Measurement recordTwo networks, six requests

GSXT returned 521 in all 6 requests from 2 Chinese networks

If an automated registry check returns 521, do not treat the failure as a supplier result. Search by exact Chinese name or credit code in a normal browser, or obtain a dated human read before payment. In our test, six scripted requests from two mainland networks returned 521 while government control hosts returned 200.

Choose the next step after a failed lookup →

· · Observations from 14 August 2026 · Extends our eight-source availability panel.

Short answer

All six requests recorded HTTP 521. A response code alone does not identify the server that sent it or the cause. The saved notes suggest a JavaScript challenge. Browser access was not measured. The 15 August client-profile matrix tests five script profiles, with the same limit.

The supported finding is six scripted requests to the GSXT front page returned 521 on 14 August 2026. Those responses cannot establish a supplier’s registry status.

Scripted requests on 14 August 2026: all 6 GSXT responses were 521; all 12 responses from two control hosts were 200. Two mainland networks, three rounds each. Browsers were not measured.
The paired-control measurement behind this study, 14 August 2026, two unrelated mainland networks. Original Currawong diagram.

What I measured

Two mainland networks, three rounds each. Control hosts were requested from the same machine in the same session. Their 200 responses show those requests worked. A network fault on the target route remains possible.

Earlier context: the separate 8 August eight-host panel records its own clients, controls and dates. The table below contains this study's observations.

14 August 2026, two Chinese networks, three rounds each
HostRoleShandong consumer broadbandShanghai cloud host
National company registry, front pageTarget521, 521, 521521, 521, 521
Registry sub-hostTarget412, 405, 412
Central government portalControl200, 200, 200200, 200, 200
Market regulator portalControl200, 200, 200200, 200, 200

The Shandong exit was confirmed independently as a China Unicom consumer address before the run. We checked because an earlier test had assumed which network a proxy port actually left from: see below.

Both tested networks were inside mainland China. The controls returned 200 in the same sessions. These results do not isolate routing, IP policy or the server that produced the target response.

What the 521 actually is

The saved CSV notes describe obfuscated JavaScript and a challenge cookie in the 521 response. That suggests a JavaScript challenge. The dataset does not contain a browser run showing that executing the script grants access.

The response notes are evidence about the tested scripts. They do not establish how the site decides to admit a client, whether a browser would load the page, or whether a company search would succeed.

The operator reported opening the page in a browser on another mainland connection that day. That report is separate from the recorded script tests; it has no instrumented browser result in this dataset.

What we did not do, and will not

We did not attempt to pass the challenge, and this page is not a guide to passing it. There is no request recipe here, no cookie construction, and no code. Working around a site's bot protection is the line our own verification work does not cross. Official-source reads belong to our scoped L3 human check. Self-service reports use a licensed business-information platform.

The challenge label comes from the saved response notes. No vendor has confirmed it, and this dataset has no raw response body to check. It covers one front page on one date. Other paths or later requests may differ.

Other codes do not identify a protection system

Earlier text attributed 15 August responses to named protection mechanisms, said a request never reached the origin, and described a court response as intermittent. The linked 14 August CSV does not contain those header captures or that time series. Those claims are withdrawn pending the original evidence.

The dated five-profile matrix and official-source retest show their own results and limits. A shared code or similar header does not by itself establish a common vendor or cause.

Two things we concluded first, and got wrong

This section is here because the errors are more instructive than the output. A measurement page that only shows the tidy ending is asking you to trust it instead of check it.

Error one: a vantage point that was not where we thought

We first treated a failed run as an Australian result. All three URLs had failed. There were two flaws. The reported exit was the same Shandong address as the other port. It was not a second country. And the control host failed on it too. That left the cause unresolved, so we excluded the observation from conclusions about the registry.

The fix was mechanical: query an IP geolocation service for each port's actual exit address before trusting any of them. The lesson is not mechanical: a failed control leaves the cause of a target failure unresolved.

Error two: nearly publishing “the registry refuses connections”

We nearly used that claim after one network test, before reading the response notes. It would have been wrong in a way that mattered. It reads as a claim about the registry's posture toward the outside world, when the recorded finding is six scripted responses from two networks.

The operator reported opening the page in a browser. That report prompted a closer look at the script responses. It was not an instrumented browser test, and we do not count it as one.

Both errors were caught before publication. They are recorded here because quietly correcting them and pretending the first output was right is the same habit that produces verification reports with no empty rows.

Why this is worth a buyer's attention

A failed scripted lookup is not evidence that a supplier is hiding a record. Ask a data provider which source it uses, when the record was read and what the result can establish. This study did not measure vendor costs, delivery times or data quality.

Self-service reports use a licensed Chinese business-information platform. A scoped L3 check adds a person reading named official sources. Each report states its source, query date and limits. See the current report scope and dated sample.

Start with the exact Chinese name and 18-character code. Check the code structure and check digit offline → This can flag a mistyped code; a valid code does not prove registration. If you need a record read, review the current report scope → The order states the source and delivery window.

Related: the eight-source availability panel this extends (data on Zenodo, DOI 10.5281/zenodo.21859883) · how to read a registration record once you have one. The host under measurement is the GSXT, the National Enterprise Credit Information Publicity System, the national China business registry. This is why the finding matters to anyone whose China due diligence assumes automated registry access.

What the same records look like when the door is not the problem

This separate provider run queried 19 dimensions for 45 selected company codes on 21–22 August 2026. The selected codes were not a set of verified supplier identities. These returned categories do not verify what any official entry point would show.

What a commercial platform returned for 45 selected company codes. Queried 21–22 August 2026.
DimensionCompanies with a record
Company type query45 of 45
Shareholders / annual reports (each)44 of 45
Change history / import-export credit (each)41 of 45
Qualification certificates36 of 45
Administrative penalty hits9 of 45

Read each returned record for its date, entity match and limits. A category hit does not establish that the record is complete or current.

Correction: the earlier zero-sanctions label was wrong. The retained administrative-penalty query has nine hits. The abnormal-operations and serious-illegality queries each returned zero hits; neither is an all-clear. See the provider-count correction and limits and the sample selection.

Questions about these results

What did the six scripted GSXT requests return?

All six recorded requests to the GSXT front page returned HTTP 521 on 14 August 2026: three from each of two mainland networks. The government controls returned 200. Browser sessions and company searches were not measured.

Does a 521 prove the registry is down or blocks foreign users?

No. A response was recorded, but the code alone does not identify its source or cause. Both tested networks were inside mainland China. The controls help bound the observation; they do not rule out a target-specific network issue.

Does this study establish the cost or quality of instant registry data?

No. We tested a root URL with scripts on one date. We did not measure vendor costs, delivery speed or data quality. Ask a provider which source it uses, when the record was read and what its result can establish.

Citing this

You may quote or reuse these results, including for commercial use. Keep the date (14 August 2026), the two mainland networks and the stated limits with them. The date is load-bearing: a status code from August 2026 says nothing about this host today.

Archived copies, each with its own DOI, resolving independently of this site: Zenodo · Harvard Dataverse · Mendeley Data.

Currawong, “GSXT returned 521 in all 6 requests from 2 Chinese networks”, three-round observations from two unrelated mainland Chinese networks with same-session controls, 14 August 2026. https://currawongweb.com/verify/gsxt-error-521/

BibTeX
@dataset{currawong_gsxt_javascript_challenge_2026,
  author    = {Bao L. Zhou},
  title     = {{China national company registry JavaScript-challenge observations: two networks, three rounds each}},
  year      = {2026},
  publisher = {Zenodo},
  doi       = {10.5281/zenodo.21959355},
  url       = {https://doi.org/10.5281/zenodo.21959355}
}

Machine-readable evidence, every host and round: the observation table (CSV, CC BY). It carries the exact hostnames, the per-round status codes and the vantage for each row, the page above states the finding, the file lets you check it.

If you re-run this from another network or date and see something different, we want to hear it. Corrections that survive checking get published here with attribution, including ones that contradict us. Browse all measured studies and methods in the research index.

This page reports connectivity observations. It is not legal advice, it is not a statement about any company, and it is not a claim about the completeness of any official database.

How we checked

Availability figures come from dated access tests. Read each observation for the route, result and limits of that test. Fill rates come from dated checks of chosen company codes through one paid data source. A hit is a returned record; it may be incomplete or mislinked. Last date marked for the checks: 22 August 2026. Use the date shown with each finding. A page update does not mean all checks were run again.

Being pushed to pay a deposit right now? The checks that matter before money moves are free to read. Time needed depends on the evidence you have.

If you want these records pulled for your own supplier: the “Just check who they are” selection of the report menu covers them, packs from $26.55. Delivery follows the window on your order confirmation. First paid order: unhappy for any reason, tell us within 14 days of delivery and it is refunded in full.