16 ms·
Never buy a .online domain
- deleted 8mo ago[deleted]
- deleted 8mo ago[deleted]
- ocdtrekkie 8mo agoA great reminder even if you aren't a Google customer, Google's love of banning people with no notice or recourse will still screw you over.
- ssiddharth 8mo agoI'm shocked there was no notification, or alert, of any kind. One moment you're there, the next, you're gone and no one will talk to you. Insanity.
- Citizen_Lame 8mo agoThat’s not fair. Google has no hesitation in banning its own customers either. Combine this with private equity vultures (namecheap) and shitty registrar, you are always one AI token away from being banned.
- e40 8mo agoShit, didn’t know that namecheap was acquired by PE! Very sad news. Is there any registrar left that isn’t crap?
- Citizen_Lame 8mo agoPorkbun is not bad, Gandi has fallen as well.
- deleted 8mo ago[deleted]
- rationalist 8mo agoDynadot
- jgwil2 8mo agoNot sure how you feel about them as a company, but I use Cloudflare because they sell domains at cost.
- e40 7mo agoOf the suggestions, I think I would lean to CF, too.
- Imustaskforhelp 8mo agoYea regarding namecheap/spaceship (their sort of subsidiary company). I once created a tool which could find me a cool short .de domain out of curiosity and I tried using namecheap bulk's domain feature. It said that https://aid.de https://aid.de was available. I was out of the moon happy (silly me) thinking that its such a good domain or something. Then I saw aid.de available in namecheap for around 2$ ish but for some reason I took a bath and hten later it showed 10$ ish. Okay, I then went to spaceship and it also showed me aid.de available. I then took my card and signed up Well the transaction took place but got refunded. It said that there was an issue or something and got insta refunded Silly me, thought that the payment had issues and decided to do payment again. This time though my refund had to wait 10 days to come back because of international laws. Now I had only very little amount stuck btu I can see someone losing substantial money/having it stuck I contacted their support and they told me that both namecheap/spaceship have a bug where some domains show available when they aren't. I haven't checked but since the amount was like 1-2$ now but this whole thing really soured my relationship with namecheap/spaceship. For context, before this, I also had a hate/love relationship with namecheap because once I bought a domain with them using crypto and also bought their vpn which was like 20 cents basically It had auto renewal on and my domain costed 1$ but crypto payment requires 10$ minimum and the VPN charged me money from that. Luckily I had spotted before the 2nd month and to be honest, like only 1 month 10 days or something and I urged the namecheap company to do what's right (in that moment because a lapse of judgement had been made from my side/error and I hoped that namecheap could realize it and do "right" instead given that the cost was only around 10$ fwiw) After waiting for many days, they finally did what's right and gave me my credits back as a one off thing and I then turned off their domains. I also used a crypto swap thing to convert b/w usdc and btc (what namecheap accepts) and I had an issue of doing two times payment after the timeperiod of btc payment (15 mins) but they also fixed that issue by adding the credits manually when I raised the issue. Their customer support at times can be good but the platform itself is a little shady in my opinion. For the VPN thing if I remember correctly, the auto renew was written with grey and I genuinely didn't read it without my specs. I am gonna keep my domain with namecheap that I have and if I get deals from namecheap/spaceship then use them, but for individual domains without deals, hell no. I know that many people don't like the centralized nature of cloudflare but cloudflare is a good thing for domains :/ I personally just buy domains from wherever's there's a deal right now as some domains I have are some that I keep for only 1 year or similar. To be honest, if I want to pick a domain-thing, I'd rather pick the one which is the cheapest or if not, then the one which only sells domains I just looked at porkbun and they only sell domain related things and at best mail (they also have a deal with proton which can be interesting to many) Porkbun is also cheap so I think I would recommend porkbun/cloudflare. I haven't decided if I will transfer my domains from namecheap or not but their customer service is nice but the same can't be said for their service sometimes in my opinion.
- palad1n 8mo agoAre there any other TLDs that are of this ilk or are we saying nothing but .com will ever do? Or .org, perhaps?
- DetroitThrow 8mo agoI would love a list of Radix TLDs or registrars who do this Safe Browsing ban with no appeal. Also, go figure Namecheap works with these morons.
- bjord 8mo agofrom their site (radix.website): .store, .online, .tech, .site, .fun, .pw, .host, .press, .space, .uno, .website not sure about other registrars
- kotaKat 8mo agoSome of these TLD also get thrown under weird arbitrary blacklists by security vendors. Sorry, can’t buy a frame.work laptop because that’s a “Malicious TLD”, according to the folks at ZScaler.
- inigyou 8mo ago[dead]
- kristofferR 8mo agoIt's not exactly the same, but a lot of owners of weird TLDs have got hit with insane renewal fees,.hosting went from $20/y to $300/y overnight. Also, some TLDs directly speculate on having very low prices for the first year or two, then 10x it on year 2 or 3.
- ectospheno 8mo agoBuy all 10 years you can when you get the domain. Renew yearly. When they pull silliness like this you have at least 9 years to migrate.
- soco 8mo agoEnshittification at its peak (or is it at its peak already?)
- FroshKiller 8mo agoThere is no peak, because it's a hole, and we can always dig deeper.
- pil0u 8mo agoOne conclusion is: > Not adding the domain to Google Search Console immediately. I don't understand. What is Google Search Console, and should I add all my domains there right now?
- notenlish 8mo agoBy adding your site to there you can get data on how many clicks & impressions your site received on google, what keywords it ranks for etc. You can also request Google to index your site on GSC as well. You should probably add your websites to GSC.
- onli 8mo agohttps://search.google.com/search-console/about https://search.google.com/search-console/about. Yes. It gives you options in cases as described here. Was called webmastertools before.
- techcode 8mo agoCan't answer if you should add them or not... But if you do - you would get some notifications from Google about that website/domain. I've only ever seen emails of the "There's an increase in 4xx/5xx errors on site/page(s)"
- Macha 8mo agoI also get “there were crawl errors”, which upon investigation are for pages that never existed (and I’ve owned the domain for 20 years, so its not a previous owner/operator thing)
- joelccr 8mo agoIf it's already in the Console when it gets blacklisted, you can appeal it without having to 'verify' ownership of the domain that, in this case, you no longer control the DNS of, because you completed that process when adding it to Console.
- embedding-shape 8mo ago> I don't understand. What is Google Search Console, and should I add all my domains there right now? Google's way of tying real identifies of people to domains, without making it explicit. Basically, your domain will be weirdly treated by a bunch of entities, none the less Google themselves, if you don't add your domain there (or some other Google property). Especially with less common TLDs, like .online, they really want to be able to tie it to some identity, so unless you add it there, eventually your domain ends up on some sort of blacklist, in the case of the author it seems they used the "Google Safe Browsing" blacklist to get the author to involve Google somehow.
- mystraline 8mo agoSo, how is this not libel by Google? The claim was that you were running an "unsafe site". Its their job to prove that, and not just "black box says so". And you have system and reputational damages. Go for small claims suit, $5000. It'll cost more than that for their attorney to go to your jurisdiction.
- moralestapia 8mo agoThis is libel, indeed.
- dathinab 8mo agobecause google safe browsing is only supposed to display a "not safe to browse" warning when using chrome browsers (and maybe some other browsers) wich you can (theoretically) dismiss(1) it's not meant to have any other consequences so basically what happens is that because of hearsay of google thinking you site is not bad Radix does what normally should involve a judge order (taking down the whole domain) (1): Yes that still would cause damages on any site with customers, but like way less and way more fixable then what happened here.
- otterley 8mo agoIt’s not libel. Defamation requires a false statement of fact. Claiming a website is “unsafe” is an opinion. (IAAL, but this is not legal advice. Consult a licensed attorney for legal advice.)
- donmcronald 7mo agoThe warning says something along the lines of "Dangerous Site Ahead. Attackers on [site] may trick you into doing something dangerous..." If I'm the only one with access to the site, they're calling me an attacker and saying that I might try to steal passwords, credit card info, etc.. If they're calling me an attacker, that seems like more than an opinion. Wouldn't they have to prove I'm a bad guy if they're asserting I'm a bad guy?
- otterley 7mo ago
- tucnak 8mo agoThe .com purist advice is sound but you're not getting four-letter domain names that way, and in some ccTLD zones you can still. I was price-gouged out of owning a single, rare .icu domain when renewal fee for it went from 20 usd to 220 usd overnight, just for this one domain... I'm pretty sure it's not Gandi, but the TLD opetator, because other .icu domains I've had were fine. I decided to eventually abandon them all anyway. Moved away from Gandi later when they started doing gouging of their own, too. What is HN's opinion on Dynadot?
- palad1n 8mo agoYeah, what the heck happened to Gandi? It used to be my go-to, but nowadays... yikes!
- timpera 8mo agoThey got sold to private equity, unfortunately. I switched to Bookmyname (by Scaleway) for some TLDs, and Infomaniak for others.
- aitchnyu 8mo agoCan we trust Cloud registrars like Bookmyname/Scaleway, Amazon Route 53, Cloudflare more than Namecheap, Gandi and co?
- Imustaskforhelp 8mo agoWait, If I remember correctly, I think its possible to now buy domains from scaleway directly within their interface https://www.scaleway.com/en/domain-names/ https://www.scaleway.com/en/domain-names/ Could be very interesting for the people who love/host on scaleway. Scaleway is a good company fwiw imo.
- merek 8mo agoThe TLD owner in this case was Radix, which also owns .store .online .tech .site .fun .pw .host .press .space .uno .website https://radix.website/ https://radix.website/
- g947o 8mo agoThey seem to be almost always associated with scam sites. So, might as well to block entire TLDs and never buy a domain under those TLDs
- eli 7mo agoThat's just because they're relatively inexpensive
- xnorswap 8mo agoThe only .fun site I know is neal.fun, which regularly features on the front page here: https://news.ycombinator.com/from?site=neal.fun https://news.ycombinator.com/from?site=neal.fun
- ivanjermakov 8mo agoI can also name https://beamng.tech/ https://beamng.tech/
- jeroenhd 8mo agoThese alternative domains are quite popular with the fediverse and other hobbyist-run groups. Affordable domains with somewhat recognisable names still available. Scam websites will use any TLD in my experience. Based on the ones that made it to my Google search results, .it and .info are the TLDs I should be blocking. When I search for "free roblox cash", most websites are .com. "Free robux" also brings forth a few .ca websites. "Free steam gift card" leads to .org and .com.
- kstrauser 8mo agoMy all time favorite Fediverse domain is jorts.horse. That’s the most delightfully random thing.
- nickweb 8mo agoHot Take: the proactive action of the registrar here is probably more beneficial than the number of false positives captured. If the registrar is aware that Google is hot on blocking potentially harmful sites, it's right that they take action expeditiously. The bigger problem is the unbanning - for which there should be a better system, probably that should take the form of the registrar having a short grace period to aid in the Google stuff (DNS verification etc.) with additional checks by the registrar to make sure it's not being used for spam/malicious content. The other point being why was Google banning you so quickly? This is the opaque part. Was the site reported? Was there some URL hijinks? That's the thing you'll probably never find out.
- iamnothere 8mo agoRelying on Google for this is actually not beneficial, as discussed here many times: https://hn.algolia.com/?q=Google+safe+browsing https://hn.algolia.com/?q=Google+safe+browsing If the registrar tracks this information, a possibly helpful course of action would be to notify or warn the domain owner that they are on the list. In the modern adversarial web, I do not want a registrar that proactively disables my domain because of some third party report.
- forgotaccount3 8mo ago> The bigger problem is the unbanning The was my first thought as well. Yes, using the Safe Browsing list feels wrong, but I don't know enough to speak definitively in that regards. However wouldn't a relatively simple solution be that if a registrar is choosing to use some third party's list of banned DNS entries that the registrar then also implement sufficient unblocked components that will allow people to be unbanned from that third party? > Add a DNS TXT or a CNAME record. I haven't had a use-case for a TXT record come up yet, but isn't it low risk enough to allow domain owners to continue to configure TXT records even if the registrar wants to ban configuring other record types? Then the person in the article could prove ownership and could then get off of the third party ban list that the registrar was utilizing.
- roblabla 8mo agoThere is _some amount_ of justification to ban TXT. There have been a few cases of C2 servers using DNS to send instructions to malware, so letting TXT slip through the cracks would still allow for that. Now whether this downside justifies the massive problem it causes on false positives...
- Tepix 8mo agoI blame both the registry and Google. If you were a lawyer, you could have fun with this. Btw, perhaps unrelatedly, we had a domain marked as unsafe by Google as well for no particular reason.
- CodeCompost 8mo agoLast year, my registrar wanted €64,99 to extend an online domain which I had created for fun. No thanks.
- ryan42 8mo agoyeah same here. I canceled my account on name.com because I had previously obtained a .art domain maybe for ~15-20 USD / yr. Then they wanted $50 USD a year to extend it. No thanks, dropped the domain and moved to namecheap
- yanis_t 8mo agoI still remember how Google banned my entire account without providing a reason for a small Android app (more than 12 years ago). To this day I have no idea why, it was absolutely green-area fit tracker or something. There was absolutely no way to know the reason or unblock my account. Turned me away from Android development forever.
- jkestner 8mo agoA relative’s business has had Google reviews frozen for years. Search results show the bad rating after some former customer and spouse left bad reviews several years ago. Appeal went into a black hole. Running a small business is at the pleasure of Silicon Valley.
- pocksuppet 7mo agoCheck with a lawyer if this counts as tortious interference. You could potentially win quite a large sum from Google.
- littlecranky67 8mo agoSame shit happend to me - got my google account blocked overnight and locked out of most of my digital life. Learned my lesson and ungoogled asap.
- seanw444 7mo agoThey want to make this the only way to run apps on Android too.
- AshamedCaptain 8mo ago> The domain ... has been suspended due to its blacklisting on Google Safe Browsing Et voilà ... ! this is precisely the slippery slope I warned about a decade ago. The indirect censorship becomes direct censorship, defeating all the arguments about the morality of such a list. And: > Not adding the domain to Google Search Console immediately. I don't need their analytics and wasn't really planning on having any content on the domain, so I thought, why bother? Big, big mistake. Yet more monopolistic power to Google.
- dizhn 8mo agoThat is the bit that jumped at me immediately too. Why would a registrar take it upon itself to suspend a domain that another entity entirely blacklisted as part of their own completely opaque process? Who is Google? God? On the flip side of the coin I cannot get a site removed that is a blatant rip off of one of our websites being actively used for invoice redirection fraud.
- avaer 8mo agoIt's like being unable to get a passport because Microsoft has you on The List, and Microsoft needs to see your passport to check why you're on the list. Considering that getting a domain is a normal part of business these days, this kind of thing should be illegal. Not to mention, why does Google have any say in this?
- riddlemethat 8mo agoYou know it's getting bad out there when corporations act like the government.
- dizhn 8mo agoIt's like the domain registrar is acting like a vassal state. I don't think Google actually has any say in their decision.
- rustyhancock 8mo ago
- iamnothere 8mo agoThe registrar relying on Google Safe Browsing as a “trigger” for suspension is the most horrifying thing I’ve seen in a while. This basically makes the entire TLD unviable for serious use.
- RHSeeger 8mo agoThe followup from that would appear to be don't use any domain that Radix controls.
- holysoles 8mo agoYeah this doesnt seem like a unique or new issue: https://news.ycombinator.com/item?id=40195410 https://news.ycombinator.com/item?id=40195410
- fc417fc802 7mo agoMore generally, I think it's advisable to prefer the ccTLDs of places that are politically stable. And (IMO) to view com/net/org as defacto US ccTLDs (technically they aren't but for all practical purposes they might as well be).
- WmWsjA6B29B4nfk 8mo agoWho said serious use is their business model though.
- mzajc 8mo ago.online is one of the many TLDs that charge a dollar for registration but bump the price to $30-$35 for renewal. So far, this seems like a good signal to tell apart serious TLDs and ones just preying on customers who sort by cheapest (or capitalizing on one-off phishing domains).
- volkercraig 8mo agoI had a .fun domain that I was using to host a small project and they pulled that on me, I just let it expire and killed the project.
- eappleby 8mo agoUnfortunate story. It wasn't clear to me that the .online TLD led to Google blacklisting the site. Why did you think that was connected?
- NikolaNovak 8mo agoMy understanding from the article is that because the registrar for this domain is using Google safe browsing for their domain suspension, something that a) shouldn't be the case and b) isn't the case for other, perhaps more mainstream TLDs
- nguyenkien 8mo agoThe registrar suspense domain because it on Google blocked list. And Google refuse to review the ban because he can't prove he own that domain (because it suspended :D).
- dathinab 8mo agoThe problem isn't Google Safe Search backlisting the side (I mean that also is a problem, but a very different one). The problem is the vanity domain registrar Radix using that as a reason to _put the whole domain on hold, including all subdomains, email entries etc._ This means: - no way to fix accidental wrong "safe search" blacklisting - if it was your main domain no mails with all the things it entails - no way to redirect API servers, apps etc. to a different domain. In general it's not just the website which it's down it's all app, APIs, or anything you had on that domain Google Safe search is meant to help keep chrome users safe from phishing etc. it is fundamentally not designed to be a Authority Institute which can unilaterally dictate which domains are no longer usable at all. Like basically what Radix did was a full domain take down of the kind you normally need a judge order for... cause by a safe browsing helper service misfiring. That is is RALLY bad, and they refuse to fix their mistake, too. You normally don't have _that_ level of fundamentally broken internal processes absurdity with the more reputable TLD operators (which doesn't mean you don't have that in edge cases, but this isn't an edge case this is there standard policy).
- NikolaNovak 8mo agoOh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. This goes right to the top for me, along the ubiquitous "please verify your account" emails with NO OPTION to click "that's NOT me, somebody misused my email". Either people who do this for a living have no clue how to do their job, or, depressingly more likely, their goals are just completely misaligned to mine as a consumer and it's all about "removing friction" (for them).
- integralid 8mo agoNo need to look for malicious intentions, this is just a feature that costs money so it's very low (or zero) priority for profit driven organisations. I wonder if finding people responsible and spamming then with their own service emails would make the team care enough to fix this. But of course that's mostly dubious, probably illegal, and shouldn't be a responsibility of some vigilante hacker
- loloquwowndueo 8mo agoWith AI these days it’d cost almost zero money. /s
- b112 8mo agoIf bartenders are legally (including criminally!) liable in some jurisdictions for their customers, then certainly a chain of legal liability can exist in other industries.
- dangus 8mo agoI don’t know that the advice is solid in terms of never buying an alternate TLD.
- swiftcoder 8mo agoThere are always the actual country TLDs, which (mostly) have specific regulations governing their use, and an actual government body to appeal to in case of unsolvable issues like this
- drcongo 8mo agoGoogle have way too much power to mess people's lives up. Especially for an organisation with basically zero customer support.
- shit_game 8mo ago> Not adding the domain to Google Search Console immediately. I don't need their analytics and wasn't really planning on having any content on the domain, so I thought, why bother? Big, big mistake. I'm not particularly familiar with SEO or the massive black box that is Google Search - is this really as critical as the author makes it seem? I have both .lol and .party domains, both through porkbun (and the TLDs seem to be administrated by Uniregistry and Famous Four Media, respectively), and both are able to be found on Google Search. It seems like this preemtive blacklisting would be the result of some heuristics on Google's end; is .online just one of the "cursed" TLDs like .tk?
- swiftcoder 8mo ago> is this really as critical as the author makes it seem? It is critical in the sense that if you want to appeal the decision in a case like this, it will go much better if you pre-verified that you own the domain. (I don't think it has much effect on google search placement at all)
- kyle-rb 8mo agoYeah I'm guessing the TLD was the main signal, based on other comments linking to a thread about "Pinggy", who was also using a .online. The fact that Namecheap is giving them out for free means they probably are more scammy on average. I've also never added domains to Google Search Console and haven't had blacklisting issue other than with a free .ml (another "cursed" TLD) site that was by default assumed to be spam by Facebook Messenger. It's unfortunate that this category exists, but I don't share the OP's .com purism; I've used a mix of TLDs and even the cheap ones like .fyi and .cc haven't come under extra scrutiny as far as I can tell.
- ranger_danger 8mo agoOne time I bought a .dev domain, which is/was run by Google, and after missing the renewal deadline by less than 24 hours, the renewal price jumped from less than $30, to $800.
- Imustaskforhelp 8mo agoIs this even legal?
- ranger_danger 7mo agoNo idea, but it would cost me more to fight it than it's worth. And other people have reported similar issues but people refused to believe them, so I doubt I would get much sympathy.
- blenderob 8mo agoWhy was the domain blacklisted though? What can we do to prevent blacklisting in the first place?
- nguyenkien 8mo agoFrom false alarm to something previous owner did. Remember domain is recycled.
- ssiddharth 8mo agoThe domain has no history as far as I could search and the site was up for almost 6 weeks with no issues before it was nuked. I used it with Apple's review process!
- xp84 8mo agoMost definitely nothing, as no sentient humans are probably involved in the process except possibly malicious people that report a site in bad faith.
- otterley 8mo agoThat’s my question. I’ve launched many fresh websites that have not been marked as unsafe by Google. If they were habitually doing this, there would be far more reports of it. I suspect there is something the author is not telling us.
- bilkow 8mo agoEven if the false-positive rate is very small (e.g. 0.01%), you probably won't be affected, but more than a hundred thousand of websites would be and that would still be an issue. I have no idea how big is the false-positive rate. There are many of reports of the same happening to other sites, some of the top ones (you can find many more by searching HN for "google safe browsing"): - https://news.ycombinator.com/item?id=33526893 https://news.ycombinator.com/item?id=33526893 - https://news.ycombinator.com/item?id=25802366 https://news.ycombinator.com/item?id=25802366 - https://news.ycombinator.com/item?id=45675015 https://news.ycombinator.com/item?id=45675015
- ghoshbishakh 8mo agoWe posted this warning on HN before: https://news.ycombinator.com/item?id=40195410 https://news.ycombinator.com/item?id=40195410 We struggled a lot when we opted for the .online domain for https://pinggy.io https://pinggy.io urls
- basilikum 8mo agoThis sounds like something ICANN should prevent. Is this not against ICANN rules? These fuckers ban emoji domains, maybe they should ban registries from arbitrarily stealing domains with no recourse. Maybe write to them and see if they can move something.
- cmsp12 8mo agohonestly all of these weird tld are expensive in the long term i dont see the point of getting them
- twapi 8mo agoOP shouldn't blame .online registry operator Radix.
- deleted 8mo ago[deleted]
- __MatrixMan__ 8mo agoWe need to rethink the web so that fewer third parties are involved in things that seem on the surface to be an A-B conversation. To say nothing of the trustworthiness of those parties, having them involved at all is needlessly brittle.
- account42 8mo ago> Update: Within 40 minutes of posting this on HN, the site has been removed from Google's Safe Search blacklist. Thank you, unknown Google hero! I've emailed Radix to remove the darn serverHold. I wouldn't party too soon - from my experience getting something removed from Google's libel machine doesn't mean the same process that put it there in the first place is fixed and it you will most likely go through the same thing again and again. > Not adding the domain to Google Search Console immediately. I don't need their analytics and wasn't really planning on having any content on the domain, so I thought, why bother? Big, big mistake. This is just another way how Google has inserted themselves as the gatekeeper of the web.
- siliconunit 8mo agotried to roll my own email server on a .xyz domain...basically a big no go, couple of emails went through, then nothing, just a black hole. Thanks corpos and the safety theatre.
- bombcar 8mo agoCall me a luddite but if it isn't one of the original big TLDs, a country TLD, or similar, I just don't trust it for anything serious.
- Imustaskforhelp 8mo agoI believe that .de domains are pretty cool (written another comment about it) but .de are $3.25 for registration and .de is the second most common after .com so from webatla, I see approx 16 million domains. I don't think that they could ban emails from .de for what its worth. Personally I like .in domains too. Makes more sense to me because I am well Indian and we all use it quite frequently/sort of intutitively know fwiw but if I just want a domain for email purposes for cheap. Honestly, .de could be good. https://tld-list.com/ https://tld-list.com/ [Try seeing the cheapest renewal rate with top level TLD and ignore .storage which costs 465$ for registration smh] Some other domains like .top exist as well in this league imo but .de is one of the best if you can find a relevant domain in .de
- jabroni_salad 7mo agoIn Defender for Exchange (or whatever they call the filter in exchange online these days), there is a checkbox that blocks .xyz and .biz as a bundle. Why those two? dunno, but microsoft especially hates them.
- elAhmo 8mo agoAnother case of Google extorting users and showing mafia-like behaviour.
- hyperionultra 8mo agoHaving .online already 5 years. No problems with email or website. Don’t understand that blog post. More problems can be with .xyz
- pverheggen 8mo agoI wonder if Radix has unknowingly created a negative feedback loop here. From Google's perspective, the DNS records disappear shortly after being flagged by Safe Browsing, which their heuristics may interpret as scammy behavior.
- _el1s7 8mo agoThis is one of the pains of centralization. And honestly, it could happen with any TLD.
- zadikian 8mo agoBut was this because it's .online? I got one and it was fine. The only issue was the usual trap with all Namecheap domains: They tell you it's all set, and it works, until they randomly email you a week later asking for email verification. If you don't do that promptly, they suspend your domain until you trigger a resend. Which is easy to fix but also strange.
- NewJazz 8mo agoThe blog post details that the TLD registry, Radix, decided that getting put on Google's safe browsing list means they put a serverhold on your domain, which prevents you from getting off the safe browsing list. So yes, this appears to be a TLD- (or at least registry-) specific issue.
- zadikian 7mo agoOh, I did read but didn't understand that Radix was the TLD owner. Makes sense.
- icase 8mo ago“never buy a non-.(com|net|org) domain” ftfy
- bombcar 8mo agoI agree, but if I ever get a chance at .edu, .mil, or .gov I'm gonna take it.
- quesera 7mo agoThere are still some fun domains grandfathered into the .edu hierarchy, from back in the day when registration criteria was not-so-strict. .mil and .gov have always been too strict for ordinary folks though.
- petterroea 8mo agoSide note: My empirical experience is that vanity domains are disliked by some enterprise security systems. I have a friend who owns a .homes domain which ended up being blocked by quad9 as well as the enterprise security system of a friend's work for ~half a year. The block cleared by itself. I had the same experience while buying another TLD. For ~1 month, certain people whose ISP "helpfully" had "safe browsing" features, simply blocked us outright. For being new and different. The learning for me was that new domains are no longer trusted, and seemingly some vanity domains get even more strict treatment.
- roger110 8mo agoBecause the entire security mechanism of the www today is "look at the domain name to make sure it matches." And the TLD is at the end where people might miss it.
- deleted 8mo ago[deleted]
- mavamaarten 8mo agoEven (uncommon) country TLD's too. I own a .vg domain which is a perfect match with the initials of my last name. My mails end up in spam quite often too, despite having set up SPF, DKIM, DMARC and all that stuff correctly. It's just not common so some security systems block it.
- deleted 8mo ago[deleted]
- MattSayar 8mo agoTook me a minute to realize Sid isn't associated with 0xide.computer. Clever domain name! Getting Google to index my personal site has been a pain. Every other search engine works fine, but ever since I switched the images on my site to .webp (a format created by Google!), my site's content just doesn't get indexed anymore. I've given up since web search traffic matters less and less these days with LLMs, and it only really bothers me when I'm trying to search for my own articles.
- ssiddharth 7mo agoHa, thank you. I spent more time than I'm willing to admit to come up with it. I use my older, much longer domain for email and identity (it used to be #3 on SERP for "Sid"). This one is just for giggles so I can blog in peace without affecting the main one.
- OutOfHere 8mo agoThe logic doesn't automatically extend to other TLDs unless they too are owned by the same firm. Alternative TLDs are often preferable because they're so much cheaper than wasting money on a .com, etc.
- Macha 8mo agoMost alternative tlds are more expensive than .com after first year teaser rates expire though
- Imustaskforhelp 8mo agohttps://tld-list.com/ https://tld-list.com/ Try looking at this website with cheapest renewal rate and removing second country TLD (so only Top level) In my opinion, .de , .ovh , .uk or personally my country's .in (yes OVH has their own TLD that you can use) .de is one of the more interesting domains to me personally even though I am not german.
- OutOfHere 8mo agoThere are various gTLD that are cheaper. For example, .top is great and among the cheapest. It however is falsely maligned by those with small brains who stereotype things.
- Imustaskforhelp 8mo agoI like .top domains as well but .de might make more sense. Considering .top domains have cheap registration and renewal. To me, it does feel as if .top are very speculative. I liked to search random things in tld-list to find unique-word.<any tld> so like random.top but my past experience says that .top domains are bought quite a lot/very speculative. If possible I like .de but I think that .top are fine too. Both are great for what its worth. > It however is falsely maligned by those with small brains who stereotype things. I didn't know about this, can you please elaborate more about it?
- OutOfHere 8mo ago
- squeefers 8mo agosorry but you cant have a domain if google ban it? how does this work?
- wordsnaking 8mo ago[dead]
- dzonga 8mo agowhy not just buy a .co.xx (country) or simply .com / .net and if hectic maybe .io
- trey-jones 8mo agoI'm sorry that the author got bitten by this. But .com purism is funny to me. I only buy GTLDs for personal projects, and I've never had a problem before. But then, I've never bought .online.
- metalliqaz 8mo agoTop of HN. Well, I guess you could say that Radix's strategy to give away domains backfired spectacularly.
- fortran77 8mo agoNever use a “free” domain is a better rule. Even if there were no technical or administrative issues, nobody trusts them.
- kkl 8mo agoI could also buy that the free domains were ran up by scammers which could have caused some of the hair trigger Safe Browsing denylisting.
- iryndin 8mo agoA list of all registered (3,231,464 domain so far) .online domains is here: https://allzonefiles.io/zone/online https://allzonefiles.io/zone/online
- wangzhongwang 8mo ago[dead]
- bjt 8mo agoIt's not about the .online TLD being "weird". The problem is that it was free. That's going to attract a swarm of fraudsters, spammers, etc, and then turn into a strong "this is probably fraud" signal in all kinds of fraud scoring systems. There are lots of domains out there other than .com that are just fine.
- garganzol 8mo agoProbably this is what's happened here. Either the OP's domain was previously used for shady activities, or the almost-free stigma puts the whole .TLD in the grey list of high-risk assets. Probably is also explains the nuclear behavior of the registrar (suspension). Free is good, but sometimes it's not.
- fckgw 8mo ago.online, .top, .xyz. info and .shop are some of the top TLDs that scammers use, precisely because of their rock bottom registrar fees that make them attractive for sites that have a shelf life of a few hours or a few days before being blocked. As a result, many places have a blanket "suspicious" flag for fresh domains under these TLDs. If you plan on building a legit site, do not use any of these cheap TLDs.
- al_borland 8mo agoPaying through the nose for a .com that is remotely memorable and easy to spell is not a great path forward for a hobbyist or someone who simply wants their own domain for email. I know someone with a .org domain, and even they have a ton of issues with false flags on their emails due to not coming from a big email provider. They’ve been blacklisted a couple times and regularly get flagged as spam. I’m surprised he hasn’t given up after dealing with this stuff for 25 years. These new TLDs, I thought, were supposed to open up more options for regular people to get a domain that is semi-decent. Instead they’re essentially useless. Some of the prices are also still insane, due to assumed “premium” status or domain squatters. There has to be a better way to police this stuff.
- 7mo ago
- peanut-walrus 8mo agoIt sucks so much that there is no standard way of linking additional domains to your main one and inheriting the reputation. Want to set up a new domain for whatever purposes (conference, new product, etc)? Be prepared to spend the first half a year fighting the various blacklists before people can actually reliably connect. Would make so much sense if you could just have a .well-known/other-domains.txt (or something something DNS) with a list of domain names that should be considered just as trustworthy as your main domain. It's not even about .online or other weird TLDs, it's just that the domain is new and therefore "not trustworthy". Even worse if you need to use your existing branding on the new domain - instantly flagged as a phishing site everywhere.
- thayne 8mo agoGoogle should really be seeing some anti-trust action for requiring you to create an account with them on their search console in order to contest being added to a blacklist used by all the major browsers.
- bhartzer 8mo agoAre you 100 percent certain that the domain name wasn't registered before and then got on the blacklist because of prior misuse? It's quite possible that the domain you chose was registered previously and dropped because the previous owner misused it and burned that domain. The .ONLINE extension has been around for several years now.
- NewJazz 8mo agoI feel like google should be sophisticated enough to tell when a domain has expired and gone up for auction/resale?
- ssiddharth 7mo agoI can't be 100% sure but googling showed nothing. My site was up for almost 6 weeks with no issues. I used the domain for Apple's review process too. No issues at all.
- Habgdnv 7mo agoI am 100 percent certain that one of my domains i registered before and now I am still looking for lawyer to help me sue my government for blocking my domain for something I never commit and refusing to remove the block - just be cause they can. short .com domain! I even paid it for 2 years because I was willing to commit.
- lasgawe 8mo agoalso I don't recommend using a .xyz domain for email sending. These domains are often marked as spam, and some email providers don’t support them.
- bradgessler 8mo agoI got og.plus that expands to OpenGraphPlus.com. At first I was stoked to have a two letter domain, but then I looked into it and learned these companies will get you hooked with a low initial price, then jack up the prices as the domain becomes established. Quite the grift. My plan is to tread lightly on that domain and be ready to back away from it when the rent seekers move in. You’d think there would be some sort of rules to the neutrality of these TLD administrators, but nope. The second time around I wised up and go ogplus.net for an API domain instead of ogplus.media. I’ll take neutrality over vanity any day.
- AndyMcConachie 8mo agohttps://www.icann.org/compliance/complaint https://www.icann.org/compliance/complaint
- defraudbah 7mo agonever buy anything than com domain especially country level domains, they are not regulated and your register can ignore whatever requirements they have to fullfil
- ksdme9 7mo agoOn a side note, thanks for wisp. I was looking for something like it so I could use it to quickly test the web builds of my tauri mobile app.
- ssiddharth 7mo agoOh wow, I didn’t even think of this use case. Could I please get in touch for a bit more info?
- jarek83 7mo agoSo this happened only because google is so big, that it can point to any website and say that it's not safe. Even if owner of a site just don't want to be in their search engine in the first place. How on earth we ended up with this company bother anyone including those that want their services? Imagine that you could get your driving license banned because you did not buy a toyota...
- nelsonic 7mo agoThe first mistake anyone makes is thinking they are “buying” anything with a domain. You’re renting it. And the company you are renting from can arbitrarily push up the price above inflation. NameCheap is good for the basics. But a .site or .online domain is a no-go beyond an MVP/test.
- deepsun 7mo agoSo Google can single-handedly break any domain? Sounds like total control of the Web.
- tamimio 7mo ago.com is definitely the gold standard, I got an .io more than a decade ago and if I would go back in time, I would just use .com, the pricing for .io been increasing for no apparent reason.
- giobox 7mo agoPeople often make the mistake of treating .io like a gTLD, when it's actually a ccTLD for the "British Indian Ocean Territory" etc. ccTLDs have always had risks, especially when they are for a really tiny region. Similar issues to .io happened with the popularity of .tv domains, which again is a ccTLD. The government of Tuvalu sought to increase income from sales of their ccTLD and prices went up. Tuvalu is such a small nation .tv domain sales ended up making a significant part of the State's income. Another fun example of the mess you can get into with ccTLDs was when the UK left the EU. All UK registered .eu domain names were cancelled following the UK exit from the bloc. gTLDs generally have some degree of insulation from State-level politics. ccTLDs permit the nation or territory they represent much more say in how they are priced and who they are sold to.
- tamimio 7mo agoInteresting, thanks for the info, definitely didn’t know that back in ~2012, but lessons learned, only .com or .org I have been buying in the past years.
- agentifysh 7mo agoDoes anybody know any good alternative to Name Cheap? It seems like they keep raising prices on all the domains. Website is very sluggish, especially for finding domains quickly.
- mdhen 7mo agocloudflare is the cheapest - they do it at cost.
- agentifysh 7mo agoWow, thanks. You were right. I Googled and it says Cloudflare is cheaper by twenty-five to fifty percent on renewals. I'm really sick of namecheap. They seem to never stop raising prices. but I'm also I'm kinda wary and afraid of moving domains and losing it.
- pocksuppet 7mo agoCloudflare is doing the enshittification strategy, enticing you now, and then extracting value later. You don't want your domains to be in Cloudflare when they lock the gates. If it's a temporary domain, go ahead I suppose.
- themafia 7mo agoThe AWS registrar is actually not bad.
- s_dev 7mo agoI've heard good things about https://www.inwx.com/ https://www.inwx.com/ I'm contemplating moving my domains from namecheap to there as they have a reputation for supporting lots of exotic domains which will make migrating easier. Lots of good stuff in this thread I was not aware of. I have a few vanity domains with personal projects so it's not a big deal if they have low SEO but good to know going forward that I should be prioritising country domains like the Irish .ie one instead of 'fun' looking domains that are memorable.
- shaky-carrousel 7mo agoMorale of the story: never ever use a registry that bases its decisions on Google Safe Browsing. Radix in this case. A very modern looking website for a really caveman support.
- pocksuppet 7mo agoThere's no way to know this until it happens to you or someone else.
- atleastoptimal 7mo agoDomains are signaling. If you have a .online domain you are signaling you can't afford the equivalent .com domain. All the TLD annoyance is a consequence of the lack of status pressure ameliorating the experience of those domain holders (in the same way you never see public health crises in rich neighborhoods)
- NewJazz 7mo agoIf you have a .online domain you are signaling you can't afford the equivalent .com domain. Or don't want to pay a $2k ransom to a name squatter... For some businesses that is a rounding error (saas, other high volume high margin stuff), but for small businesses like restaurants or event planners, spending that much on a domain name would be foolish.
- greatgib 7mo ago> Not adding the domain to Google Search Console immediately. I don't need their analytics and wasn't really planning on having any content on the domain, so I thought, why bother? Big, big mistake. That should be enough to trigger an antitrust case against Google and a split of its activities. When despite unrelated, it becomes the gatekeeper of your presence in internet.
- halapro 7mo agoA registrar using Google's signal to deactivate your service isn't Google's fault. Safe Browsing itself has an appeal process so I think legally they're covered. Users and governments surely appreciate someone filtering bad actors online, even if casualties don't.
- greatgib 7mo agoIt is the moment like that where it looks obvious for third parties to use it and only it to vet customers. To the point where you are forced to deal with Google because parties "can't do anything about it". The moment that 80%+ users go to internet through their browser but at the same time control which we site can be accessed with their safe list. The moment that you need to create an account and start using their services and accept their terms and conditions to be removed from wrongfully added "list" impacting someone.
- mustaphah 7mo agoWorth noting: emails from .online domain (and many other TLDs [1]) are also way more likely to end up in the spam folder. https://www.spamhaus.org/reputation-statistics/gtlds/malware/ https://www.spamhaus.org/reputation-statistics/gtlds/malware...
- anonzzzies 7mo agoSo never buy tlds managed by Radix then ; what a crazy thing to kill domains that are blacklisted by Google AI...
- chrishacken 7mo agoGoogle loves doing stuff like this. At my last company, before we sold it, I had to reverify our Google Business page about once a week because it would constantly just remove the verification for seemingly no reason.
- trklausss 7mo agoDoes anyone know which platform this webpage uses? I like the aesthetics and functionality :)
- sbinnee 7mo agoThe product[1] looks super cool! I can immediately think of my use case, though not for gamin. I am using LibreChat to call LLMs, installed on my home server. But when I open a webtab, it has all these browser tabs I don't want to see. I am sure there are many cases where this product can shine. [1] https://getwisp.online/ https://getwisp.online/
- miki123211 7mo agoThis story (and many others like it) just goes to show that systems that rely on domains in any way can't be called decentralized. Email isn't decentralized. Mastodon isn't decentralized. Matrix isn't decentralized. XMPP isn't decentralized. The web certainly isn't either. All of them can be killed by Safe browsing. All of them can be killed by ICAN (which is under significant influence from the US government). All of them can be killed by their domain registrar and registry operator. All of them can be killed by Let's Encrypt adding their certificates to a CRL, and refusing to issue new ones. All of these will eventually be weaponized, when the war over who controls information truly begins.
- eviks 7mo ago> All of them can be killed > Anyone can be killed, my Lord! So nothing is decentralized?
- mixmastamyk 7mo agoWas just thinking that our workstations should save DNS lookups for our most used domains over time.
- Galanwe 7mo agoICANN really is a shame. There is no oversight, no enforcement, no sense of duty of what being the custodian of internet naming system entails.
- xyz_suspended 7mo ago[dead]
- Animats 7mo agoMy only adventure with off-brand TLDs has been "aether.ltd". This was for my steampunk telegraph office, "The Aetheric Message Machine Company", an elaborate setup we ran at steampunk conventions from 2011 through 2019.[1] Text in a message, and it's banged out on a restored Teletype machine from the 1930s in a brass and glass case, then delivered by a costumed messenger.[1] This got some press coverage back when steampunk was a thing. Somehow, Zoominfo picked up the site, and rated The Aetheric Message Machine Company as having revenue of about $5 million a year and, at peak, 24 employees. We had a back story for roleplay purposes, in the operating manual for the cosplayers.[2] Someone apparently took it seriously. That was a fun project. [1] https://vimeo.com/124065314 https://vimeo.com/124065314 [2] https://aetherltd.com/public/othermanuals/operatormanual05.pdf https://aetherltd.com/public/othermanuals/operatormanual05.p...
- nazgulsenpai 7mo agoIdk, I'd still roll the dice for $0.20 TBH
- avipars 7mo agoMalwarebytes automatically blacklisted any .xyz sites, and I had to file for an exception for a domain I bought... I feel your pain
- RadixRegistry 7mo agoHi Sid, We understand how frustrating it can be when a domain stops resolving unexpectedly. We’ve sent you an email with more details on what happened and the steps taken so far. We’re also reviewing this internally to understand why the domain was flagged and how we can reduce friction in similar cases going forward. We’re happy to continue the conversation over email and share any additional context if helpful. Thank you.
- SergeAx 7mo agoThe culprit here is the TLD operator. Why on Earth would they suspend a domain because of some private web browsing blocklist? FWIW, the client may not even bother with the web browsing; there are hundreds of other things we use DNS for. Alas, the .tech domain is quite popular.