Live data from Hacker News

The Perils of an .xyz Domain

spotvirtual.com

91–100 of 282 posts

Re: The Perils of an .xyz Domain

#91

Earlier quoted context omitted.

It was wild to me too. I have an .xyz domain, which seemed appropriate for a non-commercial math site. I'd try to send links of math experiments to friends and colleagues via SMS, so they could tell me if they worked right on their phones or not. Can't tell you how much confusion and frustration it caused that the links were simply not being delivered, though all the conversation around the links went through just fi…

> which seemed appropriate for a non-commercial math site They are used by large cooperations too. The Alphabet domain is abc.xyz. Science Corp's is science.xyz.

I didn't know about abc.xyz, that's a really nice URL

Re: The Perils of an .xyz Domain

#92

Before I get into email business(I run my own email forwarding service[0]), I don't understand why provider block those domains. Then I immediately got it. The amount of spam emails from .xyz .click .faith .top is huge. And with every email comes from them, we have to run spam scanner, which isn't cheap. So we have to score those TLDs more sensitive. https://www.spamhaus.org/statistics/tlds/ can give some insight abo…

From that spamhaus link .xyz has a lower bad percentage (4.4%) than .com (5.1%) and .net (10.5%).

Re: The Perils of an .xyz Domain

#93

Before I get into email business(I run my own email forwarding service[0]), I don't understand why provider block those domains. Then I immediately got it. The amount of spam emails from .xyz .click .faith .top is huge. And with every email comes from them, we have to run spam scanner, which isn't cheap. So we have to score those TLDs more sensitive. https://www.spamhaus.org/statistics/tlds/ can give some insight abo…

Seems like an easy solution is to simply start spamming from .coms like we had to back in my day.

Re: The Perils of an .xyz Domain

#94

I have a .haus domain for personal use. I can send and receive email just fine, but I do run into a lot of apps that do some sort of misguided "validation" on the email address and reject .haus as an invalid domain. One retailer lets me use the .haus email address as a login, but once I log in and try to make a payment it requires me to enter a different "valid" email address to send the receipt to. It's very irritat…

I have a .co domain that gets rejected occasionally as well. Highly regret that domain choice since people often mistake it for .com.

I had a .co domain, and it was a pain to spell it out to people. "It's like .com, but without m" and people usually got confused, or thought it was a typo and "fixed" it as .com.

I have a .dev domain now and everything seems to be running smoothly, plus it's +20% cheaper.

Re: The Perils of an .xyz Domain

#95
post #24

> One surprising side effect of having a .xyz domain is that the mere inclusion of .xyz inside of a text message will result in a silent delivery failure for many providers. This is wild to me. Tested it out myself and I couldn't send an SMS with a spot.xyz link to/from Google Voice T-Mobile. And no "failed delivery" notice either, just a silent failure. And yet I still get so many texts that are obviously spam or ph…

...whoa, yeah same here. tried "test spot.xyz" then "test spot.com" T-mobile T-Mobile. "test spot.xyz" did not send. Even weirder, I got a confirmmation that it was delivered. It looks like T-Mobile looks for ".xyz" within the SMS and will silent drop the SMS (though it will claim it is delivered). ".xxyz" works, "..xyz" or ".xyzz" does not. "xyz" works, so does ".xy".

Use signal. If you're encrypting your message, they can't filter your message out.

Re: The Perils of an .xyz Domain

#96

Earlier quoted context omitted.

It's not censorship if one of the peers on the conversation do it. It's certainly censorship if a monopolistic or oligopolistic platform does it. And there's a lot of middle ground where things get hard,

>>It's certainly censorship if a monopolistic or oligopolistic platform does it this seems like a good point, I'll have to think on it. For this particular situation I'm having a hard time seeing the argument on the basis that .xyz domains are cheap and get used for lots of attacks as stated in the article, so is it censorship or defense? I think the question at the heart of my disagreement would be "what speech is b…

It would get deep into the grey area if Google users had any capacity of enabling the communications with those sites. As of today, Google is the one in control of the communications, and dictate who can reach anybody over most of the internet. They just don't have a policy of empowering their users to decide who they want to talk to.

What speech is being censored is harder to discover. They are blocking people from communication without any feedback, and it would take a large effort to reach them and discover who they are. Certainly most of what is blocked is spam, but that's true for whatever block you implement today, unless you spend an unreasonable amount of resources targeting it into non-spam.

Re: The Perils of an .xyz Domain

#97

Earlier quoted context omitted.

You'd be getting an unbelievable amount of SMS spam if carriers weren't allowed to block messages. There's a lot of bad actors out there.

I wonder if that's why he mentions "without a valid reason".

"We get a lot of spam from those" would fall well within a vaguely defined "valid reason", I'd think.

(Most of my SMS spam comes from .info domains.)

Re: The Perils of an .xyz Domain

#98

Earlier quoted context omitted.

I have this same problem with "obscure" .net domains. My text messages are silently dropped. The only work around I found is to not include http:// , just use the bare domain. Personally, I find this behavior of my SMS provider reprehensible.

Is it reprehensible only when it impacts you or is it still reprehensible when it's blocking hundreds of spam messages a day you might otherwise be receiving?

Surely there are better ways to reduce spam than blocking entire TLDs? I also think it's the silent, unfixable nature that annoys most people. Email spam goes into your spam box, where you can still access it. You can mark email as not being spam. No such luck here

Re: The Perils of an .xyz Domain

#99
I run email servers and I get such a massive amount of spam on "vanity" TLD's that I just block them outright. I don't automatically block them all but any that start sending serious levels of spam get blocked. Which is most of them and that block covers the whole TLD. It's just too much work to try anything else.

Now this is just for incoming email. I still allow web browsing and links to these domains through various systems and outgoing mail to those domains works.

The incoming mail though, I just can't allow it. It's just pure spam at ridiculous levels.

Re: The Perils of an .xyz Domain

#100

> One surprising side effect of having a .xyz domain is that the mere inclusion of .xyz inside of a text message will result in a silent delivery failure for many providers. This is wild to me. Tested it out myself and I couldn't send an SMS with a spot.xyz link to/from Google Voice T-Mobile. And no "failed delivery" notice either, just a silent failure. And yet I still get so many texts that are obviously spam or ph…

I have this same problem with "obscure" .net domains. My text messages are silently dropped. The only work around I found is to not include http:// , just use the bare domain. Personally, I find this behavior of my SMS provider reprehensible.

I ran into this recently even on Facebook Messenger. A friend of mine was hunting for a short domain name and I had a list of some three character .net and .org domains I recently had found that were available.

Cut and pasted the list and the message wouldn't send.

Narrowed it down to one. Typed just the bare domain. Wouldn't go through. (It was something incredibly benign like n17.org)

Couldn't find a history on that domain name for why it would have been filtered.

At least messenger responded with 'couldn't send message' but still no clue as to why... and it took me sending each domain name individually until I found the one that was failing the entire message.

Post reply on HN