Hey folks so I wrote a dropcatch bot for a ccTLD that shall remain nameless. Super stoked about it, ran it on a OVHcloud VPS (https://www.ovhcloud.com/en/vps/), polling every 2 seconds against the registry whois server. 72 hours later: IP banned, nastygram from their ops team, almost got my account terminated.
Turns out I was doing like 43k queries/day and their rate limit is 100/hour. Whoops. I thought I was being polite with 2 second intervals lol. The bot was just a python script with zero backoff, just while True: query()
Lessons:
- read the TOS before you code, not after
- exponential backoff is not optional
- I got lucky, they accepted my apology and explanation
- now I am contributing to an open source throttling library so other people dont do this
The registry actually has a formal channel for high-volume queries that I found out about later. Rrp or something? Not whois. If anyone knows details drop em here. Gonna fix my mistakes and share the fix.