Comment by pimterry

18 hours ago

For the desperate people whose tests all just broke, I have a page on my public endpoint testing server that exactly reproduces the classic design: https://example.testserver.host/. You can just use update the URL and go back to blissful ignorance.

Also open-source and self-hostable: https://github.com/httptoolkit/testserver. Lots of other endpoints too, full docs here: https://testserver.host/

If you do have tests relying on it... stop it:

> This is not a service; avoid relying on it for testing and monitoring purposes.

  • Before this submission, it genuinely never occurred to me that people would actually have tests that rely on example.com being up, let alone depend on its content.

  • Opus 5.5 in Claude code added a unit test checking DNS and internet access using example.com as the target on a project I'm building yesterday. It's an agent sandbox (I know, yet another), so the call was expected to fail, but still... It should have at least targeted a captive portal endpoint or a project owned domain.

    I caught it in review but thousands of others won't.

    That ship has sailed I would say.

  • So is wrong to use captive.apple.com for tests as well? It's nice to know your network can reach the internet and these pages are generally fairly reliable.

    [1]: https://captive.apple.com/

    • These pages are unfortunately getting special treatment from quite a few networks these days, among other things to avoid iOS users getting stuck in a loop of trying to connect, and getting disconnected by the OS due to a "non-working connection" for local-only networks like in-flight entertainment systems.

      It's a shame that we don't have any standards for the concerns of canonically testing Internet reachability and for authoritatively redirecting network users to a captive payment portal (without having to resort to ugly hacks that often break with TLS).

      2 replies →

    • If they say that it's not intended as a reliable service for testing purposes it can't be that reliable, and they might take it down or change the structure arbitrarily at any time, etc.

      So yeah I would pick something simpler for a network access test probably?

    • Just don't blame the user and/or their internet service when the service you're relying on inevitably goes down.

  • I have been naively using example.com in the browser. WHATWG URL throws if there is no origin when constructing the URL. Web apps that need to construct _just_ the pathname must go through this song and dance. `new URL("/blah", "https://example.com").pathname` This isn't relying on any external example.com service but I'm learning the lesson.

What kind of tests would this break? Aside from the advice on the page itself (which, iirc, is new anyway), i'm wondering why any testing would actually involve the contents of design of the page. Just a weird 'sanity' check?

One of the critical things I use example.com for is triggering wifi login portals as it doesn't not use SSL. Certificate pinning and all that fancy stuff has made it so the browser has an absolutely awful time figuring out what to do when https://google.com does not present itself as the same host it was earlier.

Do you do any sort of rate-limiting to stop people/bots from hammering it (accidentally or otherwise)? Or do you just let it fall over under load.

> For the desperate people whose tests all just broke...

The web page at example.com is maintained as a courtesy by IANA in order to explain the purpose of the example.com domain to wayward humans.

In the nomenclature of RFC 2119, one MUST NOT design computer systems that rely on the correct operation of an HTTP server at that domain. [0] Plus, it's _really_ rude to pound on a small-scale service being provided as a courtesy... go hit the home page of a tech megacorp (such as Microsoft or Google) or the status page for a major CDN (such as Cloudflare or Akamai) instead!

[0] I expect that someone here will want to pop up with a "gotcha" where they say something like "Oh, but IANA's email says that automated use is strongly recommended against, rather than prohibited and besides, they can't actually stop me from doing it!". To that, I reply "Sure, and standards-writers can't actually stop implementers that do the profoundly antisocial thing and do the things they MUST NOT. As any adult who's been paying attention to the world around them throughout their lives knows, there's only so much you can do to stop people who are very determined to be enormous assholes.".

  • > the status page for a major CDN (such as Cloudflare or Akamai)

    Would you settle for any old static page served by Cloudflare? For instance, example.com? https://bgp.tools/dns/example.com

    • That they've put it behind Cloudflare doesn't mean it's "served by Cloudflare"

      Maybe Cloudflare gives them a good rate, or is donating service, but it's also possible or even likely that IANA is just using Cloudflare as a vendor, and therefore is paying for all the traffic, which is why they don't want people relying on it or hammering it all the time

    •   In the nomenclature of RFC 2119, one MUST NOT design computer systems that rely on the correct operation of an HTTP server at [example.com.] Plus, it's *_really_* rude to pound on a small-scale service being provided as a courtesy.

  • > go hit the home page of a tech megacorp (such as Microsoft or Google)

    Much too big for metered data, full of ads, and importantly they all mandate HTTPS these days, which breaks my use case of forcing a captive portal on paid/login-gated Wi-Fi to render.

    example.com is (unfortunately for the IATA) the almost perfect "can I reach the Internet" service: It's unlikely to go away, supports HTTP, is fairly small, easy to remember, and I don't care if a captive portal poisons my DNS cache with a fake response temporarily.

I think we're on the verge of a big disruption coming for the example.com's business. I can see a SaaS opportunity. We can use AI to speed up time to market.

/s

  • example.com-as-a-service, although XaaS is no longer hip so now it'll be example.ai, an AI that will generate an example.com style landing page using frontier AI models. $20 / month for the beginner plan (100 requests/month), contact us for pricing.