IANA's email about why example.com changed
99 points by videah
99 points by videah
For reference, what it was like a few days ago: https://web.archive.org/web/20260928000041/https://example.com/
Example DomainThis domain is for use in documentation examples without needing permission. Avoid use in operations.
That second paragraph itself was a change made late last year; for some years before that (e.g. 2020), it had read:
This domain is for use in illustrative examples in documents. You may use this domain in literature without prior coordination or asking for permission.
And before that (e.g. 2015) it had read
This domain is established to be used for illustrative examples in documents. You may use this domain in examples without prior coordination or asking for permission.
They’ve also fiddled with the styles a few times, mostly to make it trivially worse in my opinion, or to partially roll back such a change. To my knowledge, this new one is the first time it’s included scripting or multiple languages, and I very much dislike the technique: you look away or even read slowly, and it’s replaced with something illegible; pretty, perhaps, but significantly worse.
In light of these things, I’m very baffled by the line from the email
one of the changes we made this week was to split the page content into a more basic page, augmented by a separate Javascript file with additional content beyond that.
when they’ve actually made it significantly more complex than it’s ever been, by adding JavaScript and animation and multilingual content. Still by no means complex, but at least three times as complex as it was.
With how they’ve cut the wording down over time, and more recently finally minified the response, they have cut bandwidth down, but it was never a big difference. Though I have golfed the example.com response multiple times in the past for fun. I know that website well. I remember noticing various tiny style changes and when they switched from talking of examples to literature. Though funnily enough I don’t remember noticing the big change at the end of last year. I must be slipping.
The comma splice in the new (English) text makes my eye twitch.
Why? It reads fine.
With that phrasing, it should definitely be a semicolon. They even use a semicolon in the French and Russian.
It should be a semicolon, the clauses are independent. A lot of people make this mistake, that doesn’t make it right. One of my teachers said “if you can replace it with a period, it should be a semicolon”, she was a great teacher. I hope these are clearly examples of what not to do, I know sometimes irony doesn’t come across on the internet.
It would probably save IANA (and us) a lot of trouble by just making it serve the smallest valid HTML page with a 200 response code.
I wonder if this would lead to them getting lots of emails from concerned citizens about their website being broken ("Dear Sir Slash Madam"). Followed by them having to add a "this site is not broken" disclaimer to the previously blank 200 reply :D
Smallest valid HTML page:
<!doctype html><title>x</title>
(Title is mandatory in general, though things like HTML email are allowed to omit it.)
But at that point you might as well serve an empty text/plain response.
Or if you really want to cause trouble, a 204 (No Content) response. See how browsers handle it and watch the confusion.
Oh. I expected to see a blank page, but on Firefox for android tapping that link shows a load bar but then stays on the same page.
Yep. I think that’s how it’s always been across all browsers (as long as status codes have existed, anyway). 204 doesn’t produce a document, so the browser stops the navigation. These days such behaviour is described in the HTML spec, and the section begins “Welcome to the dragon's maw.”
Fun fact: in the past I worked on Chrome's bounce tracking mitigations, and we managed to generalize our detection algorithm to catch abuses of 204 responses that would silently set tracking cookies. (Did we actually see it happening in practice? I can't remember. But there was definitely a privacy researcher who posted a POC)
It doesn't seem to say that the title must be non-empty, only that the tag must be present, so we can shave off another byte!
The title element:
Content model: Text that is not inter-element whitespace.
It must contain text, and that text must not be empty or only ASCII whitespace.
This website was built to fit into a single packet. https://github.com/diracdeltas/FastestWebsiteEver
Saw this post on here about 30 minutes ago and the blog post below came bursting out of me. Haven't written anything about this topic in months,
The new example.com is a great example of a Pause, Stop, Hide bug
Very much appreciated coming to Lobsters and becoming inspired to re-engage with some of my fav shit about computing. A nice reminder of why I keep coming to this site.
Huh. I visited example.com literally just a couple days ago, for the first time in many years, and was like "oh I guess they updated it from what I remember, I wonder when that happened."
Apparently the answer is "shortly before I visited the site!"
I don't like it. The javascript is completely unnecessary, and imo just makes the page distracting. example.com used to be a super simple page that I would load to make sure my internet was working, and now it feels much more heavy (even if the JS is small, the animation and language changes bug me).
Very interesting that you got an email back; also quite intrigued by the message of "be thankful you get a site at example.com at all, we're not obliged to put one up".
I mean sure, but it still feels like the effect they were going for could've been achieved in a more accessible manner.
By letter, the only thing IANA guarantees is that no entity other than IANA will have control over example.com . The point of the domain is to just be a safe domain you can list in configuration files and documentation that's immediately understandable as a domain name.
The HTTP service is actually a surprise to me, I always thought the browser just had a preloaded response to example.com, the page always felt a lot like it was styled in a similar way to internal browser UIs.
Arguably it shouldn't resolve to anything in the first place, since it creates unintended meaning that the domain shouldn't have. (Or in other words, Hyrum's Law.)
They could let any hosting provider willing to host the domain/page do so, with the stipulation that it must remain accessible. The provider can recoup the cost by hosting ads, analysing traffic etc.
Eh I don't like this idea. example.com is explicitly set aside as a dummy domain, making it (somewhat) part of the infrastructure of the Internet. Handing control over to a private entity is never a good idea IMO, especially if it's making them commercial money.
Built-in pages in browsers for those domains can be a great idea, actually. The infrastructure cost would be zero and it would still be clearer to the occasional novice user what those domains are.
I wonder if browser developers would be open to that idea.
I think that built-in pages are a terrible idea because the site will be different in each browser and other tools like curl won't implement a page at all leading to confusion all around.
Agreed, though that doesn't help web frameworks/cURL-like libs from trying to reach out. But yes, I'm sure a lot of traffic is due just to regular browser fetches.
Lots of people accidentally send stuff they shouldn't to example.com. IANA is doing a good public service by not letting data collection business near it.
relevant: https://lobste.rs/s/muofgb/deleteduser_com_15_pii_magnet and I didn't see an obvious submission link for https://arstechnica.com/security/2026/08/a-researcher-bought-noreply-net-companies-started-sending-him-secrets/
As of right now, this is the response they serve. It's 713 bytes (excluding HTTP headers):
$ curl example.com
<!doctype html><html lang=en><head><meta charset=utf-8><link rel=icon href=data:,><meta name=viewport content="width=device-width,initial-scale=1"><title>Example Domain</title><style>html{color-scheme:light dark;background:light-dark(#eee,#222)}body{font:16px/1.6 system-ui,sans-serif;max-width:30em;min-height:100vh;margin:auto;padding:4.75em 2em 20vh;box-sizing:border-box;display:grid;place-content:center;text-align:center}</style></head><body><p>This domain is for use in documentation examples without needing permission. This is not a service, avoid relying on it for testing and monitoring purposes.</p><a href=https://iana.org/help/example-domains>Learn more</a><script src=/s.js></script></body></html>
$ curl -s example.com | wc -c
713
If their primary objective is cutting bandwidth, then I'd suggest something like this (274 bytes after removing unnecessary whitespace):
<!doctype html>
<html lang=en>
<head>
<meta charset=utf-8>
<link rel=icon href=data:,>
<meta name=viewport content="width=device-width,initial-scale=1">
<title>Example Domain</title>
</head>
<body><a href=https://iana.org/help/example-domains>Understand this page</a></body>
</html>
The link is already part of the page now, and all real users can just click it to understand the page; the information is all there already.
If you’re golfing minification, you can remove these parts without making it invalid or changing the meaning of anything (simplifying slightly, html, head and body start and end tags are optional, and the document is already declared UTF-8 in the content-type header and even if it weren’t it wouldn’t matter as the document doesn’t go beyond ASCII).
<head>
<meta charset=utf-8>
</head>
<body>
</body>
</html>
You can also drop the ,initial-scale=1 with no observable change in behaviour on realistic browsers. (It will only make a difference if one of the words in “Understand this page” is wider than the viewport, or on early iPhone browsers on rotate.)
You could also drop the https: and write <a href=//iana.org/…>. From http://example.com, that’d make it a link to http://iana.org/help/example-domains rather than https://…, but that doesn’t really matter.
Rebelling a little more, you could drop <html lang=en>. Nothing will implicitly trust a declaration of English anyway because it’s been abused so much.
And <!doctype html> because who cares about quirks mode for something like that? And ", " and </a> because nominal validity really doesn’t matter.
<link rel=icon href=data:,>
<meta name=viewport content=width=device-width>
<title>Example Domain</title>
<a href=https://iana.org/help/example-domains>Understand this page