13 ms·
Before you buy a domain name, first check to see if it's haunted
- bagpuss 2y agoone other thing i would suggest is to set up a catch-all email for the domain and see what gets sent to it, sometimes you can access accounts associated with the domain, socials etc
- meowster 2y agoI have an interesting 3-letter.net I set up a catch-all for personal use and wasn't expecting to get flooded with emails. I was getting business emails, people trying to send money by Zelle, etc. I was kind of hoping to get something good that I could take action on in the market, so I left it on for a little bit, but then I felt bad that people's emails were not getting answered (at least bouncing), so I turned off the catch-all. Oh well.
- e40 2y agoI do that and get the occasional account signup. I also ban addresses that fet sent spam, which happens more than the account signups.
- p3rls 2y agoThe usual version of this is the popular SEO technique of buying an aged domain with a few backlinks and slapping a wordpress on it.
- andrewmcwatters 2y agoI’ll add: and if you lease a VPS, check out its address reputation and reverse DNS record.
- BOOSTERHIDROGEN 2y agoHow?
- NibsNiven 2y agoFind out the IP address of the machine hosting the domain, then do a reverse lookup on that IP address. It might show the last domain hosted on that IP address. Using dig: $>dig yourdomain.tld 1.2.3.4 $>dig -x 1.2.3.4 evilcorp.com
- mmwelt 2y agoI'm not the person you were replying to, but in the past, I've just used an IP reputation checking website, such as: https://www.apivoid.com/tools/ip-reputation-check/ https://www.apivoid.com/tools/ip-reputation-check/
- egberts1 2y agoWebsite unusable: Captcha forever waits using latest Firefox on latest iPhone13/iOS 18.0
- jsheard 2y agoIsn't it pretty safe to just assume that any IP addresses belonging to public clouds, especially cheap ones, have bad reputations?
- deleted 2y ago[deleted]
- account42 2y agoThe individual IPs may not all have too bad reputation but you don't control who shares the block with you and don't have any control over new neighbors - and that is enough for some agressive organizations (Microsoft) to block you.
- dtdynasty 2y ago> Ideally, search engine algorithms would give new domain owners a fresh start. Sadly, I think this would be instantly gamed by abusers. They would release the domain name and attempt to register as a new owner or start repeatedly doing handoffs. It's difficult to tell who the owner is changing between and whether or not the new one is a better actor than the former.
- fhub 2y agoGoogle product manager interview question - Write some code with an LLM tool that leverages a LLM to determine if the new owner of a domain is doing (a) same dodgy thing as prior owner that got flagged (b) different dodgy thing as prior owner but should be flagged (c) something completely innocuous (d) needs further review.
- jsheard 2y agoPlease don't give Google ideas for more ways they can have an algorithm arbitrarily screw you over with no recourse, they're listening.
- fhub 2y agoFollow up interview question. Update the code using your LLM code gen tool of choice that, when someone submits a complaint via an online form, feeds that complaint text back into your LLM to score it again. Points deduction if the candidate ever mentions informing the complainant of anything.
- richardw 2y agoWell, current approach guarantees you’re getting screwed over. Any improvement is beneficial unless it blocks a better approach?
- bruce511 2y agoYou're looking at this from the perspective of a haunted domain owner. And from that perspective your idea is fine. A good technique to evaluate ideas though is to try and view it from different perspectives. In this case from the owner of a non-haunted domain. Can you see any potential problem with your idea when viewed from that perspective? Now, if there are potential problems, consider the relative sizes of the two groups. Do the benefits to one outweigh harm to the other? This technique can be used every day with pretty much any idea.
- lmz 2y agoIf it was easy to reset reputation with search engines what's stopping people from saying "under new management" every once in a while for an existing poor reputation domain? Probably better to just cut their losses and find another domain.
- superkuh 2y agoFor running a mail server every new domain is haunted.
- tonyarkles 2y agoAnd cloud server IP…
- account42 2y agoNot really an issue on the same scale because it resolves itself once the domain registration has aged a bit. IP reputation is stickier.
- chrisallick 2y agothat is amazing
- lefstathiou 2y agoThis happened to me and I found this tool super helpful to get my site unblocked: https://dnsblacklist.org/ https://dnsblacklist.org/ I purchased a valuable premium domain to host a personal art collection (of anime cels). For some bizarre reason, the site was inaccessible from my work computer and it was de-listed from Google even if I typed the url itself into search. I hired a square space specialist to figure out why, to no avail. I then begged our company’s CISO to investigate and it turns out we had some firewall setting on UniFi that blocked the domain because it appeared on a list. Once I checked way back, it turns out that it was as an anime porn aggregator years back. I personally reached out to all the web filters out there (Google, Symantec, bing) and one by one filed tickets for them to mark it as art instead of pornography and it worked. I am now properly crawled on Google but still MIA on Bing, search console is giving me some BS error that’s incomprehensible, typical of MSFT.
- a_t48 2y agoI'd be somewhat interested in seeing the cels. :)
- lefstathiou 2y agohttps://www.neotokyo.com https://www.neotokyo.com I have a +100 cel backlog that I need to catalog and photograph. Was planning to do it this holiday season so check back in.
- Dalewyn 2y agoI... actually remember that address floating around and it indeed was hentai. We're talking like 20 years back. Holy shit, my brain is getting jostled by this sudden tsunami of forgotten memories. EDIT: Digging around on Wayback Machine (obviously NSFW, for the curious), apparently it was actually still around until somewhere between 2018 and '19 when it finally died. The snapshots from around 2007 are peak Web 1.5 design with stuff like affiliate buttons and table layouts. Man I miss that era.
- postcert 2y ago
- ellisv 2y agoI wonder if there’s a market for rehabilitating domain names
- mock-possum 2y ago*exorcizing domain names
- ceroxylon 2y agoYet another valuable use for the WayBack Machine, glad it got a mention.
- mouse_ 2y agoI feel like this should be the registrar's responsibility. Least they could do is give a disclaimer and/or a heavy discount.
- bebrbrhrj 2y agoInteresting. Domain as a unit of trust makes sense until it doesn't. Buying a second hand domain is like a second hand car. But you may not know it is second hand! I think the mistake here is the redirect old to new. That is always risky so only do it if deseprate. In this case I would have done the redirect from new to old. Then just use the new as a vanity url.
- account42 2y ago> Buying a second hand domain is like a second hand car. I have never hear of anyone being denied business because their car has a bad reputation from a previous owner.
- veyh 2y agoSome time ago I noticed that my side project (with a domain that is not haunted) shows up fine on Google but not Bing/DuckDuckGo. So I checked the Bing Webmaster Tools. URL Inspection says "Discovered but not crawled - The inspected URL is known to Bing but has some issues which are preventing indexation. We recommend you to follow Bing Webmaster Guidelines to increase your chances of indexation." That's quite unhelpful. What's more, when I open the "Live URL" tab, it says, in green: "URL can be indexed by Bing." It's a simple static Hugo site hosted on Cloudflare R2 (DNS mapped directly to bucket). https://pagespeed.web.dev https://pagespeed.web.dev gives it a score of 100 in every category. Anyone else had something like this happen?
- shakna 2y agoYup. I've regularly had problems with a static site [0]. Sometimes it's a top hit for my name on Bing, sometimes completely unlisted. Seems to flip back and forth - with that same message you get. It's a handwritten HTML website, enhanced with JS but not reliant on it, hosted on Cloudflare. Not quite a 100 in every PageSpeed category, but just about. [0] https://jamesmilne.org/ https://jamesmilne.org/
- bryanbraun 2y agoOP here, and yes, I've been getting that same message for musicbox.fun. I thought it just needed some time but I requested a fresh index two weeks ago, and nothing seems to have changed. :/
- dazc 2y agoA side effect of negative seo is that some stuff that hasn't worked on Google for a long time still does on Bing (They, Bing, obviously, not being the real target of the attack). I've seen a few sites become de-indexed and the 'give away' is the type of results that first appear when the penalty is eventually lifted. For example, just a dozen or so urls with really weird query strings that never existed before. The real stuff does come back after time though and, in my limited experience, it's a one-off incident. Just to add, not many sites are insignificant enough not to attract negative seo - especially this type of low-level, zero cost malarkey.
- romanhn 2y agoAnother "haunted domain" check is by trying to post about it on social media. I ran into this with my current project's domain name. After building an MVP and trying to test the social sharing functionality, I found that Facebook was blocking the domain outright. Turns out there was some spamming from it years ago. Getting it unblocked was extra fun, as the page to request manual review was itself broken! Thankfully I knew someone on the inside who alerted the relevant team, but the whole experience was quite the novel speedbump.
- nicoloren 2y agoI faced the same issue with one of my project. But, as i don't know anybody at Facebook, I left the domain and buy a new one.
- survirtual 2y agoSo much of the world is still based on who you know. This is a bug in our society I would really, really like to see fixed in my lifetime.
- mewpmewp2 2y agoI think with AI it is going to become the opposite. You only trust who you know in real life and ignore everything else.
- r2_pilot 2y agoHuh? Weird. I only trust the AI and ignore everyone in real life life. (/s for the humor impaired)
- mschuster91 2y agoThe fix is called "legal system", or rather, also making it accessible for individuals and small businesses against the large mega corporations without risking getting bankrupt in case of losing. And companies that continuously lose in judgements get fined progressively until they establish enough support infrastructure to not be a burden on society.
- e_y_ 2y agoNot quite haunted but I've had people report that my website hosted on a .quest domain is blocked on their work computer. My best guess is that their filter thinks it's gaming related (it's not) or maybe they just block all "weird" domains.
- drilbo 2y agounfortunately, blocking newer TLDs altogether seems common
- moribunda 2y agoBasic SEO stuff, you have marketplaces that check history, you have domain search engines aggregating data from multiple sources - not only ahrefs. Checking web archive is a basic operation to test if site was hosting anything fishy - not only pirated stuff or porn - often websites has been hacked and changed into link farms or simply were bought on aftermarket simply to use it's SEO value to pass the strength to other domains. Anyways good point regarding email filters.
- rsingel 2y agoNot always the easiest thing to do. A haunted domain could have been haunted 15 years ago. And Google refuses to tell you why or fix their system. Just one more place where the web gets screwed by a company too big to have to do basic customer service.
- aabhay 2y agoIn their defense (and I don’t defend Google often), addressing this really well means: - knowing all the complexities of every local, state, federal, international jurisdiction that might interfere with the whitelist - awareness of the content in question which could be millions of subpages - a customer support team that is definitely not incentivized based on tickets triaged per day, but is somehow incentivized to spend hours on “whale” tickets. - going through ticket history and solving the problem for everyone now that its policy to solve this - dealing with the inevitable rush of fraud that follows every tiny change in google systems
- praptak 2y ago"Ideally, search engine algorithms would give new domain owners a fresh start." I don't think it's possible to fix this problem without also helping bad actors. Maybe it's a problem that just isn't worth fixing. Just don't buy preexisting domains unless it's a project big enough to justify the necessary cost of due diligence.
- lukan 2y ago"Maybe it's a problem that just isn't worth fixing." There is a finite amount of short, memorisable names.
- 6031769 2y agoBut also an ever-increasing number of TLDs under which to register them.
- barryrandall 2y agoBut only .com actually matters.
- xp84 2y agoThe really bad actors just buy and discard new domains daily and silly blacklisting techniques are powerless to prevent that. I don’t think they renew and come back to try to use their domains years later.
- matheusmoreira 2y agoThen help them. If a few bad actors is the price of a free internet, so be it. I'd rather deal with those than have a whitelisted internet where you need permission to start a website.
- viraptor 2y agoI've had an opposite experience. One domain I bought was used for an entirely different purpose in the past, which got linked on a Wikipedia article in references. This gives me some good link juice and at least matches the geo area of the previous business. Since it's an extremely niche entry and low on the list of references, I decided to be slightly naughty and not touch it for a couple of years. Not sure what's the opposite of haunted in this case, but it was just as surprising.
- alentred 2y agoEnchanted?
- benreesman 2y agoAs someone who knows what active persecution on this site is I relish the opportunity to say what I really know under a pseudonym.
- markx2 2y agoAutomattic.com was bought (no idea if it was unregistered / acquired) by Matt Mullenweg when he set up the company. He also bought https://a8c.com https://a8c.com. Here in the UK with EE/BT that correctly redirects to automattic.com, but it might not for you depending on your ISP. The wayback machine shows adult content links prior to the domain being put on sale, hence the blocking.
- bagpuss 2y agosee also landslide.com - a domain that should never have been reused imo
- miragecraft 2y agoHaunted is a weird way to call them, these are stigmatized domains.
- Arwill 2y agoStigmatised would be when it commonly/publicly has a bad rep.
- miragecraft 2y agoThat’s pretty much what happened to those domains.
- Arwill 2y agoNo, those domains are completely fine, they are just marked as untrustworthy on some obscure google list.
- miragecraft 2y agoThat’s a contradictory statement.
- recursive 2y agoNo. There's no general stigma. It's just the one list.
- evilotto 2y agoThis happens with physical addresses too, for similar reasons. The ABC (Alcoholic Beverages Commision) tracks complaints against physical addresses, and too many violations will get an address banned from permits. Then a new owner comes in with a new business and gets mysteriously denied for a liquor license, even years later.
- AStonesThrow 2y agoIt is customary to revoke the right of a business to name itself if there were too many violations. If you've ever gone to a nightclub or bar which has no name, only its street address number, that's what has happened there.
- kortilla 2y agoHow can a business function without a name? So much tax paperwork requires a name. Is it just a sole proprietor that files everything under the owners name?
- AStonesThrow 2y agoIt has a name, but that name cannot be different from the address, like "The 1415 Club" on 1415 Main St.
- rvba 2y agoSounds like a very stupid custom
- 752963e64 2y ago[dead]
- christina97 2y agoTLDR: when you rent anything, double check who rented it before you and what they did with it to make sure it’s in good condition.
- ozim 2y agoConversely when you drop domain don’t forget you might have accounts on emails or some DNS verification in services that you better explicitly discontinue before just dropping domain.
- Havoc 2y agoAlso be careful connecting new domains to cloudflare. It has a habit of adding old info from presumably a previous owner. Managed to get a takedown notice thanks to that idiotic "feature" while not even aware the domain is serving anything
- xxdesmus 2y agoPlease drop me an email with what you’re seeing - justin (at) cloudflare.com ? That doesn’t sound like old info - that sounds like someone might still be reporting it for abuse even after the domain changed owners.
- Kalanos 2y agoThe domain could also have been used to run spam email campaigns, meaning that it is blacklisted by email servers
- biddendidden 2y agoEspecially on an .io TLD; it's haunted by the lovely US taking advantage of Chargossian exploitation.
- anonzzzies 2y agoI have a lot of sites (all saas) and more and more people send me cease and desists and lawyer threats because they go to google, enter 'something' that's remotely phonetically similar to a domain I run and then click on my site. They paid on some site that sounds a LITTLE bit (if you squint) like my domain and now they are scammed and want to sue me. Now I understand scammers do this as well, but I had actually someone turn up at our office (which is my business partner his home) with bank receipts with a really not so similar name, however if you type it in google we pop up first even though our businesses are not at all related.
- 8organicbits 2y agoAnother variant of this is cached or preloaded security configurations. HSTS (which forces browsers to validate HTTPS when connecting) asks browsers to cache the configuration for a set "max-age". Some sites set huge values here, like Twitter's 20 year max-age[1]. There's also the preload lists [2] to consider. This creates a problem if you want to serve non-HTTPS/unencrypted HTTP on your new domain and the previous owner didn't. MTA-STS [3] is another variant that's becoming more popular. It limits which mail servers your domain uses and enforces TLS certificate verification. "max_age" is capped to a year by the RFC. If you don't set your own policy, then the previous domain owners policy would impact any senders who previously cached the policy. Thankfully HPKP (key pinning) is obsolete, otherwise you'd also need to worry about old pinned keys too. That RFC recommended, but did not enforce, a 60 day max-age limit. These are especially tricky as the old security policy only lives in the caches of any end-user devices that previously connected to the domain. Double haunted. [1] https://alexsci.com/blog/hsts-adoption/ https://alexsci.com/blog/hsts-adoption/ [2] https://hstspreload.org/ https://hstspreload.org/ [3] https://alexsci.com/blog/smtp-downgrade-attacks-and-mta-sts/ https://alexsci.com/blog/smtp-downgrade-attacks-and-mta-sts/
- LeonM 2y agoFWIW, you can invalidate MTA-STS cache by updating the DNS assertion record to a different 'id' value. This is how you indicate a policy has changed. So the sender is supposed to obey the normal DNS TTL caching period, and re-query the assertion record if TTL expired. It should re-fetch the MTA-STS policy if the 'id' value in the DNS assertion changed, or the max_age in the previously fetched policy has expired.
- 8organicbits 2y agoAlmost, it's a little more involved. > RFC 8461 section 3.3: Conversely, if no "live" policy can be [...] fetched via HTTPS, but a valid (non-expired) policy exists in the sender's cache, the sender MUST apply that cached policy. You'll also need to host a "none" policy doc. Full instructions are here: https://www.rfc-editor.org/rfc/rfc8461.html#section-8.3 https://www.rfc-editor.org/rfc/rfc8461.html#section-8.3
- 2y ago
- flemhans 2y agoIP addresses can be haunted too, like if they were previously used for spamming.
- teddyh 2y agoCalling a domain “haunted” is an awful, terrible way to frame it. It places all the badness of the domain on the domain itself, as if the domain name had something with it which could be removed or fixed by the domain owner. Instead, what has actually happened is that the domain is blacklisted by entirely too powerful entities. The problem lies with these blacklisting entities, not with the domain, and the solution must be done there, too. It should not be a domain owner’s responsibility to get out of being unfairly blacklisted. It’s like when cars took over the streets, and instead of blaming cars for being dangerous for regular people using the streets for walking, the concept of “jaywalking” was invented by car companies to place the blame on people for daring to obstruct cars. Or the concept of “personal carbon footprint”, commonly used to move blame from companies to individuals, when in reality whatever individuals, even in aggregate, could do is utterly insignificant compared to what companies and legislation could accomplish.
- quotemstr 2y agoWho says it's the fault of the domain in some abstract sense? A house becomes haunted when something bad happens in it. It's not the fault of the rafters and joists. I think "haunted" is an apt description.
- teddyh 2y ago“Haunted” still implies that the problem exists at the house/domain, and can be fixed there. But a domain being blacklisted is not something which a domain owner can fix by themselves, they have to beg the blacklister to de-list them.
- sealeck 2y agoYou'd usually describe a house as haunted if something bad has happened in the past (e.g. a murder, evil spirits, etc) and people are superstitious about this (e.g. believe some ghosts are still living in the house). Hard to see how an owner can fix this. All the usual problems the owner can fix (floorboards need replacing, gutters need cleaning, general repairs) aren't really examples of a house being "haunted".
- r1ch 2y agoThis can also happen with IP addresses. We recently moved one of our sites to a new IP and got a trickle of complaints about it being inaccessible from various authoritarian countries. After some digging, the new IP was used as a Tor bridge (not even an exit node) over _ten years ago_. I gave up any hope of fixing that and just ordered a different IP address.
- anonym29 2y agoMy very first domain was haunted. The warning sign was firewall blocks against the domain at both school and the public library. As it turned out... a previous owner in the early 2000's was running a sort of proto-Netflix, but with VHS instead of DVD, and that was exclusively targeting the... erm... "adult entertainment" market. Wayback machine would've saved me there, had I done my due diligence!
- deleted 2y ago[deleted]
- snowwrestler 2y ago> It wasn’t until I had redirected all of my musicboxfun.com traffic to musicbox.fun that I noticed that something wasn’t right: my web traffic from organic search dropped to zero. Some practical advice here: do not change your canonical domain[1] name unless you really really have to. If he had just set his fun new domain to redirect to the existing domain, instead of making the new domain the canonical, it likely would have had no negative effect. I’m not saying this is how things should work. But the practical reality is that your domain name is like a Social Security number: it’s the basis for assigning a type of reputation score, even though it was not intended to do that originally. [1] The domain at which your web pages finally load, after all redirects have completed.
- pmarreck 2y agosounds like the makings of a business service
- 8bitme 2y agoThis sort of thing is also an issue for phone numbers, some other company could have used your new number for robocalls and gotten it spam blocked on Truecaller and similar services.
- hamilyon2 2y ago> search engines treat links to your site as a massive signal of relevance and trust I am admittedly a bit distant from SEO. The above is not true and hasn't been true for a long time.
- Pikamander2 2y agoA client of mine once swapped over to a new domain that was coincidentally one letter away from another major domain. It wasn't an attempt to typosquat or anything nefarious, but Chrome started automatically showing everyone a big scary warning page before entering the site. We looked into appealing it but there was no guarantee of it getting whitelisted in a timely manner, so we ended up canceling the domain migration before they lost too much traffic.
- campbel 2y agoI wonder if it would be a reasonable requirement of registrars to now allow domains to be purchased if they are some edit distance away from existing/active domains. Its fine if Google wants to protect its users, but ideally this would be caught sooner.
- dasil003 2y agoDefining “active” seems like the tricky part
- ajsnigrutin 2y agoThat would be a pain... Look at the milka.fr problems... Milka is also a female name over here, and that already proved to be a problem in france. But so are Mirka and Minka so yeah... no domain for them? Also Micka. Oh and mivka is (beach) sand. Want to sell beach sand? It's just one letter away from milka, so no domain for you either.
- account42 2y agoIs it really better if Mirka, Minka and Micka get to pay for a domain but won't be able to use it because the dominant webbrowser shows super scary warnings? Still seems better to raise the issue as early as possible so they can find a solution (appeal or chose a different domain) before investing into the unusable domain name. It would also mean that the dispute is at a layer (ICANN) where you at least theoretically have some rights instead of at the hands of a megacorporation that thinks the best way to reduce customer support costs is to make it impossible to get support.
- AStonesThrow 2y agoOne risk of pre-validating a domain before purchase is that it's not a good idea to tell strangers about your interest in such a property. Even automated queries are likely to spill the beans. Someone else could snag the purchase before you, or bid up the price. But it's a risk you may need to calculate.
- hggigg 2y agoYears ago I bought the carelessly discarded domain of a defence contractor that was acquired by another one. And set up a catch all email forwarder. Had weeks of fun reading all the emails that I got sent. There was nothing "secret" but plenty of social and business stuff still going on.
- rschiang 2y agoI've had this with anti-virus flagging domains and VirusTotal was helpful: https://virustotal.com https://virustotal.com But it does require manually reporting false positives to each vendor
- veunes 2y agoA risk that’s easy to overlook until it bites you