Measurement recordUpdated when we re-test

Eight official Chinese sources buyers are told to check. We asked each one for its front page.

When an official source will not load, it is easy to suspect the supplier. Often the obstacle is the source itself. This page tests the step that sourcing guides skip: does each official front door open, and in which language? It follows our registry-availability method, with dated requests, same-session controls and stated limits.

Published 8 August 2026 · · Domestic panel dated 8 and 22 August. The overseas panel below dated 26 August.

Short answer

On the test date, five of eight official verification hosts would not serve their front page — from inside mainland China — while both control hosts returned 200 in the same session. None of the three that loaded carried an English-version marker. Do not turn a failed front-door request into a conclusion about the supplier.

Added 26 August: this study now has an overseas vantage. The court enforcement portal answered mainland China and Hong Kong with 200. It refused 19 other countries with 403. See the measurement →

Before treating a failed lookup as supplier evidence

Separate a source refusing the request from a supplier having no record. The panel below measures the source only.

Each target host was requested at its root three times with a browser user agent on 8 August 2026. The browser-user-agent request returned the same status in all three rounds. An extra CLI request differed for the court-enforcement host. Control hosts were requested from the same machine in the same session.

HostWhat buyers use it forResult (3 of 3)English front page
www.gsxt.gov.cnCompany registry (GSXT)521
www.creditchina.gov.cnCredit China: penalties, dishonesty lists412
wenshu.court.gov.cnCourt judgments200No marker found
zxgk.court.gov.cnCourt enforcement records200 (browser UA only)No marker found
sbj.cnipa.gov.cnTrademark office403
credit.customs.gov.cnCustoms enterprise credit412
openstd.samr.gov.cnNational standards (GB) texts200No marker found
cx.cnca.cnCCC certification queries521
www.gov.cnControl: government host200
www.baidu.comControl: commercial host200
The user-agent finding

zxgk.court.gov.cn returned 403 to a plain command-line client and 200 to the same request with a desktop-browser user agent, in the same minute. The other seven hosts answered both clients identically. So at least one official source filters by client type, which matters if you are told “just script it”. A portal can be up for a person and down for a program.

What 521, 412 and 403 mean here

All three are answers rather than dead air: a server received the request and declined it. 521 means the host was reachable but not serving the page to this client; 412 (Precondition Failed) and 403 (Forbidden) are refusals. None of these is the signature of a blocked route. A blocked route usually produces no status code at all, and both control hosts served normally throughout.

Correction, 27 August 2026: what a 412 does and does not show

Vincent Brussee, whose 2026 Journal of Cybersecurity study of 13,508 Chinese sites this panel sits alongside, read these results and pointed out something we had not separated. In his testing the 412 responses were principally websites rejecting the testing method. They were not blocking access altogether. He reports reaching Credit China without difficulty from an ordinary browser, but not with standard measurement tooling.

I checked what we could. From a mainland Chinese line, a plain request and a request carrying a complete set of browser headers both return 412, so the refusal is not triggered by headers alone. What we cannot rule out is rejection at the TLS-fingerprint layer or behind a JavaScript challenge — exactly what an ordinary browser passes and a measurement tool does not. A re-test through an overseas browser was discarded: that route fails its own control test against government hosts, and a failure we cannot attribute is not evidence.

So the honest reading of the two 412 hosts has changed. This panel measured many locations and one client. It can say those hosts did not serve their front page to the tool used here, from anywhere. It cannot say they are unreachable, and the earlier wording, “refuse every client”, claimed more than the data supports. That wording is corrected here and in the published dataset. The court enforcement finding is unaffected: it rests on the same client returning 403 from nineteen countries and 200 from Hong Kong, a comparison inside one method — methods are never mixed.

Follow-up, 14 August 2026: what the 521 actually is

The 521 on www.gsxt.gov.cn is not an outage. Re-tested six days later from two unrelated Chinese networks, a Shandong consumer broadband line and a Shanghai cloud host. The registry returned 521 on every attempt while www.gov.cn and www.samr.gov.cn returned 200 in the same seconds. The 521 response carries X-Via-JSL and a __jsluid_s cookie, and its body is obfuscated JavaScript that computes a __jsl_clearance_s cookie. That is the documented signature of a JavaScript challenge: a client that runs the script gets a cookie and is let through on a later request. A client that does not run it stays on 521 forever.

Full write-up of this finding, with the two wrong conclusions we reached first: the registry answers browsers and refuses scripts. So the honest reading is not “the registry is down”. It is: the registry answers people and refuses machines. A person with a browser reaches it. That was confirmed independently on 14 August 2026 by opening it in an ordinary consumer browser. Scripts, APIs, crawlers and bulk tools do not. That is why Chinese registration data has no reliable automated route. Every check on this site is run by a person in a browser, because scrapers get refused.

We do not attempt to defeat that challenge, and this page is not a guide to doing so. The status codes above are what an automated client sees. They measure machine access. Whether the site works for you is a separate question. Challenge attribution is based on the response signature and on secondary technical write-ups; vendor documentation does not describe it.

Method

  • Requests. HTTPS GET to each host root, three rounds, recording the status code. Round one was sent as a matched pair: a plain command-line user agent and a desktop-browser user agent, to expose client filtering. Rounds two and three used the browser user agent.
  • Controls. www.gov.cn (a Chinese government host) and www.baidu.com (a Chinese commercial host) were requested in the same session. Both returned 200, so the failures are specific to these hosts — the connection itself, and China generally, both passed the control, unlike .gov.cn generally.
  • English detection. For hosts that served, the first 120 KB of front-page markup was scanned for English-version markers (an English link, lang="en", an /en/ path). This is a front-page markup scan, nothing deeper.
  • What we did not do. No searches were submitted, no CAPTCHA was touched, no data was collected from any of these portals, and nothing was proxied or mirrored. Measuring whether a front door opens is a different activity from walking through it.

What this does not establish

  • This panel says nothing about overseas access. The eight hosts above were measured from inside mainland China only. Two earlier attempts at an overseas vantage were discarded because they failed their own control test. The route did not carry .gov.cn at all, so target and control failed together and the data proved nothing. That gap was closed on 26 August with a vantage that passes the control rule. The result is a separate panel and is reported below, not merged into this one.
  • Nothing beyond the front page. A 200 on the root does not mean a search completes: the interactive path may require verification steps this measurement never touched. And an English sub-site could exist somewhere the front-page markup does not announce.
  • Nothing permanent. One connection, one date. A host that refuses this week may serve next week. A different Chinese ISP may see something else. Re-test before citing it; conditions move.
  • Nothing about any company. An unreachable portal is a fact about infrastructure on a date. It is no evidence that a record is missing, or that anyone is concealing anything.

What a buyer does with this

The uncomfortable reading is this. The standard advice is to check the official sources yourself. It assumes a stack of portals that, on our test date, mostly declined to serve their own front pages even from inside China, and offered no English when they did. That is not a reason to skip verification. It is the reason verification is usually executed China-side by someone for whom these portals, their search paths and their verification steps are a daily logistics problem. That is the work this desk does, with the source and query date named per line.

What is still doable while those portals are refusing. Two checks need none of them. Validate the 18-character code offline → The arithmetic runs in your browser, so no Chinese host is involved at all. Read the registered scope text the supplier already sent you → That gives a first-pass factory-or-trader signal from a document you already hold. Both are free, and neither is affected by the availability measured above.

Related: the registry-availability record this panel extends · how to read a registration record once you have one.

Re-probed two weeks later: seven of eight unchanged, one moved

This study is a snapshot, and a snapshot of client filtering can go out of date. So I ran the same probe again on 22 August 2026. Same target set, same two user agents, no redirects followed, no retries, control hosts in the round, this time from the domestic vantage point.

Eight official hosts plus two controls, re-probed after two weeks. Domestic vantage; controls healthy.
Result after two weeksHosts
Status code identical to 8 August7 of 8, plus both controls
Changed: stopped refusing command-line clients (403/200 → 200/200)1: the court enforcement portal

Refusal here is a persistent state. It never resolved on retry. Seven of eight hosts returned exactly the same code a fortnight apart. That is the part of this study that holds up. “try again later” is not a workaround for these sources.

The host that moved is the more useful finding, and it cuts against the study as much as for it. Client filtering changed within two weeks, so any statement of the form “this source cannot be opened” carries the date I checked it and needs re-probing. Written once and left standing, it rots.

The overseas round of 22 August was voided in full. A government control host returned nothing while a commercial control returned 200, which under this study’s own rule 3 means the round describes the link. The targets stay unmeasured. Both rounds and the controls: the two-week retest; raw records in china-official-source-retest-2026-08-22.json.

Re-probed a month later: all eight hosts back on the 8 August pattern

The probe ran again on 7 September 2026 from the same domestic vantage. Same eight targets, same two user agents, no redirects followed, no retries. Both control hosts answered 200.

Eight official hosts plus two controls, re-probed thirty days after the 8 August baseline. Domestic vantage; controls healthy. Queried 7 September 2026.
Result after thirty daysHosts
Status codes identical to 8 August, for both clients8 of 8, plus both controls
Still serving no front page to either client5 of 8
Answering a browser but refusing the command-line client1 of 8: the court enforcement portal

The court enforcement portal is the host to watch. On 22 August it had stopped refusing command-line clients. On 7 September it refused them again, with the same 403 as on 8 August. Client filtering on that host is not a one-way change. It moves in both directions within weeks, so a dated observation is the only kind worth quoting.

The overseas round of 7 September was voided under rule 3, as the 22 August round was. The government control host reset the connection while the commercial control answered 200, so that round describes the egress and says nothing about the targets. Dataset: china-official-source-panel-retest-2026-09-07.csv; raw probe: official-source-probe-2026-09-07-direct.json.

26 August: the first valid overseas vantage

Every version of this page until today carried the same admission in its limits section. That it could say nothing about access from outside China, because both attempts at an overseas vantage had failed their own control test. That is now resolved. The panel below was measured from 20 locations in 20 countries and territories, in two independent rounds on 26 August 2026, using public measurement nodes whose network paths are unrelated to ours.

The same eight hosts and two controls, requested from overseas nodes on 26 August 2026. “Inside” is a mainland Chinese cloud host requested in the same period with a desktop-browser user agent.
HostInside mainland ChinaFrom overseas nodesReading
zxgk.court.gov.cn
Court enforcement records
200403 from 19 countries
200 from Hong Kong
Answers China and Hong Kong; refuses the rest
sbj.cnipa.gov.cn
Trademark office
403301 redirectBehaves differently by origin
www.gsxt.gov.cn
Company registry
521 (JS challenge)403Refuses both, by different means
wenshu.court.gov.cn
Court judgments
200200Serves everyone
openstd.samr.gov.cn
National standards
200200Serves everyone
www.creditchina.gov.cn
Credit China
412412Refuses everyone alike
credit.customs.gov.cn
Customs enterprise credit
412412Refuses everyone alike
cx.cnca.cn
CCC certification
521521Refuses everyone alike
www.gov.cn
Control
200200✓ Controls healthy: the route works
www.baidu.com
Control
200200✓ Controls healthy: the route works
Read this narrowly, because the narrow reading is the one that survives

Of eight hosts, one shows a clean split between China and everywhere else. Two behave differently by origin without being cleanly blocked. Three did not serve their front page to the tool used here, from any location we tested, and two served it from every location. So the sentence this panel supports is not “China blocks foreign access to official records”. It is narrower and more useful. The specific database a buyer needs in order to check whether a supplier is a listed judgment defaulter is the one that answers inside China and refuses outside it.

How we separated geography from client filtering

This page has already documented that at least one of these hosts filters on client type rather than location. On 8 August the court enforcement portal returned 403 to a command-line client and 200 to a browser user agent in the same minute. A 403 from abroad could therefore be about the client as much as the country. Two independent observations rule that out:

  • The portal stopped filtering by client between 8 and 15 August. The seven-day retest recorded the change: 403/200 became 200/200. The fourteen-day retest on 22 August found it unchanged, so by the time of this measurement both client types were being served inside China.
  • Hong Kong is the control that isolates origin. Every overseas node ran the same tool, sending the same request in the same shape. The Hong Kong node received 200; nodes in 19 other countries received 403. When the client is held constant and only the origin changes, the origin is the variable that is doing the work. That node answered in the second round only. The refusals are the replicated half: India, Turkey and the United States were measured in both rounds, and were refused in both.

Neither observation tells us how the distinction is enforced, and we have not tried to find out. Filtering could sit at the network edge, in a CDN rule, or in the application. This panel reports what a request receives. The mechanism behind it is out of scope.

Method, and the rule that voided two earlier attempts

  • Nodes. Public measurement nodes in Austria, Bulgaria, Cyprus, Finland, Germany, Hong Kong, India, Indonesia, Iran, Israel, Kazakhstan, Moldova, the Netherlands, Romania, Russia, Serbia, Singapore, Turkey, Ukraine and the United States. Their network paths are unrelated to ours, which is the entire point, and the thing our own two attempts could not offer.
  • The control rule. This study voids any round in which the control hosts do not answer, because a round where target and control fail together describes the link, and nothing else. Both earlier overseas attempts were voided under that rule, as was the overseas round of 22 August. In both rounds reported here the controls returned 200.
  • Two rounds. Never one. A single snapshot cannot separate a persistent refusal from a momentary fault, so the panel was run twice. Every host’s dominant status was identical across both rounds.
  • Independently checkable. Each round is retained by the measurement service at a public report URL. The court-enforcement rounds are 48dc04dek23b and 48dc4c0ck9d0 — open either and you are looking at the same raw measurement we are.

What this overseas panel still does not establish

  • Nothing about a person with a browser. These are automated requests from data-centre nodes. A buyer sitting in Rotterdam with an ordinary browser and an ordinary connection may see something different, and we have not measured that.
  • Nothing about intent. A 403 is a refusal. It is not a motive. Geographic access rules exist for many reasons, including licensing, load and abuse control.
  • Nothing permanent. Two rounds on one day. Client filtering on this very host changed within two weeks in August; origin filtering can change just as fast. The date on this panel is load-bearing.
  • Nothing beyond the front door. A 200 means the root responded. It does not mean a search completes, and it does not mean the record you want is reachable behind it.

The data. Every observation behind this panel, one row per node per host per round — 240 rows across 34 countries and territories, with the public report URL on each row: CSV · JSON. Recompute any figure above from it yourself.

Archived independently of this site, each with its own DOI: Zenodo · Harvard Dataverse · figshare. If this page ever disappears, the measurement does not.

Independent context: Vincent Brussee, “Conceptualizing the reverse great firewall”, Journal of Cybersecurity 12(1), 2026, measured 13,508 Chinese government websites from 14 countries and reports 91.3% availability from Shanghai, 66.4% from Hong Kong and 46.7–49.7% elsewhere. That study did not segment by function. This panel is eight hosts chosen for what a foreign buyer actually needs, and our Hong Kong result sits where his numbers predict it would.

What the records hold, for anyone deciding whether the obstacle is worth clearing

Five of eight sources refused. That is a statement about doors. Whether the effort of getting past them is justified depends on what is behind, which this study does not measure. On 21–22 August 2026 I queried nineteen registry dimensions for 45 Chinese manufacturers through a licensed commercial route.

What a licensed route returned for 45 manufacturers. Queried 21–22 August 2026.
DimensionCompanies with a record
Legal form and current status45 of 45
Shareholders and annual reports44 of 45
Change history and import/export credit41 of 45
Qualification certificates36 of 45

The file behind the refusal is substantial. That is the honest case for arranging China-side access rather than concluding the record is not worth reaching, and it is also why this study exists. A buyer needs to know which of those doors will not open before deciding how to get the file.

This is a different access route. It is not a way around the refusals measured above, and it does not contradict any observation in this study.

Citing this panel

Quote or reproduce these results freely, including commercially, provided the test dates (8 and 22 August 2026 domestic; 26 August 2026 overseas), the vantage for each panel and the stated limits travel with them. The dates are load-bearing: a status code from August 2026 says nothing about these hosts today. Machine-readable evidence, every host and round: the domestic panel data · the overseas panel data.

Archived copies, each with its own DOI, resolving independently of this site: Zenodo · Harvard Dataverse · figshare.

Currawong, “Five of eight official Chinese sources would not open”, three-round observations of eight official hosts with same-session controls, 8 August 2026, from one consumer connection inside mainland China. https://currawongweb.com/verify/china-official-source-availability/

BibTeX
@dataset{currawong_verify_china_official_source_availability_china_official_source_panel_2026_08_08_2026,
  author    = {Bao L. Zhou},
  title     = {{China official verification source availability panel}},
  year      = {2026},
  publisher = {Zenodo},
  doi       = {10.5281/zenodo.21859883},
  url       = {https://doi.org/10.5281/zenodo.21859883}
}

@dataset{currawong_verify_china_official_source_availability_china_official_source_overseas_2026_08_26_2026,
  author    = {Bao L. Zhou},
  title     = {{Which Chinese official verification portals answer from outside China: 240 observations}},
  year      = {2026},
  publisher = {Zenodo},
  doi       = {10.5281/zenodo.22108839},
  url       = {https://doi.org/10.5281/zenodo.22108839}
}

If you re-run this from another network or date and see something different, we want to hear it. Corrections that survive checking get published here with attribution, including ones that contradict us.

Browse all measured studies and methods in the research index.

This page reports connectivity observations. It is not legal advice, and it is not a statement about any company or about the completeness of any official database.

Official source timing out? Run the free company lookup. It returns the registered name, status and scope, with source and query date on each line.