Story of an expiring domain name

Goodbye, synthethics.eu, a domain for confronting companies about their AI music adoption. Also, the University of Colorado sent me spam.

Fabio Barbero published on
6 min, 1194 words

Categories: Random

Tags: Tech

Last summer, after getting lost on the Monte Rosa with my dad and visiting a friend who became a shepherd in the Pyrenees, I did a bikepacking tour with two good friends of mine. Each one of these adventures deserves its own post, which I might write one day.

During this bike tour, my friends stopped at a Lidl supermarket in Austria to grab some snacks for the road, while I was guarding our bikes outside. While inefficiently communicating over a walkie-talkie, my friend told me he was certain the music in the supermarket was AI-generated. He said a lot of the lyrics (e.g. "in the heart of the night") and the overall music really sounded like AI slop.

I couldn't quite believe it. I then found an older Reddit post reporting a similar experience in a Lidl in Vienna. At the time, I was rapidly moving away from the excitement of a new niche technology towards concerns about the impact this technology could and was having on our society. This felt like a good example of "yeah, you probably shouldn't do that", and of the dubious choices brands make to maximise their profit.

So I wanted to act. I wanted to understand what their reasoning was, and maybe voice my disappointment. And this felt like the perfect excuse to buy a domain name. In case you don't know, many developers love buying domain names for projects they might never do.

Side note: one thing that is still unclear to me in tech is how exactly domain names are provided. My understanding is that there is a big central organisation that allows countries or organisations to have "top-level domains", like .com or .eu, and then these can decide the conditions of "sale" of their domain names. Although a domain name can never be "bought", you can only rent it for an agreed amount of time. It is still unclear to me how the whole economy of it works, who sets the price, and how prices are prevented from skyrocketing.

The plan was simple. Get a domain name, pretend to be a "collective of people" investigating AI adoption in companies, contact all companies that were found to use AI music in their stores online, and get a clearer picture.

After getting some ideas from LLMs (I know, the irony...), I settled on the beautiful name "SynthEthics", which I still find to be a very clever play on words. I got a ".eu" domain because I was planning on targeting European companies, and because I really like .eu domains.

While checking that my website, at the time of writing, was indeed archived on the Internet Wayback Machine, I found out that the domain name was previously (2010-2019) used for: "Ethical and regulatory challenges raised by synthetic biology", posts in German about loans and financial habits, and Finnish adult entertainment spam.

Anyway, I set up a simple HTML page with some vague explanation, and set up a mailbox to send emails to different companies. That failed badly. I barely got any responses. Here's a chart:

CompanySentRepliesResult
Lidl10No reply
OBI10No reply
KFC10No reply
Brico21Automated ticket receipt
Marionnaud21Out-of-office auto-reply
Carrefour12Routing acknowledgement + substantive answer

Carrefour Belgium (a supermarket chain) replied with the following statement (translated from French):

We do not currently use AI for music selection1 in our shops, but this is one of Carrefour’s projects for 2026–2028. It will enable us to create royalty-free music based on various annual themes, such as Christmas, for example.

I found all this quite boring. Nothing much to say here, other than I am a little disappointed.

But, you see, I made a terrible mistake. A mistake I am very glad I made on this domain and not on any of my other projects. I wrote the email address as plain text on the website.

Sooo, a small reminder as to why you shouldn't do that: the web is constantly scraped for a variety of reasons. Archiving, research, ... and LLM training and spamming. Now, I really underestimated the amount of spam you get from an exposed email address. Especially on a website that I did not post anywhere, did not optimise SEO for, and that I expected to be barely discoverable. What a fool.

Yep. The vast majority of these emails were from businesses, the majority claiming to be located in India, offering "tech services". Emails were frequently titled "SEO Optimisation", "App idea??", "Quote". These people had clearly never visited my website ("Would you be interested in building mobile app for your business: www.synthethics.eu with latest features like secure mobile payments, real-time updates, AI Chatbot and personalised recommendations?"), and had scraped emails from a list of websites. I confronted one company about it, and they claimed they found my website by searching on Google, which is a blatant lie, as I could not find my website on Google even if I typed my full domain name into it.

Stacked bar chart of spam emails by type

To justify my Master's degree in data science, here are some more plots with this data:

Bar chart of spam arrival hours in UTC, with workday bands for India, Europe and US Eastern time

Bar chart of the top spam sender domains

What is concerning is that, of the spam emails I received, most of them came from legitimate-looking websites. For instance, one of them came directly from the University of Chicago (uchicago.edu), and one from Hackensack Meridian Health, "New Jersey's Top-Ranked Hospital Network". They apparently recently had a data leak of their customers' data. I did not dig deep into it, but there seems to have been an issue with infrastructure set up by Convio (now Blackbaud), a US company selling online fundraising software to charities and universities.

I reported these issues to all these companies, some as early as December 2025, but have not heard back yet. One company website changed from a Mexican construction company to a casino company. So who knows what's happening there. If you are interested in getting more data for this, reach out to me.

How can you avoid getting spam like this? Well, the old trick of replacing "@" with "(at) this domain" surprisingly seems to work. I have a more advanced solution on this website for my private email, which decrypts a JavaScript string when visiting the site.

So yeah, goodbye, expiring domain. I hope the next owner will make good use of it!

## Footnotes

1

This translation is unsatisfactory in my opinion, as "music selection" is only one of the possible translations. Original text here: "Nous n'utilisons actuellement pas l'IA pour la sélection de la musique dans nos magasin, mais cela fait partie des projets de Carrefour pour 2026-2028. Cela nous permettra de créer de la musique libre de droits autour des différents thèmes annuels tels que Noël par exemple."