Example.com just launched the biggest redesign in decades

1 day ago (debugbear.com)

For the desperate people whose tests all just broke, I have a page on my public endpoint testing server that exactly reproduces the classic design: https://example.testserver.host/. You can just use update the URL and go back to blissful ignorance.

Also open-source and self-hostable: https://github.com/httptoolkit/testserver. Lots of other endpoints too, full docs here: https://testserver.host/

  • If you do have tests relying on it... stop it:

    > This is not a service; avoid relying on it for testing and monitoring purposes.

    • Before this submission, it genuinely never occurred to me that people would actually have tests that rely on example.com being up, let alone depend on its content.

    • Opus 5.5 in Claude code added a unit test checking DNS and internet access using example.com as the target on a project I'm building yesterday. It's an agent sandbox (I know, yet another), so the call was expected to fail, but still... It should have at least targeted a captive portal endpoint or a project owned domain.

      I caught it in review but thousands of others won't.

      That ship has sailed I would say.

      2 replies →

    • I have been naively using example.com in the browser. WHATWG URL throws if there is no origin when constructing the URL. Web apps that need to construct _just_ the pathname must go through this song and dance. `new URL("/blah", "https://example.com").pathname` This isn't relying on any external example.com service but I'm learning the lesson.

  • What kind of tests would this break? Aside from the advice on the page itself (which, iirc, is new anyway), i'm wondering why any testing would actually involve the contents of design of the page. Just a weird 'sanity' check?

  • One of the critical things I use example.com for is triggering wifi login portals as it doesn't not use SSL. Certificate pinning and all that fancy stuff has made it so the browser has an absolutely awful time figuring out what to do when https://google.com does not present itself as the same host it was earlier.

  • Do you do any sort of rate-limiting to stop people/bots from hammering it (accidentally or otherwise)? Or do you just let it fall over under load.

  • > For the desperate people whose tests all just broke...

    The web page at example.com is maintained as a courtesy by IANA in order to explain the purpose of the example.com domain to wayward humans.

    In the nomenclature of RFC 2119, one MUST NOT design computer systems that rely on the correct operation of an HTTP server at that domain. [0] Plus, it's _really_ rude to pound on a small-scale service being provided as a courtesy... go hit the home page of a tech megacorp (such as Microsoft or Google) or the status page for a major CDN (such as Cloudflare or Akamai) instead!

    [0] I expect that someone here will want to pop up with a "gotcha" where they say something like "Oh, but IANA's email says that automated use is strongly recommended against, rather than prohibited and besides, they can't actually stop me from doing it!". To that, I reply "Sure, and standards-writers can't actually stop implementers that do the profoundly antisocial thing and do the things they MUST NOT. As any adult who's been paying attention to the world around them throughout their lives knows, there's only so much you can do to stop people who are very determined to be enormous assholes.".

    • > go hit the home page of a tech megacorp (such as Microsoft or Google)

      Much too big for metered data, full of ads, and importantly they all mandate HTTPS these days, which breaks my use case of forcing a captive portal on paid/login-gated Wi-Fi to render.

      example.com is (unfortunately for the IATA) the almost perfect "can I reach the Internet" service: It's unlikely to go away, supports HTTP, is fairly small, easy to remember, and I don't care if a captive portal poisons my DNS cache with a fake response temporarily.

  • I think we're on the verge of a big disruption coming for the example.com's business. I can see a SaaS opportunity. We can use AI to speed up time to market.

    /s

    • example.com-as-a-service, although XaaS is no longer hip so now it'll be example.ai, an AI that will generate an example.com style landing page using frontier AI models. $20 / month for the beginner plan (100 requests/month), contact us for pricing.

I'm wondering how many automated tests this change broke.

Yes, I know it's not the example.com's fault, and it's a side effect of Hyrum's Law:

> This is not a service, avoid relying on it for testing and monitoring purposes.

Don't we all have a few fragile tests?

  • If 1.1.1.1 ever stops responding to pings…

    • … then you'll be back in the world before CloudFlare set up its public DNS service, which is also the world where taking over 1.1.1.1 in the first place came at the price of having to measure how many people had ignorantly or lazily put four ones into somewhere that they had to fill in an IP address, and how much bogus and positively risky (to them) traffic there was being caused by people just thinking 'I will just use 1.1.1.1, which is not a real IP address.'.

      Just before COVID, a random unidentifiable person reported that 1.1.1.1 saw 60Mb/s of ICMP echo traffic. When APNIC first experimented with making it a valid network almost a decade before that, it was being sent 50Mb/s of general IP traffic. Amusingly, a side-effect of what CloudFlare has done is that it has stopped all of that traffic leaving the edges of the Internet, and funnelling in to one big central place.

      There are those who remember the risks of 'just use 1.1.1.1' and how the people who did that used be characterized as 'bad Internet citizens'. The ServerFault answer (q.v.) is from 2011.

      * https://serverfault.com/a/339782

      1 reply →

    • I don’t use this one, because I remember when long, long ago it was in some random IP address block belonging to someone, and this particular address didn’t reply to ping.

      Likely for good reason, even back then there would have bound to be lots of misconfigured endpoints trying to access 1.1.1.1, so just blocking it at the earliest point possible kept at lot of the annoyance away. Nowadays, it’s an anycast address, so it’s slightly less bad.

      But for me, old habits die hard.

    • I've already seen a couple of train hotspots respond locally to pings directed at 1.1.1.1 and 8.8.8.8, apparently in effort to convince devices that they are on a good network event if the internet itself is broken due to being in the tunnel.

    • > 1.1.1.1

      Pinging such an address is inherently a troublesome practice. This address, like many public DNS servers (resolvers as well as root and authoritative ones), uses "anycast" routing methodology.

      https://en.wikipedia.org/wiki/Anycast

      Pinging an anycast address will yield a cornucopia of different results. Of course, people who naïvely "ping" a recognizable or easy-to-type IPv4 address get what they deserve, especially when they enshrine it into software, unit tests, or the LLM coughs up such tokens on their behalf.

      Fundamentally, the question is "what do you really want to test?" by pinging a particular IPv4? Do you want to test Layer 3 connectivity? Test your ISP's backbone and connectivity? Test only your upstream router? Test the existence of ICMP in your stack and theirs?

      ... the possibilities are endless. Your router can do anything. Ping zombo.com.

      24 replies →

  • that's a really good point I'd not considered but if you just hash the response and the followups remain consistent (they do in this case)... you're gonna do just fine.

> there's a gradual opacity transition

Looks like they removed this and instead just show all languages with no CSS animation now.

  • Yes, the revised version that alternated through the translations was posted a week ago on Monday. It was revised to no longer do that on Friday based on reasonable feedback that it wasn't the best idea for accessibility. Now all the translations are presented together, but your preferred language will be bumped to the top based on your browser language preference.

  • Oh that's good, I had that complaint when it first changed. It was difficult to read the entire chunk of text before it transitioned to a different language. And then who knows how long it took to loop back round to english

  • Aww, I was wondering if I was just looking at an older version. How disappointing. But I suppose, unsurprising given the conversation here. I'm sure such transitions would be bringing a surprising amount of instrumentation down.

    It still probably is as it is now. But there's better arguments to support localization than transitions.

    • For some reason the localization still requires javascript... (I'm pretty sure the transition could have been done in just CSS as well)

      1 reply →

Discussed here a few days ago: https://news.ycombinator.com/item?id=49915060

  • And the "statement" in this article is the text from that email, disingenuously edited. I'm not sure why, but it rubs me the wrong way.

    • The hilariously ironic thing is that Dunk, a Google Engineer, went out of their way to make a hyperlink of "example dot com" so that people could tap and visit the site, even where Davies' email specifically reiterates that the domain is for documentation purposes only and nobody should ever be actually visiting the site!

      McCarthy of DebugBear clearly noticed this admonition and perhaps the mistake as well, because they have carefully highlighted "example.com" without linking to it, although they apparently have visited the site in order to copy and cite screenshots and unpack the CSS, and describe an extensive history of it.

This has rendered my usecase for example.org worthless. I used this website several times per week to clean my glasses as it provided a nearly completely white website - optimal for allowing me to spot smudges on my glasses. It is now black by default for me, or grey.

I am devastated.

The page mentions example.com 14 times and not a single one is a link

Kinda interesting that this is getting so much attention.

Ultimately, the example.com domain is just there so you can use it in documentation or code examples. Your expectation about the actual example.com domain should basically be none at all, maybe with the exception that it's hopefully not doing actively malicious things like serving malware or running a catchall mailbox feeding spammers.

Whatever HTML they server or if they serve anything at all... shouldn't matter.

> There is no requirement there is a HTTP service present on the host in order to fulfill its purpose, we just operate it as a courtesy.

I guess this is also done to prevent bad actors from abusing the fact that this domain is hit by people who might not know what they're doing (the ones copy-pasting code without reading it)

  • More the DNS and DNSSEC and the like. Whether or not there is actually an HTTP server responding is irrelevant to whether or not those securely point anywhere but a malicious system.

  • Yeah there’s definitely a lot of sensitive data that gets sent to the domain just because of people not changing configs

I appreciate that there must be a lot of traffic hitting this web server so maybe every little bit of savings counts, but I kinda wish the HTML wasn't so heavily compressed.

I remember getting my start with web development by simply reading the source code of sites I found interesting and trying to recreate them. example.com isn't exactly very interesting but it feels like compressing the HTML isn't in the spirit of things either.

On a side note I'd love to see how complicated (or maybe simple) the hosting setup for this site actually is behind the scenes.

  • It's static content in Cloudflare CDN. Seems unlikely that many requests actually hit any kind of origin server. If I were building something like this the origin would be Cloudflare R2 (or similar) object storage, with a very long cache lifetime. Nothing to update, nothing to maintain.

    But beyond that, what are you referring to as compression? When I look at the source I see a VERY short easily human-readable HTML page. It doesn't have newlines, but I wouldn't consider that compression. It also references a short, but non-obfuscated javascript file at https://example.com/s.js .

    Maybe I misunderstood what you're referring to...

I'm not sure I believe that IANA's goal of reducing serving costs is met by a site where each letter is wrapped in a <span>...

separate shower thought: Microsoft have used contoso.com as the example domain in their docs for 25+ years. I bet the logs for that domain are absolutely wild.

> Since most of the traffic to the site is automated it tends not to fetch the Javascript file, reducing overall data requirements.

Well, IATA – give me api.example.com or sniff my user agent and I'll be out of your hair :)

This is mine now! <link rel=icon href=data:,>

  • I put this on all my websites that don’t have a favicon. I hate the default browser behavior of making a request to /favicon.ico without being asked.

So they made a prior tweak to reduce fetches of favicon.ico ( by link rel="icon" href="data:," ) but why do they still serve the overlarge meaningless html page to requests for robots.txt ?!

Given that they have gotten spiked by automated requests lately, aka agents, wouldn't this at least be respected by the big players?

Also, as they are using Cloudflare, wouldn't a discussion (or a note from IANA or CF) about how they configured CF request rejection and how one should love CF's flat rate static serving be appropriate?

Am I missing something?

  • It's quite sad to see incompetence at these levels. This is a static page that loads JS. They even inject styles via JS...

    • It’s not incompetence they are intentionally doing as much as possible via javascript to reduce their bandwidth costs. This is because most access to the domain is automated (not using a browser, using curl etc) and doesn’t load javascript

      2 replies →

It's been about 10 years since I last saw this site and accidentally visited it a few days ago and thought "I don't remember it looking like this"

Really funny coincidence, I noticed amazon wasn't loading a couple hours ago. Thought it was my internet so went to example.com to check and noticed the redesign. Figured it was a while ago though.

Maybe this is the most web-development thing possible: even example.com eventually became a frontend project.

> Along with introducing multi-language support, the JavaScript code also inserts an SVG book icon.

Wait - using JS for dynamic content is understandable, but why using it for inserting a static SVG?

  • I wonder if it's injecting both through javascript to minimize breaking people's tests. Trying to reduce dealing with non-ascii characters and svg tags.

  • Reducing egress bandwidth, if you have automated clients that don't support JS you save precious bytes from being served by not embedding the SVG, which at example.com scale may be worth it

  • Why does this site need JS at all? It appears to inject all of the other languages via client side JS. Why can't they all just be served from the server?

  • Simple answer is the article is wrong, I tried it with disabled JS and still see the SVG.

    The whole article reads like something put together with AI, so maybe it’s not too surprising.

    • You may want to check your settings again or clear you cache as there is definitely a `s.js`[0] file that inserts the `<svg>` element into the HTML DOM[1], which you can see does not contain the element itself.

      0

      ```

      var B = document.body, P, p; B.children[0].insertAdjacentHTML("afterend", "<p lang=ar dir=rtl>هذا النطاق مُخصص للاستخدام في أمثلة التوثيق دون الحاجة إلى إذن. هذه ليست خدمة، يُرجى تجنب الاعتماد عليها لأغراض الاختبار والمراقبة.</p><p lang=zh>该域名仅用于文档示例,无需获得许可。这并非一项服务,请勿将其用于测试和监控目的。</p><p lang=fr>L’usage de ce domaine est réservé à des exemples de documentation, sans autorisation préalable. Il ne s’agit pas d’un service ; son utilisation à des fins de test ou de surveillance est à éviter.</p><p lang=ru>Данный домен предназначен для использования в примерах документации без необходимости получения предварительного разрешения. Это не сервис; не рекомендуется его использование для тестирования и мониторинга.</p><p lang=es>Este dominio está destinado al uso en ejemplos de documentación sin necesidad de permiso. Esto no es un servicio; evitar utilizarlo para realizar pruebas o monitoreos.</p><a href=https://iana.org/help/example-domains>Learn more</a>"); P = [...B.querySelectorAll("p")]; P[0].lang = "en"; navigator.languages.some(l => p = P.find(p => p.lang == l.split("-")[0])); p = p || P[0]; B.prepend(p); B.insertAdjacentHTML("afterbegin", '<style>svg{display:block;margin:-2.75em auto 0;opacity:.55}p+p{font-size:.875em;opacity:.6}</style><svg viewBox=0,0,20,20 width=44 height=44 fill=currentColor aria-hidden=true><path fill=none stroke=currentColor stroke-width=1.3 stroke-linejoin=round d="M6 4H3v12q4 0 7 1.5-1-3.5-4-4.5V2q3.5 1 4 3v12.5q3-1.5 7-1.5V4q-4.5 0-7 1"/><g transform=rotate(-6,13.6,8.3)><path id=q d="M11.5 6.6h1.8v1.8l-1 1.6-.6-.3.8-1.3h-1z"/><use href=#q x=2.4 /></g></svg>')

      ```

      1

      ```

      <!doctype html> <html lang=en> <head> <meta charset=utf-8> <link rel=icon href=data:,> <meta name=viewport content="width=device-width,initial-scale=1"> <title>Example Domain</title> <style> html { color-scheme: light dark; background: light-dark(#eee,#222) }

                  body {
                      font: 16px/1.6 system-ui,sans-serif;
                      max-width: 26em;
                      margin: auto;
                      padding: 25vh 2em 2em;
                      text-align: center
                  }
              </style>
          </head>
          <body>
              <p>This domain is for use in documentation examples without needing permission. This is not a service; avoid relying on it for testing and monitoring purposes.</p>
              <script src=/s.js></script>
          </body>

      </html>

      ```

      1 reply →

It seems that they changed it again and now there is minified HTML with english message + simple script that injects the other languages and the icon, no animation. Which to me seems much more sensible.

I actually noticed that! I was debugging some HTTP proxy and typed out an HTTP/1.1 request by hand in netcat, and was wondering why I saw a giant blob of dynamic nonsense instead of a small bit of markup.

(This was when it had the language scroll though, I think moving the extras to JS should have resolved that issue; maybe I was misremembering the details too.)

example.com is not a user-facing service. I don't want to disparage the designer, but it's not meant to be pretty. It's meant to be small so you can copy its response to an automated test or visually verify its correctness, or just out of the bandwidth consideration you'd still be serving it to billions of requestors, even if you insist it's not meant to be used that way.

  • I believe your use is what they're trying to discourage.

    example.com is meant to be legally allowed to be used in text such as "You visit a website (example.com) to browse the internet"

    It is not meant to be queried by automated tests or used as a service.

    • I never queried it _automatically_, but many projects do. They might not have set out to provide that use, but what happened has happened, and breaking this implicit contract for a silly redesign is an odd choice.

  • > and was wondering why I saw a giant blob of dynamic nonsense instead of a small bit of markup.

    It's 4.5x the size of the original. Which sounds bad, until you notice this means it's 2540 bytes and serves the explanatory text in 6x the number of languages. And it's now served with brotli compression, for a total of 1713 bytes. Or 334 bytes if you only request the HTML (which still has a usable page with the full English version of the explanatory text), like a basic scraper or a health check would. So for the vast majority of traffic, it's now half the size of the old version.

    I notice it's been through several revisions, the pre-2025 version of the site most people are familiar with is 1270 bytes because it didn't make use of any minification, and it also triggered an unnecessary `/favicon.ico` request because it didn't use the trick to cancel the request.

  • > It's meant to be small [...], even if [...] it's not meant to be used that way

    It is not, in fact, _meant_ to be used that way.

What should I use for example URLs in my testa.

I just wonder how much unintended traffic they receive.

eg If they put DNS, NTP etc on it... Likely billions per hour or something equally ludicrous.

Deluge is likely an exponential understatement.

I did not know about that empty favicon trick, and I will be adding it to all my base HTML templates for my Flask projects where I get annoyed at all the 404s scrolling past as my browser keeps requesting a favicon that will not exist in that form.

I just don't understand why the operator, IANA, has to use Cloudflare for example.com

It cannot manage a one page website. WTF

There are no page "aseets", no need for images, CSS, etc. It was a text-only website to test connectivity

iana.org forwards to Cloudflare, too

Fortunately the FTP server service still works

Without assistance from a third party

If it's been a sensible decision to use Cloudflare for some period of time then why did IANA wait until now

(Yes, I know they used Akamai in the past)

  • Cloudflare is the latest in a number of different CDN providers we've used to serve this over many years. I guess the question is, why is it important not to use a CDN?

    • HN is currently anti Cloudflare. The only thing worse probably would’ve been to serve the static files on GitHub.io

  • Same reason everyone else uses CF. Static page CDN only became too cheap to meter ~16 years ago, but if CF was around in the 90s IANA would have used it in the 90s too

  • NB. IANA isn't responsible for "root servers"

    It's only responsible for root.zone, root.hints, .arpa and .int zones

    AS112 is a volunteer project not a company

  • If it's a name in com/net/org only meant for documentation then why serve a page there for decades. If traffic is a problem then take it offline

    Years ago IANA started requiring a user-agent header

    FTP access to root.zone remains

  • Well, it's a popular website. By using Cloudflare I think they will save a lot of bandwidth and traffic because the page and assets can be cached.

it's nice, and it surprised me when I saw the redesign.... I use it to navigate into captive wifi portals that always seem to be misconfigured.

  • Same here! Yes, I used it as the well-known site that supported unencrypted http and no HSTS. Yes, I was one of those guys using the site "as a service" rather than simply documentation. Admittedly, it was perhaps interchangeable with other sites, but since it reliably worked for that purpose, I couldn't be arsed to find other ones.

    Isn't there a dedicated site called nohttps or something? NeverSSL? I just tried http NeverSSL, and it redirected me to an https page with a random hostname and an Amazon SSL certificate!

    Does example.com still function this way, with http and no HSTS? I noticed that my Chrome browser was immediately redirected in the customary way.

I find the text shown on this site passive agressive.

When a newbie learning programming sees this message, then this is a downer.

"Hello World from example.com [more info]"

  • I find it pretty neutral, if maybe a bit bureaucratic. It explains what this domain does, and what it’s not supposed to be used for – that’s it.

  • >When a newbie learning programming

    A newbie shouldn't test their programs using example.com

    • Nonsense. One may very well explain to a newbie how to link to an external site using example.com as target. Though I would not do it, with that layout. I would link to Google probably.

Static test is still, IMHO best, but if they want that fancy transition they could at least have used a gif. All that js is terrible overkill.

  • The language translation animation only lasted a few days. Now it’s static with English at the top and translations below.

  • You understand that the GIF would be larger than the JS, right? (Apart from other problems with this idea.)

  • Overkill for a web of humans loading sites in browsers. Not overkill for a dead internet with swarms of agents DDoSing everything in sight.

We (IPinfo) have a practice of adopting low-maintenance, high-utility services. Generally, we adopt websites that would have become defunct and run them as services.

Even though IANA says example.com is intended for documentation purposes and not as a service, I feel that it nonetheless serves as a service to the broader internet. I think there are some cornerstone services on the internet, regardless of the maintainers' intentions or their legal definitions.

For example, we ourselves sometimes have to recognize that we are not a standard API service. Considering that we expect to process 3 trillion requests this year, a major outage could take down a good chunk of IT systems everywhere. So, we invested in infrastructure to avoid outages. We then started adopting other cornerstone services and running them indefinitely because we might as well support the users who depend on them because we have infrastructure to support them and us.

  • For a moment I thought you were saying ipinfo runs example.com.

    Instead it just seems to be an advert for ipinfo on a post about example.com?

    • Not an advert. I wish we ran example.com. However, we run a few other services.

      The issue with example.com is this statement:

      > This domain is for use in documentation examples without needing permission. This is not a service; avoid relying on it for testing and monitoring purposes.

      The problem is that, disclaimer or not, if a website provides a useful utility, people will use it as a service.

      If example.com breaks, IANA can reasonably say it was never intended to be stable. But that does not change the fact that people will use it for testing and monitoring.

      What we do is adopt legacy services whose maintainers can no longer afford, want, or have the resources to maintain them, and invest in keeping them running reliably.

      1 reply →

  • Example.com is one of the sites I visit most often for troubleshooting my connection on the go. It's great for tickling a captive Wi-Fi login that didn't trigger properly.

  • I think what you describe is exactly right, it has organically become a service and it is maintained with that in mind. That doesn't mean you shouldn't be clear about what its for and what should be avoided. Otherwise it is setting up an implicit contract that it will service those needs without limitation which turns it into an even bigger dependency.

IANA and ICANN should be moved under UN ITU from a non profit, so that they don't make breaking changes without approval.

What would have been nice is that depending on the visitors IP address’s region, showing a localised message instead of fixed number of languages

  • This feels like a “falsehood developers think about localization.”

    It’s always funny when I get French YouTube ads. As if YouTube is desperately trying to offload the adbuys anywhere they can by pretending that Canada must mean French.

    • I hate this with a passion. Google is very guilty of this. Their AI summary very often insists on replying in the (IP) local language, nevermind the language of my HTTP headers, Google profile, or the actual natural language request...

  • I think the whole point is for it to be a static site that is easily distributed with little-to-no overhead, as it probably receives a non-trivial amount of traffic.

    • Yep, that's exactly their reasoning:

      > As it tends to be heavily trafficked, the overall bandwidth is a key consideration

  • That assumes that (i) every region has a primary language, and (ii) everyone in that region speaks that language, both of which are false.

    (And false often enough that guessing language based on IP address works badly in practice, I hear.)