> There is no requirement there is a HTTP service present on the host in order to fulfill its purpose, we just operate it as a courtesy.

I guess this is also done to prevent bad actors from abusing the fact that this domain is hit by people who might not know what they're doing (the ones copy-pasting code without reading it)

More the DNS and DNSSEC and the like. Whether or not there is actually an HTTP server responding is irrelevant to whether or not those securely point anywhere but a malicious system.

Yeah there’s definitely a lot of sensitive data that gets sent to the domain just because of people not changing configs

I don't understand, what risk would there be if they chose _not_ to serve a site?

Someone else could

No, because they can't register the domain, it's already taken, no matter if a web service is running behind it or not

It's just part and parcel of owning the domain. It's one thing to have the domain, but the next step is offering an active website so that people that actually put that domain in a browser can see it's a placeholder.

This is not the point discussed here.

> Someone else could

When you own a domain, you can choose not to serve anything on HTTP/S, and still nobody can come and serve some other website on your domain, because they don’t control the DNS records.

Why HTTP? Why not SSH? When I try to connect to it that way, I get no response. How will I know it's a placeholder?

HTTP is used by billions of people while SSH is not. It should be pretty apparent. Why do people answer my phone calls and texts but everyone is ignoring my smoke signals?

What is the smoke signal for “we’ve been trying to reach you about your car’s extended warranty“?