upvote
If you do have tests relying on it... stop it:

> This is not a service; avoid relying on it for testing and monitoring purposes.

reply
Before this submission, it genuinely never occurred to me that people would actually have tests that rely on example.com being up, let alone depend on its content.
reply
Same, and now I’m grinning ear to ear!
reply
Opus 5.5 in Claude code added a unit test checking DNS and internet access using example.com as the target on a project I'm building yesterday. It's an agent sandbox (I know, yet another), so the call was expected to fail, but still... It should have at least targeted a captive portal endpoint or a project owned domain.

I caught it in review but thousands of others won't.

That ship has sailed I would say.

reply
If it breaks in those thousands of projects, that will be an important lesson to review your agents more carefully. So a net win?
reply
More likely the agents will fix it as fast as they made it and people will continue not caring so much about reviewing what agents are doing for cases where they don't care so much (which is a lot of cases)
reply
So is wrong to use captive.apple.com for tests as well? It's nice to know your network can reach the internet and these pages are generally fairly reliable.

[1]: https://captive.apple.com/

reply
A HTTP request for http://www.msftncsi.com/ncsi.txt returning 200 OK and the text Microsoft NCSI. This is the url windows has been using for decades to determine if the device is online. It is highly reliable.
reply
These pages are unfortunately getting special treatment from quite a few networks these days, among other things to avoid iOS users getting stuck in a loop of trying to connect, and getting disconnected by the OS due to a "non-working connection" for local-only networks like in-flight entertainment systems.

It's a shame that we don't have any standards for the concerns of canonically testing Internet reachability and for authoritatively redirecting network users to a captive payment portal (without having to resort to ugly hacks that often break with TLS).

reply
reply
Woah, amazing! Do you know if any popular network stacks actually support it?

But even just having an RFC to yell about is great, thank you :)

reply
If they say that it's not intended as a reliable service for testing purposes it can't be that reliable, and they might take it down or change the structure arbitrarily at any time, etc.

So yeah I would pick something simpler for a network access test probably?

reply
Just don't blame the user and/or their internet service when the service you're relying on inevitably goes down.
reply
Why not ping 8.8.8.8 or 1.1.1.1 or time.windows.com? Things that are actually designed to be highly available services
reply
Is there any reason to believe captive.apple.com is any less "designed to be highly available" than time.windows.com?

It's a static page that every Apple device relies on saying only:

  <HTML><HEAD><TITLE>Success</TITLE></HEAD><BODY>Success</BODY></HTML>
reply
The only risk is that Apple hasn't announced it as being reliable or promised to keep it up or the format the same in any way. They could 100% pull it out from under everyone, with modifications in their OSes prepared for the change
reply
Also some captive portals fake/emulate responses from this service.
reply
1.1 is enough.

  ~$ ping -c1 1.1
  PING 1.1 (1.0.0.1) 56(84) bytes of data.
  64 bytes from 1.0.0.1: icmp_seq=1 ttl=56 time=7.89 ms
  
  --- 1.1 ping statistics ---
  1 packets transmitted, 1 received, 0% packet loss, time 0ms
  rtt min/avg/max/mdev = 7.888/7.888/7.888/0.000 ms
reply
When did this start working? Did they backport IPv6-style addressing, or did I just never know this?
reply
Thanks! I'd forgotten that 1.1 and 1.1.1 resolve. I'll not infrequently ping 1.1.1.1.1 with overzealous typing. That will, alas, not resolve.
reply
I have been naively using example.com in the browser. WHATWG URL throws if there is no origin when constructing the URL. Web apps that need to construct _just_ the pathname must go through this song and dance. `new URL("/blah", "https://example.com").pathname` This isn't relying on any external example.com service but I'm learning the lesson.
reply
What kind of tests would this break? Aside from the advice on the page itself (which, iirc, is new anyway), i'm wondering why any testing would actually involve the contents of design of the page. Just a weird 'sanity' check?
reply
People depend on all sorts of weird stuff working exactly as expected. https://www.hyrumslaw.com/

As an example, depending on "man -w" not outputting anything to stderr: https://unix.stackexchange.com/questions/405783/why-does-man...

reply
Our saas had an internal-use, undocumented, publicly accessibly but not publicly used (by us) health endpoint that included an internal version number.

We removed the version and a few customers complained we broke their stuff.

reply
I landed a massive database upgrade on a payroll system years ago, end-to-end standardization, cleanup, and improvement with a seamless rollout.

Our back clapping was interrupted by an angry customer phone call. One of our customers had gotten access to our internal schema and had a massive reporting setup in Access solving most of his needs.

I ended up converting his reports using some internal tools we had. Customers will grab anything to give them.

[The caliber and depth of his reports were such I wish we would have bought them instead of making me spend months building out our own reports.]

reply
> [The caliber and depth of his reports were such I wish we would have bought them instead of making me spend months building out our own reports.]

Learning from customers is some of the best learning you can do. :)

reply
I had one customer that managed to figure out which stored procs were tied to which reports we were using. Then he would deliberately break it in weird subtle ways them and call tech support 'just to see how we would react'.
reply
The API surface is what’s exposed, not just what’s documented.

This is probably an even more important principle in the age of LLMs.

reply
While not the same thing, I was once stung by a test failing because a dependency of a dependency decided on a minor version bump that foo@example.com wasn't a valid email address.
reply
Probably akin to: https://xkcd.com/1172/
reply
I knew what this was before clicking on the link, but for a lot of people, it may be a 1053.
reply
One of the critical things I use example.com for is triggering wifi login portals as it doesn't not use SSL. Certificate pinning and all that fancy stuff has made it so the browser has an absolutely awful time figuring out what to do when https://google.com does not present itself as the same host it was earlier.
reply
I like using http://neverssl.com/ for that... easy to remember (although I guess example.com was as well).
reply
Same server also has an endpoint for that: http://no-tls.testserver.host. Sends RST for any attempted TLS connections, so clients always fall back to plain HTTP.

Also as a _long_ list of other specialist TLS endpoint configurations if you're interested, which can be arbitrarily combined, see https://testserver.host/#tls-endpoints.

That gives neat tricks like https://tls-v1-2--expired--incomplete-chain--http2.testserve...: only accepts TLS 1.2, then sends an expired certificate but fails to send the intermediate cert for the chain (so the client must infer it) and then negotiates HTTP/2 for the connection on top. Fun!

reply
Do you do any sort of rate-limiting to stop people/bots from hammering it (accidentally or otherwise)? Or do you just let it fall over under load.
reply
> For the desperate people whose tests all just broke...

The web page at example.com is maintained as a courtesy by IANA in order to explain the purpose of the example.com domain to wayward humans.

In the nomenclature of RFC 2119, one MUST NOT design computer systems that rely on the correct operation of an HTTP server at that domain. [0] Plus, it's _really_ rude to pound on a small-scale service being provided as a courtesy... go hit the home page of a tech megacorp (such as Microsoft or Google) or the status page for a major CDN (such as Cloudflare or Akamai) instead!

[0] I expect that someone here will want to pop up with a "gotcha" where they say something like "Oh, but IANA's email says that automated use is strongly recommended against, rather than prohibited and besides, they can't actually stop me from doing it!". To that, I reply "Sure, and standards-writers can't actually stop implementers that do the profoundly antisocial thing and do the things they MUST NOT. As any adult who's been paying attention to the world around them throughout their lives knows, there's only so much you can do to stop people who are very determined to be enormous assholes.".

reply
> the status page for a major CDN (such as Cloudflare or Akamai)

Would you settle for any old static page served by Cloudflare? For instance, example.com? https://bgp.tools/dns/example.com

reply
That they've put it behind Cloudflare doesn't mean it's "served by Cloudflare"

Maybe Cloudflare gives them a good rate, or is donating service, but it's also possible or even likely that IANA is just using Cloudflare as a vendor, and therefore is paying for all the traffic, which is why they don't want people relying on it or hammering it all the time

reply

  In the nomenclature of RFC 2119, one MUST NOT design computer systems that rely on the correct operation of an HTTP server at [example.com.] Plus, it's *_really_* rude to pound on a small-scale service being provided as a courtesy.
reply
> go hit the home page of a tech megacorp (such as Microsoft or Google)

Much too big for metered data, full of ads, and importantly they all mandate HTTPS these days, which breaks my use case of forcing a captive portal on paid/login-gated Wi-Fi to render.

example.com is (unfortunately for the IATA) the almost perfect "can I reach the Internet" service: It's unlikely to go away, supports HTTP, is fairly small, easy to remember, and I don't care if a captive portal poisons my DNS cache with a fake response temporarily.

reply
I think we're on the verge of a big disruption coming for the example.com's business. I can see a SaaS opportunity. We can use AI to speed up time to market.

/s

reply
example.com-as-a-service, although XaaS is no longer hip so now it'll be example.ai, an AI that will generate an example.com style landing page using frontier AI models. $20 / month for the beginner plan (100 requests/month), contact us for pricing.
reply
Enterprise ready. Coming soon in Q4.
reply