Measurement record · One mainland host, five client profiles
GSXT returned 521 for all 5 scripted client profiles
All five script profiles returned 521 in our mainland test; the control host returned 200. Browser-like settings did not help these requests. If a supplier lookup fails, ask which source was used before drawing a conclusion about the company.
What to ask when a lookup fails →
Short answer
Changing the client’s visible profile did not change the result. All five setups returned 521. They changed the user agent, browser headers, HTTP/2 or TLS profile. The codes do not reveal the gate’s rule. We did not test whether running JavaScript would change them.
Decision: keep the supplier status unresolved until a person reads the live record through an accessible route.
What I measured
One host, one session, five script profiles, three rounds each. The setups changed the user agent, headers, protocol or TLS profile. The same-session control returned 200 to all five. That does not identify the cause of the target responses.
Earlier context: the separate 8 August eight-host panel records its own clients, controls and dates. The table below contains this study's observations.
| Client profile | Spoofs UA | Browser headers | TLS fingerprint | Runs JS | Registry | Control |
|---|---|---|---|---|---|---|
| A: bare curl | no | no | no | no | 521, 521, 521 | 200, 200, 200 |
| B: user agent only | yes | no | no | no | 521, 521, 521 | 200, 200, 200 |
| C: full browser headers | yes | yes | no | no | 521, 521, 521 | 200, 200, 200 |
| D: full headers, HTTP/2 | yes | yes | no | no | 521, 521, 521 | 200, 200, 200 |
| E: Chrome TLS impersonation | yes | yes | yes | no | 521, 521, 521 | 200, 200, 200 |
Profile C was configured with Accept, Accept-Language, Accept-Encoding, four Sec-Fetch-* headers and Upgrade-Insecure-Requests. Profile E used curl-impersonate v2.1.0 with the curl_chrome100 profile. The CSV calls this a genuine Chrome fingerprint. It has no saved handshake to prove that claim. The table describes the configured profile.
We requested front pages only. No search was run, no record was retrieved, and nothing was done to solve or bypass the challenge. This page reports which clients are refused. It does not describe how to get past the refusal, and we will not publish that.
What the five profiles showed
Read each result within the tested profiles, host and date.
“Send a browser user agent.” Profile B did exactly that and changed nothing. So did every profile after it.
“It only blocks foreign IP addresses.” Every request above came from inside mainland China. Being on a Chinese network is not sufficient. The 14 August test recorded 521 from two other mainland networks. Three tested mainland networks thus returned the same code.
“It is fingerprinting your TLS handshake.” Profile E used Chrome TLS impersonation and also returned 521. This does not rule out TLS as one of several signals. The run did not isolate the server's decision rule.
None of these five clients ran JavaScript. The saved response notes suggest a challenge, but we did not test whether running it would admit a browser. Other signals may also affect the response.
What we still have not measured, including one thing we stated too strongly
Our 14 August page previously said, of the registry front page: “Run the same URL in a browser and it returns 200.” That sentence is an inference. It is not one of our observations. Every row in that study's dataset is a scripted request. It should have been written as an inference from the start, and we are correcting it here and leaving the correction visible.
The operator reports opening the site in a browser inside China. No browser capture is saved in this dataset. The remaining limits are:
- Browser, inside China: not systematically measured. Operator-reported as working.
- Browser, outside China: not measured.
- Script, outside China: attempted and abandoned. Our Australian egress could not reach the control hosts either, so that vantage measures nothing about the registry. The null rows are in the dataset precisely so nobody reads them as a finding.
Browser success remains unmeasured here. Do not use the script table as evidence that a browser loads the page or completes a search.
A control host that discriminates too, and the wrong conclusion we drew from it
The CSV records three bare requests to the market-regulator control, all 403. Its notes describe five later bare requests at 403 and five browser-UA requests at 200. Those repeats are notes, not separate data columns. We had called the difference from an earlier 200 result drift; different clients made that date-only claim unsupported.
Keep the control result with its client, date and method. Different codes under two profiles do not isolate the server’s decision rule. The central-government control returned 200 to all five profiles in this session; this does not promise a future result.
Why this matters if you are buying from China
The practical consequence is narrow and concrete: all five tested script profiles received 521 from this root URL in this session. We did not test all pipelines, browser sessions or data vendors.
This matters in two situations. When a supplier check “fails”, the gate may be the cause rather than anything about the supplier. When a vendor quotes cheap instant registry data, ask which source it came from and when it was last retrieved. This test did not measure a vendor's costs, response times or data quality.
Self-service reports use a licensed Chinese business-information platform. A scoped L3 check adds a person reading named official sources. Each report states its source, query date and limits. See the current report scope and dated sample.
Related: the 14 August challenge measurement this extends (data on Zenodo, DOI 10.5281/zenodo.21959355) · the eight-source availability panel · how to read a registration record once you have one.
What the record contains, once a client profile is no longer the question
This separate provider run queried 19 dimensions for 45 selected company codes on 21–22 August 2026. We chose codes with one search result. That did not prove identity. These returned categories do not verify what any official entry point would show.
| Dimension | Companies with a record |
|---|---|
| Company type query | 45 of 45 |
| Shareholders / annual reports (each) | 44 of 45 |
| Change history / import-export credit (each) | 41 of 45 |
| Qualification certificates | 36 of 45 |
| Administrative penalty hits | 9 of 45 |
Read each returned record for its date, entity match and limits. A category hit does not establish that the record is complete or current.
Correction: the earlier zero-sanctions label was wrong. The retained administrative-penalty query has nine hits. The abnormal-operations and serious-illegality queries each returned zero hits; neither is an all-clear. See the provider-count correction and limits and the sample selection.
Citing this
Archived copy with its own DOI, resolving independently of this site: Harvard Dataverse. A Zenodo archive of this matrix is in preparation. The Zenodo record previously linked here belongs to the 14 August challenge measurement and does not contain this matrix.
You may quote or reuse these results, including for commercial use. Keep the date (15 August 2026), the mainland Alibaba Cloud host and the limits with them. The date is load-bearing: a status code from August 2026 does not establish this host's current behaviour. Keep the request profile with the date.
Currawong, “GSXT returned 521 for all 5 scripted client profiles”, three-round observations from one mainland Chinese host with same-session controls, 15 August 2026.
https://currawongweb.com/verify/can-a-script-open-gsxt/Dataset:https://doi.org/10.7910/DVN/VPQU7E
BibTeX
@dataset{currawong_china_registry_client_profiles_2026,
author = {Bao L. Zhou},
title = {{China company registry client-profile matrix: five client fingerprints, three rounds each}},
year = {2026},
publisher = {Harvard Dataverse},
doi = {10.7910/DVN/VPQU7E},
url = {https://doi.org/10.7910/DVN/VPQU7E}
}Machine-readable evidence, every profile and round: the observation table (CSV, CC BY). It carries the configured profiles, per-round status codes, collection notes and excluded no-response rows. Use it to check the counts and their limits.
If you re-run this from another network or date and see something different, we want to hear it. Corrections that survive checking get published here with attribution, including ones that contradict us. Browse all measured studies and methods in the research index.
This page reports connectivity observations. It is not legal advice, it is not a statement about any company, and it is not a claim about the completeness of any official database.
How we checked
Availability figures come from dated access tests. Read each observation for the route, result and limits of that test. Fill rates come from dated checks of chosen company codes through one paid data source. A hit is a returned record; it may be incomplete or mislinked. Last date marked for the checks: 22 August 2026. Use the date shown with each finding. A page update does not mean all checks were run again.
Being pushed to pay a deposit right now? The checks that matter before money moves are free to read. Time needed depends on the evidence you have.
If you want these records pulled for your own supplier: the “Just check who they are” selection of the report menu covers them, packs from $26.55. Delivery follows the window on your order confirmation. First paid order: unhappy for any reason, tell us within 14 days of delivery and it is refunded in full.