the desperate people whose tests all just broke, I have a page on my public endpoint testing server that exactly reproduces the classic design: https://example.testserver.host/. You can just use update the URL and go back to blissful ignorance.
What kind of tests would this break? Aside from the advice on the page itself (which, iirc, is new anyway), i'm wondering why any testing would actually involve the contents of design of the page. Just a weird 'sanity' check?
Our saas had an internal-use, undocumented, publicly accessibly but not publicly used (by us) health endpoint that included an internal version number.
We removed the version and a few customers complained we broke their stuff.
> For the desperate people whose tests all just broke...
The web page at example.com is maintained as a courtesy by IANA in order to explain the purpose of the example.com domain to wayward humans.
In the nomenclature of RFC 2119, one MUST NOT design computer systems that rely on the correct operation of an HTTP server at that domain. [0] Plus, it's _really_ rude to pound on a small-scale service being provided as a courtesy... go hit the home page of a tech megacorp (such as Microsoft or Google) or the status page for a major CDN (such as Cloudflare or Akamai) instead!
[0] I expect that someone here will want to pop up with a "gotcha" where they say something like "Oh, but IANA's email says that automated use is strongly recommended against, rather than prohibited and besides, they can't actually stop me from doing it!". To that, I reply "Sure, and standards-writers can't actually stop implementers that do the profoundly antisocial thing and do the things they MUST NOT. As any adult who's been paying attention to the world around them throughout their lives knows, there's only so much you can do to stop people who are very determined to be enormous assholes.".
egorfine 34 minutes ago [-]
I think we're on the verge of a big disruption coming for the example.com's business. I can see a SaaS opportunity. We can use AI to speed up time to market.
/s
aghuang 27 minutes ago [-]
Enterprise ready. Coming soon in Q4.
selcuka 9 hours ago [-]
I'm wondering how many automated tests this change broke.
Yes, I know it's not the example.com's fault, and it's a side effect of Hyrum's Law:
> This is not a service, avoid relying on it for testing and monitoring purposes.
Don't we all have a few fragile tests?
teraflop 6 hours ago [-]
That's an excellent reason to change the page design occasionally, so that people learn not to rely on it (the hard way if necessary).
brookst 7 hours ago [-]
If 1.1.1.1 ever stops responding to pings…
anyfoo 2 hours ago [-]
I don’t use this one, because I remember when long, long ago it was in some random IP address block belonging to someone, and this particular address didn’t reply to ping.
Likely for good reason, even back then there would have bound to be lots of misconfigured endpoints trying to access 1.1.1.1, so just blocking it at the earliest point possible kept at lot of the annoyance away. Nowadays, it’s an anycast address, so it’s slightly less bad.
But for me, old habits die hard.
tesnorindian 2 hours ago [-]
If 1.1.1.1 fails, I will try 8.8.8.8
ButlerianJihad 5 hours ago [-]
> 1.1.1.1
Pinging such an address is inherently a troublesome practice. This address, like many public DNS servers (resolvers as well as root and authoritative ones), uses "anycast" routing methodology.
Pinging an anycast address will yield a cornucopia of different results. Of course, people who naïvely "ping" a recognizable or easy-to-type IPv4 address get what they deserve, especially when they enshrine it into software, unit tests, or the LLM coughs up such tokens on their behalf.
Fundamentally, the question is "what do you really want to test?" by pinging a particular IPv4? Do you want to test Layer 3 connectivity? Test your ISP's backbone and connectivity? Test only your upstream router? Test the existence of ICMP in your stack and theirs?
... the possibilities are endless. Your router can do anything. Ping zombo.com.
zettabomb 3 hours ago [-]
Why is pinging an anycast address an issue? Most people, myself included, ping addresses like 1.1.1.1 to check for internet connectivity. It's a perfectly valid check, you don't need a fine grained test all the time. If it fails, then I go looking in detail. Most of the time it will pass.
Pinging a domain name could fail for a variety of other reasons, particularly if it's not a reliable site. Cloudflare's business is being reliable; few sites would be a better choice.
its-summertime 2 hours ago [-]
The problem is pinging 1.1.1.1 can end up hitting a really really close-by server. You could be having ISP issues and 1.1.1.1 could end up being closer to you than the issue is, so you get okay ping results but still unable to access resources on the other side of the issue
zettabomb 2 hours ago [-]
You're thinking far too hard. If I can ping 1.1.1.1, it means traffic is flowing from inside my network, to outside my network. I'm not going to diagnose my ISP's issues, that's their job, I just need to know that it's not my problem.
mcapodici 2 hours ago [-]
Most of my connection issues are between the street and my computer, I don't think Cloudflare got there. Yet.
account42 2 hours ago [-]
You can have routing issues that alow some IP addresses to work and others not, anycast or not. It's not supposed to be a comprehensive connectivity report, just a sanity check that the intertubes are connected at all.
QuantumNomad_ 5 hours ago [-]
I ping 1.1.1.1 to see if my internet is working or not after a couple of websites don’t load. I reboot the router. I keep the terminal where I’m pinging 1.1.1.1 open until I start seeing responses and then I know my internet is back. Then I continue my web browsing and other online activities.
M4v3R 3 hours ago [-]
I’m so lazy I just type `ping 1.1` and it still works (apparently 1.0.0.1 is also always up).
justinator 3 hours ago [-]
It's much faster just pinging 127.0.0.1 for such purposes. Try it!
2 hours ago [-]
4 hours ago [-]
frizlab 5 hours ago [-]
Same
ffaccount2 2 hours ago [-]
Fun fact, ping is the standard windows way to wait a given number of seconds[0]. You're supposed to ping 127.0.0.1, but I saw a lot of scripts pinging 1.1.1.1 or 8.8.8.8
Don't see why this is relevant, ping is not traceroute or http. If you just want to test if packets can leave your network then its a good enough test and anycast doesn't affect that.
chews 9 hours ago [-]
that's a really good point I'd not considered but if you just hash the response and the followups remain consistent (they do in this case)... you're gonna do just fine.
jamdav16 10 hours ago [-]
> there's a gradual opacity transition
Looks like they removed this and instead just show all languages with no CSS animation now.
kijeda 6 hours ago [-]
Yes, the revised version that alternated through the translations was posted a week ago on Monday. It was revised to no longer do that on Friday based on reasonable feedback that it wasn't the best idea for accessibility. Now all the translations are presented together, but your preferred language will be bumped to the top based on your browser language preference.
johnnyanmac 9 hours ago [-]
Aww, I was wondering if I was just looking at an older version. How disappointing. But I suppose, unsurprising given the conversation here. I'm sure such transitions would be bringing a surprising amount of instrumentation down.
It still probably is as it is now. But there's better arguments to support localization than transitions.
p-t 8 hours ago [-]
For some reason the localization still requires javascript... (I'm pretty sure the transition could have been done in just CSS as well)
thaumasiotes 6 hours ago [-]
> For some reason the localization still requires javascript
Well, no. The purpose of the redesign is to move as much of the page content as possible into an external javascript file. There's no question of what parts of the page require javascript; the question is what parts of the page can be moved into javascript.
And the "statement" in this article is the text from that email, disingenuously edited. I'm not sure why, but it rubs me the wrong way.
creatonez 3 hours ago [-]
What makes you think it's edited?
frogulis 3 hours ago [-]
Yeah apologies, bad wording on my part. I really just meant the removal of the opening line which made it clear that it was a correspondence: "I am happy to try and answer any questions you have."
adithyassekhar 9 hours ago [-]
The page mentions example.com 14 times and not a single one is a link
ndriscoll 8 hours ago [-]
You also failed to make it a link. In order to automatically create links, you should use the format https://example.com/ with scheme included. So in your case you'd do https://example.com/
adithyassekhar 8 hours ago [-]
Guess I am part of the problem. Thank you for the link kind stranger.
arcanemachiner 9 hours ago [-]
Outrageous. How will people ever find it?!
oneeyedpigeon 2 hours ago [-]
By typing it or copy+pasting it, which is much more time consuming and much less convenient.
(I actually tried the select, share [sic], open in browser route, but for some reason I only saw opera as an option, not chrome, the browser I actually use for everything. Links still rule.)
pipes 13 minutes ago [-]
What should I use for example URLs in my testa.
zahrevsky 10 hours ago [-]
> There is no requirement there is a HTTP service present on the host in order to fulfill its purpose, we just operate it as a courtesy.
I guess this is also done to prevent bad actors from abusing the fact that this domain is hit by people who might not know what they're doing (the ones copy-pasting code without reading it)
zamadatix 10 hours ago [-]
More the DNS and DNSSEC and the like. Whether or not there is actually an HTTP server responding is irrelevant to whether or not those securely point anywhere but a malicious system.
jgx0 10 hours ago [-]
Yeah there’s definitely a lot of sensitive data that gets sent to the domain just because of people not changing configs
krackers 10 hours ago [-]
I don't understand, what risk would there be if they chose _not_ to serve a site?
dylan604 9 hours ago [-]
Someone else could
altermetax 9 hours ago [-]
No, because they can't register the domain, it's already taken, no matter if a web service is running behind it or not
dylan604 8 hours ago [-]
It's just part and parcel of owning the domain. It's one thing to have the domain, but the next step is offering an active website so that people that actually put that domain in a browser can see it's a placeholder.
notpushkin 3 hours ago [-]
This is not the point discussed here.
> Someone else could
When you own a domain, you can choose not to serve anything on HTTP/S, and still nobody can come and serve some other website on your domain, because they don’t control the DNS records.
valleyer 6 hours ago [-]
Why HTTP? Why not SSH? When I try to connect to it that way, I get no response. How will I know it's a placeholder?
pests 6 hours ago [-]
HTTP is used by billions of people while SSH is not. It should be pretty apparent. Why do people answer my phone calls and texts but everyone is ignoring my smoke signals?
dofm 2 hours ago [-]
What is the smoke signal for “we’ve been trying to reach you about your car’s extended warranty“?
dfox 57 minutes ago [-]
It seems that they changed it again and now there is minified HTML with english message + simple script that injects the other languages and the icon, no animation. Which to me seems much more sensible.
2 hours ago [-]
1vuio0pswjnm7 7 hours ago [-]
I just don't understand why the operator, IANA, has to use Cloudflare for example.com
It cannot manage a one page website. WTF
There are no page "aseets", no need for images, CSS, etc. It was a text-only website to test connectivity
iana.org forwards to Cloudflare, too
Fortunately the FTP server service still works
Without assistance from a third party
If it's been a sensible decision to use Cloudflare for some period of time then why did IANA wait until now
(Yes, I know they used Akamai in the past)
kijeda 6 hours ago [-]
Cloudflare is the latest in a number of different CDN providers we've used to serve this over many years. I guess the question is, why is it important not to use a CDN?
cheschire 37 minutes ago [-]
HN is currently anti Cloudflare. The only thing worse probably would’ve been to serve the static files on GitHub.io
gucci-on-fleek 5 hours ago [-]
IANA has a history of hosting even more important services with third-parties [0] [1], so this doesn't seem too problematic to me.
Same reason everyone else uses CF. Static page CDN only became too cheap to meter ~16 years ago, but if CF was around in the 90s IANA would have used it in the 90s too
1vuio0pswjnm7 4 hours ago [-]
NB. IANA isn't responsible for "root servers"
It's only responsible for root.zone, root.hints, .arpa and .int zones
AS112 is a volunteer project not a company
1vuio0pswjnm7 4 hours ago [-]
If it's a name in com/net/org only meant for documentation then why serve a page there for decades. If traffic is a problem then take it offline
Years ago IANA started requiring a user-agent header
FTP access to root.zone remains
1vuio0pswjnm7 5 hours ago [-]
*assets
NicoJuicy 7 hours ago [-]
Well, it's a popular website. By using Cloudflare I think they will save a lot of bandwidth and traffic because the page and assets can be cached.
2 hours ago [-]
tesnorindian 2 hours ago [-]
IANA and ICANN should be moved under UN ITU from a non profit, so that they don't make breaking changes without approval.
accountrequired 4 hours ago [-]
This is mine now!
<link rel=icon href=data:,>
xigoi 2 hours ago [-]
I put this on all my websites that don’t have a favicon. I hate the default browser behavior of making a request to /favicon.ico without being asked.
soltanov 2 hours ago [-]
Maybe this is the most web-development thing possible: even example.com eventually became a frontend project.
tty456 5 hours ago [-]
It's been about 10 years since I last saw this site and accidentally visited it a few days ago and thought "I don't remember it looking like this"
danhite 6 hours ago [-]
So they made a prior tweak to reduce fetches of favicon.ico ( by link rel="icon" href="data:," )
but why do they still serve the overlarge meaningless html page to requests for robots.txt ?!
Given that they have gotten spiked by automated requests lately, aka agents, wouldn't this at least be respected by the big players?
Also, as they are using Cloudflare, wouldn't a discussion (or a note from IANA or CF) about how they configured CF request rejection and how one should love CF's flat rate static serving be appropriate?
Am I missing something?
etatester 2 hours ago [-]
It's quite sad to see incompetence at these levels. This is a static page that loads JS. They even inject styles via JS...
bmarch 2 hours ago [-]
It’s not incompetence they are intentionally doing as much as possible via javascript to reduce their bandwidth costs. This is because most access to the domain is automated (not using a browser, using curl etc) and doesn’t load javascript
which does appear to say that yes, IANA hosts this
gavino 9 hours ago [-]
Really funny coincidence, I noticed amazon wasn't loading a couple hours ago. Thought it was my internet so went to example.com to check and noticed the redesign. Figured it was a while ago though.
pona-a 4 hours ago [-]
I actually noticed that! I was debugging some HTTP proxy and typed out an HTTP/1.1 request by hand in netcat, and was wondering why I saw a giant blob of dynamic nonsense instead of a small bit of markup.
(This was when it had the language scroll though, I think moving the extras to JS should have resolved that issue; maybe I was misremembering the details too.)
example.com is not a user-facing service. I don't want to disparage the designer, but it's not meant to be pretty. It's meant to be small so you can copy its response to an automated test or visually verify its correctness, or just out of the bandwidth consideration you'd still be serving it to billions of requestors, even if you insist it's not meant to be used that way.
eugenekolo 4 hours ago [-]
I believe your use is what they're trying to discourage.
example.com is meant to be legally allowed to be used in text such as "You visit a website (example.com) to browse the internet"
It is not meant to be queried by automated tests or used as a service.
creatonez 3 hours ago [-]
> and was wondering why I saw a giant blob of dynamic nonsense instead of a small bit of markup.
It's 4.5x the size of the original. Which sounds bad, until you notice this means it's 2540 bytes and serves the explanatory text in 6x the number of languages. And it's now served with brotli compression, for a total of 1713 bytes. Or 334 bytes if you only request the HTML (which still has a usable page with the full English version of the explanatory text), like a basic scraper or a health check would. So for the vast majority of traffic, it's now half the size of the old version.
I notice it's been through several revisions, the pre-2025 version of the site most people are familiar with is 1270 bytes because it didn't make use of any minification, and it also triggered an unnecessary `/favicon.ico` request because it didn't use the trick to cancel the request.
scubbo 4 hours ago [-]
> It's meant to be small [...], even if [...] it's not meant to be used that way
It is not, in fact, _meant_ to be used that way.
Gualdrapo 10 hours ago [-]
> Along with introducing multi-language support, the JavaScript code also inserts an SVG book icon.
Wait - using JS for dynamic content is understandable, but why using it for inserting a static SVG?
worg 9 hours ago [-]
Reducing egress bandwidth, if you have automated clients that don't support JS you save precious bytes from being served by not embedding the SVG, which at example.com scale may be worth it
autoexec 9 hours ago [-]
Wouldn't removing the pointless SVG image entirely save the most precious bytes from being served no matter if JS (or SVG) is supported or not?
schiffern 7 hours ago [-]
>pointless SVG image
Why aren't we all eating inexpensive gruel instead of "pointless" food? Same reason.
It's good to have a little color/flavor/spice in life.
account42 2 hours ago [-]
Ah yes because bog standard corporate design is how you add color/flavor/spice in life.
afavour 10 hours ago [-]
Simple answer is the article is wrong, I tried it with disabled JS and still see the SVG.
The whole article reads like something put together with AI, so maybe it’s not too surprising.
zamadatix 10 hours ago [-]
I get nothing but a gray page with the following with JS disabled https://i.imgur.com/81aYPeB.png in Firefox via javascript.enabled set to false.
ajcp 10 hours ago [-]
You may want to check your settings again or clear you cache as there is definitely a `s.js`[0] file that inserts the `<svg>` element into the HTML DOM[1], which you can see does not contain the element itself.
0
```
var B = document.body, P, p;
B.children[0].insertAdjacentHTML("afterend", "<p lang=ar dir=rtl>هذا النطاق مُخصص للاستخدام في أمثلة التوثيق دون الحاجة إلى إذن. هذه ليست خدمة، يُرجى تجنب الاعتماد عليها لأغراض الاختبار والمراقبة.</p><p lang=zh>该域名仅用于文档示例,无需获得许可。这并非一项服务,请勿将其用于测试和监控目的。</p><p lang=fr>L’usage de ce domaine est réservé à des exemples de documentation, sans autorisation préalable. Il ne s’agit pas d’un service ; son utilisation à des fins de test ou de surveillance est à éviter.</p><p lang=ru>Данный домен предназначен для использования в примерах документации без необходимости получения предварительного разрешения. Это не сервис; не рекомендуется его использование для тестирования и мониторинга.</p><p lang=es>Este dominio está destinado al uso en ejemplos de documentación sin necesidad de permiso. Esto no es un servicio; evitar utilizarlo para realizar pruebas o monitoreos.</p><a href=https://iana.org/help/example-domains>Learn more</a>");
P = [...B.querySelectorAll("p")];
P[0].lang = "en";
navigator.languages.some(l => p = P.find(p => p.lang == l.split("-")[0]));
p = p || P[0];
B.prepend(p);
B.insertAdjacentHTML("afterbegin", '<style>svg{display:block;margin:-2.75em auto 0;opacity:.55}p+p{font-size:.875em;opacity:.6}</style><svg viewBox=0,0,20,20 width=44 height=44 fill=currentColor aria-hidden=true><path fill=none stroke=currentColor stroke-width=1.3 stroke-linejoin=round d="M6 4H3v12q4 0 7 1.5-1-3.5-4-4.5V2q3.5 1 4 3v12.5q3-1.5 7-1.5V4q-4.5 0-7 1"/><g transform=rotate(-6,13.6,8.3)><path id=q d="M11.5 6.6h1.8v1.8l-1 1.6-.6-.3.8-1.3h-1z"/><use href=#q x=2.4 /></g></svg>')
body {
font: 16px/1.6 system-ui,sans-serif;
max-width: 26em;
margin: auto;
padding: 25vh 2em 2em;
text-align: center
}
</style>
</head>
<body>
<p>This domain is for use in documentation examples without needing permission. This is not a service; avoid relying on it for testing and monitoring purposes.</p>
<script src=/s.js></script>
</body>
</html>
```
notpushkin 3 hours ago [-]
``` doesn’t work on HN, prepend two spaces to each line to get a code block.
Regardless, it’s a lot of code, so maybe better move it out to a pastebin/gist?
pranshuchittora 2 hours ago [-]
Andddd it broke all my EVALs... ;)
grugdev42 1 hours ago [-]
And example.net!
3 hours ago [-]
monskov 10 hours ago [-]
who's job was it to make incremental stylesheet changes on example.com in the 2010s?
failbuffer 10 hours ago [-]
The government. It was a top secret skunkworks project to see if centering a <div> was possible.
johnnyanmac 9 hours ago [-]
I see the government continues to try solving impossible problems in the shadows. A pity.
efilife 3 hours ago [-]
Whose. Who's is a contraction of who + is
dangoodmanUT 9 hours ago [-]
the copy on example.com looks llm-generated now...
chews 11 hours ago [-]
it's nice, and it surprised me when I saw the redesign.... I use it to navigate into captive wifi portals that always seem to be misconfigured.
Same here! Yes, I used it as the well-known site that supported unencrypted http and no HSTS. Yes, I was one of those guys using the site "as a service" rather than simply documentation. Admittedly, it was perhaps interchangeable with other sites, but since it reliably worked for that purpose, I couldn't be arsed to find other ones.
Isn't there a dedicated site called nohttps or something? NeverSSL? I just tried http NeverSSL, and it redirected me to an https page with a random hostname and an Amazon SSL certificate!
Does example.com still function this way, with http and no HSTS? I noticed that my Chrome browser was immediately redirected in the customary way.
Are you perhaps on an untrusted network which is spoofing that url to make it redirect somewhere else?
Arainach 8 hours ago [-]
No, NeverSSL changed to have SSL a while back - around the time that Chrome/Firefox started throwing big warning signs and/or blocking non-https pages.
red369 8 hours ago [-]
Wait, are you saying neverssl.com now sometimes uses SSL?
If this is a joke, it's over my head. If not, I'm not knowledgeable enough in this space to pass judgement, but that would seem crazy to me. Like the owner should consider a domain name change :)
notpushkin 3 hours ago [-]
It has SSL on the main domain, and some subdomains without SSL (wildcard perhaps?). The main domain (when accessed over SSL?) redirects to a subdomain with plain HTTP.
Kinda weird setup!
Edit: okay, the subdomains also have SSL. I guess the random subdomain thing is to make sure it hasn’t been cached in a “this site has HTTPS” list. The HTTPS is needed, of course, to please the browser makers, as the parent says.
My browser (iOS safari) just takes me to the ssl version from that link, so “never ssl” seems wrong?
onedognight 4 hours ago [-]
http://example.com/ works for me in Safari, warning that the site is “not secure”, but only if I type it in by hand.
lifeisloving 9 hours ago [-]
Ive been using example1.com recently for availability type testing for what its worth.
nilslindemann 4 hours ago [-]
I find the text shown on this site passive agressive.
When a newbie learning programming sees this message, then this is a downer.
"Hello World from example.com [more info]"
notpushkin 3 hours ago [-]
I find it pretty neutral, if maybe a bit bureaucratic. It explains what this domain does, and what it’s not supposed to be used for – that’s it.
nilslindemann 2 hours ago [-]
BTW, a "background:white;" for the body improves things. But still, the versions from 2013 or 2019 are much better in my opinion.
reddalo 2 hours ago [-]
>When a newbie learning programming
A newbie shouldn't test their programs using example.com
nilslindemann 2 hours ago [-]
Nonsense. One may very well explain to a newbie how to link to an external site using example.com as target. Though I would not do it, with that layout. I would link to Google probably.
Static test is still, IMHO best, but if they want that fancy transition they could at least have used a gif. All that js is terrible overkill.
Barbing 6 hours ago [-]
The language translation animation only lasted a few days. Now it’s static with English at the top and translations below.
bossyTeacher 4 hours ago [-]
It's English at the top for you. The top language depends on your browser settings afaik.
notpushkin 3 hours ago [-]
You understand that the GIF would be larger than the JS, right? (Apart from other problems with this idea.)
Arainach 8 hours ago [-]
Overkill for a web of humans loading sites in browsers. Not overkill for a dead internet with swarms of agents DDoSing everything in sight.
cute_boi 9 hours ago [-]
IANA, a natural monopoly, can't even host simple html page is kinda funny.
hidelooktropic 10 hours ago [-]
It's down?
7 hours ago [-]
reincoder 10 hours ago [-]
We (IPinfo) have a practice of adopting low-maintenance, high-utility services. Generally, we adopt websites that would have become defunct and run them as services.
Even though IANA says example.com is intended for documentation purposes and not as a service, I feel that it nonetheless serves as a service to the broader internet. I think there are some cornerstone services on the internet, regardless of the maintainers' intentions or their legal definitions.
For example, we ourselves sometimes have to recognize that we are not a standard API service. Considering that we expect to process 3 trillion requests this year, a major outage could take down a good chunk of IT systems everywhere. So, we invested in infrastructure to avoid outages. We then started adopting other cornerstone services and running them indefinitely because we might as well support the users who depend on them because we have infrastructure to support them and us.
sevg 7 hours ago [-]
For a moment I thought you were saying ipinfo runs example.com.
Instead it just seems to be an advert for ipinfo on a post about example.com?
kijeda 10 hours ago [-]
I think what you describe is exactly right, it has organically become a service and it is maintained with that in mind. That doesn't mean you shouldn't be clear about what its for and what should be avoided. Otherwise it is setting up an implicit contract that it will service those needs without limitation which turns it into an even bigger dependency.
judge2020 8 hours ago [-]
Not to mention indefinitely. Any decommission, even decades in the future, will be messy. Or imagine if ipinfo got bought up by private equity and they turned off the free service, or maybe attached some sort of agent-pay token to the response[0] so that they collect revenue from running it when possible.
Example.com is one of the sites I visit most often for troubleshooting my connection on the go. It's great for tickling a captive Wi-Fi login that didn't trigger properly.
LeoPanthera 7 hours ago [-]
neverssl.com is slightly better for that, since it resists caching.
3 hours ago [-]
sajithdilshan 11 hours ago [-]
What would have been nice is that depending on the visitors IP address’s region, showing a localised message instead of fixed number of languages
Waterluvian 10 hours ago [-]
This feels like a “falsehood developers think about localization.”
It’s always funny when I get French YouTube ads. As if YouTube is desperately trying to offload the adbuys anywhere they can by pretending that Canada must mean French.
what 8 hours ago [-]
Do you have ca-fr (or whatever) in your accept language header?
ffaccount2 2 hours ago [-]
I want to read content only in a specific language. This is different language than the language of the country I live in. I have my operating system, my keyboard layout, my browser, my accept languages header, everything configured to the language I want.
And get I often get websites and ads in the language of the country my IP points to
account42 2 hours ago [-]
Google famously think they know better than you what languages you want.
Cidan 10 hours ago [-]
I think the whole point is for it to be a static site that is easily distributed with little-to-no overhead, as it probably receives a non-trivial amount of traffic.
account42 2 hours ago [-]
Then they should have just kept it english only without any script.
zahrevsky 10 hours ago [-]
Yep, that's exactly their reasoning:
> As it tends to be heavily trafficked, the overall bandwidth is a key consideration
justinpombrio 4 hours ago [-]
That assumes that (i) every region has a primary language, and (ii) everyone in that region speaks that language, both of which are false.
(And false often enough that guessing language based on IP address works badly in practice, I hear.)
int0x29 10 hours ago [-]
Just check the Accept-Language header
erhuve 10 hours ago [-]
I believe it's just using the official languages of the UN
sajithdilshan 10 hours ago [-]
Interesting, didn’t know that. Also I would have expected German and Hindi to be official UN languages given the number of native speakers in the world
gunalx 10 hours ago [-]
Guess most of German speaking and Hindi speaking also know English.
Also open-source and self-hostable: https://github.com/httptoolkit/testserver. Lots of other endpoints too, full docs here: https://testserver.host/
As an example, depending on "man -w" not outputting anything to stderr: https://unix.stackexchange.com/questions/405783/why-does-man...
We removed the version and a few customers complained we broke their stuff.
The web page at example.com is maintained as a courtesy by IANA in order to explain the purpose of the example.com domain to wayward humans.
In the nomenclature of RFC 2119, one MUST NOT design computer systems that rely on the correct operation of an HTTP server at that domain. [0] Plus, it's _really_ rude to pound on a small-scale service being provided as a courtesy... go hit the home page of a tech megacorp (such as Microsoft or Google) or the status page for a major CDN (such as Cloudflare or Akamai) instead!
[0] I expect that someone here will want to pop up with a "gotcha" where they say something like "Oh, but IANA's email says that automated use is strongly recommended against, rather than prohibited and besides, they can't actually stop me from doing it!". To that, I reply "Sure, and standards-writers can't actually stop implementers that do the profoundly antisocial thing and do the things they MUST NOT. As any adult who's been paying attention to the world around them throughout their lives knows, there's only so much you can do to stop people who are very determined to be enormous assholes.".
/s
Yes, I know it's not the example.com's fault, and it's a side effect of Hyrum's Law:
> This is not a service, avoid relying on it for testing and monitoring purposes.
Don't we all have a few fragile tests?
Likely for good reason, even back then there would have bound to be lots of misconfigured endpoints trying to access 1.1.1.1, so just blocking it at the earliest point possible kept at lot of the annoyance away. Nowadays, it’s an anycast address, so it’s slightly less bad.
But for me, old habits die hard.
Pinging such an address is inherently a troublesome practice. This address, like many public DNS servers (resolvers as well as root and authoritative ones), uses "anycast" routing methodology.
https://en.wikipedia.org/wiki/Anycast
Pinging an anycast address will yield a cornucopia of different results. Of course, people who naïvely "ping" a recognizable or easy-to-type IPv4 address get what they deserve, especially when they enshrine it into software, unit tests, or the LLM coughs up such tokens on their behalf.
Fundamentally, the question is "what do you really want to test?" by pinging a particular IPv4? Do you want to test Layer 3 connectivity? Test your ISP's backbone and connectivity? Test only your upstream router? Test the existence of ICMP in your stack and theirs?
... the possibilities are endless. Your router can do anything. Ping zombo.com.
Pinging a domain name could fail for a variety of other reasons, particularly if it's not a reliable site. Cloudflare's business is being reliable; few sites would be a better choice.
[0]: https://stackoverflow.com/questions/1672338/how-to-sleep-for...
Looks like they removed this and instead just show all languages with no CSS animation now.
It still probably is as it is now. But there's better arguments to support localization than transitions.
Well, no. The purpose of the redesign is to move as much of the page content as possible into an external javascript file. There's no question of what parts of the page require javascript; the question is what parts of the page can be moved into javascript.
IANA's email about why example.com changed - https://news.ycombinator.com/item?id=49915060 - Sept 2026 (20 comments)
(I actually tried the select, share [sic], open in browser route, but for some reason I only saw opera as an option, not chrome, the browser I actually use for everything. Links still rule.)
I guess this is also done to prevent bad actors from abusing the fact that this domain is hit by people who might not know what they're doing (the ones copy-pasting code without reading it)
> Someone else could
When you own a domain, you can choose not to serve anything on HTTP/S, and still nobody can come and serve some other website on your domain, because they don’t control the DNS records.
It cannot manage a one page website. WTF
There are no page "aseets", no need for images, CSS, etc. It was a text-only website to test connectivity
iana.org forwards to Cloudflare, too
Fortunately the FTP server service still works
Without assistance from a third party
If it's been a sensible decision to use Cloudflare for some period of time then why did IANA wait until now
(Yes, I know they used Akamai in the past)
[0]: https://root-servers.org/
[1]: https://datatracker.ietf.org/doc/html/rfc6305.html
It's only responsible for root.zone, root.hints, .arpa and .int zones
AS112 is a volunteer project not a company
Years ago IANA started requiring a user-agent header
FTP access to root.zone remains
Given that they have gotten spiked by automated requests lately, aka agents, wouldn't this at least be respected by the big players?
Also, as they are using Cloudflare, wouldn't a discussion (or a note from IANA or CF) about how they configured CF request rejection and how one should love CF's flat rate static serving be appropriate?
Am I missing something?
eg If they put DNS, NTP etc on it... Likely billions per hour or something equally ludicrous.
Deluge is likely an exponential understatement.
which does appear to say that yes, IANA hosts this
(This was when it had the language scroll though, I think moving the extras to JS should have resolved that issue; maybe I was misremembering the details too.)
example.com is not a user-facing service. I don't want to disparage the designer, but it's not meant to be pretty. It's meant to be small so you can copy its response to an automated test or visually verify its correctness, or just out of the bandwidth consideration you'd still be serving it to billions of requestors, even if you insist it's not meant to be used that way.
example.com is meant to be legally allowed to be used in text such as "You visit a website (example.com) to browse the internet"
It is not meant to be queried by automated tests or used as a service.
It's 4.5x the size of the original. Which sounds bad, until you notice this means it's 2540 bytes and serves the explanatory text in 6x the number of languages. And it's now served with brotli compression, for a total of 1713 bytes. Or 334 bytes if you only request the HTML (which still has a usable page with the full English version of the explanatory text), like a basic scraper or a health check would. So for the vast majority of traffic, it's now half the size of the old version.
I notice it's been through several revisions, the pre-2025 version of the site most people are familiar with is 1270 bytes because it didn't make use of any minification, and it also triggered an unnecessary `/favicon.ico` request because it didn't use the trick to cancel the request.
It is not, in fact, _meant_ to be used that way.
Wait - using JS for dynamic content is understandable, but why using it for inserting a static SVG?
It's good to have a little color/flavor/spice in life.
The whole article reads like something put together with AI, so maybe it’s not too surprising.
0
```
var B = document.body, P, p; B.children[0].insertAdjacentHTML("afterend", "<p lang=ar dir=rtl>هذا النطاق مُخصص للاستخدام في أمثلة التوثيق دون الحاجة إلى إذن. هذه ليست خدمة، يُرجى تجنب الاعتماد عليها لأغراض الاختبار والمراقبة.</p><p lang=zh>该域名仅用于文档示例,无需获得许可。这并非一项服务,请勿将其用于测试和监控目的。</p><p lang=fr>L’usage de ce domaine est réservé à des exemples de documentation, sans autorisation préalable. Il ne s’agit pas d’un service ; son utilisation à des fins de test ou de surveillance est à éviter.</p><p lang=ru>Данный домен предназначен для использования в примерах документации без необходимости получения предварительного разрешения. Это не сервис; не рекомендуется его использование для тестирования и мониторинга.</p><p lang=es>Este dominio está destinado al uso en ejemplos de documentación sin necesidad de permiso. Esto no es un servicio; evitar utilizarlo para realizar pruebas o monitoreos.</p><a href=https://iana.org/help/example-domains>Learn more</a>"); P = [...B.querySelectorAll("p")]; P[0].lang = "en"; navigator.languages.some(l => p = P.find(p => p.lang == l.split("-")[0])); p = p || P[0]; B.prepend(p); B.insertAdjacentHTML("afterbegin", '<style>svg{display:block;margin:-2.75em auto 0;opacity:.55}p+p{font-size:.875em;opacity:.6}</style><svg viewBox=0,0,20,20 width=44 height=44 fill=currentColor aria-hidden=true><path fill=none stroke=currentColor stroke-width=1.3 stroke-linejoin=round d="M6 4H3v12q4 0 7 1.5-1-3.5-4-4.5V2q3.5 1 4 3v12.5q3-1.5 7-1.5V4q-4.5 0-7 1"/><g transform=rotate(-6,13.6,8.3)><path id=q d="M11.5 6.6h1.8v1.8l-1 1.6-.6-.3.8-1.3h-1z"/><use href=#q x=2.4 /></g></svg>')
```
1
```
<!doctype html> <html lang=en> <head> <meta charset=utf-8> <link rel=icon href=data:,> <meta name=viewport content="width=device-width,initial-scale=1"> <title>Example Domain</title> <style> html { color-scheme: light dark; background: light-dark(#eee,#222) }
</html>```
Regardless, it’s a lot of code, so maybe better move it out to a pastebin/gist?
Isn't there a dedicated site called nohttps or something? NeverSSL? I just tried http NeverSSL, and it redirected me to an https page with a random hostname and an Amazon SSL certificate!
Does example.com still function this way, with http and no HSTS? I noticed that my Chrome browser was immediately redirected in the customary way.
Are you perhaps on an untrusted network which is spoofing that url to make it redirect somewhere else?
If this is a joke, it's over my head. If not, I'm not knowledgeable enough in this space to pass judgement, but that would seem crazy to me. Like the owner should consider a domain name change :)
Kinda weird setup!
Edit: okay, the subdomains also have SSL. I guess the random subdomain thing is to make sure it hasn’t been cached in a “this site has HTTPS” list. The HTTPS is needed, of course, to please the browser makers, as the parent says.
When a newbie learning programming sees this message, then this is a downer.
"Hello World from example.com [more info]"
A newbie shouldn't test their programs using example.com
IANA's email about why example.com changed
https://news.ycombinator.com/item?id=49915060
Even though IANA says example.com is intended for documentation purposes and not as a service, I feel that it nonetheless serves as a service to the broader internet. I think there are some cornerstone services on the internet, regardless of the maintainers' intentions or their legal definitions.
For example, we ourselves sometimes have to recognize that we are not a standard API service. Considering that we expect to process 3 trillion requests this year, a major outage could take down a good chunk of IT systems everywhere. So, we invested in infrastructure to avoid outages. We then started adopting other cornerstone services and running them indefinitely because we might as well support the users who depend on them because we have infrastructure to support them and us.
Instead it just seems to be an advert for ipinfo on a post about example.com?
0: https://blog.cloudflare.com/monetization-gateway-beta/
It’s always funny when I get French YouTube ads. As if YouTube is desperately trying to offload the adbuys anywhere they can by pretending that Canada must mean French.
And get I often get websites and ads in the language of the country my IP points to
> As it tends to be heavily trafficked, the overall bandwidth is a key consideration
(And false often enough that guessing language based on IP address works badly in practice, I hear.)