I just wanted to post this here because I want to help you all and hurt gen.xyz as much as possible. I had a .xyz domain through njal.la which I used to host jellyfin, homeassistant, and other basic things for friends and family. My domain recently became inaccessible without any notice. After a while of troubleshooting, I found that it had been reported to xyz as abuse, and they must have done zero investigation whatsoever before serverholding my domain. I thought about opening a ticket with xyz to get my domain back, but realized that I no longer wish to buy from some shitty company that will take down any site without warning. Bought a .com domain since they are somewhat reputable, and I would advise everyone here to never buy a .xyz domain. Angry rant over.

  • peskywarrior@lemmy.world
    link
    fedilink
    English
    arrow-up
    82
    arrow-down
    8
    ·
    edit-2
    2 years ago

    Just wanted to say in case others see this, you can buy a .xyz domain from reputable places (maybe for a higher cost). I believe the OP is talking about the specific site ‘gen.xyz’.

    I have an xyz domain with Cloudflare, host many things on it (like Jellyfin), and haven’t had any issues yet.

    Edit: as many have pointed out, my understanding of registrars was wrong and gen.xyz actually owns all xyz tlds. Sleep in fear if you own one I suppose

    • viking@infosec.pub
      link
      fedilink
      English
      arrow-up
      48
      ·
      2 years ago

      The thing is that gen.xyz is the registrar itself, i.e. the highest authority for this tld. If they blacklist domains, you’re screwed.

    • Snot Flickerman@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      15
      arrow-down
      1
      ·
      2 years ago

      Cloudflare can still go bad, but its usually for high-capacity users who are using way more than the average. I haven’t seen any homeserver users get hit with any trouble, but I’ve seen a couple small businesses have bad situations with Cloudflare, although it honestly seems like the minority.

      Cloudflare has issues but for most its probably fine.

      • peskywarrior@lemmy.world
        link
        fedilink
        English
        arrow-up
        9
        ·
        2 years ago

        From what I’ve seen/heard, if you follow the ToS (usually by not proxy-ing hosts that shouldn’t be proxied or are in violation if they are) there’s nothing to be afraid of ¯⁠\⁠_⁠(⁠ツ⁠)⁠_⁠/⁠¯

    • HumanPerson@sh.itjust.worksOP
      link
      fedilink
      English
      arrow-up
      7
      ·
      2 years ago

      I bought from njal.la. they were almost entirely unhelpful but pointed me to the site for the tld. It appeared through their wording that gen.xyz who owns the xyz tld was responsible for taking the domain down. I bought my new domain through porkbun tho.

    • danhab99@programming.dev
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 years ago

      How expensive can “reputable” be. I got danhab99.xyz for like ¯⁠\⁠(⁠°⁠_⁠o⁠)⁠/⁠¯ $20/year?? Who cares

        • LifeInMultipleChoice@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          2 years ago

          This is all news to me. I thought .xyz was owned by Google after they became Alphabet and had that ABC.XYZ site years ago.

          Love when I see stuff like this and get to learn something new

  • earmuff@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    14
    ·
    2 years ago

    Also, don‘t use it for any mail servers. Spam Assassin gives a negative score by default on *.xyz domains. Stupid as shit, but I had to learn the hard way.

  • TWeaK@lemm.ee
    link
    fedilink
    English
    arrow-up
    20
    arrow-down
    7
    ·
    2 years ago

    I mean, a jellyfin server is typically full of copyright protected material. I also wouldn’t expect them to notify you in advance, however they should still send some notice when they stop providing the service you’ve paid for.

    • HumanPerson@sh.itjust.worksOP
      link
      fedilink
      English
      arrow-up
      10
      arrow-down
      1
      ·
      2 years ago

      It typically is, and I won’t comment on whether mine is, but that isn’t enough reason to take it down. I was quite careful about who I gave access to, as well as making sure people had secure passwords. It is highly unlikely that anyone got in and saw any copyright violation before reporting it.

    • givesomefucks@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      arrow-down
      41
      ·
      2 years ago

      Yeah, dude tried to open his own personal Netflix and is surprised it got taken down.

      From post history he managed to keep it up for less than a month.

      I’m betting by “friends” he meant either online friends he’s never met, or people he wanted to impress.

      So they gave zero fucks and handed it out to more people. Like, just the idea that you’re giving it to so many people that you actually buy a domain?

      There’s a reason everyone isn’t already doing it already.

      • HumanPerson@sh.itjust.worksOP
        link
        fedilink
        English
        arrow-up
        23
        arrow-down
        3
        ·
        edit-2
        2 years ago

        I kept it up for more than a year. By friends I mean like 3 people I know in real fucking life, and I made them all set secure passwords. Way to assume the worst about people, it is a very healthy attitude to have.

        • oldfart@lemm.ee
          link
          fedilink
          English
          arrow-up
          9
          arrow-down
          2
          ·
          2 years ago

          This whole thread is depressing to read, full of corporate bootlickers putting blame on you.

  • umami_wasabi@lemmy.ml
    link
    fedilink
    English
    arrow-up
    8
    ·
    2 years ago

    Shit. I have my peraonal domain hosted on .xyz for email. Guess time to migrate. Any TLD suggestions?

  • slazer2au@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    3
    ·
    2 years ago

    Yeah the cheaper the domain the more likely it is for abuse to occur and your own domain to be lumped into that category.

    • HumanPerson@sh.itjust.worksOP
      link
      fedilink
      English
      arrow-up
      6
      ·
      2 years ago

      I had mine through njal.la. It was the registry itself that locked it though. I switched registrar too after njalla took a long time to respond to my question with a vague, unhelpful, and short response.

    • dinckel@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 years ago

      I have mine through namecheap too, although the name server is from cloudflare now. The only issue i’ve had was some shitty forums preventing registrations from anything that wasn’t @gmail.com