> There is no requirement there is a HTTP service present on the host in order to fulfill its purpose, we just operate it as a courtesy.
I guess this is also done to prevent bad actors from abusing the fact that this domain is hit by people who might not know what they're doing (the ones copy-pasting code without reading it)
Yeah there’s definitely a lot of sensitive data that gets sent to the domain just because of people not changing configs
I don't understand, what risk would there be if they chose _not_ to serve a site?
More the DNS and DNSSEC and the like. Whether or not there is actually an HTTP server responding is irrelevant to whether or not those securely point anywhere but a malicious system.