Measurement record · One mainland host, five client profiles

GSXT returned 521 for all 5 scripted client profiles

All five script profiles returned 521 in our mainland test; the control host returned 200. Browser-like settings did not help these requests. If a supplier lookup fails, ask which source was used before drawing a conclusion about the company.

What to ask when a lookup fails →

· · Observations from 15 August 2026 · Extends our 14 August challenge measurement

Short answer

Changing the client’s visible profile did not change the result. All five setups returned 521. They changed the user agent, browser headers, HTTP/2 or TLS profile. The codes do not reveal the gate’s rule. We did not test whether running JavaScript would change them.

Decision: keep the supplier status unresolved until a person reads the live record through an accessible route.

What I measured

One host, one session, five script profiles, three rounds each. The setups changed the user agent, headers, protocol or TLS profile. The same-session control returned 200 to all five. That does not identify the cause of the target responses.

Earlier context: the separate 8 August eight-host panel records its own clients, controls and dates. The table below contains this study's observations.

15 August 2026 · Alibaba Cloud host inside mainland China · three rounds per cell
Client profileSpoofs UABrowser headersTLS fingerprintRuns JSRegistryControl
A: bare curlnononono521, 521, 521200, 200, 200
B: user agent onlyyesnonono521, 521, 521200, 200, 200
C: full browser headersyesyesnono521, 521, 521200, 200, 200
D: full headers, HTTP/2yesyesnono521, 521, 521200, 200, 200
E: Chrome TLS impersonationyesyesyesno521, 521, 521200, 200, 200

Profile C was configured with Accept, Accept-Language, Accept-Encoding, four Sec-Fetch-* headers and Upgrade-Insecure-Requests. Profile E used curl-impersonate v2.1.0 with the curl_chrome100 profile. The CSV calls this a genuine Chrome fingerprint. It has no saved handshake to prove that claim. The table describes the configured profile.

We requested front pages only. No search was run, no record was retrieved, and nothing was done to solve or bypass the challenge. This page reports which clients are refused. It does not describe how to get past the refusal, and we will not publish that.

What the five profiles showed

Read each result within the tested profiles, host and date.

“Send a browser user agent.” Profile B did exactly that and changed nothing. So did every profile after it.

“It only blocks foreign IP addresses.” Every request above came from inside mainland China. Being on a Chinese network is not sufficient. The 14 August test recorded 521 from two other mainland networks. Three tested mainland networks thus returned the same code.

“It is fingerprinting your TLS handshake.” Profile E used Chrome TLS impersonation and also returned 521. This does not rule out TLS as one of several signals. The run did not isolate the server's decision rule.

None of these five clients ran JavaScript. The saved response notes suggest a challenge, but we did not test whether running it would admit a browser. Other signals may also affect the response.

What we still have not measured, including one thing we stated too strongly

Our 14 August page previously said, of the registry front page: “Run the same URL in a browser and it returns 200.” That sentence is an inference. It is not one of our observations. Every row in that study's dataset is a scripted request. It should have been written as an inference from the start, and we are correcting it here and leaving the correction visible.

The operator reports opening the site in a browser inside China. No browser capture is saved in this dataset. The remaining limits are:

  • Browser, inside China: not systematically measured. Operator-reported as working.
  • Browser, outside China: not measured.
  • Script, outside China: attempted and abandoned. Our Australian egress could not reach the control hosts either, so that vantage measures nothing about the registry. The null rows are in the dataset precisely so nobody reads them as a finding.

Browser success remains unmeasured here. Do not use the script table as evidence that a browser loads the page or completes a search.

A control host that discriminates too, and the wrong conclusion we drew from it

The CSV records three bare requests to the market-regulator control, all 403. Its notes describe five later bare requests at 403 and five browser-UA requests at 200. Those repeats are notes, not separate data columns. We had called the difference from an earlier 200 result drift; different clients made that date-only claim unsupported.

Keep the control result with its client, date and method. Different codes under two profiles do not isolate the server’s decision rule. The central-government control returned 200 to all five profiles in this session; this does not promise a future result.

Why this matters if you are buying from China

The practical consequence is narrow and concrete: all five tested script profiles received 521 from this root URL in this session. We did not test all pipelines, browser sessions or data vendors.

This matters in two situations. When a supplier check “fails”, the gate may be the cause rather than anything about the supplier. When a vendor quotes cheap instant registry data, ask which source it came from and when it was last retrieved. This test did not measure a vendor's costs, response times or data quality.

Self-service reports use a licensed Chinese business-information platform. A scoped L3 check adds a person reading named official sources. Each report states its source, query date and limits. See the current report scope and dated sample.

Start with the exact Chinese name and 18-character code. Check the code structure and check digit offline → This can flag a mistyped code; a valid code does not prove registration. If you need a record read, review the current report scope → The order states the source and delivery window.

Related: the 14 August challenge measurement this extends (data on Zenodo, DOI 10.5281/zenodo.21959355) · the eight-source availability panel · how to read a registration record once you have one.

What the record contains, once a client profile is no longer the question

This separate provider run queried 19 dimensions for 45 selected company codes on 21–22 August 2026. We chose codes with one search result. That did not prove identity. These returned categories do not verify what any official entry point would show.

What a licensed, authorised route returned for 45 Chinese manufacturers. Queried 21–22 August 2026.
DimensionCompanies with a record
Company type query45 of 45
Shareholders / annual reports (each)44 of 45
Change history / import-export credit (each)41 of 45
Qualification certificates36 of 45
Administrative penalty hits9 of 45
Provider results for 45 selected company codes. Queried 21–22 August 2026. Company type query: 45 of 45; Shareholders / annual reports (each): 44 of 45; Change history / import-export credit (each): 41 of 45; Qualification certificates: 36 of 45; Administrative penalty hits: 9 of 45.
Provider results for 45 selected codes. Queried 21–22 August 2026; a category hit does not verify the underlying record.

Read each returned record for its date, entity match and limits. A category hit does not establish that the record is complete or current.

Correction: the earlier zero-sanctions label was wrong. The retained administrative-penalty query has nine hits. The abnormal-operations and serious-illegality queries each returned zero hits; neither is an all-clear. See the provider-count correction and limits and the sample selection.

Citing this

Archived copy with its own DOI, resolving independently of this site: Harvard Dataverse. A Zenodo archive of this matrix is in preparation. The Zenodo record previously linked here belongs to the 14 August challenge measurement and does not contain this matrix.

You may quote or reuse these results, including for commercial use. Keep the date (15 August 2026), the mainland Alibaba Cloud host and the limits with them. The date is load-bearing: a status code from August 2026 does not establish this host's current behaviour. Keep the request profile with the date.

Currawong, “GSXT returned 521 for all 5 scripted client profiles”, three-round observations from one mainland Chinese host with same-session controls, 15 August 2026. https://currawongweb.com/verify/can-a-script-open-gsxt/ Dataset: https://doi.org/10.7910/DVN/VPQU7E

BibTeX
@dataset{currawong_china_registry_client_profiles_2026,
  author    = {Bao L. Zhou},
  title     = {{China company registry client-profile matrix: five client fingerprints, three rounds each}},
  year      = {2026},
  publisher = {Harvard Dataverse},
  doi       = {10.7910/DVN/VPQU7E},
  url       = {https://doi.org/10.7910/DVN/VPQU7E}
}

Machine-readable evidence, every profile and round: the observation table (CSV, CC BY). It carries the configured profiles, per-round status codes, collection notes and excluded no-response rows. Use it to check the counts and their limits.

If you re-run this from another network or date and see something different, we want to hear it. Corrections that survive checking get published here with attribution, including ones that contradict us. Browse all measured studies and methods in the research index.

This page reports connectivity observations. It is not legal advice, it is not a statement about any company, and it is not a claim about the completeness of any official database.

How we checked

Availability figures come from dated access tests. Read each observation for the route, result and limits of that test. Fill rates come from dated checks of chosen company codes through one paid data source. A hit is a returned record; it may be incomplete or mislinked. Last date marked for the checks: 22 August 2026. Use the date shown with each finding. A page update does not mean all checks were run again.

Being pushed to pay a deposit right now? The checks that matter before money moves are free to read. Time needed depends on the evidence you have.

If you want these records pulled for your own supplier: the “Just check who they are” selection of the report menu covers them, packs from $26.55. Delivery follows the window on your order confirmation. First paid order: unhappy for any reason, tell us within 14 days of delivery and it is refunded in full.