TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Before you buy a domain name, first check to see if it's haunted

936 pointsby bryanbraun7 months ago

43 comments

lefstathiou7 months ago
This happened to me and I found this tool super helpful to get my site unblocked: <a href="https:&#x2F;&#x2F;dnsblacklist.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;dnsblacklist.org&#x2F;</a><p>I purchased a valuable premium domain to host a personal art collection (of anime cels). For some bizarre reason, the site was inaccessible from my work computer and it was de-listed from Google even if I typed the url itself into search.<p>I hired a square space specialist to figure out why, to no avail. I then begged our company’s CISO to investigate and it turns out we had some firewall setting on UniFi that blocked the domain because it appeared on a list. Once I checked way back, it turns out that it was as an anime porn aggregator years back. I personally reached out to all the web filters out there (Google, Symantec, bing) and one by one filed tickets for them to mark it as art instead of pornography and it worked. I am now properly crawled on Google but still MIA on Bing, search console is giving me some BS error that’s incomprehensible, typical of MSFT.
评论 #41952254 未加载
评论 #41959329 未加载
评论 #41969323 未加载
评论 #41952442 未加载
romanhn7 months ago
Another &quot;haunted domain&quot; check is by trying to post about it on social media. I ran into this with my current project&#x27;s domain name. After building an MVP and trying to test the social sharing functionality, I found that Facebook was blocking the domain outright. Turns out there was some spamming from it years ago. Getting it unblocked was extra fun, as the page to request manual review was itself broken! Thankfully I knew someone on the inside who alerted the relevant team, but the whole experience was quite the novel speedbump.
评论 #41953201 未加载
评论 #41956004 未加载
评论 #41969338 未加载
评论 #41955451 未加载
dtdynasty7 months ago
&gt; Ideally, search engine algorithms would give new domain owners a fresh start.<p>Sadly, I think this would be instantly gamed by abusers. They would release the domain name and attempt to register as a new owner or start repeatedly doing handoffs. It&#x27;s difficult to tell who the owner is changing between and whether or not the new one is a better actor than the former.
评论 #41952814 未加载
评论 #41951814 未加载
评论 #41953404 未加载
评论 #41954298 未加载
评论 #41953813 未加载
评论 #41951944 未加载
veyh7 months ago
Some time ago I noticed that my side project (with a domain that is not haunted) shows up fine on Google but not Bing&#x2F;DuckDuckGo.<p>So I checked the Bing Webmaster Tools. URL Inspection says &quot;Discovered but not crawled - The inspected URL is known to Bing but has some issues which are preventing indexation. We recommend you to follow Bing Webmaster Guidelines to increase your chances of indexation.&quot;<p>That&#x27;s quite unhelpful. What&#x27;s more, when I open the &quot;Live URL&quot; tab, it says, in green: &quot;URL can be indexed by Bing.&quot;<p>It&#x27;s a simple static Hugo site hosted on Cloudflare R2 (DNS mapped directly to bucket). <a href="https:&#x2F;&#x2F;pagespeed.web.dev" rel="nofollow">https:&#x2F;&#x2F;pagespeed.web.dev</a> gives it a score of 100 in every category.<p>Anyone else had something like this happen?
评论 #41952227 未加载
评论 #41952238 未加载
评论 #41955156 未加载
8organicbits7 months ago
Another variant of this is cached or preloaded security configurations.<p>HSTS (which forces browsers to validate HTTPS when connecting) asks browsers to cache the configuration for a set &quot;max-age&quot;. Some sites set huge values here, like Twitter&#x27;s 20 year max-age[1]. There&#x27;s also the preload lists [2] to consider. This creates a problem if you want to serve non-HTTPS&#x2F;unencrypted HTTP on your new domain and the previous owner didn&#x27;t.<p>MTA-STS [3] is another variant that&#x27;s becoming more popular. It limits which mail servers your domain uses and enforces TLS certificate verification. &quot;max_age&quot; is capped to a year by the RFC. If you don&#x27;t set your own policy, then the previous domain owners policy would impact any senders who previously cached the policy.<p>Thankfully HPKP (key pinning) is obsolete, otherwise you&#x27;d also need to worry about old pinned keys too. That RFC recommended, but did not enforce, a 60 day max-age limit.<p>These are especially tricky as the old security policy only lives in the caches of any end-user devices that previously connected to the domain. Double haunted.<p>[1] <a href="https:&#x2F;&#x2F;alexsci.com&#x2F;blog&#x2F;hsts-adoption&#x2F;" rel="nofollow">https:&#x2F;&#x2F;alexsci.com&#x2F;blog&#x2F;hsts-adoption&#x2F;</a><p>[2] <a href="https:&#x2F;&#x2F;hstspreload.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;hstspreload.org&#x2F;</a><p>[3] <a href="https:&#x2F;&#x2F;alexsci.com&#x2F;blog&#x2F;smtp-downgrade-attacks-and-mta-sts&#x2F;" rel="nofollow">https:&#x2F;&#x2F;alexsci.com&#x2F;blog&#x2F;smtp-downgrade-attacks-and-mta-sts&#x2F;</a>
评论 #41960792 未加载
评论 #41971002 未加载
Pikamander27 months ago
A client of mine once swapped over to a new domain that was coincidentally one letter away from another major domain. It wasn&#x27;t an attempt to typosquat or anything nefarious, but Chrome started automatically showing everyone a big scary warning page before entering the site. We looked into appealing it but there was no guarantee of it getting whitelisted in a timely manner, so we ended up canceling the domain migration before they lost too much traffic.
评论 #41956928 未加载
r1ch7 months ago
This can also happen with IP addresses. We recently moved one of our sites to a new IP and got a trickle of complaints about it being inaccessible from various authoritarian countries. After some digging, the new IP was used as a Tor bridge (not even an exit node) over _ten years ago_. I gave up any hope of fixing that and just ordered a different IP address.
rsingel7 months ago
Not always the easiest thing to do. A haunted domain could have been haunted 15 years ago. And Google refuses to tell you why or fix their system.<p>Just one more place where the web gets screwed by a company too big to have to do basic customer service.
评论 #41952644 未加载
p3rls7 months ago
The usual version of this is the popular SEO technique of buying an aged domain with a few backlinks and slapping a wordpress on it.
lmz7 months ago
If it was easy to reset reputation with search engines what&#x27;s stopping people from saying &quot;under new management&quot; every once in a while for an existing poor reputation domain? Probably better to just cut their losses and find another domain.
snowwrestler7 months ago
&gt; It wasn’t until I had redirected all of my musicboxfun.com traffic to musicbox.fun that I noticed that something wasn’t right: my web traffic from organic search dropped to zero.<p>Some practical advice here: do not change your canonical domain[1] name unless you really really have to.<p>If he had just set his fun new domain to redirect to the existing domain, instead of making the new domain the canonical, it likely would have had no negative effect.<p>I’m not saying this is how things <i>should</i> work. But the practical reality is that your domain name is like a Social Security number: it’s the basis for assigning a type of reputation score, even though it was not intended to do that originally.<p>[1] The domain at which your web pages finally load, after all redirects have completed.
viraptor7 months ago
I&#x27;ve had an opposite experience. One domain I bought was used for an entirely different purpose in the past, which got linked on a Wikipedia article in references. This gives me some good link juice and at least matches the geo area of the previous business. Since it&#x27;s an extremely niche entry and low on the list of references, I decided to be slightly naughty and not touch it for a couple of years. Not sure what&#x27;s the opposite of haunted in this case, but it was just as surprising.
评论 #41955814 未加载
anonzzzies7 months ago
I have a lot of sites (all saas) and more and more people send me cease and desists and lawyer threats because they go to google, enter &#x27;something&#x27; that&#x27;s remotely phonetically similar to a domain I run and then click on my site. They paid on some site that sounds a LITTLE bit (if you squint) like my domain and now they are scammed and want to sue me. Now I understand scammers do this as well, but I had actually someone <i>turn</i> <i>up</i> at our office (which is my business partner his home) with bank receipts with a really not so similar name, however if you type it in google we pop up first even though our businesses are not at all related.
praptak7 months ago
<i>&quot;Ideally, search engine algorithms would give new domain owners a fresh start.&quot;</i><p>I don&#x27;t think it&#x27;s possible to fix this problem without also helping bad actors. Maybe it&#x27;s a problem that just isn&#x27;t worth fixing. Just don&#x27;t buy preexisting domains unless it&#x27;s a project big enough to justify the necessary cost of due diligence.
评论 #41958042 未加载
评论 #41952986 未加载
评论 #41954841 未加载
evilotto7 months ago
This happens with physical addresses too, for similar reasons. The ABC (Alcoholic Beverages Commision) tracks complaints against physical addresses, and too many violations will get an address banned from permits. Then a new owner comes in with a new business and gets mysteriously denied for a liquor license, even years later.
评论 #41953825 未加载
superkuh7 months ago
For running a mail server <i>every</i> new domain is haunted.
评论 #41952834 未加载
评论 #41971079 未加载
moribunda7 months ago
Basic SEO stuff, you have marketplaces that check history, you have domain search engines aggregating data from multiple sources - not only ahrefs.<p>Checking web archive is a basic operation to test if site was hosting anything fishy - not only pirated stuff or porn - often websites has been hacked and changed into link farms or simply were bought on aftermarket simply to use it&#x27;s SEO value to pass the strength to other domains.<p>Anyways good point regarding email filters.
bebrbrhrj7 months ago
Interesting. Domain as a unit of trust makes sense until it doesn&#x27;t. Buying a second hand domain is like a second hand car. But you may not know it is second hand!<p>I think the mistake here is the redirect old to new. That is always risky so only do it if deseprate. In this case I would have done the redirect from new to old. Then just use the new as a vanity url.
评论 #41971058 未加载
bagpuss7 months ago
one other thing i would suggest is to set up a catch-all email for the domain and see what gets sent to it, sometimes you can access accounts associated with the domain, socials etc
评论 #41951541 未加载
评论 #41951718 未加载
8bitme7 months ago
This sort of thing is also an issue for phone numbers, some other company could have used your new number for robocalls and gotten it spam blocked on Truecaller and similar services.
hggigg7 months ago
Years ago I bought the carelessly discarded domain of a defence contractor that was acquired by another one. And set up a catch all email forwarder. Had weeks of fun reading all the emails that I got sent. There was nothing &quot;secret&quot; but plenty of social and business stuff still going on.
AStonesThrow7 months ago
One risk of pre-validating a domain before purchase is that it&#x27;s not a good idea to tell strangers about your interest in such a property.<p>Even automated queries are likely to spill the beans. Someone else could snag the purchase before you, or bid up the price. But it&#x27;s a risk you may need to calculate.
ellisv7 months ago
I wonder if there’s a market for rehabilitating domain names
评论 #41952210 未加载
flemhans7 months ago
IP addresses can be haunted too, like if they were previously used for spamming.
ozim7 months ago
Conversely when you drop domain don’t forget you might have accounts on emails or some DNS verification in services that you better explicitly discontinue before just dropping domain.
anonym297 months ago
My very first domain was haunted. The warning sign was firewall blocks against the domain at both school and the public library. As it turned out... a previous owner in the early 2000&#x27;s was running a sort of proto-Netflix, but with VHS instead of DVD, and that was exclusively targeting the... erm... &quot;adult entertainment&quot; market.<p>Wayback machine would&#x27;ve saved me there, had I done my due diligence!
markx27 months ago
Automattic.com was bought (no idea if it was unregistered &#x2F; acquired) by Matt Mullenweg when he set up the company. He also bought <a href="https:&#x2F;&#x2F;a8c.com" rel="nofollow">https:&#x2F;&#x2F;a8c.com</a>.<p>Here in the UK with EE&#x2F;BT that correctly redirects to automattic.com, but it might not for you depending on your ISP.<p>The wayback machine shows adult content links prior to the domain being put on sale, hence the blocking.
评论 #41953420 未加载
e_y_7 months ago
Not quite haunted but I&#x27;ve had people report that my website hosted on a .quest domain is blocked on their work computer. My best guess is that their filter thinks it&#x27;s gaming related (it&#x27;s not) or maybe they just block all &quot;weird&quot; domains.
评论 #41952940 未加载
rschiang7 months ago
I&#x27;ve had this with anti-virus flagging domains and VirusTotal was helpful: <a href="https:&#x2F;&#x2F;virustotal.com" rel="nofollow">https:&#x2F;&#x2F;virustotal.com</a><p>But it does require manually reporting false positives to each vendor
andrewmcwatters7 months ago
I’ll add: and if you lease a VPS, check out its address reputation and reverse DNS record.
评论 #41951777 未加载
评论 #41951679 未加载
hamilyon27 months ago
&gt; search engines treat links to your site as a massive signal of relevance and trust<p>I am admittedly a bit distant from SEO. The above is not true and hasn&#x27;t been true for a long time.
miragecraft7 months ago
Haunted is a weird way to call them, these are stigmatized domains.
评论 #41953627 未加载
mouse_7 months ago
I feel like this should be the registrar&#x27;s responsibility. Least they could do is give a disclaimer and&#x2F;or a heavy discount.
Kalanos7 months ago
The domain could also have been used to run spam email campaigns, meaning that it is blacklisted by email servers
veunes7 months ago
A risk that’s easy to overlook until it bites you
pmarreck7 months ago
sounds like the makings of a business service
Havoc7 months ago
Also be careful connecting new domains to cloudflare. It has a habit of adding old info from presumably a previous owner.<p>Managed to get a takedown notice thanks to that idiotic &quot;feature&quot; while not even aware the domain is serving anything
评论 #41954685 未加载
chrisallick7 months ago
that is amazing
ceroxylon7 months ago
Yet another valuable use for the WayBack Machine, glad it got a mention.
teddyh7 months ago
Calling a domain “haunted” is an awful, terrible way to frame it. It places all the badness of the domain <i>on the domain itself</i>, as if the domain name had something with it which could be removed or fixed by the domain owner. Instead, what has actually happened is that the domain is <i>blacklisted</i> by entirely too powerful entities. The problem lies with these blacklisting entities, not with the domain, and the solution must be done there, too. It should not be a domain owner’s responsibility to get out of being unfairly blacklisted.<p>It’s like when cars took over the streets, and instead of blaming cars for being dangerous for regular people using the streets for walking, the concept of “jaywalking” was invented by car companies to place the blame on people for daring to obstruct cars. Or the concept of “personal carbon footprint”, commonly used to move blame from companies to individuals, when in reality whatever individuals, even in aggregate, could do is utterly insignificant compared to what companies and legislation could accomplish.
评论 #41955151 未加载
评论 #41955181 未加载
评论 #41955071 未加载
评论 #41955732 未加载
评论 #41955308 未加载
评论 #41955558 未加载
评论 #41955454 未加载
评论 #41955461 未加载
biddendidden7 months ago
Especially on an .io TLD; it&#x27;s haunted by the lovely US taking advantage of Chargossian exploitation.
christina977 months ago
TLDR: when you rent anything, double check who rented it before you and what they did with it to make sure it’s in good condition.
benreesman7 months ago
As someone who knows what active persecution on this site is I relish the opportunity to say what I really know under a pseudonym.