Measurement recordUpdated when we re-test
GSXT requests: 11 of 12 overseas nodes returned 403.
A failed registry request leaves the company unchecked. In our overseas script tests, 11 nodes returned 403 and one returned 521. A buyer’s browser search may behave differently. Try the exact name or code, or arrange a dated record read.
Short answer
The saved August requests to www.gsxt.gov.cn returned 521 from the mainland connection. Overseas, 11 target nodes returned 403 and one returned 521. The control requests returned 200, but most overseas target and control nodes were different.
These were scripted requests to the home page. They do not show whether a buyer could open the site in a real browser or complete a company search. A status code alone does not identify the cause.
Decision: a failed lookup says nothing about the company. Keep the supplier decision open until the identity record is read through an accessible official route or a dated human check.
The observations
The tables summarize requests to host roots. Mainland controls used the same connection and session. The overseas round used separate node sets with only two matched nodes. None of these rows tests a company search.
8 August 2026: consumer connection, mainland China
Each target has one CLI request and three browser-user-agent requests. Each control has one CLI request and one browser-user-agent request. The table below counts only the browser-user-agent requests; the CSV retains both profiles.
| Host | Role | Result | Attempts |
|---|---|---|---|
www.gsxt.gov.cn | Target | 521 | 3 of 3 |
www.creditchina.gov.cn | Target | 412 | 3 of 3 |
www.gov.cn | Control: Chinese government host | 200 | 1 of 1 |
www.baidu.com | Control: Chinese commercial host | 200 | 1 of 1 |
In the first round, the CLI request and the browser-user-agent request returned the same status for each host. Changing that header alone did not change these results. Both requests still came from a script, so this does not rule out client filtering.
5 August 2026: same connection, three days earlier
| Host | Role | Result | Attempts |
|---|---|---|---|
www.gsxt.gov.cn | Target | 521 | 3 of 3 |
www.gov.cn | Control: Chinese government host | 200 | same moment |
The earlier collection notes list three default-CLI repeats and one extra request with browser headers, all returning 521 for GSXT. The table counts the three CLI repeats. The public CSV contains a summary status. It does not list all four attempts. Results on two dates do not establish a trend.
13 August 2026: twelve countries, through a third-party node network
The earlier rows used one mainland connection. This round used a third-party node network. Its target requests came from hosts listed in twelve countries, through a different path from our own proxy.
| Node | www.gsxt.gov.cn (target) | www.gov.cn (control) |
|---|---|---|
| Indonesia: Jakarta | 403 | 200 |
| Iran | 403 | 200 |
| Austria: Vienna | 521 | — |
| Switzerland, Spain, Israel, India, Kazakhstan, Netherlands, Russia, Ukraine, Vietnam | 403 (all) | — |
| Germany, Italy, Portugal, Sweden, Singapore, Türkiye, Israel, India, Iran | — | 200 (all) |
No target node returned 200; all 12 control nodes returned 200. The CSV lists 12 target nodes in 12 countries and 12 control nodes in 10 countries. Only two nodes, Jakarta (id1) and Iran (ir4), requested both hosts. Those pairs returned 403 for GSXT and 200 for the control. Different hosts can use different routes or protection systems; these pairs do not isolate the cause.
Our earlier proxy test also failed against an Australian government host. The node network avoids that same proxy path. It adds a new set of results, but leaves most target and control nodes unpaired.
The IANA registry lists 521 as unassigned. Its meaning depends on the system returning it. A 412 response normally means a request precondition failed. These saved codes do not identify the responding server or intermediary, or prove why the request failed. Later 14 August observations reported JavaScript challenge content in 521 responses; that dated observation does not prove that a browser search completed.
How the controls help, and what they leave open
A failed request can involve the target, network, client or timing. Controls narrow the possibilities; they do not identify every cause:
www.baidu.com: the successful request shows this connection could receive a response from that commercial host. It does not test all routes to China.www.gov.cn: the control returned 200 while the target returned a different status. This distinguishes the two observed requests; one host cannot establish availability for all.gov.cnsites.- The user-agent pair: both clients were scripts. One sent a browser User-Agent header, but did not become a browser or execute JavaScript. Equal status codes do not rule out other client checks.
These tests requested home pages only. They did not submit company searches, solve CAPTCHA or copy registry records. A home-page response does not show that a search will work.
The method for measuring China official source availability explains paired test locations, client headers and controls. Use it to assess the design or plan a repeat test.
What this does not establish
- Nothing about any company. A registry that will not load is not evidence that a record is missing, that a supplier is unregistered, or that anyone is concealing anything. It is a fact about the portal on a date. It says nothing about any counterparty.
- Nothing about what a real browser abroad would see. The overseas rows come from a node network: no JavaScript, no browser fingerprint, no session: so they measure what a script sees, and only that. A portal that returns 403 to those clients could still serve a page, or a verification step: to a person with a browser. That gap is open, and until it is closed the overseas rows say that programmatic requests are declined. What a human buyer sees may differ.
- Nothing permanent. Three dates. The mainland rows are one connection. The overseas rows are one moment across twelve countries. A portal that errors this week may serve normally next week, and a different Chinese ISP may see something else entirely. Re-test before citing it; conditions move.
- Nothing about the interactive path. Even when the portal loads, it may require verification steps before returning a record. A 200 on the front page would not by itself mean a search will complete.
A conclusion we withdrew
Our earlier guide said Chinese government sites could not be reached from abroad. It relied on TLS failures through one proxy for gsxt.gov.cn, creditchina.gov.cn and www.gov.cn. One path could not support that broad claim.
The added control, www.abf.gov.au, also failed TLS through that egress while returning 200 over the direct connection from China. This undermined the claim that the failure was unique to Chinese government hosts. It did not identify which part of the proxy path or destination handling caused it, or prove that every destination was healthy.
We withdrew the overseas claim. The old measurements remain in the archive as a record of that mistake. The 13 August node results are a separate test. They do not make the earlier claim valid.
Check each path’s exit IP before comparing results. Our collection notes report that a shell profile added a proxy to a run labelled “direct”. Both runs then used the same exit. Labels alone did not prove that the paths differed.
If you need the registration record anyway
If the portal fails, you can still check the details you already hold. In the order we would try it:
- Ask the supplier for the 18-character Unified Social Credit Code in writing and check it against the business licence and the contract. Our code checker validates the structure and check digit in your browser, with no portal access and nothing sent anywhere. The licence’s scope text can be read the same way in the free in-browser check.
- Ask a counterpart inside China to run the search and send the output with the date they ran it.
- Have the check run China-side and returned with its sources, query date and stated limits: what this desk does.
Related: how to read a registration record once you have one · where registry checks sit among the things that actually decide an order · the eight-source availability panel that extends this measurement.
What a buyer ends up with when the portal will not open
A commercial provider is a separate way to request records. Saved files dated 21–22 August 2026 contain results for the same 45 company codes. Selected counts are below. They do not prove direct access to the official portal or complete records. See the NHTSA manufacturer study for the source frame.
| Dimension | Company codes with a hit |
|---|---|
| Company type query | 45 of 45 |
| Shareholders / annual reports (each) | 44 of 45 |
| Changes / import-export (each) | 41 of 45 |
| Qualification certificates | 36 of 45 |
Ask which source supplied the record, when it was checked and what is missing. These results do not establish that a China-based person is required, or that a buyer can obtain the same fields free.
Correction, 8 September 2026: eight codes returned branch-record hits. A hit does not verify a production address. The earlier claim that no access method could improve the result was unsupported. For the penalty counts and other limits, read what follows a name match.
Questions about these results
Why will gsxt.gov.cn not open?
Our saved scripted requests returned 521 from the mainland connection and mostly 403 from overseas nodes in August 2026. These codes do not establish the cause or the current state of the portal. A failed request is not evidence about a supplier.
Is China’s company registry blocked outside China?
This study cannot establish a general geographic block. The rows outside China came from a node network rather than from browsers. They show scripted request results, not that a person with a browser sees nothing. The 12 target nodes in 12 countries had only two nodes in common with the controls.
How do the control requests help?
Two overseas nodes requested both the registry and the control host, returning 403 and 200 respectively. That shows different outcomes for those requests. It does not rule out differences in routing, protection systems or client handling.
Citing this measurement
You may quote these figures, including for commercial use, with their dates and limits. August status codes do not show whether the portal works today. Data files: the 5 August paired-control data and the 8 August replication and the 13 August twelve-country round.
Archived copies, each with its own DOI, resolving independently of this site: Zenodo · Harvard Dataverse · figshare (the 5 and 8 August rounds). An earlier Zenodo link on this page pointed at the related official-source availability panel, which holds only one of this study’s data files. That link was removed on 21 August 2026 and the correct record is the one above.
A citation with everything it needs:
Currawong, “GSXT requests: 11 of 12 overseas nodes returned 403”, observations of 5 and 8 August 2026 from one consumer connection inside mainland China, and of 13 August 2026 from twelve countries through a third-party node network.
https://currawongweb.com/verify/china-company-registry-availability/
BibTeX
@dataset{currawong_verify_china_company_registry_availability_2026,
author = {Bao L. Zhou},
title = {{China company registry availability observations}},
year = {2026},
publisher = {Zenodo},
doi = {10.5281/zenodo.21947623},
url = {https://doi.org/10.5281/zenodo.21947623}
}If your test differs, send the date, location, client and control results. We review supported corrections and credit their source.
Browse all measured studies and methods in the research index.
This page reports connectivity observations. It is not legal advice, not a compliance opinion, and not a statement about any company’s registration status.
Our comparison of 17 saved registry and database records checks what matched under limited rules. Some checks compare only field presence or text length; they do not prove the full records are the same.
Being pushed to pay a deposit right now? The checks that matter before money moves are free to read.
If you want these records pulled for your own supplier: the “Just check who they are” selection of the report menu covers them, packs from $26.55. Delivery follows the window on your order confirmation. First paid order: unhappy for any reason, tell us within 14 days of delivery and it is refunded in full.