Discovering geoportal SDI platforms
Shared catalog and service stacks (catalog_type: Geoportal). Overview and short probe table: discovery-geoportals.md. Regional / municipal viewers: discovery-geoportals-viewers.md. Search-engine syntax (Google, Censys, Shodan, and FOFA as a Censys alternative): discovery-search-tools.md.
Do not add dataset-level records (a single CSW UUID, a STAC item, an ArcGIS layer id). One public catalog UI = one registry record.
GeoNetwork (geonetwork)
ISO 19115 / CSW catalog. Gallery: gallery-urls.csv. European nodes also appear in the INSPIRE geoportal.
Signals: title “GeoNetwork”, path /geonetwork or /srv/eng/catalog.search, footer “GeoNetwork opensource”. The English catalog locale en-core.json sets poweredBy to “Powered by GeoNetwork opensource” (895 hosts in September 2026, including catalogo.idegrancanaria.es).
Confirm: https://host/geonetwork/srv/eng/csw?SERVICE=CSW&VERSION=2.0.2&REQUEST=GetCapabilities (drop /geonetwork if the app is at the site root). Also /srv/api or /srv/api/site. A site-root redirect to /geonetwork/.../catalog.search (Città Metropolitana di Torino) or a live /geonetwork/srv/eng/catalog.search catalog (RSDI Basilicata Catalogo RSDI; GéoArdèche /q reports 143 records; Atmo Nouvelle-Aquitaine branded title; Lille Métropole gn_search_georchestra) is enough when CSW also matches. The default title “My GeoNetwork catalogue” still counts when CSW and search JSON match. GeoOrchestra-themed GeoNetwork stays geonetwork (no georchestra software id). Do not set geonetwork on a CMS geoportal landing when /geonetwork/srv 404s (also leftover Spanish IDE hubs: IDEEX, Gran Canaria, IDERIOJA, Cartagena, Pontevedra). Do not set geonetwork on EPA Maps GIS (gis.epa.ie): the maps landing is a different product from live GeoNetwork at /geonetwork (EPA Ireland Catalogue). Do not set geonetwork on the IDEE geoportal hub (www.idee.es); CODSI is already tagged.
| Tool | Query |
|---|---|
intitle:"GeoNetwork" "opensource" -site:github.com | |
inurl:/srv/eng/catalog.search | |
inurl:geonetwork "CSW" site:.europa.eu | |
| Censys (web) | web.endpoints.http.html_title: "GeoNetwork" |
| FOFA | title="GeoNetwork" |
| Censys | web.endpoints.http.body: "GeoNetwork opensource" |
| FOFA | body="GeoNetwork opensource" |
| FOFA | body="gn_search_default" |
| FOFA | body="gn-bottom-bar" |
| FOFA | body="datahub-root" |
| Shodan | http.title:"GeoNetwork" |
| GitHub | geonetwork4_api_url https filename:toml |
gn_search_default is the default search bundle in catalog/views/api/index.html (/static/gn_search_default.js). gn-bottom-bar is the footer class in the default search template. Use those when a site drops the “GeoNetwork opensource” footer. datahub-root is the geonetwork-ui Datahub element (apps/datahub/src/index.html). Confirm CSW numberOfRecordsMatched > 0; drop stock samples (“Sample record, please remove”), sandboxes, and a second hostname of a catalog already registered (same system/site/siteId).
GitHub code search does not turn core-geonetwork forks into a portal list. geonetwork4_api_url in default.toml is usually a relative /geonetwork/srv/api. The absolute-URL form (geonetwork4_api_url https filename:toml) is the deployment-config pass; in September 2026 the only public absolute URL was https://data.geopf.fr/catalog, already an endpoint of cartes.gouv.fr.
False positives: documentation, GeoNetwork GitHub, harvested remote catalogs listed inside another GeoNetwork. Register the catalog root (https://host/geonetwork or https://host/), not a single metadata UUID.
OpenWIS (openwis)
WMO meteorological metadata catalog. Source: OpenWIS/openwis. Reuses GeoNetwork-style CSW paths.
Signals: OpenWIS branding (not generic GeoNetwork footer); meteorological/WIS catalog chrome.
Confirm: GET CSW GetCapabilities or the OpenWIS catalog UI. Only set openwis when the product branding says OpenWIS; otherwise use geonetwork.
banner.jsp loads images/openwis/header-left.jpg (2 hosts in September 2026, both dcpc-nwp.meteo.fr titled OpenWIS Home). body="OpenWIS" matched 28, and the first hits are bare-IP 302 redirects.
| Tool | Query |
|---|---|
"OpenWIS" (catalogue OR CSW OR WIS) | |
| Censys | web.endpoints.http.body: "images/openwis/header-left.jpg" |
| FOFA | body="images/openwis/header-left.jpg" |
| Censys | web.endpoints.http.body: "OpenWIS" |
| FOFA | body="OpenWIS" |
GeoNode (geonode)
Layer/map catalog, often with a bundled GeoServer.
Confirm: /api/layers/ or /api/datasets/ (GeoNode 4). CSW at /catalogue/csw?service=CSW&version=2.0.2&request=GetCapabilities.
| Tool | Query |
|---|---|
"GeoNode" (layers OR maps) inurl:/layers -site:geonode.org | |
inurl:/api/layers/ geonode | |
| Censys | web.endpoints.http.body: "geonode/css/base.css" |
| FOFA | body="geonode/css/base.css" |
| Censys | web.endpoints.http.body: "GeoNode" |
| FOFA | body="GeoNode" |
| Shodan | http.html:"GeoNode" |
geonode/templates/base.html links geonode/css/base.css (564 hosts in September 2026). Skip demo.geonode.org and the project docs. Forks of geonode/geonode are the software, not a portal list.
Geonodo (geonodo)
Chilean IDE platform from the Secretaría Ejecutiva SNIT - IDE Chile. Product page: Descubre Geonodo. Institutions install a node; the public metadata catalog is Laravel Livewire plus pycsw.
Signals: phrase “Descubre N datos territoriales”; assets under /images/metadatagis/; topic “Inteligencia militar” (intelligenceMilitary); catalog path /{instance}/catalog (examples: /catalog, /ide-los-lagos/catalog, /sinia/catalog, /R00/catalog); CSW at /csw.
Confirm: the catalog HTML contains both “datos territoriales” and /images/metadatagis/. CSW: https://host/csw?service=CSW&version=2.0.2&request=GetCapabilities (pycsw; the capabilities comment includes pycsw). One record per public catalog. Do not also register bundled GeoServer as a second catalog. A WordPress or GrapesJS homepage in front of geonodo. is still this software when the catalog matches.
False positives: GeoNode, including hosts named geonodo (/api/layers/, /api/datasets/, geonode/css/base.css). Standalone GeoServer. GeoNetwork /geonetwork/srv. ArcGIS Hub.
| Tool | Query |
|---|---|
"datos territoriales" "Inteligencia militar" | |
inurl:/catalog "datos territoriales" site:.cl | |
| Censys | web.endpoints.http.body: "metadatagis" |
| FOFA | body="metadatagis" |
| FOFA | body="datos territoriales" |
| Shodan | http.html:"metadatagis" |
Palapa (palapa)
Indonesian simpul jaringan geoportal from Badan Informasi Geospasial (GSPalapa). Open source (GPL). GitHub: agrisoft/gspalapa.
Signals: title “Geoportal Palapa”; path /main/; login /gspalapa/; footer Palapa V.x / BIG; pycsw CSW at /csw; bundled GeoServer at /geoserver.
Confirm: GET the catalog UI (often /main/) and match the Palapa title or /gspalapa/ login. CSW: https://host/csw?service=CSW&version=2.0.2&request=GetCapabilities (pycsw). One record per public Palapa node, not a second copy of /geoserver on the same host.
| Tool | Query |
|---|---|
intitle:"Geoportal Palapa" site:.go.id | |
inurl:/gspalapa/ OR inurl:/main/ "Geoportal Palapa" | |
| Censys | web.endpoints.http.html_title: "Geoportal Palapa" |
| FOFA | title="Geoportal Palapa" |
| Shodan | http.title:"Geoportal Palapa" |
False positives: GeoNode JIGN nodes (/api/datasets/); standalone GeoServer catalogs with no Palapa UI; Ina-Geoportal (tanahair.indonesia.go.id); provincial /WebPortal/ Vue shells unless the Palapa title or /gspalapa/ is present; CKAN Satu Data hosts named Palapa (for example satudatapalapa.*).
GeoServer (geoserver)
OGC service middleware. Register it when it is the catalog (layer list / GetCapabilities as the public product), not merely the backend behind GeoNode, Palapa, or ArcGIS.
Confirm: https://host/geoserver/ows?service=WMS&version=1.3.0&request=GetCapabilities (sometimes /ows without /geoserver). Web admin title “GeoServer: Welcome”.
index.html says “GeoServer admin console” on the redirect page (1,159 hosts in September 2026, including geoserver.gz-ce.si). app="GeoServer" still finds the service when that page is not indexed, so keep both.
| Tool | Query |
|---|---|
intitle:"GeoServer: Welcome" OR inurl:/geoserver/web | |
inurl:/geoserver/ows GetCapabilities | |
| Censys | web.endpoints.http.body: "GeoServer admin console" |
| FOFA | body="GeoServer admin console" |
| Censys (hosts) | host.services.software.product = "GeoServer" |
| FOFA | app="GeoServer" |
| FOFA | app="GeoServer" && country="ID" |
| FOFA | title="GeoServer" |
| FOFA | header="GeoServer" |
| Shodan | product:GeoServer or http.title:"GeoServer" |
title="GeoServer: Welcome" is a weak FOFA filter. On .nl (26 September 2026) it returned 0, as did title="GeoServer: Welkom", body="GeoServer Web Map Service", body="This GeoServer instance is running version", and server="GeoServer". FOFA stores the redirect title GeoServer: Redirecting. app="GeoServer" && host=".nl" (45) and body="GeoServer admin console" && host=".nl" (43) only see that welcome page. The queries that named live servers were title="GeoServer" && host=".nl" (56), header="GeoServer" && host=".nl" (39), and body="/geoserver/ows" && host=".nl" (14). host="geoserver." && host=".nl" (344) is ineffective: almost every row is a parked geoserver.{name}.nl vhost (Plesk, domain-for-sale, or a default page). host=".nl" is a substring; keep names that end in .nl. Do not add a second record when the same GetCapabilities is already registered on an *.avi.deltares.nl / *.openearth.nl pair.
On .be (26 September 2026) the same welcome-page filters were empty or thin: title="GeoServer: Welcome", title="GeoServer: Welkom", title="GeoServer: Bienvenue", body="GeoServer Web Map Service", body="This GeoServer instance is running version", server="GeoServer", body="/geoserver/ows", and body="geoserver/wms" were 0. app="GeoServer" && host=".be" (16) and body="GeoServer admin console" && host=".be" (16) only see the redirect title GeoServer: Redirecting. The queries that named servers were title="GeoServer" && host=".be" (18), body="geoserver" && host=".be" (62, same set as body="/geoserver/"), and header="GeoServer" && host=".be" (6; this also matches unrelated sites such as visit.gent.be). host="geoserver." && host=".be" (87) is parked geoserver.{name}.be vhosts (cPanel, Plesk, domain-for-sale). cert="geoserver" && host=".be" (23) is mostly shared certificate names for Flanders AMT test portals, not extra catalogs. host=".be" is a substring; keep names that end in .be. Root-mounted servers (WMS at /wms or /ows, not /geoserver/ows) still show up in title="GeoServer". Do not add a second record for the GeoServer behind an existing catalog on another host of the same product (geo.bipt-data.be behind www.bipt-data.be).
On .ch (26 September 2026) the welcome-page filters were again the wrong first query. title="GeoServer: Welcome", server="GeoServer", body="This GeoServer instance is running version", body="GeoServer Web Map Service", body="This is the Web administration interface", and domain=".ch" && title="GeoServer" were 0. body="/geoserver/ows" and body="geoserver/ows" were 1 (www.bmfmaps.ch, which did not answer). app="GeoServer" (13), body="GeoServer admin console" (13), and title="GeoServer: Redirecting" (13) are the same six welcome pages. The queries that named servers were title="GeoServer" && host=".ch" (15, 7 names that end in .ch), header="GeoServer" && host=".ch" (5; this also matches unrelated sites), and body="geoserver" && host=".ch" (81, same set as body="GeoServer" and body="/geoserver/"). body="geoserver.org" was 4 and did not add servers. host="geoserver." && host=".ch" (128, 71 names ending in .ch) is mostly parked geoserver.{name}.ch vhosts, but it is the query that finds live servers whose welcome page is not indexed (geoserver.nagra.ch, geoserver.geofor.ch). country="CH" && title="GeoServer" (54) is mostly non-.ch hosts. host=".ch" is a substring; keep names that end in .ch. Root-mounted servers (WMS at /ows, not /geoserver/ows) still show up in title="GeoServer" (geoserver.kopa.ch). Do not add a second record for the Lisag karten-werk.ch WMS behind www.geoportal.ch/ktur, or for the GeoServer behind an existing GeoNode on the same host (sustainable-caucasus.unepgrid.ch).
On .sk (26 September 2026) the welcome-page filters were empty or a single host. title="GeoServer: Welcome", title="GeoServer: Vitajte", title="GeoServer: Presmerovanie", title="GeoServer: 欢迎", server="GeoServer", body="GeoServer Web Map Service", body="This GeoServer instance is running version", banner="GeoServer", body="org.geoserver.web", body="WMS_Capabilities", port="8080" && host=".gov.sk", and icon_hash="-1437701105" were 0. app="GeoServer", body="GeoServer admin console", title="GeoServer", and title="GeoServer: Redirecting" are the same welcome page (gis.geocloud.gov.sk). The queries that named servers were body="geoserver" && host=".sk" (40, same set as body="/geoserver/", 24 names ending in .sk; many rows only mention GeoServer), host="geoserver" && host=".sk" (10; this finds root-mounted geoserver.sav.sk and geoserver.iesprit.sk, whose indexed title is a 404), and header="GeoServer" && host=".sk" (4, including GeoWebCache at map.collect.tmapy.sk). host="geoserver." && host=".sk" is that same hostname set, not a parked-vhost flood. country="SK" && app="GeoServer" (5) adds non-.sk hosts. host=".sk" is a substring; keep names that end in .sk. Global GetCapabilities is often disabled (No workspace specified); the public service is a workspace path (/geoserver/psk/ows) or root /ows. Do not add gis.geocloud.gov.sk beside the national geoportal geoportal.gov.sk, the GeoServer behind GeoNode ccibis.priestoroveplanovanie.sk, or geoserver.geodeticca.sk / vip.geodeticca.sk behind the Geodeticca municipal viewers. geoserver.vuvh.sk is ArcGIS Server.
On .cz (26 September 2026) the same welcome-page filters were empty or thin. title="GeoServer: Welcome", body="GeoServer Web Map Service", server="GeoServer", body="This GeoServer instance is running version", cert="geoserver", and body="geoserver.org" were 0. app="GeoServer", body="GeoServer admin console", and title="GeoServer: Redirecting" were the same 3 welcome pages. The queries that named servers were title="GeoServer" && host=".cz" (7; this also matches rangefinder shops dalkomery.cz, laserove-dalkomery.cz, and www.geoprodej.cz), header="GeoServer" && host=".cz" (10; this also matches FTP on port 8021), body="geoserver" && host=".cz" (57, same set as body="/geoserver/"), body="/geoserver/ows" && host=".cz" (16, mostly Data Procon viewers that point at g2.dataprocon.cz), and host="geoserver." && host=".cz" (24; many of those vhosts are parked, filtered, or down). host=".cz" is a substring (cz.d4d-portal.info); keep names that end in .cz. Root-mounted servers (WMS at /ows, not /geoserver/ows) still show up in title="GeoServer" (gisserver.aimdc.rlp.cz, geoserver.ibot.cas.cz). Do not add a second record for viewer hosts that only embed one GeoServer (geo.dataprocon.cz, sber.dataprocon.cz, and sber2.dataprocon.cz all use g2.dataprocon.cz). Do not add geoserver.vsb.cz beside gisak.vsb.cz, or geoserver.cenia.cz beside gis.cenia.cz.
On .at (26 September 2026) the welcome-page filters were empty. title="GeoServer: Welcome", title="GeoServer: Willkommen", body="GeoServer Web Map Service", body="This GeoServer instance is running version", and server="GeoServer" with host=".at" were 0. app="GeoServer" && host=".at" and body="GeoServer admin console" && host=".at" were 1 and not an .at host. cert=".at" matches ZeroSSL certificates issued in Austria (Issuer Country: AT), not the .at public suffix. country="AT" && title="GeoServer" (about 1,465) and app="GeoServer" && country="AT" are IP geolocation; the pages reviewed had no .at names. The queries that named servers were title="GeoServer" && host=".at" (11, four names ending in .at), body="geoserver" && host=".at" (90, same set as body="/geoserver/" and body="GeoServer"), host="geoserver." && host=".at" (20, including cPanel ports on geoserver.ece.iiasa.ac.at), header="GeoServer" && host=".at" (4), and body="geoserver/wms" && host=".at" (12, mostly indrz campus maps and the eHAO viewer). host=".at" is a substring; keep names that end in .at. Lower Austria publishes OGD at /at.gv.noe.geoserver, not /geoserver. sdi1.noe.gv.at, sdi2.noe.gv.at, and sdi3.noe.gv.at are the same GetCapabilities as sdi.noe.gv.at. Do not add a second record for the GeoServer behind an existing GeoNode (geonode.lebensraumvernetzung.at), or for an indrz campus map or the eHAO viewer.
On .si (26 September 2026) the welcome-page filters were empty. title="GeoServer: Welcome", title="GeoServer: Dobrodošli", title="GeoServer: Preusmerjanje", server="GeoServer", header="GeoServer", body="/geoserver/ows", body="org.geoserver.web", banner="GeoServer", and icon_hash="-1437701105" with host=".si" were 0. title="GeoServer: Redirecting" and body="GeoServer admin console" were the same 3 welcome pages. app="GeoServer" && host=".si" (8) and body="This GeoServer instance is running version" (3) are that welcome set plus the Chinese redirect title GeoServer: 欢迎. body="GeoServer Web Map Service" was 1, body="geoserver.org" was 3, and cert="geoserver" (2) includes PostgreSQL on www.eterra.si:5432. host=".gov.si" && body="geoserver", app="GeoServer" && host=".gov.si", and domain="gov.si" && title="GeoServer" were 0 even though gis.arso.gov.si (empty title) and prostor.zgs.gov.si (title Pregledovalnik ZGS) are indexed; geoserver.geo-zs.si is absent. The queries that named servers were title="GeoServer" && host=".si" (6), body="geoserver" && host=".si" (32, same set as body="/geoserver/" and body="GeoServer"), host="geoserver." && host=".si" (11, same set as host="geoserver" && host=".si"; this finds 404-titled geoserver.vinograd.si), and body="geoserver/wms" && host=".si" (9, the eTerra viewer). country="SI" && app="GeoServer" (12) adds bare IPs. host=".si" is a substring (si.mapping.ma); keep names that end in .si. Root-mounted WMS is at /ows on geoserver.gz-ce.si (title GZC_data, AccessConstraints INTERNAL USE, no public layers). Do not add test-geoserver.gz-ce.si beside it, www.eterra.si / geomap.si / www.geomap.si beside eterra.si, the Leaflet Quick Start hosts kataster.gis.si / sport.gis.si / portal.volkovi.si, or the test host geoserver-test.kf-digital.si.
On .pl (26 September 2026) the welcome-page filters were empty or thin. title="GeoServer: Welcome", title="GeoServer: Witamy", title="GeoServer: Serdecznie Witamy", body="GeoServer Web Map Service", server="GeoServer", and body="org.geoserver.web" with host=".pl" were 0. body="This GeoServer instance is running version" was 4 (geoserver.ecudo.usz.edu.pl, already registered, and geoplotfinder.pl, which does not resolve). app="GeoServer" (11), body="GeoServer admin console" (6), title="GeoServer" (10), and title="GeoServer: Redirecting" (6) are the same welcome pages. FOFA stores GeoServer: Redirecting or GeoServer: 欢迎, not the live Polish title GeoServer: Serdecznie Witamy. icon_hash="-1437701105" (10) is unrelated sites. The queries that named servers were body="geoserver" (142, the same set as body="/geoserver/"), body="geoserver/wms" (56, mostly ipmap.pl and netgis.pl municipal viewers), host="geoserver." (54; many rows are parked geoserver.{name}.pl vhosts or wildcard DNS), header="GeoServer" (5; this also matches unrelated sites), and body="/geoserver/ows" (2, the CBK PAN snow hosts). cert="geoserver" was 2 and not a public catalog. host=".pl" is a substring; keep names that end in .pl. Servers on a high port still show up (fpo.ug.edu.pl:8080, mybus.zimslupsk.pl:8090). Do not add a second record when GetCapabilities is identical (geoserver.ztikm.szczecin.pl matches geoserver.ecudo.usz.edu.pl; snieg.cbkpan.pl and whereissnow.com match snow.cbkpan.pl; maps-mp.uav.pansa.pl matches maps.uav.pansa.pl). Do not add the GeoServer behind an ipmap.pl, netgis.pl, or gisoncloud.pl SIP viewer, the staff-only GeoZasób GeoServer (geozasob2.igik.edu.pl), or a vendor or project backend (powerwms.gisbox.pl, geoserver.3ckstudio.pl, SmartFactor UUID workspaces).
On .ro (26 September 2026) the welcome-page filters were empty. title="GeoServer: Welcome", title="GeoServer: Bun venit", title="GeoServer: Redirecting", body="GeoServer admin console", body="GeoServer Web Map Service", server="GeoServer", header="GeoServer", banner="GeoServer", body="/geoserver/ows", body="geoserver.org", body="org.geoserver.web", and body="geoserver" && host=".gov.ro" were 0. app="GeoServer" && host=".ro" was 1 (gis.eprim.ro, whose indexed title is a 404). FOFA stores the Chinese redirect title GeoServer: 欢迎 (6, the Arad vhosts), not GeoServer: Welcome. The queries that named servers were title="GeoServer" && host=".ro" (6), body="This GeoServer instance is running version" (6, the same Arad set), body="geoserver" (66, the same set as body="/geoserver/"; many rows only mention GeoServer), body="geoserver/wms" (7, viewers such as GEOINT4ENV, DTEClimate, and the Visoro GeoNode), host="geoserver." (21, the same set as host="geoserver"; this includes Windows ports on geoserver.avaprime.ro, a 502 on geoserver.roifn.ro, and live Tomcat hosts), and cert="geoserver" (1, a maintenance page). icon_hash="-1437701105" (15) is unrelated sites. country="RO" && app="GeoServer" (12) and country="RO" && title="GeoServer" (11) add bare IPs whose other vhost is .ro (pmtgv.ro, hip.pmb.ro) plus non-.ro hosts (services.geo-spatial.org, gis.forbiom.eu, a Synology NAS). host=".ro" is a substring (ro.d4d-portal.info); keep names that end in .ro. Root-mounted /ows on nanoterra hosts is HTTP 401, not a public catalog. Do not add a second record for the same GetCapabilities (primariaarad.ro and www.primariaarad.ro match gis.primariaarad.ro). geoserver2.geoecomar.ro and geoserver3.geoecomar.ro publish different layer sets. Do not add the GeoServer behind GeoNode (geonode.graphit.ro, www.geosmart.ro, geoint4env.meteoromania.ro titled GeoNode Local GeoServer), an IngeeaCity viewer (egis.cjsibiu.ro), or a welcome page with no published layers (gis.primariaarad.ro, gismaps.go.ro).
On .hu (26 September 2026) the welcome-page filters were empty. title="GeoServer: Welcome", title="GeoServer: Üdvözöljük", title="GeoServer: Átirányítás", title="GeoServer: Redirecting", body="GeoServer admin console", body="GeoServer Web Map Service", body="This GeoServer instance is running version", body="/geoserver/ows", server="GeoServer", and cert="geoserver" were 0. app="GeoServer" && host=".hu" was 2 and title="GeoServer" && host=".hu" was 2 (www.geoserver.hu is a site named Geoserver, not this software). The queries that named servers were body="/geoserver/" && host=".hu" (66, the same set as body="geoserver"; many rows are CMS pages that only mention GeoServer) and host="geoserver." && host=".hu" (138, the same set as host="geoserver" && host=".hu"). Most of that hostname set is a wildcard on geoserver.hu (Matomo login and Jitsi Meet). header="GeoServer" and body="geoserver/web" were 6. icon_hash="-1437701105" (25) is unrelated. host=".hu" is a substring (hu.d4d-portal.info); keep names that end in .hu. Jetty hosts whose indexed title is Error 404 still serve /geoserver/ows (eszr3.ipolyerdo.hu:6443, eszr.kaszort.hu:6061, eszr.uni-sopron.hu:6161, temre.hu:8080). Do not add geoserver.pecsifa.hu:8080 beside the registered Pécs Zöldkataszter (pecsifahu), empty geoserver.hodaszfalt.hu, the stock install agro.pannonhosting.hu:8090, or the *.geoserver.hu wildcard.
On .ru (26 September 2026) the welcome-page filters were empty or thin. title="GeoServer: Welcome", title="GeoServer: Добро пожаловать", title="GeoServer: Перенаправление", body="GeoServer Web Map Service", server="GeoServer", body="org.geoserver.web", banner="GeoServer", and domain=".ru" && app="GeoServer" were 0. body="This GeoServer instance is running version" was 1 (geoanswer.ru, already registered). app="GeoServer" (16), body="GeoServer admin console" (4), and title="GeoServer: Redirecting" (4) are the same welcome pages. FOFA stores GeoServer: Redirecting or GeoServer: 欢迎, not Welcome. icon_hash="-1437701105" (24) is unrelated sites. cert="geoserver" (4) is not a public catalog. The queries that named servers were body="geoserver" (140, the same set as body="/geoserver/"), host="geoserver." (45, the same set as host="geoserver"), title="GeoServer" (15), body="geoserver/wms" (12), and header="GeoServer" (5). host=".ru" is a substring; keep names that end in .ru. GeoServer Cloud is mounted at /geoserver/cloud on geoserver.sputnix-group.ru, so /geoserver/ows is 404. Do not add a second record when GetCapabilities is identical (climate.mipt.ru and nature.mipt.ru match arctic.mipt.ru; a/b/c/d.geoserver.sputnix-group.ru match geoserver.sputnix-group.ru; a/b/c/d.isogd.gorodperm.ru are the GeoServer behind isogd.gorodperm.ru). Do not add geoserverdev.agroassist.ru beside geoserver.agroassist.ru, or geoserver.dev.meteocube.ru beside geoserver.meteocube.ru. Do not add the GeoServer behind a municipal planning viewer on the same host (dobroe-edtp.ru, lipetskii-edtp.ru, ik-yakutsk.ru).
On .bg (26 September 2026) the welcome-page filters were empty. title="GeoServer: Welcome", title="GeoServer: Добре дошли", title="GeoServer: Redirecting", body="GeoServer admin console", header="GeoServer", server="GeoServer", body="This GeoServer instance is running version", host="geoserver.", host="geoserver", cert="geoserver", and body="org.geoserver.web" were 0. app="GeoServer" && host=".bg" was 1 (maps.mapex.bg:9090, indexed title Error 404). title="GeoServer" && host=".bg" was 1 (inspire.eea.government.bg). body="geoserver/wms" was 0 and body="/geoserver/ows" was 2 (Tobel viewers). The query that named servers was body="geoserver" && host=".bg" (21, the same set as body="/geoserver/"). host=".bg" is a substring (osgl.grf.bg.ac.rs, bg.d4d-portal.info); keep names that end in .bg. country="BG" && app="GeoServer" (5) and country="BG" && title="GeoServer" (3) add bare IPs and non-.bg hosts (geoserver.cartgeo.com). Servers whose indexed title is Error 404 still serve /geoserver/ows (portal.seea.government.bg:8080, auerportal.seea.government.bg:8080, geoserv.vivacom.bg, is.ngic.bg:8080, maps.mapex.bg:9090). title="WebMAP" && host=".bg" (11) is the open-source WebMAP viewers already registered, plus the vendor home webmap.bg. host="gis." && host=".bg" (128) is mostly ArcGIS, Tomcat, and unrelated gis. names; it is the query that finds gis.varnamap.bg (Apache Tomcat title, GeoServer at /geoserver/ows). Do not add portal.seea.government.bg beside auerportal.seea.government.bg (identical AUER GetCapabilities), www.gis.varnamap.bg beside gis.varnamap.bg, the stock installs geoserv.vivacom.bg and is.ngic.bg:8080 (sample layers and a default contact; is.ngic.bg on HTTPS is 403), the Mapex multi-tenant backend maps.mapex.bg:9090 behind Tobel viewers, or the GeoServer mentioned by an existing Tobel or WebMAP catalog.
On .gr (26 September 2026) the welcome-page filters were empty. title="GeoServer: Welcome", title="GeoServer: Καλώς ήρθατε", title="GeoServer: 欢迎", body="GeoServer Web Map Service", body="This GeoServer instance is running version", server="GeoServer", and body="org.geoserver.web" were 0. app="GeoServer" (11), body="GeoServer admin console" (11), and title="GeoServer: Redirecting" (11) are the same welcome pages. FOFA stores GeoServer: Redirecting, not the live title GeoServer: Welcome. title="GeoServer" was 13 (that same set). header="GeoServer" was 7 and banner="GeoServer" was 4; both also match unrelated hosts. body="/geoserver/ows" was 5 and mostly pages that only mention GeoServer. icon_hash="-1437701105" (7) is unrelated. cert="geoserver" (3) and body="geoserver.org" (2) are not extra catalogs (geoserver.karteco.gr is a landing page). The queries that named servers were body="geoserver" (82, the same set as body="/geoserver/"), host="geoserver." (41, the same set as host="geoserver"), and body="geoserver/wms" (16). country="GR" && app="GeoServer" (20) adds bare IPs. host=".gr" is a substring; keep names that end in .gr. Jetty hosts whose indexed title is Error 404 still serve /geoserver/ows (geoserver.atmohub.gr, climdat.meteo.noa.gr:8080, www.iono.noa.gr:8081). Do not add a second record when GetCapabilities is identical (storm-edge.ims.forth.gr matches geoserver.ims.forth.gr and oikos.ims.forth.gr; dl03.di.uoa.gr:8090 matches dl003.madgik.di.uoa.gr:8090; traffic.survey.ntua.gr:8080 matches gisanalysis.gr:8080; medbs-rdbfis.ath.hcmr.gr:9443 matches medbs-rdbfis.hcmr.gr:9443; geoserver.test.doy.ggde.gr matches geoserver.doy.ggde.gr). Do not add the stock install services.marre.gr (sample layers only), the empty welcome geosrv.ath.hcmr.gr, the staging host geoserver.eprm-staging.ypen.gr, the OpenID wall geoserver.lpis.opekepe.gov.gr, GeoNode Local GeoServer with no layers (geonode.dotsoft.gr, necca.dotsoft.gr), or the Zois multi-tenant UUID workspace dump geoserver.cloud5.zoisgr.gr. geoserver.gr is an aerial-photo company, not this software.
On .kz (26 September 2026) the welcome-page filters were empty or a single host. title="GeoServer: Welcome", title="GeoServer: Добро пожаловать", title="GeoServer: Redirecting", body="GeoServer admin console", body="GeoServer Web Map Service", and server="GeoServer" with host=".kz" were 0. app="GeoServer" (4), title="GeoServer" (2), title="GeoServer: 欢迎" (2), and body="This GeoServer instance is running version" (2) are the same welcome page (geoserver.e-geoprom.kz, indexed as GeoServer: 欢迎) plus the pastures host whose indexed title is Error 404. FOFA stores GeoServer: 欢迎, not Welcome or the live Russian title GeoServer: Добро пожаловать. cert="geoserver", body="geoserver/web", body="org.geoserver.web", and icon_hash="-1437701105" were 0. The queries that named servers were body="geoserver" (41), body="/geoserver/ows" (21), body="geoserver/wms" (10), header="GeoServer" (2, test-gis.epn.kz, which body="geoserver" missed), and host="geoserver." (2, the same set as host="geoserver"). country="KZ" && app="GeoServer" (13) adds bare IPs and non-.kz hosts (geoserver.ccalm.org). host=".kz" is a substring; keep names that end in .kz. A host whose indexed title is Error 404 can still serve /geoserver/ows (pastures.kazniizhik.kz:8443). Do not add kazniizhik-pastures.kz beside pastures.kazniizhik.kz. Do not add the GeoServer behind GeoNode (map.gov.kz, morainelakes.kz), Geonomics (alag.kz, map.almobl.kz, map.e-mangistau.kz, map.e-zhetisu.kz, map.ikostanay.kz; ialmobl.kz and imangystau.kz are those same geoportals), or RGIS (eatyrau.kz, e-jambyl.kz, geo-shym.kz, eaqtobe.kz, e-sqo.kz, geopavlodar.kz). Do not add the test host test-gis.epn.kz behind the subsoil platform minerals.e-qazyna.kz.
On .tr (26 September 2026) the welcome-page filters were empty. title="GeoServer: Welcome", title="GeoServer: Hoş Geldiniz", title="GeoServer: Hoşgeldiniz", title="GeoServer: 欢迎", server="GeoServer", body="GeoServer Web Map Service", body="This GeoServer instance is running version", body="/geoserver/ows", body="geoserver/web", cert="geoserver", body="org.geoserver.web", body="geoserver.org", icon_hash="-1437701105", and domain=".tr" && title="GeoServer" were 0. title="GeoServer: Redirecting" (9), app="GeoServer" (11), and body="GeoServer admin console" (9) are the same welcome pages (KabArt and Olgu). title="GeoServer" (10) is that set plus the Temelsu login. The queries that named servers were body="geoserver" (79, the same set as body="/geoserver/"), header="GeoServer" (13; this finds Sampaş map. hosts and Tomcat titles Error 404 that still serve /geoserver/ows), host="geoserver." (30, the same set as host="geoserver"; many rows are 403, 404, or parked), and body="geoserver/wms" (11, mostly pages that only mention GeoServer). banner="GeoServer" was 1 (atlas.faceteknoloji.com.tr:8080). country="TR" && app="GeoServer" (29) and country="TR" && title="GeoServer" (21) are IP geolocation: bare IPs plus the same KabArt and Olgu welcome pages, and the already registered geoserver.moskbilisim.com. host=".tr" is a substring; keep names that end in .tr. Root-mounted WMS is at /ows on ogc.kabart.com.tr (/geoserver/web is 404). Do not add ogc2.kabart.com.tr or ogc3.kabart.com.tr beside ogc.kabart.com.tr, the NODA vhosts (agro, agroworks, srbisa, erp, www, geoserver.noda.com.tr:8080, agronoda-test) beside geoserver.noda.com.tr, or atlas.faceteknoloji.com.tr beside geoserver.faceteknoloji.com.tr. Do not add the Sampaş GeoServer (workspace smpns) behind an existing Kent Rehberi (map.adiyaman.bel.tr, map.rize.bel.tr, keos.rize.bel.tr, owa.cukurova.bel.tr). Do not add the stock-only Esenyurt hosts, the Olgu template replicated on olgu / test / destek / maps, the empty yerci.nabi.com.tr, the cemetery viewer backend konmeb.konya.bel.tr, or login walls (uys.uab.gov.tr, geoserver.temelsu.net.tr:10443).
On .cy (26 September 2026) the welcome-page filters were empty or a single host. title="GeoServer: Welcome", title="GeoServer: Redirecting", title="GeoServer: Καλώς ήρθατε", body="GeoServer admin console", server="GeoServer", body="This GeoServer instance is running version", body="/geoserver/ows", body="org.geoserver", body="geoserver.org", cert="geoserver", and banner="GeoServer" were 0. app="GeoServer" (2), title="GeoServer" (2), title="GeoServer: 欢迎" (2), header="GeoServer" (2), and body="GeoServer Web Map Service" (2) are the same welcome page (maritime.eratosthenes.cut.ac.cy; live title GeoServer: Welcome, GetCapabilities HTTP 401). The query that named servers was body="geoserver" && host=".cy" (7, the same set as body="/geoserver/"): that welcome page plus the maps.cy viewer, whose HTML only says “powered by GeoServer” and whose public service is cadastral.maps.cy/geoserver/ows. body="geoserver/wms" is that viewer. host="geoserver" && host=".cy" is FTP on geoserver.cut.ac.cy:21. host=".cy" is a substring (cy.gov.tw, cy.gazzetta.gr, *.cy.ztccloud.com.cn); keep names that end in .cy. country="CY" && app="GeoServer" (about 184) and country="CY" && title="GeoServer" are IP geolocation: a honeypot on 85.190.230.133 (random high ports, title GeoServer: Welcome), the maritime host, and 81.4.181.210 (ylatis.eu, not a .cy name). host=".cy" && port="8080" (479) is the same substring noise. Registered fixcyprus.cy and solarprognosis.cut.ac.cy are indexed under their site titles, not as GeoServer. Do not add the Basic-auth welcome maritime.eratosthenes.cut.ac.cy, or a second record for maps.cy / www.maps.cy beside cadastral.maps.cy.
On .uk (26 September 2026) the welcome-page filters were empty or the same small set. title="GeoServer: Welcome", title="GeoServer: 欢迎", server="GeoServer", banner="GeoServer", body="This GeoServer instance is running version", body="org.geoserver.web", and domain="gov.uk" && app="GeoServer" were 0. domain="gov.uk" is not a registrable domain (those are names such as leicester.gov.uk). app="GeoServer" (11), body="GeoServer admin console" (11), and title="GeoServer: Redirecting" (11) are the same welcome pages. FOFA stores GeoServer: Redirecting, not GeoServer: Welcome. title="GeoServer" was 13. body="GeoServer Web Map Service" was 2, body="/geoserver/ows" was 2, body="geoserver/wms" was 6, body="geoserver/web" was 3, and body="geoserver.org" was 3. icon_hash="-1437701105" (19) is unrelated sites. The queries that named servers were header="GeoServer" (72), body="geoserver" (263, the same set as body="/geoserver/"), and host="geoserver." (212, the same set as host="geoserver"). body="geoserver" is mostly Urban Intelligence PlaceMaker and Call For Sites tenants (*.urbanintelligence.co.uk) that only mention GeoServer. host="geoserver." is mostly parked geoserver.{name}.uk vhosts (cPanel, Plesk, domain-for-sale). cert="geoserver" (23) is mostly exeGesIS and Ramblers hostnames, not extra catalogs. country="GB" && app="GeoServer" (563) is IP geolocation and mostly non-.uk hosts. host=".uk" is a substring; keep names that end in .uk. A Tomcat or IIS title, or indexed Error 404, can still serve /geoserver/ows (geoserver.leicester.gov.uk, map.hyndburnbc.gov.uk). Root-mounted WMS is at /ows on exeGesIS hosts (geoserver-web-ramblers.esdm.co.uk; /geoserver/web is 404). Do not add a second record when GetCapabilities is identical (irdr-15-577.gtm.ucl.ac.uk matches geo.irdr.ucl.ac.uk; geoserver11.esdm.co.uk matches geoserver-web-ramblers.esdm.co.uk; geoserver9.esdm.co.uk matches geoserver19.esdm.co.uk; www.wrecksite.uk matches geoserver.wrecksite.uk; beta.geoserver.esd.org.uk and geoserver.beta.esd.org.uk match geoserver.esd.org.uk). Do not add srsp-ows.jncc.gov.uk (redirects to registered ows.remotesensing.data.gov.scot), the GeoServer behind GeoNode geonode.gis.qub.ac.uk, empty welcomes whose only layer name is WMS, stock spearfish / tasmania installs (g.umd.me.uk, geoserver20.esdm.co.uk), the exeGesIS MasterMap farm (geoserver9 / geoserver19), Urban Intelligence viewers, or HTTP 401/403 (data.wdm.co.uk, tms.homesengland.org.uk, geoserver.enwl.co.uk, gisserver.aurora.nats.co.uk). geoserver.gofibre.co.uk answers but WMS and WFS are disabled.
On .se (26 September 2026) the welcome-page filters were empty or the same small set. title="GeoServer: Welcome", title="GeoServer: Välkommen", title="GeoServer: 欢迎", body="This GeoServer instance is running version", server="GeoServer", body="/geoserver/ows", body="org.geoserver.web", and banner="GeoServer" were 0. app="GeoServer" (8), body="GeoServer admin console" (8), and title="GeoServer: Redirecting" (8) are the same welcome pages. FOFA stores GeoServer: Redirecting, not Welcome. The queries that named servers were title="GeoServer" && host=".se" (10), body="geoserver" (66, the same set as body="/geoserver/"), host="geoserver." (17), header="GeoServer" (4), and body="geoserver/wms" (5). cert="geoserver" (24) is the shared gis.lu.se certificate (Moodle, git, 502s), not extra catalogs. icon_hash="-1437701105" (35) is personal sites. host=".se" is a substring (www.kubolab.se.ritsumei.ac.jp); keep names that end in .se. A host whose indexed title is Welcome to nginx! can still serve /geoserver/ows (geoserver.analysportalnorr.se). Root-mounted WMS is at /ows on services.sbk.goteborg.se (No workspace specified; REST is 401). gis.skanetrafiken.se answers GetCapabilities, but the TLS chain is missing an intermediate. Do not add the GeoServer behind an existing catalog (nvgis.naturvardsverket.se lavin workspace, karta.halmstad.se, gis.sgi.se / gis.swedgeo.se, ALA spatial.biodiversitydata.se), the 403 BGA service mapsext.sgi.se, the login viewer mymap.skyforest.se, the stock Sokigo stack www.pumpval.se:8080 (sample workspaces and the default contact), or the Ledningskollen basemap karta3.ledningskollen.se.
On .no (26 September 2026) the welcome-page filters were empty. title="GeoServer: Welcome", title="GeoServer: Velkommen", body="GeoServer Web Map Service", body="This GeoServer instance is running version", server="GeoServer", header="GeoServer", banner="GeoServer", cert="geoserver", body="org.geoserver", body="/geoserver/ows", body="geoserver.org", and icon_hash="-1437701105" with host=".no" were 0. app="GeoServer" (4), body="GeoServer admin console" (2), title="GeoServer" (4), title="GeoServer: Redirecting" (2), and title="GeoServer: 欢迎" (2) are the same two welcome pages (ogckart-sn1.atlas.vegvesen.no and geo.droneflow.no). FOFA stores GeoServer: Redirecting or GeoServer: 欢迎, not Welcome. The queries that named servers were body="geoserver" (37, the same set as body="/geoserver/"; many rows are GeoSak municipal viewers, outage maps, and pages that only mention GeoServer), host="geoserver." (14, the same set as host="geoserver"), and body="geoserver/wms" (4) / body="geoserver/web" (4). country="NO" && app="GeoServer" (5) adds bare IPs. One IP is a root-mounted Placepoint GeoServer whose GetCapabilities OnlineResource names the development host; production geoserver.placepoint.no is absent from host="geoserver.", global /ows answers No workspace specified, and the public service is /default/ows. host=".no" is a substring; keep names that end in .no. host="wms." (36) and host="ogc." (15) are mostly MET Norway, IIS, and 403s, not extra GeoServers (wms.scansurvey.no is GeoServer with no named layers). Root-mounted WMS is at /ows on ogckart-sn1.atlas.vegvesen.no (/geoserver/web is 404). Do not add geoserver.pilot.bwlab.no beside geoserver.barentswatch.no (identical GetCapabilities), the Placepoint development host beside geoserver.placepoint.no, the GeoSak Publikumsportal hosts (they call an internal GeoServer), the empty wms.scansurvey.no, the RX project dump geoserver.regiox.no, or the 403 hosts geoserver.skanska.no and geoserver.smd.sintef.no.
On .fi (26 September 2026) the welcome-page filters were empty or the same small set. title="GeoServer: Welcome", title="GeoServer: Tervetuloa", title="GeoServer: Uudelleenohjaus", title="GeoServer: 欢迎", body="GeoServer Web Map Service", body="This GeoServer instance is running version", server="GeoServer", cert="geoserver", banner="GeoServer", body="org.geoserver.web", and body="geoserver.org" were 0. app="GeoServer" (8), body="GeoServer admin console" (8), and title="GeoServer: Redirecting" (8) are the same welcome pages. FOFA stores GeoServer: Redirecting, not Welcome. title="GeoServer" was 12 (that set plus geoserver.fi, a site titled Geoserver, not this software). The queries that named servers were body="geoserver" (82, the same set as body="/geoserver/"), host="geoserver." (31, the same set as host="geoserver"), header="GeoServer" (5), body="geoserver/wms" (5), and body="/geoserver/ows" (3). host="paikkatieto." && host=".fi" (29) finds municipal vhosts whose indexed title is the Louhi default page or Error 404 and that still serve /geoserver/ows (paikkatieto.rovaniemi.fi:8080). body="geoserver-api" && host=".fi" (28) is the Keskeytyskartta outage-map product, not a layer catalog. country="FI" && title="GeoServer" (25) and country="FI" && app="GeoServer" (20) are IP geolocation and mostly non-.fi hosts. host=".fi" is a substring (comune.fi.it, fi.fossa.greengold.se); keep names that end in .fi. icon_hash="-1437701105" (2) is DHCP briefings. A Jetty title Error 404 can still serve /geoserver/ows (paikkatieto.rovaniemi.fi:8080). Do not add the stock install paikkatieto.tyrnava.fi (sample layers and the default contact Claudius Ptolomaeus / OSGeo). Do not add login walls (paikkatieto.hanko.fi, paikkatieto.koski.fi, paikkatieto.kemijarvi.fi, paikkatieto.imatra.fi, paikkatieto.uurainen.fi, paikkatieto.kemi.fi, paikkatieto.kotka.fi, paikkatieto.paimio.fi). Do not add the GeoServer behind an existing catalog (geonode.utu.fi and geodata.utu.fi are UTU GeoNode; balfi.nsdc.fmi.fi and snow.nsdc.fmi.fi use data.nsdc.fmi.fi; toteumatieto.infraweb.fi uses iwkunto2.infraweb.fi; osallistuvavantaa.fi uses gis.vantaa.fi). Do not add geoserver.reformaattori.fi (four snapshot layers, workspace sjl_dev).
On .eu (26 September 2026) the welcome-page filters were empty or the same small set. title="GeoServer: Welcome", title="GeoServer: 欢迎", body="GeoServer Web Map Service", body="This GeoServer instance is running version", server="GeoServer", body="org.geoserver.web", and banner="GeoServer" were 0. title="GeoServer: Redirecting" (4), body="GeoServer admin console" (4), and app="GeoServer" (6) are the same welcome pages (desirmed.openearth.eu, nwdm.openearth.eu, ows.emodnet.eu). FOFA stores GeoServer: Redirecting, not GeoServer: Welcome. icon_hash="-1437701105" (3) is unrelated (uhrenklinik.eu). cert="geoserver" (1) is a 403 on a staging host. The queries that named servers were title="GeoServer" (11), header="GeoServer" (19), body="geoserver" (180, the same set as body="/geoserver/"; many rows only mention GeoServer, including Copernicus data-store clones and Kielce civic sites), body="geoserver/wms" (36), body="geoserver/web" (17), body="/geoserver/ows" (6), and host="geoserver." (48, the same set as host="geoserver"). host=".eu" is a substring (it also matches .eus and .eu. inside other names); keep names that end in .eu. A host whose indexed title is Error 404 or HTTP状态 404 can still serve /geoserver/ows (gis.forbiom.eu:8443, geoserver.gfm.eodc.eu, geoserver.ixmap.eu). Do not add desirmed.openearth.eu beside desirmed.avi.deltares.nl (identical GetCapabilities). Do not add geoserver.riscbal.uib.eu (404; the live server is geoserver.riscbal.uib.cat). Do not add www.emodnet-physics.eu:8181 or arctic.emodnet-physics.eu:8181 beside geoserver.emodnet-physics.eu. Do not add the stock install geoserver.prop1.eu (default contact Claudius Ptolomaeus), the placeholder geoserver.s4polarin.eu (one red-square layer), the Natural Earth dump raptor-geo.raptor-map.eu, or the DestinE UUID workspace dump geoserver.insula.destine.eu. Do not add the GeoServer behind an existing catalog (geoserver.sochic-h2020.eu behind catalog.sochic-h2020.eu, geoserver.s4oceanice.eu behind catalog.s4oceanice.eu, geoserver.gis.lifewatch.eu behind geonetwork.gis.lifewatch.eu, GeoNode Local GeoServer on geoportal.lifewatchitaly.eu, or datatest.lifewatchdev.eu beside geoportal.lifewatchdev.eu). Do not add the empty proprietary service geo.city-care.eu, the workspace-gated welcome geo.hillforts.eu (the public map is a uMap), or mappingforyou.eu (default contact, basemap factory).
On .id (26 September 2026) the welcome-page filters were empty or the same small set. title="GeoServer: Welcome", server="GeoServer", body="geoserver.org", and body="org.geoserver.web" were 0. domain="go.id", domain="ac.id", domain="or.id", and domain="co.id" combined with body="geoserver" were 0: domain= is the registrable domain, and those labels are public suffixes, so they do not match babelprov.go.id. app="GeoServer" (6), body="GeoServer admin console" (5), title="GeoServer: Redirecting" (5), and title="GeoServer" (7) are the same welcome pages. FOFA stores GeoServer: Redirecting or GeoServer: 欢迎 (wms.adat.id), not Welcome. The queries that named servers were body="geoserver" && host=".id" (338), body="geoserver/wms" (110), host="geoserver." (68, the same set as host="geoserver"), body="/geoserver/ows" (11), and header="GeoServer" (4). When that body query is too broad, split it by public suffix: host=".go.id" (135), host=".my.id" (75), host=".co.id" (37), host=".web.id" (9), host=".or.id" (4), host=".sch.id" (4), host=".ac.id" (2). host=".id" is a substring (gatons.id.lv, *.id.*.cpanel.site); keep names that end in .id. country="ID" && body="geoserver" (about 2,030) is IP geolocation. icon_hash="-1437701105" (75) is unrelated. A Tomcat or Error 404 title can still serve /geoserver/ows (geoserver.jagakampung.id, geoportal.hstkab.go.id). Do not add a second record when GetCapabilities is identical (petaperuntukan.dprkpp.web.id matches petaperuntukan.surabaya.go.id; geodata.kotacerdas.id matches registered GeoNode geodata.ikn.go.id). Do not add the GeoServer behind an existing catalog (geoserver-geoportal.samarindakota.go.id behind geoportal.samarindakota.go.id). Do not add GeoNode Local GeoServer (geoportal.kuburaya.go.id, peta.balikpapan.go.id, geoportal.sambas.go.id, map.kemendagri.go.id, geodata.cilegon.go.id). Do not add stock sample installs (wms.adat.id, api.adat.id), the OSM-and-sample stack gis.ffws-bbwscitarum.id, demo workspaces on geoserver.osmap.id, the default-contact host geoserver.tersmhvra.web.id (Claudius Ptolomaeus, Spearfish and Tasmania), empty welcomes (geoserver.tirtakahuripan.co.id, geoserver.rohilkab.go.id), or the vendor copy geoserver.geowebgis.id beside geoserver.georca.id.
On .au (26 September 2026) the welcome-page filters were empty or the same small set. title="GeoServer: Welcome" && host=".au" was 0. body="This GeoServer instance is running version" and body="org.geoserver.web" were 0. app="GeoServer" (22), body="GeoServer admin console" (21), and title="GeoServer" (18) are the same welcome pages. FOFA stores GeoServer: Redirecting or GeoServer: 欢迎, not Welcome. The queries that named servers were body="geoserver" (112, 73 names ending in .au; many rows only mention GeoServer), host="geoserver." (64; mostly parked geoserver.{name}.au vhosts whose title is the parent domain), header="GeoServer" (39), body="geoserver/wms" (22), and host="gs.cloud.ga.gov.au" (13). body="/geoserver/ows" was 2. cert="geoserver" (4) is not extra catalogs. country="AU" && title="GeoServer" (about 1,064) is IP geolocation. host=".au" is a substring (geoserver.au.corp.innocoverinsurance.com); keep names that end in .au. Root-mounted WMS is at /ows on *.gs.cloud.ga.gov.au (/geoserver/web is 404). Several of those hosts fail the TLS handshake, and HTTP is CloudFront 403. Do not add testing.gs.cloud.ga.gov.au (title test service). Do not add geoserver-imos-org-au.aodn.org.au beside geoserver-123.aodn.org.au (same AODN WMS). Do not add geoserver-static.aodn.org.au or staticgeoserver-ci-eb-geoserver-static-prod.prod.aodn.org.au (identical GetCapabilities; basemap and context layers for the registered AODN portal). Do not add pal.firenorth.org.au behind NAFI firenorth.org.au. Do not add the stock install geoserver.jakeclarke.au (spearfish, tasmania, tiger-ny), the default-abstract host geoserver.microflitelive.com.au (online resource geoserver.org), the client-file service geo.backpaddock.com.au, the untitled vendor host geoserver.hosting.gradata.com.au, HTTP 401/403 (kmi.dbca.wa.gov.au, geoserver.apps.aims.gov.au, geoserver.pricefinder.com.au), or staging adp-geoserver-staging.aurin.org.au.
On .org (26 September 2026) title="GeoServer: Welcome" && host=".org" returned 1. body="GeoServer Web Map Service" and server="GeoServer" were 0. body="This GeoServer instance is running version" was 14. body="GeoServer admin console" (61) and title="GeoServer: Redirecting" (61) are the same welcome pages. FOFA stores GeoServer: Redirecting or GeoServer: 欢迎 (19), not Welcome. app="GeoServer" (180) is that welcome set plus a wildcard of Error 404 vhosts on *.dmpcw.org:8080. The queries that named servers were title="GeoServer" (91), header="GeoServer" (72), body="/geoserver/ows" (75), body="geoserver/wms" (289), and host="geoserver." (363, the same set as host="geoserver"). host=".org" is a substring (it matches .org.uk, .org.au, and names such as something.org.example); keep names that end in .org. host="geoserver." also returns the project site geoserver.org, documentation, Jenkins, and cPanel ports. A Tomcat or Error 404 title can still serve /geoserver/ows (geoserver.i-bec.org, geoserver.forestproductivity.org, geoserver.gtsu.org). body="geoserver/wms" is mostly GeoNode Local GeoServer and viewers. Do not add azurh-geoservices.atmosud.org beside geoservices.atmosud.org (same AtmoSud service title and contact). Do not add geoserver.openlandmap.org beside geoserver.earthmonitor.org (identical GetCapabilities; the Open Earth Monitor catalog already points at that WMS). Do not add geoserver.oceantrack.org beside global.oceantrack.org. Do not add pcrs.geopal.org behind GeoNetwork catalogue.geopal.org, geoserver.pdc.org beside arcgis.pdc.org, geoserver.newmexicowaterdata.org beside catalog.newmexicowaterdata.org, or geoserver.oacloud.org beside geoserver.oxfordarchaeology.com. Do not add GeoNode Local GeoServer (zansdi.org, png-geoportal.org, geoportal.govmu.org, acma.africanmarineatlas.org, data.cicarb.org, nileportal.org). Do not add the stock install geo.gilly.org, the SMAP/NDSI tile dump geoserver.ccalm.org (default contact Claudius Ptolomaeus), the vendor server geoserver.gtsu.org, personal workspaces on geoserver.arij.org:8080, the two-layer photo set opendata.cen-nouvelle-aquitaine.org, or the *.dmpcw.org and *.crctool.org wildcards.
On .br (26 September 2026) the welcome-page filters were empty. title="GeoServer: Welcome", title="GeoServer: Bem-vindo", title="GeoServer: Redirecionando", body="GeoServer Web Map Service", and server="GeoServer" with host=".br" were 0. The live Portuguese title is GeoServer: Bem-vindo (geoserver.londrina.pr.gov.br); FOFA stores GeoServer: Redirecting or GeoServer: 欢迎. app="GeoServer" (47), body="GeoServer admin console" (33), title="GeoServer: Redirecting" (33), and title="GeoServer" (48) are that welcome-page set. body="This GeoServer instance is running version" was 5. header="GeoServer" was 33. cert="geoserver" was 3 (Apache default pages or HTTP 404, not extra catalogs). The queries that named servers were body="/geoserver/" && host=".br" (422; many rows only mention GeoServer, including BlueGeo municipal viewers, blogs, and Paraná secretariat homepages), host="geoserver." && host=".br" (175; many rows are IIS, nginx, Apache default pages, 403, or 502), body="geoserver/wms" (95), and body="/geoserver/ows" (11). host=".br" is a substring; keep names that end in .br. HTTPS /geoserver/ows can be 404 while HTTP answers (geoserver.londrina.pr.gov.br). A Jetty title Error 404, or port 8080/8443, can still serve /geoserver/ows (geoserver.sosma.org.br:8080, firegateway.inspectral.com.br:8080, geoserver.planorioparaiba.com.br:8080 and :8443). Do not add geoserver.sefin.caucaia.ce.gov.br beside GeoNode geonode.sefin.caucaia.ce.gov.br. Do not add geral.geoserver.geo.mcr.pr.gov.br beside geoserver.geo.mcr.pr.gov.br. Do not add plataforma.seeg.eco.br:8600 beside geoserver.plataforma.seeg.eco.br (the same four IBGE boundary layers). Do not add the stock installs geoserver.amambai.ms.gov.br, geoserver-is-samar.gsinima.com.br, and geoserver.amep-ppart.com.br, the Suple Sistemas multi-tenant stack geoserver.suplesistemas.com.br (sample workspaces plus homolog client workspaces), empty DataGeoPlan hosts (dev-geoserver.datageoplan.com.br, minio.datageoplan.com.br, s3.datageoplan.com.br), or login walls (geoserver.svma.prefeitura.sp.gov.br is HTTP 401; geoserver.spu.gestao.gov.br, geoserver.saovicente.sp.gov.br, and geoserver.mata-atlantica.sibbr.gov.br are HTTP 403). geoserver.londrina.pr.gov.br is SIGLON, a separate WMS from the ArcGIS portal geo.londrina.pr.gov.br.
On .ar (26 September 2026) the welcome-page filters were empty or the same small set. title="GeoServer: Welcome", title="GeoServer: Bienvenido", title="GeoServer: Bienvenida", title="GeoServer: Redirigiendo", title="GeoServer: 欢迎", body="GeoServer Web Map Service", body="This GeoServer instance is running version", server="GeoServer", banner="GeoServer", cert="geoserver", body="org.geoserver.web", and body="geoserver.org" with host=".ar" were 0. The live Spanish title is GeoServer: Bienvenido (geoserver.fch.unicen.edu.ar); FOFA stores GeoServer: Redirecting. app="GeoServer" (13), body="GeoServer admin console" (13), and title="GeoServer: Redirecting" (13) are that welcome-page set. title="GeoServer" was 15 and header="GeoServer" was 14. icon_hash="-1437701105" (11) is unrelated. country="AR" && app="GeoServer" (16) and country="AR" && title="GeoServer" (9) are IP geolocation and add bare IPs. The queries that named servers were body="geoserver" (307, the same set as body="/geoserver/"), body="geoserver/wms" (129), host="geoserver." (49, the same set as host="geoserver"), and body="/geoserver/ows" (17). host=".ar" is a substring (analytics.ar.vayama.com, ar.jycic.cn); keep names that end in .ar. A root title Error 404 or HTTP状态 404 can still serve /geoserver/ows (geoserver.buenosaires.gob.ar). mapas.catastrotucuman.gov.ar returns HTTP 400 on / and WMS on /geoserver/ows. /geoserver can be 404 while /geoserver/web/ and /geoserver/ows answer (idemza2.mendoza.gov.ar). Do not add gis.pergamino.gob.ar beside ide.pergamino.gob.ar, sigap.municipioderawson.gov.ar beside geoserver.municipioderawson.gob.ar, or www.servicios.catastro.misiones.gov.ar beside servicios.catastro.misiones.gov.ar (identical GetCapabilities). Do not add geoserver.ideba.gba.gob.ar behind the IDEBA visualizers, geoserver.fch.unicen.edu.ar beside GeoNetwork ide.fch.unicen.edu.ar, the GeoServer on ide01.fceia.unr.edu.ar beside the GeoNetwork on that host, or geonode.senasa.gov.ar beside geonode.senasa.gob.ar. Do not add stock installs (www.vialidad.gba.gob.ar:8443 is spearfish, tasmania, and tiger-ny; geoserver.indec.gob.ar is mostly sample layers plus a precenso workspace), GeoNode Local GeoServer on test and demo hosts (geoportal-demo.kan.com.ar, geoportal-test.cfi.org.ar, geoportal-test.vialidadentrerios.gob.ar, dev.idejuy.jujuy.gob.ar, ide2.dev.arsat.com.ar, gestorgeo-inec.kan.com.ar, geoexpress-qa.kan.com.ar), empty GeoNode welcomes (adifse.ide-dev.arsat.com.ar, enacom.ide-dev.arsat.com.ar, ide.geoproyecto.com.ar), the QA host geoserver.qa.relex.ar, or HTTP 403 (geoserver.jujuy.gob.ar, geoserver.mapasalud.gba.gob.ar).
On .com (26 September 2026) title="GeoServer: Welcome" && host=".com" was 0, as were body="GeoServer Web Map Service", server="GeoServer", and body="org.geoserver.web". app="GeoServer" (334), body="GeoServer admin console" (249), and title="GeoServer: Redirecting" (246) are the same welcome pages. FOFA stores GeoServer: Redirecting or GeoServer: 欢迎 (26), not Welcome. The queries that named servers were title="GeoServer" (381), header="GeoServer" (294), host="geoserver." (1,449; many rows are parked geoserver.{name}.com vhosts or cPanel ports), body="geoserver/wms" (520), body="/geoserver/ows" (203), body="geoserver/web" (216), cert="geoserver" (236), banner="GeoServer" (17), and body="This GeoServer instance is running version" (23). body="geoserver" (5,644) is the same set as body="/geoserver/". icon_hash="-1437701105" (3,041) is unrelated. host=".com" is a substring (it matches .com.au and similar); keep names that end in .com. Random labels on *.jyjfkj.com:10000 are one honeypot. Do not add a second record when GetCapabilities is identical (maps1 through maps6 and maps.geosolutionsgroup.com; geo and geo2.cassia-technologies.com; geoserver, geoserver-1, and geoserver-3.gtrmax.com). Do not add stock spearfish / tasmania / tiger installs, the GeoServer behind an existing catalog (geoserver.copphil.geoville.com beside the CopPhil portal; Lig'Air on geoserver.scan-datamining.com), or HTTP 401 hosts.
On .net (26 September 2026) the welcome-page filter was empty. title="GeoServer: Welcome" && host=".net" and server="GeoServer" && host=".net" were 0. body="This GeoServer instance is running version" was 2. title="GeoServer: Redirecting" (18) and body="GeoServer admin console" (18) are the same welcome pages. FOFA stores GeoServer: Redirecting or GeoServer: 欢迎, not Welcome. app="GeoServer" was 35 and title="GeoServer" was 31. The queries that named servers were header="GeoServer" (51), body="geoserver/wms" (63), body="/geoserver/ows" (24), host="geoserver." (163), and body="geoserver" (530). host="geoserver." is mostly parked vhosts, cPanel ports, and names that only contain .net. (*.net.au, *.net.cn, *.net.ua). body="geoserver" is mostly pages that mention GeoServer, including a *.nwbd.net wildcard. host=".net" is a substring; keep names that end in .net. A root title Error 404 or HTTP状态 404 can still serve /geoserver/ows. Do not add stock installs (geo.everytrack.net, gisapps.net:8080, breakpoint-geoserver.ddns.net), the TotalEnergies BEST and GeoNode hosts on *.tgscloud.net beside registered geonode-p.eugeaprod.iasp.tgscloud.net, GeoNode Local GeoServer (miide.veogeo.net), the FirEUrisk UUID raster dump geoserver.fireurisk.satways.net, vendor or project stacks (geoserver.agtrix.net, geoserverv2.viamap.net, geoserver223.projektnav.net, geoserver226.projektnav.net, geo.datvangvietnam.net), the single Hamburg damage-map mosaic geoserver.rolfschr.net, or the unattributed Cuba dump geoserver.code43w.net (sample layers and the default contact). geoserver.sictax.net is the WMS behind the AMCO open-data portal sictaxamco.com.
On .cn (26 September 2026) the keyword geoserver.cn returned 0. title="GeoServer: Welcome", body="GeoServer Web Map Service", banner="GeoServer", body="org.geoserver.web", and domain=".cn" && app="GeoServer" were 0 or 1. body="GeoServer admin console" (13) and title="GeoServer: Redirecting" (13) are the same welcome pages. FOFA stores GeoServer: Redirecting or GeoServer: 欢迎 (2), not Welcome. app="GeoServer" was 26 and title="GeoServer" was 16. The queries that named servers were host="geoserver" && host=".cn" (228, the same set as host="geoserver."), header="GeoServer" (117), server="GeoServer" (100), body="geoserver/web" (28), and body="geoserver/wms" (13). body="geoserver" (723) is the same set as body="/geoserver/" and is mostly pages that only mention GeoServer. body="/geoserver/ows" was 4. icon_hash="-1437701105" (80) is unrelated. host=".gov.cn" && body="geoserver" was 8 and host=".edu.cn" && body="geoserver" was 9. host=".cn" is a substring; keep names that end in .cn. A root title Error 404 or HTTP状态 404 can still serve /geoserver/ows. HTTPS on the root often times out while HTTP answers (qzzhzj.quanzhou.gov.cn:8080, bdc.xixia.gov.cn:8089). Do not add a second port when GetCapabilities is identical (geoserver.nyag.com.cn:8001 and :8080). Do not add stock installs (geoserver.trafficsys.cn is spearfish, tasmania, and tiger-ny), GeoNode Local GeoServer (dtbgis.cn:9090, 地图帮), the CityFun basemap warehouse map8.cityfun.com.cn beside the registered CityFun ArcGIS directories, tile caches (wxgzh.yzglq.gov.cn:9004 is Yangzhou Tianditu zoom levels; gis.jsywatercloud.cn:8765 is Anyang tile slices), multi-tenant dumps (geoserver.sciento.cn UUID rasters; geoserver.nas.cpolar.cn is a cpolar tunnel), the two-layer survey backend geoserver.huace.cn, empty welcomes (lpm.darkmap.cn, geoserver.app-test.sjtubimx.cn), or the beta workspace geoserver.zwuavlive.cn.
On .in (26 September 2026) the welcome-page filter was empty. title="GeoServer: Welcome" && host=".in" returned 0, as did body="GeoServer Web Map Service" and server="GeoServer". The live title is still GeoServer: Welcome (geoserver.mcd.gov.in, geoserver.wasca.in); FOFA stores GeoServer: Redirecting or GeoServer: 欢迎. app="GeoServer" (11), body="GeoServer admin console" (4), and title="GeoServer: Redirecting" (4) are that welcome-page set. The queries that named servers were body="/geoserver/" && host=".in" (107, the same set as a later body="geoserver" && (host=".gov.in" || host=".nic.in" || host=".ac.in" || host=".res.in" || host=".org.in") which added no further .in names), host="geoserver." && host=".in" (84; this finds geoserver.mcd.gov.in, whose root body does not contain the word GeoServer), body="geoserver/wms" (25), header="GeoServer" (9), and title="GeoServer" (6). host="geoserver." is mostly a wildcard on geoserver.in (task managers, travel sites, “under construction”) plus parked or 502 hosts. host=".in" is a substring (it also matches .info and .in. inside other names); keep names that end in .in. A root title Error 404 can still serve /geoserver/ows (maps.airace.in, solarcitiesportal.upneda.org.in:9012). Do not add www.tripura-fews.in or tripura-fews.in:9013 beside tripura-fews.in (identical GetCapabilities; OnlineResource is 203.122.5.20:9013). Do not add teams.wasca.in:8003 or xpertkonnect.in:8080 beside geoserver.wasca.in (the same waterbodies workspace behind the Varuni app at wasca.in). Do not add empty welcomes whose only layer name is WMS (geoserver.sgcgis.in, webdcra.ncrmp.gov.in:8080). Do not add the multi-tenant server solarcitiesportal.upneda.org.in:9012 (UP solar rooftops plus DRC tax, coal-mine, and agro workspaces; the public site is the UPNEDA rooftop calculator). Do not add vendor or project backends (geoserver.vasundharaa.in stock layers plus client uploads; maps.airace.in project orthophotos and a demo workspace; cacbwhp-pmis.in:8080 and portalcyberswift.in:8080 are the same DNPL imagery; www.blog-earthfields.in is the EarthFields land marketplace). geoserver.nesdr.gov.in is a VPN portal. gis-geoserver.nic.in and airquality.iirs.gov.in did not answer. body="geoserver" && host=".edu.in" was 0. apartgis.aau.ac.in fails a default TLS probe (self-signed chain); with verification relaxed, /geoserver/ows publishes the APART web GIS (workspace apart) and the public map is https://apartgis.aau.ac.in/publicmap/defaultMap.php. Added tripura-fews.in (FEWS Tripura; workspaces fews and fews_manual; stock spearfish / tasmania / tiger layers are still published) and apartgis.aau.ac.in. geoserver.mcd.gov.in was already recorded.
On .int (26 September 2026) the welcome-page filters were empty. app="GeoServer" && host=".int", title="GeoServer" && host=".int", and body="GeoServer admin console" && host=".int" were 0. domain=".int" is not a registrable domain, so domain=".int" combined with app=, title=, header=, host=, or body= was 0 even when the same host was indexed (domain was spc.int, who.int, itu.int). host=".int" is a substring: it also matches geoserver.int.example.com and names such as eu-central-1.int.maps.*. Keep names that end in .int. The queries that named servers were header="GeoServer" && host=".int" (5; opmgeoserver.gem.spc.int and the registered gis.wcpfc.int), host="geoserver" && host=".int" (10, including geoserver.wpro.who.int and geoserver.vesselmap.wcpfc.int), and body="/geoserver/" && host=".int" (23). body="geoserver/wms" was the registered GeoNode hosts only. body="/geoserver/ows", server="GeoServer", cert="geoserver", and body="geoserver/web" were 0. host="gis." && host=".int" and host="geo." && host=".int" add GIS hostnames whose pages do not contain the word GeoServer, and also many non-.int names. Scope a mention search with domain="spc.int" (or who.int, esa.int, eumetsat.int, ecmwf.int, itu.int), not domain=".int". Do not add geoserver.vesselmap.wcpfc.int beside gis.wcpfc.int (same address; WMS is HTTP 401). Do not add ECMWF dev or preprod stores, or xds.ecmwf.int (no /geoserver/ows; the production store is the registered STAC catalog ecds.ecmwf.int). Do not add ssag.sccoe.esa.int (OSM and Natural Earth basemap styles for the SSAG GUI). Do not add the GeoServer behind GeoNode (geonode.rimes.int, geoportal.cilss.int). geoserver.wpro.who.int is HTTP 503. winston.gsd.spc.int is a static page and /geoserver/ows is 404.
On .jp (26 September 2026) the keyword geoserver.jp returned 2 rows (a bare IP and geoserver.jp-int.tigerguardinsure.com, which does not end in .jp). Welcome-page filters were empty: title="GeoServer: Welcome", title="GeoServer: ようこそ", title="GeoServer: Redirecting", title="GeoServer: 欢迎", app="GeoServer", body="GeoServer admin console", server="GeoServer", body="GeoServer Web Map Service", body="This GeoServer instance is running version", body="/geoserver/ows", body="geoserver/wms", and body="org.geoserver.web" with host=".jp" were 0. The queries that named hosts were body="geoserver" && host=".jp" (30, the same set as body="/geoserver/"; 18 names ending in .jp, many of them blogs and company pages that only mention GeoServer), title="GeoServer" (3, geoserver.foresttosea.jp and cs-dev.foresttosea.jp), host="geoserver." (7, including the Sakura rental-server mail host), header="GeoServer" (2, analytics.jp.budgetair.com), and cert="geoserver" (1, app-geoserver-1.mapweb.jp). country="JP" && app="GeoServer" and country="JP" && title="GeoServer" are IP geolocation: bare IPs and a honeypot on 64.176.57.89 with random high ports titled GeoServer: Welcome. country="JP" && body="geoserver" is the same class of non-.jp hosts. domain="go.jp" and domain="lg.jp" are public suffixes, not registrable domains, so those domain= filters return 0. host=".jp" is a substring (analytics.jp.budgetair.com); keep names that end in .jp, or scope with host=".go.jp", host=".lg.jp", host=".ac.jp", host=".or.jp", host=".co.jp", or host=".ne.jp". The registered Nagasaki server gissv03.pref.nagasaki.jp is absent from FOFA. A Jetty title Error 404 can still serve /geoserver/ows (dsmap.city.toyama.lg.jp). Do not add the Forest to Sea dev host cs-dev.foresttosea.jp (/geoserver/ows is 404). Do not add the Vertex System client-workspace dump www.vertexsys.co.jp (default contact Claudius Ptolomaeus; Aeon, road-price, and survey workspaces). Do not add the Sakura VPS default name ik1-328-24393.vs.sakura.ne.jp:8080 (workspace coi, default contact). Do not add the GeoServer behind the Bois free disaster app bois-free.bousai.genavis.jp (sample layers plus three diars tables). Do not add app-geoserver-1.mapweb.jp or gs.kisho.mapweb.jp (no public WMS). geoserver.token.co.jp and geoserver.sakura.ne.jp did not serve GetCapabilities.
On .ca (26 September 2026) the welcome-page filter was thin. app="GeoServer" && host=".ca" returned 10 rows (five hosts: welcome pages titled GeoServer: Redirecting or GeoServer: 欢迎, or Error 404). title="GeoServer: Welcome", server="GeoServer", and body="GeoServer Web Map Service" were not the queries that named servers. FOFA stores GeoServer: Redirecting or GeoServer: 欢迎, not Welcome. The queries that named servers were body="geoserver" && host=".ca" (98, the same class as body="/geoserver/"; many rows only mention GeoServer), host="geoserver." && host=".ca" (25; this finds geoserver.cwfif.nrcan.gc.ca, whose root title is empty), body="geoserver/wms" (16), title="GeoServer" (7), header="GeoServer" (5), cert="geoserver" (4), and body="/geoserver/ows" (2). host=".ca" is a substring (geoserver.ca.capitaltwelve.com, projects.saltonsea.ca.gov, ca.zengzeng.me); keep names that end in .ca. A root title Error 404 can still serve /geoserver/ows (services.canada1water.ca, beta.idf-cc-uwo.ca:8080). Do not add geoserver.cwfif.nrcan.gc.ca or cwfis.cfs.nrcan.gc.ca/geoserver beside the registered Canadian Wildland Fire Information System (cwfis.cfs.nrcan.gc.ca). Do not add GeoNode Local GeoServer (data.nsercresnet.ca, geonode.cedvs.umontreal.ca). Do not add staging or dev hosts (geoserver-dev.bgcengineering.ca is an OAuth wall and a UUID dump with stock spearfish / tasmania / tiger layers; geoserver-new.mapaki.ca and geoserver-testing.mapaki.ca sit behind the Mapaki portal; beta.idf-cc-uwo.ca:8080 uses the default Claudius Ptolomaeus contact). Do not add company or consultant project servers that still ship the sample dataset or the default contact (gst.geoactivity.ca, maps.roottwo.ca, geoserver.marktrueman.ca). geo.ec.gc.ca has no named layers. geo.wirl.carleton.ca and geo.obv-yamaska.qc.ca are HTTP 403 on GetCapabilities. Added services.canada1water.ca.
On .us (26 September 2026) the welcome-page filter was empty. title="GeoServer: Welcome" && host=".us" returned 0. The registry had no GeoServer record whose hostname ends in .us. FOFA stores GeoServer: Redirecting, not Welcome. app="GeoServer" (1), body="GeoServer admin console" (1), title="GeoServer: Redirecting" (1), and title="GeoServer" (1) are the same welcome page (geoserver.ogb.state.ms.us). server="GeoServer", body="GeoServer Web Map Service", body="This GeoServer instance is running version", body="/geoserver/ows", banner="GeoServer", body="org.geoserver", title="GeoServer: 欢迎", body="geoserver" && host=".k12.", and body="geoserver" && host=".lib." were 0. The queries that named hosts were body="geoserver" && host=".us" (31), host="geoserver." && host=".us" (13), body="geoserver/wms" (8), and header="GeoServer" (5). body="geoserver/web" was 2 and cert="geoserver" was 1. icon_hash="-1437701105" (2) is unrelated. host=".us" is a substring of .usa, .usgs, .usace, .us.com, and of a us. label (geoserver.us.capitaltwelve.com); keep names that end in .us. body="geoserver" && host=".state." (10) also returns *.state.gov, not only *.state.*.us. host=".ci." is Côte d'Ivoire and random labels, not US city domains. A root title Error 404 can still serve /geoserver/ows (dev.terrafire.us:8084). Do not add geoserver.ogb.state.ms.us:443 beside geoserver.ogb.state.ms.us. Do not add the empty WMS geoserver.vialytics.us (service title only), the dev raster stack dev.terrafire.us:8084 (SpherAware block-status layers), or the AcuGIS GeoSuite product site carto.skge.us (default OSGeo contact and a QGIS tutorial workspace). www.waterqualitydata.us is already registered and only mentions GeoServer.
Do not register the /geoserver/web login as a catalog if a public WMS/WFS catalog is already represented by a parent GeoNode, Palapa, or GeoNetwork record on the same host. Prefer one record per public catalog UI.
CubeWerx CubeSERV (cubewerx)
Commercial OGC server (WMS, WMTS, WFS, WCS, CSW, OGC API) in the Stratos platform. Vendor: cubewerx.com. Register when CubeSERV is the public catalog, not a hidden backend.
Signals: path /cubewerx/cubeserv; GetCapabilities ServiceProvider or title CubeWerx / CubeSERV; Stratos catalogue CSW.
Confirm: GET WMS or CSW GetCapabilities that names CubeWerx. One record per public service root, not per layer.
| Tool | Query |
|---|---|
inurl:/cubewerx/cubeserv (WMS OR CSW OR GetCapabilities) | |
"CubeWerx" OR CubeSERV (WMS OR geoportal OR CSW) -site:cubewerx.com | |
| Censys | web.endpoints.http.body: "CubeWerx" |
| FOFA | body="CubeWerx" |
Hexagon M.App Enterprise (mappenterprise)
Hexagon geoportal / browser GIS. Vendor: hexagon.com/products/m-app-enterprise. Distinct from GeoMedia WebMap (geomediawebmap) and ERDAS APOLLO (erdasapollo).
Signals: path /Apps/; M.App Enterprise or Hexagon Geospatial branding; OGC WMS/WFS from the same estate.
Confirm: GET the public Apps portal and match M.App / Hexagon Geospatial. One record per public portal, not per app.
| Tool | Query |
|---|---|
"M.App Enterprise" OR "M.App" (geoportal OR Apps) Hexagon -site:hexagon.com | |
inurl:/Apps/ (geoportal OR "M.App") | |
| Censys | web.endpoints.http.body: "M.App Enterprise" |
| FOFA | body="M.App Enterprise" |
ArcGIS Hub (arcgishub)
Hub sites and Open Data sites on ArcGIS Online. Gallery: hub.arcgis.com. Hosts: *.hub.arcgis.com, *opendata.arcgis.com, plus custom domains.
Signals: /api/search/v1; /api/feed/dcat-us/1.1.json; hubcdn.arcgis.com/opendata-ui; or ArcGIS Enterprise /portal/apps/sites/ with opendata-ui / hub-site assets.
Confirm: match a Hub/Sites signal and a public content or data gallery. Map-first hubs stay catalog_type: Geoportal; dataset-first hubs may be Open data portal (discovery-opendata.md). Custom-domain examples include Bloemendaal (hubcdn.arcgis.com/opendata-ui, /api/search/v1, DCAT-US). Do not set arcgishub from ArcGIS Enterprise /portal/home/ alone; confirm /portal/apps/sites/ (or a custom-domain Hub) with opendata-ui / hub-site.
Checked 24 September 2026. FOFA stores the registrable domain (arcgis.com), so domain!="hub.arcgis.com" does not drop city.hub.arcgis.com. Exclude SaaS hosts with domain!="arcgis.com". host= is a substring: host="hub.arcgis.com" already matches those tenants (1,829, same count as domain="hub.arcgis.com").
The Hub shell loads https://hubcdn.arcgis.com/opendata-ui/... and, on current sites, <meta name="hub-site-head-content">. <meta name="opendata-ui/config/asset-manifest"> is the same shell (5,973 hosts, almost the same set as body="opendata-ui"), including ArcGIS Online — it is not an Enterprise-only signal. body="/portal/apps/sites/" is 1,071 and does not shrink when combined with body!="hubcdn.arcgis.com", because the path also appears on pages that only link to a Sites app. Confirm the live host serves the Sites shell (opendata-ui or hub-site) before setting arcgishub.
| Tool | Query |
|---|---|
site:hub.arcgis.com | |
site:opendata.arcgis.com "{city or agency}" | |
"ArcGIS Hub" "open data" -site:esri.com | |
| Censys | web.names: "hub.arcgis.com" |
| FOFA | host="hub.arcgis.com" |
| FOFA | domain="opendata.arcgis.com" |
| FOFA | body="hubcdn.arcgis.com/opendata-ui" |
| FOFA | body="hubcdn.arcgis.com/opendata-ui" && domain!="arcgis.com" |
| FOFA | body="hub-site-head-content" |
| FOFA | body="/portal/apps/sites/" |
| crt.sh | %.hub.arcgis.com |
Do not hunt with body="opendata-ui" alone (5,998; the token also appears on Enterprise pages that are not Hub shells), body="hub.js" (12,006, unrelated), title="ArcGIS Hub" (the default untitled shell), or body="/api/feed/dcat-us/1.1.json" (the feed URL is not in the HTML). body="opendata.arcgis.com" is link text (70), not the host list — use domain="opendata.arcgis.com" (1,113). body="hubcdn.arcgis.com/opendata-ui" is 5,444; the same query with domain!="arcgis.com" is 2,676 custom-domain shells. body="hub-site-head-content" is 1,904 and misses older custom domains that only reference the CDN CSS.
ArcGIS Server / Enterprise (arcgisserver)
REST services directory. Confirm: https://host/arcgis/rest/info?f=pjson or /arcgis/rest/services?f=pjson (path may be /server/rest/services or /rest/services). If f=pjson returns HTTP 400, retry f=json.
host=".com" is a substring, so it also matches .com.au and other compound suffixes. Checked 25 September 2026: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".com" returned 70 assets, mostly arcgis.com / arcgisonline.com infrastructure. Exclude those domains. title="ArcGIS" on port 6443 or 6080 finds organizational servers, but FOFA stamps that title on every hostname that shares the IP; keep one GIS hostname per IP. header="ArcGIS REST" && host=".com" is not usable. app="ArcGIS" is not a FOFA rule.
host=".cy" is also a substring. Checked 26 September 2026: it matches infix labels such as erp-base.cy.example.com and cy.sycdn.*, not only the .cy TLD. body="ArcGIS REST Services Directory" && title="Folder: /" && host=".cy" returned 0, and that body phrase with country="CY" was also 0, while 7 .cy servers were already registered. title="Folder: /" && country="CY" is a document-management system. header="ArcGIS" && country="CY" is 0. Prefer country="CY" together with a real suffix (host=".gov.cy", host=".ac.cy", host=".org.cy", host=".com.cy"). IIS welcome pages on gis. / geoportal hostnames still need a live /server/rest/services or /arcgis/rest/services GET; folder names alone are not a public catalog when every folder returns token required.
host=".nc" is a substring of .nc.gov and .nc.us (North Carolina) and of labels such as .ncsu. Checked 26 September 2026: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".nc" returned only three gouv.nc services directories, while five .nc servers were already registered. Pair with country="NC" and keep hosts whose name ends in .nc.
host=".li" is a substring of .live, .link, .life, .limo, and of a li. label (li.maps.arcgis.com). Checked 26 September 2026: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".li" returned 0, and that body phrase with country="LI" was also 0. The registry had 0 .li ArcGIS servers. domain=".li" is 0: domain= is the registrable domain, not a TLD. Regex host~="\\.li$" is 820010 on this plan. Keep hosts whose name ends in .li.
host=".sg" is a substring of a sg. label (sg.varashmtg.gov.ua), of .sgc / .sgi / .sgm, and of .sg. inside other names (geo.sg.ch). Checked 26 September 2026: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".sg" returned 0. country="SG" is IP geolocation (AWS and Cloudflare in Singapore), not the .sg TLD: title="ArcGIS" && country="SG" was 99 and body="/arcgis/rest/services" && country="SG" was 925, almost all outside .sg. Use the public suffixes host=".gov.sg", host=".edu.sg", host=".org.sg", host=".com.sg", and host=".net.sg", and keep hosts whose name ends in .sg.
host=".lu" is a substring of .lu.se, .lu.ch, .lu.it, .lu.lv, and of .lu. inside other names (maps.lu.ma). Checked 26 September 2026: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".lu" returned 0, and the body phrase alone with host=".lu" was also 0, while 3 .lu servers were already registered (maps.vdl.lu, geo2.uni.lu, arcweb.liser.lu). title="Folder: /" && country="LU", title="Répertoire : /" && host=".lu", header="ArcGIS" && country="LU", body="/server/rest/services" && host=".lu", and domain="lu" && title="ArcGIS" were 0. app="ESRI-ArcGIS" && country="LU" is only geo2.uni.lu and tonic-geo2.uni.lu. title="ArcGIS" && country="LU" (9) is that university server plus admintools.sigcom.lu (Admin Tools, not a catalog). body="/arcgis/rest/services" && host=".lu" (41) is pages that embed the path. port="6443" && country="LU" (211) is mostly bare IPs; port="6443" && host=".lu" (17) keeps geo2.uni.lu. Prefer country="LU" with a GIS hostname, and keep hosts whose name ends in .lu. Use host="gis." && country="LU" (11, six names ending in .lu), host="maps." && country="LU", host="sig." && country="LU", and host="sigcom.lu". An IIS welcome page or an ACME title can still publish /server/rest/services (gis.bettembourg.lu). GET /arcgis/rest/services?f=pjson and /server/rest/services?f=pjson. Skip token error 499 on every folder (gis.redange.lu), a 403 services directory (gis.sebes.lu), and a second hostname of an existing directory (tonic-geo2.uni.lu repeats geo2.uni.lu).
host=".mt" is a substring of .mt.gov (Montana) and of a mt. label (mt.merkator.co.th). Checked 26 September 2026: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".mt" returned 0, and the body phrase alone with host=".mt" and with country="MT" was also 0, while 3 .mt servers were already registered (geoservices.transport.gov.mt, mapserver.pa.org.mt, eraportal.org.mt). domain="org.mt", domain="edu.mt", and domain="com.mt" are 0: domain= is the registrable domain (gov.mt, pa.org.mt), not a public suffix. title="ArcGIS" && host=".mt" (2) is Montana gisservice.mt.gov. title="ArcGIS" && country="MT" (2) and app="ESRI-ArcGIS" && country="MT" (1) are bare IP 80.85.109.142 (certificate CN ARCGIS.SRCGIS.ORG; /arcgis/rest/services returns license error 9027). port="6443" && country="MT" (57) and port="6080" && country="MT" (8) are VPN, Kubernetes, and appliances. title="Folder: /" && country="MT" is ARRIS modems. header="ArcGIS" && host=".mt" is mt.merkator.co.th. app="ArcGIS" is 820300. A 3-letter token such as host="geo" is dropped (0) even when geoservices.transport.gov.mt is indexed; use a longer label (host="geoservices", host="mapserver"). Use the public suffixes host=".gov.mt", host=".org.mt", host=".edu.mt", host=".com.mt", and host=".net.mt", and keep hosts whose name ends in .mt. body="esri" && host=".gov.mt" is the registered Transport Malta server. host="mapserver" && host=".org.mt" is mapserver.pa.org.mt. host="eraportal.org.mt" finds the registered ERA server. Prefixes geoportal., gisportal., webgis., arcgis., and gisserver. on those suffixes were 0. egis.transport.gov.mt is a 404 on the same IP as geoservices.transport.gov.mt. Cloudflare returns 403 for pamapserver.pa.org.mt.
host=".xyz" also matches the label xyz.maps.arcgis.com, not only the .xyz TLD. Checked 26 September 2026: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".xyz" returned 0, and the body phrase alone with host=".xyz" was also 0. The registry had 0 .xyz ArcGIS servers. title="ArcGIS REST Services Directory", body="esri/admin.css", body="/server/rest/services", title="Portal for ArcGIS", body="arcgis/sharing/rest", body="fullVersion" && body="currentVersion", and port="6443" && title="ArcGIS" were 0. app="ArcGIS" is 820300. title="ArcGIS" && host=".xyz" (3) is a 3D-tiles viewer that mentions ArcGIS and an ArcGIS Maps SDK sample. title="Folder: /" && host=".xyz" (47) is folder-management marketing sites. port="6443" && host=".xyz" (2671), port="6080" && host=".xyz" (319), and port="6443" && cert=".xyz" (2882) are HTTP 400 and unrelated hosts. header="ArcGIS" && host=".xyz" (5) is xyz.maps.arcgis.com plus cyzarsq.xyz:7443 (Portal for ArcGIS; /arcgis/rest/services is a portal error and public item search returns 0). host="arcgis." && host=".xyz" (6) is arcgis.netseclab.xyz (11.5 Hosted folder: Toronto sample layers and a service named Test; private URL is *.svc.cluster.local) and arcgis.app.ausmlab.xyz (read timeout). body="/arcgis/rest/services" && host=".xyz" (69) is pages that embed the path; drop services.arcgis.com and server.arcgisonline.com. body="esri/themes" and body="js.arcgis.com" are JS API apps and lookalike login pages, not services directories. Keep hosts whose name ends in .xyz. GET /arcgis/rest/services?f=json.
host=".ua" is a substring of .uae and of a ua. label. Checked 26 September 2026: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".ua" returned 0, and the body phrase alone with host=".ua" was also 0, while the registry had ArcGIS Hub portals on .ua and no ArcGIS Server records on hosts ending in .ua. title="Folder: /" && host=".ua" is Drive Folder Size. title="Папка: /" matches “Безопасная домашняя папка” hosting pages. body="Каталог служб" matches taxi-company directories. app="ArcGIS" is 820300. title="ArcGIS" && host=".ua" (37), body="esri/admin.css" && host=".ua" (24), and app="ESRI-ArcGIS" && host=".ua" (24) are the same organizational servers; *.varashmtg.gov.ua aliases share one directory. header="ArcGIS" && host=".ua" also finds web-adaptor hosts whose HTML title is empty. port="6443" && host=".gov.ua" without an ArcGIS title is not ArcGIS. Keep hosts whose name ends in .ua. GET /arcgis/rest/services?f=pjson, /server/rest/services?f=pjson, and other web-adaptor paths such as /mayno/rest/services. Skip token error 499 on every folder (gis.pmrada.gov.ua), a login wall (askod.ternopilcity.gov.ua), test servers (service2.ombk.omr.gov.ua, service3.ombk.omr.gov.ua), and a second hostname of an existing directory (www.gis.varashmtg.gov.ua and mon., ph., sg., sed., gv., gw. on varashmtg.gov.ua repeat gis.varashmtg.gov.ua). mbk.adm-km.gov.ua:6443 is the server behind the registered Hub. gisserver.kyivcity.gov.ua is absent from the FOFA title index; the public directory is /mayno/rest/services.
host=".us" is a substring of .usa, .usgs, .usace, .us.com, and of a us. label (gis.us.fo, us.gis.stantec.com). Checked 26 September 2026: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".us" returned 2 (opcgis.deq.state.ms.us, gis.co.benton.or.us), while 389 .us ArcGIS servers were already registered. title="ArcGIS REST Services Directory", domain="us", and port="6080" && title="ArcGIS" && host=".us" were 0. title="ArcGIS" && host=".us" was 29 and body="esri/admin.css" && host=".us" was 5; most of those hosts do not end in .us. header="ArcGIS" && host=".us" was 14. port="6443" && title="ArcGIS" && host=".us" was 4. port="6443" && host=".us" was 208 and is mostly DDNS and VPS. app="ArcGIS" is 820300. host~="\\.us$" is 820010. body="/arcgis/rest/services" && host=".us" (93) is pages that embed the path (pairr.us, onlinehome.us). Keep hosts whose name ends in .us. The .us locality space is {name}.{st}.us (and k12, ci, co, dst, state under that), not country="US". Repeat each prefix for every postal suffix (.ak.us through .wy.us, plus .as.us, .gu.us, .mp.us, .pr.us, .vi.us). Checked sizes with all of those suffixes OR-ed: host="gis." 116, host="maps." 52, host="arcgis" 22, host="map." 29, host="gisportal" 16, host="gisweb" 8, host="geo." 7, host="ags." 6, host="gismap" 6, host="webgis" 4, host="gis2." 4, host="gisdata" 3, host="mapping." 2, host="gisserver" 1, host="gis1." 1, host="geoweb" 0. Second-level names such as cityof*.us and *county.us are not under a state suffix; take them from host="gis." && host=".us" and host="maps." && host=".us" (250 and 202) after dropping hosts that do not end in .us. An IIS welcome page on those names can still publish /arcgis/rest/services or /server/rest/services (gis.aurora.il.us, maps.ci.perrysburg.oh.us). GET both paths with f=pjson. Skip token error 499 on every folder (arcgis.ashlandcountyoh.us), an empty directory (gis.clearcreekcounty.us), a stock SampleWorldCities server (gis.co.simpson.ms.us), and a second hostname of an existing directory (arcgis.co.pepin.wi.us repeats gis.co.pepin.wi.us; gis.chisagocounty.us repeats gis.chisagocountymn.gov; gisweb.dotd.state.la.us repeats gisweb.dotd.la.gov; gismap.co.red-lake.mn.us repeats gismap.co.norman.mn.us).
On .uz the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".uz", the body phrase alone, title="Folder: /" && host=".uz", title="ArcGIS REST Services Directory", title="ArcGIS" && host=".uz", body="esri/admin.css" && host=".uz", and body="Каталог сервисов REST" && country="UZ" were 0 on 26 September 2026, while 3 .uz ArcGIS servers were already registered (db.ngis.uz, gis.agro.uz, gis.boshplan.uz). app="ArcGIS" is 820300. host=".uz" is a substring of .uzh and of a uz. label (gis.uz.ac.zw); keep hosts whose name ends in .uz. country="UZ" is IP geolocation. FOFA indexes the manager title ArcGIS on port 6443, not /arcgis/rest/services. Use title="ArcGIS" && country="UZ" (3 bare IPs), body="esri/admin.css" && country="UZ" (the same 3), and app="ESRI-ArcGIS" && country="UZ" (the same 3). The certificate CN on each IP supplies the name: db.ngis.uz (already registered), IMG.AGRO.UZ (does not resolve; public services are gis.agro.uz), and SUEZGIS.ROPES.UZ (does not resolve; ropes.uz/server/rest/services is version 11.3 with token error 499 on every folder). header="ArcGIS" && host=".uz" is ropes.uz. host="gis." && host=".uz" (31) and title="IIS Windows Server" on gis. / ngis / arcgis / geoportal hostnames find gis.uzspace.uz and portal.ngis.uz (IIS welcome; live REST timed out) plus the registered db.ngis.uz. body="/arcgis/rest/services" && host=".uz" (25) and body="js.arcgis.com" && host=".uz" are pages that embed Esri Online (services-ap1.arcgis.com, server.arcgisonline.com), not a .uz services directory. port="6443" && host=".uz" is Kubernetes and unrelated apps. Skip token error 499 on every folder (ropes.uz).
host=".np" is a substring of a np. label (np.arcgis.maps.transport.nsw.gov.au, np.herpatlas.org). Checked 26 September 2026: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".np", the body phrase alone, title="ArcGIS" && host=".np", body="esri/admin.css" && host=".np", app="ESRI-ArcGIS" && host=".np", header="ArcGIS" && host=".np", title="Portal for ArcGIS" && host=".np", body="currentVersion" && body="folders" && country="NP", port="6443" && host=".gov.np", and port="6080" && host=".gov.np" were 0. The registry had 0 .np ArcGIS servers. app="ArcGIS" is 820300. country="NP" is IP geolocation, not the TLD: title="ArcGIS" && country="NP", app="ESRI-ArcGIS" && country="NP", and body="esri/admin.css" && country="NP" are only 202.45.144.115 (ports 6443 and 6080, self-signed CN DCDL2DK2). cert="DCDL2DK2" is that IP. PTR 144-115.nitc.gov.np does not resolve, and /arcgis/rest/services on the IP timed out. port="6443" && country="NP" (160) and port="6080" && country="NP" (97) are firewalls, Kubernetes, and Laravel. body="/arcgis/rest/services" && country="NP" (26) and body="arcgis/rest" && host=".np" (15) are pages that embed server.arcgisonline.com tiles (dhm.gov.np, gis.kathmandu.gov.np). Use the public suffixes host=".gov.np", host=".edu.np", host=".org.np", host=".com.np", and host=".net.np", and keep hosts whose name ends in .np. Probe host="gis.", host="maps.", host="map.", and host="geoportal" on those suffixes, then GET /arcgis/rest/services?f=json and /server/rest/services?f=json. host="gis." && host=".gov.np" (16) is gis.kathmandu.gov.np (already dmaps), a Drupal site, a Laravel 500, and a 502. host="maps." && host=".gov.np" is a Next.js app. host="map." && host=".gov.np" is Leaflet. Skip ArcGIS Online tile consumers and a bare IP.
| Tool | Query |
|---|---|
intitle:"Folder: /" "ArcGIS REST Services Directory" | |
inurl:/arcgis/rest/services | |
| Censys | host.services.software.product = "ArcGIS" |
| FOFA | body="ArcGIS REST Services Directory" && title="Folder: /" |
| FOFA | title="ArcGIS" && country="UZ" |
| FOFA | body="esri/admin.css" && country="UZ" |
| FOFA | app="ESRI-ArcGIS" && country="UZ" |
| FOFA | header="ArcGIS" && host=".uz" |
| FOFA | host="gis." && host=".uz" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="ngis" || host="arcgis" || host="geoportal") && host=".uz" |
| FOFA | title="ArcGIS" && country="NP" |
| FOFA | app="ESRI-ArcGIS" && country="NP" |
| FOFA | body="esri/admin.css" && country="NP" |
| FOFA | cert="DCDL2DK2" |
| FOFA | host="gis." && host=".gov.np" |
| FOFA | host="maps." && host=".gov.np" |
| FOFA | host="map." && host=".gov.np" |
| FOFA | host="geoportal" && (host=".gov.np" || host=".edu.np" || host=".org.np" || host=".com.np") |
| FOFA | port="6443" && host=".gov.np" |
| FOFA | port="6080" && host=".gov.np" |
| FOFA | body="ArcGIS REST Services Directory" && title="Folder: /" && host=".xyz" |
| FOFA | title="ArcGIS" && host=".ua" |
| FOFA | body="esri/admin.css" && host=".ua" |
| FOFA | app="ESRI-ArcGIS" && host=".ua" |
| FOFA | header="ArcGIS" && host=".ua" |
| FOFA | title="ArcGIS" && host=".gov.ua" |
| FOFA | title="ArcGIS" && host=".edu.ua" |
| FOFA | title="ArcGIS" && host=".xyz" |
| FOFA | header="ArcGIS" && host=".xyz" |
| FOFA | host="arcgis." && host=".xyz" |
| FOFA | body="esri/admin.css" && host=".xyz" |
| FOFA | body="/arcgis/rest/services" && host=".xyz" && body!="services.arcgis.com" && body!="server.arcgisonline.com" |
| FOFA | body="esri/themes" && host=".xyz" |
| FOFA | body="js.arcgis.com" && host=".xyz" |
| FOFA | host="gis." && host=".mn.us" |
| FOFA | host="maps." && host=".mn.us" |
| FOFA | host="arcgis" && host=".mn.us" |
| FOFA | host="map." && host=".mn.us" |
| FOFA | host="gisportal" && host=".mn.us" |
| FOFA | host="gisweb" && host=".mn.us" |
| FOFA | host="geo." && host=".mn.us" |
| FOFA | host="ags." && host=".mn.us" |
| FOFA | host="gismap" && host=".mn.us" |
| FOFA | host="gis2." && host=".mn.us" |
| FOFA | host="gisdata" && host=".mn.us" |
| FOFA | host="mapping." && host=".mn.us" |
| FOFA | host="webgis" && host=".mn.us" |
| FOFA | host="gisserver" && host=".mn.us" |
| FOFA | host="gis1." && host=".mn.us" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="arcgis" || host="gisportal" || host="gisweb" || host="map.") && host=".mn.us" |
| FOFA | host="gis." && country="LU" |
| FOFA | title="ArcGIS" && country="LU" |
| FOFA | host="sigcom.lu" |
| FOFA | port="6443" && host=".lu" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="sig." || host="geoportail" || host="arcgis") && country="LU" |
| FOFA | body="esri" && host=".gov.mt" |
| FOFA | host="geoservices." && (host=".gov.mt" || host=".org.mt" || host=".edu.mt" || host=".com.mt" || host=".net.mt") |
| FOFA | host="mapserver." && (host=".gov.mt" || host=".org.mt" || host=".edu.mt" || host=".com.mt" || host=".net.mt") |
| FOFA | host="eraportal.org.mt" |
| FOFA | title="ArcGIS" && country="MT" |
| FOFA | app="ESRI-ArcGIS" && country="MT" |
| FOFA | title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" |
| FOFA | body="ArcGIS REST Services Directory" && host=".com" && host!="arcgis.com" && host!="arcgisonline.com" && host!="esri.com" |
| FOFA | port="6443" && title="ArcGIS" && host=".com" && host!="arcgis.com" && host!="arcgisonline.com" && host!="esri.com" |
| FOFA | port="6080" && title="ArcGIS" && host=".com" && host!="arcgis.com" && host!="arcgisonline.com" && host!="esri.com" |
| FOFA | title="ArcGIS" && host=".edu" && title!="Hub" && title!="Experience" && title!="Web Application" |
| FOFA | body="esri/admin.css" && host=".edu" |
| FOFA | port="6443" && title="ArcGIS" && host=".edu" |
| FOFA | port="6080" && title="ArcGIS" && host=".edu" |
| FOFA | header="ArcGIS" && host=".edu" |
| FOFA | host="arcgis" && host=".edu" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="arcgis" || host="gisserver" || host="geodata" || host="gisportal") && host=".edu" |
| FOFA | title="ArcGIS" && host=".uk" |
| FOFA | body="/arcgis/rest/services" && host=".uk" |
| FOFA | port="6443" && title="ArcGIS" && host=".uk" |
| FOFA | title="ArcGIS" && host=".fi" |
| FOFA | body="esri/admin.css" && host=".fi" |
| FOFA | title="IIS Windows Server" && (host="kartta" || host="paikkatieto" || host="rajapinta" || host="aineisto" || host="arcgis.") && host=".fi" |
| FOFA | title="IIS Windows Server" && (host="karta" || host="kartor" || host="geodata" || host="gis." || host="arcgis.") && host=".se" |
| FOFA | host="geodata." && host=".se" |
| FOFA | host="geoportal." && host=".se" |
| FOFA | header="ArcGIS" && host=".se" |
| FOFA | title="ArcGIS" && host=".no" |
| FOFA | body="esri/admin.css" && host=".no" |
| FOFA | host="arcgis" && host=".no" |
| FOFA | title="IIS Windows Server" && (host="kart" || host="gis." || host="arcgis") && host=".no" |
| FOFA | host="kart." && host=".kommune.no" |
| FOFA | title="IIS Windows Server" && (host="kort" || host="gis." || host="arcgis" || host="vefsja" || host="luk") && host=".is" |
| FOFA | host="kort." && host=".is" |
| FOFA | host="gis." && host=".is" |
| FOFA | host="luk." && host=".is" |
| FOFA | body="/arcgis/rest/services" && host=".is" |
| FOFA | host="arcgis" && host=".fo" |
| FOFA | host="gis." && host=".fo" |
| FOFA | host="kort." && host=".fo" |
| FOFA | body="arcgis" && host=".fo" |
| FOFA | body="/arcgis/rest/services" && host=".fo" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="arcgis" || host="kort.") && host=".fo" |
| FOFA | host="geo." && country="LI" |
| FOFA | host="geodaten" && country="LI" |
| FOFA | domain="llv.li" |
| FOFA | body="arcgis" && host=".li" |
| FOFA | host="map." && country="LI" |
| FOFA | (host=".gov.sg" || host=".edu.sg" || host=".org.sg" || host=".com.sg" || host=".net.sg") && (title="ArcGIS" || body="esri/admin.css" || header="ArcGIS") |
| FOFA | (host=".gov.sg" || host=".edu.sg" || host=".org.sg" || host=".com.sg" || host=".net.sg") && (host="gis." || host="maps." || host="arcgis" || host="geoportal" || host="geospatial") |
| FOFA | body="arcgis/rest/services" && host=".com.sg" |
| FOFA | host="maps." && host=".gov.sg" |
| FOFA | title="ArcGIS" && host=".lt" |
| FOFA | body="esri/admin.css" && host=".lt" |
| FOFA | port="6443" && title="ArcGIS" && host=".lt" |
| FOFA | header="ArcGIS" && host=".lt" |
| FOFA | host="arcgis" && host=".lt" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="geoportal" || host="arcgis") && host=".lt" |
| FOFA | host="gis." && host=".lt" |
| FOFA | host="geoportal." && host=".lt" |
| FOFA | title="ArcGIS" && host=".ro" && title!="Hub" && title!="Experience" && title!="Web Application" |
| FOFA | body="esri/admin.css" && host=".ro" |
| FOFA | body="/arcgis/rest/services" && title="ArcGIS" && host=".ro" |
| FOFA | body="/server/rest/services" && host=".ro" |
| FOFA | body="administrator has disabled the Services Directory" && host=".ro" |
| FOFA | host="arcgis" && host=".ro" |
| FOFA | host="gis." && host=".rowater.ro" |
| FOFA | port="6080" && host=".ro" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="harta." || host="harti." || host="geoportal" || host="inspire." || host="arcgis") && host=".ro" |
| FOFA | title="ArcGIS" && host=".org" && title!="Hub" && title!="Experience" |
| FOFA | body="esri/admin.css" && host=".org" |
| FOFA | port="6443" && title="ArcGIS" && host=".org" |
| FOFA | header="ArcGIS REST" && host=".org" |
| FOFA | host="arcgis." && host=".org" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="arcgis." || host="gisportal" || host="gisserver") && host=".org" |
| FOFA | title="ArcGIS" && host=".ie" |
| FOFA | body="esri/admin.css" && host=".ie" |
| FOFA | body="/arcgis/rest/services" && host=".ie" |
| FOFA | title="IIS Windows Server" && (host="maps." || host="gis." || host="arcgis.") && host=".ie" |
| FOFA | host="maps." && host=".ie" |
| FOFA | host="gis." && host=".ie" |
| FOFA | host="webservices." && host=".ie" |
| FOFA | host="gisserver" && host=".ie" |
| FOFA | title="Répertoire : /" && host=".fr" |
| FOFA | title="ArcGIS" && host=".fr" && title!="Hub" && title!="Experience" |
| FOFA | body="esri/admin.css" && host=".fr" |
| FOFA | title="IIS Windows Server" && (host="sig." || host="sig-" || host="carto" || host="portailsig" || host="arcgis" || host="geoportail") && host=".fr" |
| FOFA | title="ArcGIS" && host=".es" && title!="Hub" && title!="Experience" |
| FOFA | body="esri/admin.css" && host=".es" |
| FOFA | host="arcgis." && host=".es" |
| FOFA | title="IIS Windows Server" && (host="geoportal." || host="gis." || host="arcgis") && host=".es" |
| FOFA | host="geoportal." && host=".es" |
| FOFA | title="ArcGIS" && host=".cat" |
| FOFA | body="esri/admin.css" && host=".cat" |
| FOFA | host="agportal" && host=".cat" |
| FOFA | host="sig." && host=".cat" |
| FOFA | host="gis." && host=".cat" |
| FOFA | host="geoportal" && host=".cat" |
| FOFA | host="mapes." && host=".cat" |
| FOFA | title="IIS Windows Server" && (host="sig." || host="gis." || host="mapes." || host="geoportal" || host="arcgis" || host="geoserveis" || host="ide.") && host=".cat" |
| FOFA | title="ArcGIS" && country="PL" |
| FOFA | title="ArcGIS" && host=".pl" |
| FOFA | body="esri/admin.css" && country="PL" |
| FOFA | port="6443" && title="ArcGIS" && country="PL" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="mapa" || host="mapy." || host="geoportal" || host="sip." || host="arcgis") && host=".pl" |
| FOFA | title="ArcGIS" && host=".pt" && title!="Hub" && title!="Experience" |
| FOFA | body="esri/admin.css" && host=".pt" |
| FOFA | port="6443" && title="ArcGIS" && host=".pt" |
| FOFA | host="arcgis" && host=".pt" |
| FOFA | title="IIS Windows Server" && (host="sig." || host="gis." || host="geoportal" || host="mapas." || host="arcgis" || host="ide.") && host=".pt" |
| FOFA | body="/arcgis/rest/services" && host=".pt" |
| FOFA | title="ArcGIS" && host=".de" && title!="Hub" && title!="Blog" |
| FOFA | body="esri/admin.css" && host=".de" |
| FOFA | port="6443" && title="ArcGIS" && host=".de" |
| FOFA | host="arcgis." && host=".de" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="geoportal" || host="geodaten" || host="karten" || host="arcgis" || host="geodienste") && host=".de" |
| FOFA | title="ArcGIS" && host=".dk" |
| FOFA | body="esri/admin.css" && host=".dk" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="kort." || host="arcgis" || host="webgis") && host=".dk" |
| FOFA | host="gis." && host=".dk" |
| FOFA | host="webgis" && host=".dk" |
| FOFA | host="arcgis." && host=".dk" |
| FOFA | host="kort." && host=".dk" |
| FOFA | title="ArcGIS" && host=".ch" && title!="Hub" && title!="Experience" |
| FOFA | body="esri/admin.css" && host=".ch" |
| FOFA | port="6443" && title="ArcGIS" && host=".ch" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="map." || host="geo." || host="geoportal" || host="arcgis" || host="webgis") && host=".ch" |
| FOFA | title="ArcGIS" && host=".it" |
| FOFA | body="esri/admin.css" && host=".it" |
| FOFA | host="arcgis" && host=".it" |
| FOFA | port="6443" && title="ArcGIS" && host=".it" |
| FOFA | title="IIS Windows Server" && (host="sit." || host="gis." || host="geoportale" || host="webgis" || host="mappe." || host="arcgis" || host="cartografia") && host=".it" |
| FOFA | body="esri" && (host="sit." || host="gis." || host="webgis" || host="geoportale" || host="cartografia" || host="mappe" || host="territorio" || host="sdi.") && host=".it" |
| FOFA | title="ArcGIS" && host=".ca" && title!="Hub" && title!="Experience" |
| FOFA | body="esri/admin.css" && host=".ca" |
| FOFA | port="6443" && title="ArcGIS" && host=".ca" |
| FOFA | port="6080" && title="ArcGIS" && host=".ca" |
| FOFA | header="ArcGIS" && host=".ca" |
| FOFA | host="arcgis." && host=".ca" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="arcgis." || host="geoportal" || host="carte" || host="cartes.") && host=".ca" |
| FOFA | title="ArcGIS" && host=".gr" |
| FOFA | body="esri/admin.css" && host=".gr" |
| FOFA | port="6443" && title="ArcGIS" && host=".gr" |
| FOFA | port="6080" && title="ArcGIS" && host=".gr" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="geoportal" || host="arcgis" || host="webgis") && host=".gr" |
| FOFA | host="geoportal." && host=".gr" |
| FOFA | host="webgis" && host=".gr" |
| FOFA | title="ArcGIS" && host=".hr" |
| FOFA | body="esri/admin.css" && host=".hr" |
| FOFA | body="esri" && (host="gis." || host="webgis" || host="arcgis" || host="geoportal") && host=".hr" |
| FOFA | header="ArcGIS" && host=".hr" |
| FOFA | host="arcgis" && host=".hr" |
| FOFA | host="webgis" && host=".hr" |
| FOFA | host="arcportal" && host=".hr" |
| FOFA | title="IIS Windows Server" && host="gis" && host=".hr" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="webgis" || host="geoportal" || host="arcgis" || host="karte") && host=".hr" |
| FOFA | app="ESRI-ArcGIS" && country="HR" |
| FOFA | title="ArcGIS" && country="CY" |
| FOFA | body="esri/admin.css" && country="CY" |
| FOFA | port="6443" && title="ArcGIS" && country="CY" |
| FOFA | host="arcgis" && country="CY" |
| FOFA | host="gis." && country="CY" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="geoportal" || host="arcgis" || host="webgis") && (host=".gov.cy" || host=".ac.cy" || host=".org.cy" || host=".com.cy") |
| FOFA | title="IIS Windows Server" && host=".gov.cy" |
| FOFA | title="ArcGIS" && host=".bg" && title!="Hub" && title!="Experience" && title!="Web Application" |
| FOFA | body="esri/admin.css" && host=".bg" |
| FOFA | port="6443" && title="ArcGIS" && host=".bg" |
| FOFA | header="ArcGIS" && host=".bg" |
| FOFA | host="arcgis" && host=".bg" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="geoportal" || host="arcgis" || host="webgis") && host=".bg" |
| FOFA | host="gis." && host=".bg" |
| FOFA | title="ArcGIS" && host=".za" |
| FOFA | body="esri/admin.css" && host=".za" |
| FOFA | header="ArcGIS" && host=".za" |
| FOFA | host="arcgis" && host=".za" |
| FOFA | body="ArcGIS Enterprise" && host=".za" |
| FOFA | port="6443" && title="ArcGIS" && host=".za" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="geoportal" || host="arcgis" || host="webgis" || host="citymaps") && host=".za" |
| FOFA | host="gis." && host=".gov.za" |
| FOFA | host="maps." && host=".gov.za" |
| FOFA | host="gisportal" && host=".za" |
| FOFA | host="citymaps" && host=".za" |
| FOFA | host="geoportal." && host=".za" |
| FOFA | body="esri" && host=".gov.ng" |
| FOFA | header="ArcGIS" && country="NG" |
| FOFA | title="ArcGIS" && country="NG" |
| FOFA | port="6443" && title="ArcGIS" && country="NG" |
| FOFA | app="ESRI-ArcGIS" && country="NG" |
| FOFA | host="gis." && host=".gov.ng" |
| FOFA | cert="arcgis" && country="NG" |
| FOFA | title="IIS Windows Server" && host=".gov.ng" |
| FOFA | title="IIS Windows Server" && host=".gov.mz" |
| FOFA | host="gis." && host=".gov.mz" |
| FOFA | host="mozgis.gov.mz" |
| FOFA | host="mireme.gov.mz" |
| FOFA | body="/arcgis/rest/services" && host=".gov.mz" |
| FOFA | body="/server/rest/services" && host=".gov.mz" |
| FOFA | body="MapServer" && host=".gov.mz" |
| FOFA | body="esri" && host=".gov.mz" |
| FOFA | body="arcgis" && host=".mz" |
| FOFA | body="webappviewer" && host=".mz" |
| FOFA | title="ArcGIS" && host=".tr" && title!="Blog" |
| FOFA | body="esri/admin.css" && host=".tr" |
| FOFA | host="arcgis." && host=".tr" |
| FOFA | header="ArcGIS" && host=".tr" |
| FOFA | port="6443" && title="ArcGIS" && host=".tr" |
| FOFA | host="cbs." && host=".gov.tr" && (title="ArcGIS" || body="esri") |
| FOFA | title="IIS Windows Server" && (host="cbs." || host="gis." || host="harita" || host="arcgis" || host="geoportal" || host="webgis" || host="kentrehberi") && host=".tr" |
| FOFA | title="ArcGIS" && host=".at" |
| FOFA | body="esri/admin.css" && host=".at" |
| FOFA | port="6443" && title="ArcGIS" && host=".at" |
| FOFA | host="gisenterprise" && host=".at" |
| FOFA | host="gis." && host=".gv.at" |
| FOFA | host="geodaten." && host=".at" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="geodaten." || host="geoportal" || host="maps." || host="gisenterprise" || host="webgis") && host=".at" |
| FOFA | title="ArcGIS" && host=".au" && title!="Hub" && title!="Experience" && title!="Web Application" |
| FOFA | body="esri/admin.css" && host=".au" |
| FOFA | header="ArcGIS" && host=".au" |
| FOFA | host="arcgis." && host=".au" |
| FOFA | port="6443" && title="ArcGIS" && host=".au" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="arcgis." || host="spatial" || host="geoportal" || host="mapping.") && host=".au" |
| FOFA | title="ArcGIS" && host=".nz" && title!="Hub" && title!="Experience" |
| FOFA | body="esri/admin.css" && host=".nz" |
| FOFA | port="6443" && title="ArcGIS" && host=".nz" |
| FOFA | host="arcgis." && host=".nz" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="mapping." || host="arcgis" || host="geoportal") && host=".nz" |
| FOFA | host="gis." && host=".govt.nz" |
| FOFA | host="maps." && host=".govt.nz" |
| FOFA | host="spatial." && host=".nz" |
| FOFA | host="geo." && host=".govt.nz" |
| FOFA | title="ArcGIS" && host=".in" && title!="Hub" && title!="Experience" && title!="Data Store" |
| FOFA | body="esri/admin.css" && host=".in" |
| FOFA | header="ArcGIS" && host=".in" |
| FOFA | port="6443" && title="ArcGIS" && host=".in" |
| FOFA | host="arcgis." && host=".in" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="geoportal" || host="arcgis" || host="webgis") && host=".in" |
| FOFA | host="gis." && host=".sa" |
| FOFA | host="gis." && host=".gov.sa" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="geoportal" || host="arcgis") && host=".sa" |
| FOFA | host="geospatial." && host=".sa" |
| FOFA | title="ArcGIS" && host=".sa" |
| FOFA | body="esri/admin.css" && host=".sa" |
| FOFA | title="ArcGIS" && host=".pk" |
| FOFA | body="esri/admin.css" && host=".pk" |
| FOFA | port="6443" && title="ArcGIS" && host=".pk" |
| FOFA | header="ArcGIS" && host=".pk" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="gismaps" || host="geoportal" || host="maps." || host="arcgis") && host=".pk" |
| FOFA | title="ArcGIS" && host=".eg" |
| FOFA | body="ArcGIS Enterprise" && host=".eg" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="geoportal" || host="arcgis") && host=".eg" |
| FOFA | host="gis." && host=".eg" |
| FOFA | host="gis." && host=".gov.eg" |
| FOFA | host="geoportal." && host=".eg" |
| FOFA | host="maps." && host=".eg" |
| FOFA | title="البوابة الجغرافية" && host=".eg" |
| FOFA | header="ArcGIS" && host=".ae" |
| FOFA | body="esri" && (host="gis." || host="maps." || host="geoportal" || host="arcgis") && host=".ae" |
| FOFA | host="gis." && host=".ae" |
| FOFA | host="gis." && host=".gov.ae" |
| FOFA | host="maps." && host=".ae" |
| FOFA | host="geoportal." && host=".ae" |
| FOFA | host="arcgis" && host=".ae" |
| FOFA | host="arcgis" && host=".iq" |
| FOFA | host="gis." && host=".iq" |
| FOFA | host="gis." && host=".gov.iq" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="geoportal" || host="arcgis") && host=".iq" |
| FOFA | title="ArcGIS" && country="IQ" |
| FOFA | body="esri/admin.css" && country="IQ" |
| FOFA | port="6443" && title="ArcGIS" && country="IQ" |
| FOFA | title="ArcGIS" && host=".mx" && title!="Hub" && title!="Experience" && title!="Web Application" |
| FOFA | body="esri/admin.css" && host=".mx" |
| FOFA | title="ArcGIS" && country="MX" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="sig." || host="mapas." || host="geoportal" || host="arcgis") && host=".mx" |
| FOFA | port="6443" && title="ArcGIS" && host=".mx" |
| FOFA | port="6080" && title="ArcGIS" && host=".mx" |
| FOFA | title="ArcGIS" && host=".gov.co" |
| FOFA | body="esri/admin.css" && host=".gov.co" |
| FOFA | header="ArcGIS" && host=".gov.co" |
| FOFA | port="6443" && title="ArcGIS" && host=".gov.co" |
| FOFA | port="6080" && title="ArcGIS" && host=".gov.co" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="sig." || host="mapas." || host="geoportal" || host="arcgis" || host="geovisor" || host="ide.") && host=".gov.co" |
| FOFA | host="sig." && host=".gov.co" |
| FOFA | host="mapas." && host=".gov.co" |
| FOFA | host="geoportal." && host=".gov.co" |
| FOFA | host="gis." && host=".gov.co" |
| FOFA | title="IIS Windows Server" && host="gis" && (host=".gov.il" || host=".muni.il" || host=".org.il" || host=".ac.il" || host=".co.il") |
| FOFA | host="gis." && host=".gov.il" |
| FOFA | host="gis." && host=".muni.il" |
| FOFA | host="gis." && host=".co.il" |
| FOFA | host="gis." && host=".org.il" |
| FOFA | host="gis." && host=".ac.il" |
| FOFA | host="ags." && (host=".gov.il" || host=".co.il" || host=".org.il") |
| FOFA | host="gisviewer" && host=".muni.il" |
| FOFA | port="6443" && title="ArcGIS" && country="IL" |
| FOFA | title="ArcGIS" && host=".nl" && title!="Hub" && title!="Experience" |
| FOFA | body="esri/admin.css" && host=".nl" |
| FOFA | port="6443" && title="ArcGIS" && host=".nl" |
| FOFA | header="ArcGIS" && host=".nl" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="geo." || host="geodata." || host="geoportaal" || host="geoservices" || host="kaart" || host="maps." || host="arcgis") && host=".nl" |
| FOFA | host="geoservices." && host=".nl" |
| FOFA | host="geodata." && host=".nl" |
| FOFA | host="geoportaal." && host=".nl" |
| FOFA | host="arcgis" && host=".nl" |
| FOFA | host="geopublisher.nl" |
| FOFA | body="ArcGIS REST Services Directory" && title="Folder: /" && host=".eu" |
| FOFA | host="discomap" && host=".eu" |
| FOFA | header="ArcGIS" && host=".eu" |
| FOFA | header="ArcGIS" && host=".europa.eu" |
| FOFA | host="arcgis" && host=".europa.eu" |
| FOFA | title="ArcGIS" && host=".eu" && title!="Hub" && title!="Experience" && title!="Data Store" && title!="Web Application" |
| FOFA | body="esri/admin.css" && host=".eu" |
| FOFA | port="6443" && title="ArcGIS" && host=".eu" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="sig." || host="geoportal" || host="maps." || host="arcgis" || host="geo.") && host=".eu" |
| FOFA | host="gis." && host=".eu" |
| FOFA | host="geoportal." && host=".eu" |
| FOFA | host="gis." && host=".ee" |
| FOFA | host="kaart." && host=".ee" |
| FOFA | host="geoportaal" && host=".ee" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="kaart" || host="maps." || host="geoportaal" || host="arcgis") && host=".ee" |
| FOFA | body="esri" && host="gis." && host=".ee" |
| FOFA | header="ArcGIS" && host=".ee" |
| FOFA | host="gis." && host=".lv" |
| FOFA | host="gisportal" && host=".lv" |
| FOFA | host="geodata" && host=".lv" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="karte" || host="kartes" || host="geoportal" || host="geodata" || host="arcgis") && host=".lv" |
| FOFA | body="esri" && (host="gis." || host="karte" || host="geodata") && host=".lv" |
| FOFA | country="LV" && title="ArcGIS" |
| FOFA | country="LV" && body="esri/admin.css" |
| FOFA | title="ArcGIS" && host=".cn" && title!="Hub" && title!="Experience" && title!="Blog" |
| FOFA | body="esri/admin.css" && host=".cn" |
| FOFA | port="6080" && title="ArcGIS" && host=".cn" |
| FOFA | port="6443" && title="ArcGIS" && host=".cn" |
| FOFA | title="GeoScene" && host=".cn" |
| FOFA | body="/geoscene/rest/services" && host=".cn" |
| FOFA | title="ArcGIS" && host=".my" && title!="Hub" && title!="Experience" && title!="Data Store" |
| FOFA | body="esri/admin.css" && host=".my" |
| FOFA | body="ArcGIS Enterprise" && host=".my" |
| FOFA | header="ArcGIS" && host=".my" |
| FOFA | port="6443" && title="ArcGIS" && host=".my" |
| FOFA | port="6080" && title="ArcGIS" && host=".my" |
| FOFA | host="arcgis" && host=".my" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="arcgis" || host="geoportal" || host="webgis" || host="spatial") && host=".my" |
| FOFA | host="gis." && host=".gov.my" |
| FOFA | host="geoportal." && host=".my" |
| FOFA | title="ArcGIS" && country="TH" |
| FOFA | body="esri/admin.css" && country="TH" |
| FOFA | port="6443" && title="ArcGIS" && country="TH" |
| FOFA | port="6080" && title="ArcGIS" && country="TH" |
| FOFA | header="ArcGIS" && country="TH" |
| FOFA | host="gis." && host=".go.th" |
| FOFA | host="gisportal" && country="TH" |
| FOFA | host="arcgis." && country="TH" |
| FOFA | host=".co.th" && title="ArcGIS" |
| FOFA | host=".or.th" && title="ArcGIS" |
| FOFA | host=".ac.th" && host="gis." |
| FOFA | host=".or.th" && host="gis." |
| FOFA | body="/arcgis/rest/services" && host=".go.th" |
| FOFA | title="IIS Windows Server" && host="gis." && host=".go.th" |
| FOFA | title="ArcGIS" && host=".vn" |
| FOFA | body="esri/admin.css" && host=".vn" |
| FOFA | header="ArcGIS" && host=".vn" |
| FOFA | host="arcgis" && host=".vn" |
| FOFA | port="6443" && title="ArcGIS" && host=".vn" |
| FOFA | port="6080" && title="ArcGIS" && host=".vn" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="arcgis" || host="geoportal" || host="webgis" || host="bando") && host=".vn" |
| FOFA | header="ArcGIS" && host=".gov.ph" |
| FOFA | host="controlmap" && host=".gov.ph" |
| FOFA | title="ArcGIS" && host=".gov.ph" |
| FOFA | title="ArcGIS" && country="PH" |
| FOFA | body="esri/admin.css" && country="PH" |
| FOFA | port="6443" && title="ArcGIS" && country="PH" |
| FOFA | port="6080" && title="ArcGIS" && country="PH" |
| FOFA | host="gis." && host=".gov.ph" |
| FOFA | host="maps." && host=".gov.ph" |
| FOFA | host="gisportal" && host=".ph" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="arcgis" || host="geoportal" || host="webgis" || host="spatial") && host=".ph" |
| FOFA | body="/arcgis/rest/services" && host=".gov.ph" |
| FOFA | title="ArcGIS" && host=".gob.pe" |
| FOFA | body="esri/admin.css" && host=".gob.pe" |
| FOFA | port="6080" && title="ArcGIS" && host=".gob.pe" |
| FOFA | port="6443" && title="ArcGIS" && host=".gob.pe" |
| FOFA | header="ArcGIS" && host=".gob.pe" |
| FOFA | body="/arcgis/rest/services" && host=".gob.pe" |
| FOFA | (host="gis." || host="geo." || host="geoportal" || host="sigeo" || host="geoserv" || host="catastro" || host="sig." || host="mapas." || host="visor." || host="ide." || host="webgis") && host=".gob.pe" && (body="esri" || title="ArcGIS" || port="6443" || port="6080") |
| FOFA | title="ArcGIS" && host=".cz" |
| FOFA | body="esri/admin.css" && host=".cz" |
| FOFA | header="ArcGIS" && host=".cz" |
| FOFA | host="arcgis" && host=".cz" |
| FOFA | host="ags." && host=".cz" |
| FOFA | cert="arcgis" && host=".cz" |
| FOFA | port="6443" && title="ArcGIS" && host=".cz" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="mapy." || host="geoportal" || host="arcgis" || host="ags.") && host=".cz" |
| FOFA | body="esri" && (host="gis." || host="ags." || host="geoportal.") && host=".cz" |
| FOFA | host="maparcgis" && host=".cz" |
| FOFA | title="ArcGIS" && host=".sk" |
| FOFA | body="esri/admin.css" && host=".sk" |
| FOFA | country="SK" && body="esri/admin.css" |
| FOFA | country="SK" && title="ArcGIS" && title!="Hub" && title!="Experience" && title!="Web Application" |
| FOFA | header="ArcGIS" && host=".sk" |
| FOFA | country="SK" && header="ArcGIS" |
| FOFA | host="arcgis" && host=".sk" |
| FOFA | host="ags." && host=".sk" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="mapa" || host="mapy." || host="geoportal" || host="arcgis" || host="ags." || host="geo.") && host=".sk" |
| FOFA | body="esri" && (host="gis." || host="arcgis" || host="geoportal" || host="maps.") && host=".sk" |
| FOFA | title="ArcGIS" && host=".net" && title!="Hub" && title!="Experience" && title!="Web Application" && title!="Blog" && title!="Data Store" |
| FOFA | body="esri/admin.css" && host=".net" |
| FOFA | body="ArcGIS Enterprise" && host=".net" |
| FOFA | header="ArcGIS REST" && host=".net" |
| FOFA | port="6443" && title="ArcGIS" && host=".net" |
| FOFA | port="6080" && title="ArcGIS" && host=".net" |
| FOFA | host="arcgis" && host=".net" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="arcgis" || host="gisserver" || host="geodata" || host="gisportal" || host="geoportal") && host=".net" |
| FOFA | title="ArcGIS" && host=".ec" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="sig." || host="geoportal" || host="arcgis" || host="mapas." || host="geovisor") && host=".ec" |
| FOFA | host="cnelep.gob.ec" |
| FOFA | port="6443" && title="ArcGIS" && country="EC" |
| FOFA | body="esri" && (host="gis." || host="sig." || host="geoportal" || host="arcgis") && host=".ec" |
| FOFA | title="ArcGIS" && host=".br" && title!="Hub" && title!="Experience" && title!="Web Application" |
| FOFA | body="esri/admin.css" && host=".br" |
| FOFA | body="ArcGIS Enterprise" && host=".br" |
| FOFA | header="ArcGIS" && host=".br" |
| FOFA | port="6443" && title="ArcGIS" && host=".br" |
| FOFA | port="6080" && title="ArcGIS" && host=".br" |
| FOFA | host="arcgis" && host=".br" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="sig." || host="geoportal" || host="mapas." || host="arcgis" || host="geo.") && host=".br" |
| FOFA | title="ArcGIS" && host=".ar" && title!="Web Application" |
| FOFA | body="ArcGIS Enterprise" && host=".ar" |
| FOFA | body="esri/admin.css" && country="AR" |
| FOFA | port="6080" && title="ArcGIS" && country="AR" |
| FOFA | title="ArcGIS" && country="AR" |
| FOFA | host="arcgis" && host=".ar" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="sig." || host="mapas." || host="geoportal" || host="arcgis" || host="ide.") && host=".ar" |
| FOFA | title="ArcGIS" && host=".uy" && title!="Hub" && title!="Experience" && title!="Web Application" |
| FOFA | body="esri/admin.css" && host=".uy" |
| FOFA | host="arcgis" && host=".uy" |
| FOFA | body="arcgis" && host=".uy" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="sig." || host="mapas." || host="geoportal" || host="arcgis") && host=".uy" |
| FOFA | host="gis." && host=".uy" |
| FOFA | host="sig." && host=".uy" |
| FOFA | host="mapas." && host=".uy" |
| FOFA | host="geoportal." && host=".uy" |
| FOFA | title="ArcGIS" && host=".rw" && title!="Hub" && title!="Experience" && title!="Web Application" && title!="Data Store" |
| FOFA | body="esri/admin.css" && host=".rw" |
| FOFA | header="ArcGIS" && host=".rw" |
| FOFA | host="gis." && host=".rw" |
| FOFA | host="arcgis" && host=".rw" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="geodata" || host="geoportal" || host="arcgis" || host="masterplan") && host=".rw" |
| FOFA | country="RW" && title="ArcGIS" |
| FOFA | title="ArcGIS" && host=".be" |
| FOFA | body="esri/admin.css" && host=".be" |
| FOFA | port="6443" && title="ArcGIS" && host=".be" |
| FOFA | port="6080" && title="ArcGIS" && host=".be" |
| FOFA | header="ArcGIS" && host=".be" |
| FOFA | header="ArcGIS REST" && host=".be" |
| FOFA | host="arcgis" && host=".be" |
| FOFA | body="ArcGIS Enterprise" && host=".be" |
| FOFA | cert="arcgis" && host=".be" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="geo." || host="geoportaal" || host="geoportail" || host="kaart." || host="arcgis" || host="geodata" || host="geoservices") && host=".be" |
| FOFA | body="esri" && (host="gis." || host="geo." || host="geoportaal" || host="geoportail" || host="kaart." || host="arcgis" || host="geodata" || host="geoservices" || host="carto") && host=".be" |
| FOFA | title="ArcGIS" && host=".tw" && title!="Hub" && title!="Experience" && title!="Web Application" && title!="Data Store" |
| FOFA | body="esri/admin.css" && host=".tw" |
| FOFA | port="6443" && title="ArcGIS" && host=".tw" |
| FOFA | header="ArcGIS" && host=".tw" |
| FOFA | host="arcgis" && host=".tw" |
| FOFA | host="gisportal" && host=".tw" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="map." || host="arcgis") && host=".tw" |
| FOFA | host="gis." && host=".gov.tw" |
| FOFA | host="map." && host=".gov.tw" |
| FOFA | title="ArcGIS" && country="PS" |
| FOFA | body="esri/admin.css" && country="PS" |
| FOFA | port="6443" && title="ArcGIS" && country="PS" |
| FOFA | body="esri" && host=".ps" && country="PS" |
| FOFA | host=".pna.ps" && (title="ArcGIS" || body="esri/admin.css" || port="6443") |
| FOFA | title="ArcGIS" && host=".gov.ps" |
| FOFA | host="gis." && host=".cr" |
| FOFA | host="sig." && host=".cr" |
| FOFA | host="mapas." && host=".cr" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="sig." || host="mapas." || host="geoportal" || host="arcgis" || host="ide.") && host=".cr" |
| FOFA | title="ArcGIS" && host=".si" && title!="Hub" && title!="Experience" && title!="Web Application" |
| FOFA | body="esri/admin.css" && host=".si" |
| FOFA | host="arcgis." && host=".si" |
| FOFA | host="gis." && host=".gov.si" |
| FOFA | host="gisserver" && host=".si" |
| FOFA | (host="gis." || host="gis1." || host="gis2." || host="gis3." || host="gisserver" || host="arcgis.") && host=".si" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="geoportal" || host="arcgis" || host="prostor" || host="webgis" || host="zemljevid") && host=".si" |
| FOFA | body="esri" && host=".jo" |
| FOFA | host="gis." && host=".jo" |
| FOFA | host="maps." && host=".jo" |
| FOFA | (host="gis." || host="maps." || host="geoportal" || host="sdi" || host="arcgis") && host=".gov.jo" |
| FOFA | title="IIS Windows Server" && host=".gov.jo" |
| FOFA | app="ESRI-ArcGIS" && country="JO" |
| FOFA | title="ArcGIS" && country="CL" |
| FOFA | body="esri/admin.css" && country="CL" |
| FOFA | port="6443" && title="ArcGIS" && country="CL" |
| FOFA | port="6080" && title="ArcGIS" && country="CL" |
| FOFA | app="ESRI-ArcGIS" && country="CL" |
| FOFA | title="ArcGIS" && host=".cl" && title!="Hub" && title!="Experience" && title!="Web Application" |
| FOFA | body="esri/admin.css" && host=".cl" |
| FOFA | host="arcgis." && host=".cl" && country="CL" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="sig." || host="ide." || host="arcgis" || host="geoportal" || host="sit." || host="mapas.") && country="CL" |
| FOFA | title="IIS Windows Server" && host=".gob.cl" |
| FOFA | title="ArcGIS" && host=".info" && title!="Hub" && title!="Experience" && title!="Web Application" && title!="Data Store" |
| FOFA | body="esri/admin.css" && host=".info" |
| FOFA | port="6443" && title="ArcGIS" && host=".info" |
| FOFA | port="6080" && title="ArcGIS" && host=".info" |
| FOFA | host="arcgis" && host=".info" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="arcgis" || host="gisserver" || host="geodata" || host="gisportal" || host="geoportal") && host=".info" |
| FOFA | title="ArcGIS" && country="BY" |
| FOFA | body="esri/admin.css" && country="BY" |
| FOFA | port="6443" && title="ArcGIS" && country="BY" |
| FOFA | app="ESRI-ArcGIS" && country="BY" |
| FOFA | title="ArcGIS" && host=".by" |
| FOFA | body="esri/admin.css" && host=".by" |
| FOFA | host="gismap.by" |
| FOFA | host="gis." && host=".by" && country="BY" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="gismap" || host="maps." || host="geoportal" || host="arcgis") && host=".by" |
| FOFA | host="gis." && host=".info" |
| FOFA | host="geoportal." && host=".info" |
| FOFA | title="ArcGIS" && host=".hu" && title!="Hub" && title!="Experience" && title!="Web Application" |
| FOFA | body="esri/admin.css" && host=".hu" |
| FOFA | port="6443" && title="ArcGIS" && host=".hu" |
| FOFA | app="ESRI-ArcGIS" && host=".hu" |
| FOFA | body="/arcgis/rest/services" && host=".hu" |
| FOFA | host="gis." && host=".hu" |
| FOFA | host="terkep." && host=".hu" |
| FOFA | host="gisqatar.org.qa" |
| FOFA | host="gis." && host=".gov.qa" |
| FOFA | host="geoportal." && host=".qa" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="geoportal" || host="arcgis") && host=".qa" |
| FOFA | title="ArcGIS" && country="QA" |
| FOFA | app="ESRI-ArcGIS" && country="QA" |
| FOFA | body="esri" && host=".gov.qa" |
| FOFA | header="ArcGIS" && host=".gov.lk" |
| FOFA | port="6443" && host=".gov.lk" |
| FOFA | port="6080" && host=".gov.lk" |
| FOFA | host="gis." && host=".gov.lk" |
| FOFA | host="arcgis." && host=".lk" |
| FOFA | host="geoportal." && host=".lk" |
| FOFA | title="IIS Server" && (host="gis." || host="maps." || host="arcgis" || host="geoportal") && host=".lk" |
| FOFA | title="ArcGIS" && country="LK" |
| FOFA | app="ESRI-ArcGIS" && country="LK" |
| FOFA | body="esri" && host=".gov.lk" |
| FOFA | title="ArcGIS" && host=".mn" && title!="Hub" && title!="Experience" && title!="Urban" && title!="Data Store" |
| FOFA | body="esri/admin.css" && host=".mn" |
| FOFA | port="6443" && title="ArcGIS" && host=".mn" |
| FOFA | app="ESRI-ArcGIS" && country="MN" |
| FOFA | title="ArcGIS" && country="MN" |
| FOFA | body="/arcgis/rest/services" && host=".mn" |
| FOFA | domain="ubhub.mn" |
| FOFA | host="gis." && country="MN" |
| FOFA | body="ArcGIS REST Services Directory" && title="Folder: /" && host=".nc" && country="NC" |
| FOFA | body="ArcGIS REST" && country="NC" |
| FOFA | header="ArcGIS" && country="NC" |
| FOFA | host="carto." && country="NC" |
| FOFA | host="arcgis" && country="NC" && host!=".nc.gov" && host!=".nc.us" |
| FOFA | title="IIS Windows Server" && (host="arcgis" || host="sig." || host="mysig") && country="NC" |
| FOFA | host=".georep.nc" |
| FOFA | title="ArcGIS" && host=".om" && title!="Hub" && title!="Experience" && title!="Survey123" |
| FOFA | body="esri/admin.css" && host=".om" |
| FOFA | port="6443" && title="ArcGIS" && host=".om" |
| FOFA | app="ESRI-ArcGIS" && country="OM" |
| FOFA | title="ArcGIS" && country="OM" |
| FOFA | body="/arcgis/rest/services" && host=".om" |
| FOFA | body="/server/rest/services" && host=".om" |
| FOFA | host="gis." && host=".om" |
| FOFA | host="geoportal" && host=".om" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="geoportal" || host="arcgis") && host=".om" |
| FOFA | host=".gob.gt" && body="arcgis" |
| FOFA | host=".gob.gt" && body="esri" |
| FOFA | body="arcgis" && country="GT" |
| FOFA | header="ArcGIS" && country="GT" |
| FOFA | host="sig." && host=".gob.gt" |
| FOFA | host="gis." && country="GT" |
| FOFA | host="mapas." && country="GT" |
| FOFA | title="ArcGIS" && host=".lb" |
| FOFA | body="esri/admin.css" && host=".lb" |
| FOFA | body="esri" && host=".gov.lb" |
| FOFA | body="esri" && host=".edu.lb" |
| FOFA | body="esri" && host=".org.lb" |
| FOFA | port="6443" && title="ArcGIS" && country="LB" |
| FOFA | app="ESRI-ArcGIS" && country="LB" |
| FOFA | title="IIS Windows Server" && host=".gov.lb" |
| FOFA | host="gis." && host=".gov.lb" |
| FOFA | host="gis." && host=".lb" |
| FOFA | host="maps." && host=".gov.lb" |
| FOFA | title="ArcGIS" && host=".rs" |
| FOFA | body="esri/admin.css" && host=".rs" |
| FOFA | port="6443" && title="ArcGIS" && host=".rs" |
| FOFA | title="ArcGIS" && country="RS" |
| FOFA | app="ESRI-ArcGIS" && country="RS" |
| FOFA | host="gis." && host=".gov.rs" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="geoportal" || host="arcgis") && host=".rs" |
| FOFA | host="geoportal." && country="RS" |
| FOFA | title="ArcGIS" && host=".kr" && title!="Hub" && title!="Experience" && title!="Urban" && title!="Data Store" |
| FOFA | body="esri/admin.css" && host=".kr" |
| FOFA | header="ArcGIS" && host=".kr" |
| FOFA | port="6443" && title="ArcGIS" && host=".kr" |
| FOFA | port="6080" && title="ArcGIS" && host=".kr" |
| FOFA | title="ArcGIS" && country="KR" |
| FOFA | body="esri/admin.css" && country="KR" |
| FOFA | app="ESRI-ArcGIS" && country="KR" |
| FOFA | port="6443" && title="ArcGIS" && country="KR" |
| FOFA | port="6080" && title="ArcGIS" && country="KR" |
| FOFA | body="esri" && host="gis." && host=".go.kr" |
| FOFA | body="ArcGIS REST" && host=".go.kr" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="map." || host="geoportal" || host="arcgis" || host="geo.") && host=".kr" |
| FOFA | title="ArcGIS" && host=".ba" |
| FOFA | body="esri/admin.css" && host=".ba" |
| FOFA | port="6443" && title="ArcGIS" && host=".ba" |
| FOFA | title="ArcGIS" && country="BA" |
| FOFA | app="ESRI-ArcGIS" && country="BA" |
| FOFA | host="gis." && host=".ba" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="webgis" || host="arcgis") && host=".ba" && country="BA" |
| FOFA | host="maps." && host=".ba" |
| FOFA | title="ArcGIS" && host=".ke" && title!="Hub" && title!="Data Store" |
| FOFA | body="esri/admin.css" && host=".ke" |
| FOFA | port="6443" && title="ArcGIS" && host=".ke" |
| FOFA | header="ArcGIS" && host=".ke" |
| FOFA | title="ArcGIS" && country="KE" |
| FOFA | app="ESRI-ArcGIS" && country="KE" |
| FOFA | title="IIS Windows Server" && (host="gis." || host="maps." || host="arcgis" || host="geoportal") && host=".ke" |
| FOFA | host="gis." && host=".ke" |
| FOFA | title="ArcGIS" && host=".hk" |
| FOFA | body="esri/admin.css" && host=".hk" |
| FOFA | port="6443" && title="ArcGIS" && host=".hk" |
| FOFA | body="esri/admin.css" && country="HK" |
| FOFA | app="ESRI-ArcGIS" && country="HK" |
| FOFA | body="/arcgis/" && host=".gov.hk" |
| FOFA | host="csdi.gov.hk" |
| FOFA | host="map.gov.hk" |
| FOFA | body="/arcgis/rest/services" && host=".mc" |
| FOFA | body="montecarto" && host=".mc" |
| FOFA | host="geoportail" && host=".mc" |
| FOFA | host="geo-portail" && host=".mc" |
| FOFA | title="ArcGIS" && country="BT" |
| FOFA | body="esri/admin.css" && country="BT" |
| FOFA | header="ArcGIS" && country="BT" |
| FOFA | body="rest/services" && country="BT" |
| FOFA | host="arcgis" && host=".gov.bt" |
| FOFA | host=".gov.bt" && (host="gis" || host="geo" || host="map" || host="arcgis" || host="spatial" || host="geoportal") |
| FOFA | title="IIS Windows Server" && host=".gov.bt" |
| FOFA | title="ArcGIS" && country="BH" |
| FOFA | body="esri/admin.css" && country="BH" |
| FOFA | app="ESRI-ArcGIS" && country="BH" |
| FOFA | cert="arcgis" && country="BH" |
| FOFA | host="gis." && host=".bh" |
| FOFA | host="geoportal" && host=".bh" |
| FOFA | body="/arcgis/rest/services" && host=".bh" |
| FOFA | domain="ma-investment.gov.bh" |
| FOFA | host=".gov.bh" && (host="gis." || host="arcgis" || host="maps.") |
| FOFA | title="IIS Windows Server" && host=".gov.bh" |
| FOFA | host=".gouv.mc" && (host="geo" || host="gis" || host="sig" || host="carto" || host="map.") |
| FOFA | title="ArcGIS" && host=".gov.pr" |
| FOFA | body="esri/admin.css" && host=".gov.pr" |
| FOFA | body="esri" && host=".gov.pr" |
| FOFA | host="gis." && host=".gov.pr" |
| FOFA | host="gis." && host=".gobierno.pr" |
| FOFA | app="ESRI-ArcGIS" && host=".gov.pr" |
| FOFA | host="gis." && (host=".gov.mo" || host=".edu.mo" || host=".org.mo" || host=".com.mo") |
| FOFA | host="gis.gov.mo" |
| FOFA | cert="gis.gov.mo" |
| FOFA | port="6443" && host=".gov.mo" |
| FOFA | title="ArcGIS" && country="MO" |
| Shodan | http.html:"ArcGIS REST Services Directory" |
FOFA has no app="ArcGIS" rule (API error 820300). The services-directory HTML title is Folder: /, so title="ArcGIS REST Services Directory" returns nothing. title="Folder: /" alone is a generic directory listing. Pair the body fingerprint with that title. The second FOFA query finds directories that omit the English product sentence (GeoPublisher and some Dutch web adaptors). header="ArcGIS REST", body="/server/rest/services", and the localized product titles tried in September 2026 were subsets of the first query or returned 0.
On .pr the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".pr", the body phrase alone, body="/server/rest/services" && host=".pr", header="ArcGIS" && host=".pr", port="6443" && title="ArcGIS" && host=".pr", port="6080" && title="ArcGIS" && host=".pr", host="arcgis" && host=".pr", title="Carpeta: /" && host=".gov.pr", body="Directorio de servicios REST" && host=".pr", and cert="arcgis" && host=".gov.pr" each returned 0 on 26 September 2026. The registry had 0 .pr ArcGIS servers. app="ArcGIS" is 820300. host=".pr" is a substring of .pr.gov.br (Paraná, Brazil: geo.londrina.pr.gov.br) and of the US label pr.gov (sige.pr.gov, gis.vivienda.pr.gov); host=".edu.pr" also matches edu.pr.senac.br and edu.pr.co. Keep hosts whose name ends in .pr. pr.gov is the .gov TLD, not this ccTLD; the registered Puerto Rico servers (sige.pr.gov, sigejp.pr.gov, www.sigela.pr.gov) are outside this query. country="PR" is IP geolocation: title="ArcGIS" && country="PR" (6) is ArcGIS Web Application on uprm.edu, and port="6443" && country="PR" is Winflector, PBXware, and FortiGate. FOFA indexes the manager title ArcGIS or esri/admin.css, not /server/rest/services. Use the public suffix host=".gov.pr" (288 hosts; the only GIS names are gis.caguas.gov.pr and gis.guaynabocity.gov.pr): title="ArcGIS" && host=".gov.pr" (2), body="esri" && host=".gov.pr" (2), body="esri/admin.css" && host=".pr" (the Caguas manager plus pr.gov names), and host="gis." && host=".gov.pr" (4). title="ArcGIS", body="arcgis", and body="esri" on .edu.pr, .com.pr, .org.pr, .net.pr, .ac.pr, .est.pr, .prof.pr, .isla.pr, and .gobierno.pr were 0 except host="gis." && host=".gobierno.pr" (1, gis.gobierno.pr, title Not Found). host="maps." && host=".com.pr" is maps.google.com.pr. title="IIS Windows Server" && host=".gov.pr" (1) is permits.guaynabocity.gov.pr. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Caguas publishes under /server/rest/services). Skip a root whose only public folder is Hosted (gis.caguas.gov.pr: DEM and Utilities return token error 499; Hosted is one road feature layer), an expired certificate (gis.guaynabocity.gov.pr, FOFA title 502), and hosts that reset the connection (gis.gobierno.pr).
On .mo the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".mo", the body phrase alone, and the same phrase with country="MO" each returned 0 on 26 September 2026, while the registry already had 2 .mo ArcGIS servers (webmap.gis.gov.mo, gis.dsec.gov.mo). body="/arcgis/rest/services" && host=".gov.mo", body="/server/rest/services" && host=".mo", body="arcgis/rest" && host=".gov.mo", header="ArcGIS" on .gov.mo / .edu.mo / .org.mo / .com.mo, cert="arcgis" on those suffixes, title="Portal for ArcGIS", title="資料夾: /", title="Pasta: /", body="servicesDirectory", body="esri/css", and body="js.arcgis.com" were 0. app="ArcGIS" is 820300. domain="gov.mo" is 0: .gov.mo is a public suffix, so domain= is the registrable name (gis.gov.mo, ssm.gov.mo), not gov.mo. host=".mo" is a substring of .mo.gov (Missouri), .mo.gov.cz, .money, .mobi, and a mo. label. title="ArcGIS" && host=".mo" (2) is arcgis.mo.gov.cz and mohic.mo.gov, not Macau. host="arcgis" && host=".mo" is the Czech host. Keep hosts whose name ends in .mo. country="MO" is IP geolocation: title="ArcGIS" && country="MO" (24), body="esri/admin.css" && country="MO", app="ESRI-ArcGIS" && country="MO", and body="/arcgis/rest/services" && country="MO" are the same CEM Macau .com vhosts plus bare IPs 202.175.182.52, 202.175.18.253, 202.175.18.246, and 202.175.47.236, none of them a .mo name. Do not register a bare IP. FOFA does not index the services-directory HTML on this TLD. Use the public suffixes with a GIS label: host="gis." && (host=".gov.mo" || host=".edu.mo" || host=".org.mo" || host=".com.mo") (32). That list is gis.gov.mo (also host="gis.gov.mo" and cert="gis.gov.mo"), gis.dsec.gov.mo, and gis.dspa.gov.mo. port="6443" && host=".gov.mo" (1) is ssm.gov.mo:6443; the same IP on :6443 is IIS “403 - Forbidden”, and port="6443" && host=".com.mo" is bank and airline WAFs. title="ArcGIS" on .edu.mo, .org.mo, and .com.mo was 0, as were um.edu.mo, mpu.edu.mo, and usj.edu.mo with port 6443 or an Esri body. GET /arcgis/rest/services?f=pjson. The gis.gov.mo names cadastre, traffic, sdi, m, and webmap4* (DSEDJ, DSSCU, CTT, IAS, IH, FDC) return the same services JSON as the already registered webmap.gis.gov.mo. www.gis.gov.mo/geoportal/ is a retired landing page that links cadastre.gis.gov.mo and webmap.gis.gov.mo. Skip gis.dspa.gov.mo (redirects to a Leaflet app at apps.dspa.gov.mo/gis) and map.um.edu.mo (UM eMap, Leaflet, no ArcGIS REST).
On .hk the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".hk", the body phrase alone, title="ArcGIS REST Services Directory", body="ArcGIS REST 服務目錄", title="資料夾: /", body="/geoscene/rest/services", cert="arcgis" && host=".hk", title="ArcGIS" && host=".gov.hk", and domain="gov.hk" && port="6443" each returned 0 on 26 September 2026, while the registry already had 2 .hk ArcGIS servers (www1.map.gov.hk, foa-arcgis.ad.arch.hku.hk). title="Folder: /" && host=".hk" (21) is print shops and stationery. app="ArcGIS" is 820300. host=".hk" is a substring (map.gov.hk.usitestat.com); keep hosts whose name ends in .hk. FOFA indexes the manager title ArcGIS on port 6443, esri/admin.css, or a page that mentions /arcgis/, not /server/rest/services. Use title="ArcGIS" && host=".hk" (3; the only server is dev.stoneroad.com.hk:6443), body="esri/admin.css" && host=".hk" (1, the same host), and port="6443" && title="ArcGIS" && host=".hk" (1). body="esri/admin.css" && country="HK" (27) and app="ESRI-ArcGIS" && country="HK" (29) are that host plus bare IPs and non-.hk names (utm.hkgisportal.com, gis.afcdmarine.com); use ip="..." for a vhost and do not register a bare IP. title="ArcGIS" && country="HK" (88) is Esri marketing, ArcGIS Online, and those same managers. body="/arcgis/rest/services" && host=".hk" (9) and body="服務目錄" && host=".hk" (29) are not services directories. body="/arcgis/" && host=".gov.hk" (27) is mostly the Town Planning Board site and login walls; the GIS names are www.hkmapservice.gov.hk, 3d.map.gov.hk, and the already registered portal.csdi.gov.hk. Also probe host="csdi.gov.hk" (25) and host="map.gov.hk" (12): a “Document Moved” or GeoInfo Map title can still publish /server/rest/services or /arcgis/rest/services. title="IIS Windows Server" on gis. / maps. / map. / arcgis / geoportal hostnames with host=".hk" was 0; title="IIS Windows Server" && host=".gov.hk" (12) is mail and apps, plus transform.geodetic.gov.hk. host="gis." && host=".gov.hk" was 0. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (CSDI publishes under /server/rest/services). Skip a second hostname of GeoInfo Map (www.map.gov.hk repeats www1.map.gov.hk), a second adaptor of the same owning portal (p1hosting.csdi.gov.hk, p2hosting.csdi.gov.hk, and static.csdi.gov.hk repeat hosting.csdi.gov.hk), a dev root whose only public folder is Utilities (dev.stoneroad.com.hk:6443; the TLS chain omits an intermediate), token error 499 on Hosted / open / po, HKMS 2.0 (www.hkmapservice.gov.hk returns 403 on /server/rest/services), the 3D map viewer (3d.map.gov.hk), and hosts that do not answer (arcgisdemo.esrichina.hk).
On .ke the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".ke", the body phrase alone, title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" && host=".ke", and the body phrase with country="KE" each returned 0 on 26 September 2026, while the registry already had 3 .ke ArcGIS servers (gis.kenha.co.ke, gisportal.kengen.co.ke, portal.miningcadastre.go.ke). header="ArcGIS REST" && host=".ke", cert="arcgis" && host=".ke", title="Portal for ArcGIS" && host=".ke", port="6080" && title="ArcGIS" && host=".ke", and body="/server/rest/services" && host=".ke" were 0. app="ArcGIS" is 820300. host=".ke" is a substring (ke.uw.edu.pl); keep hosts whose name ends in .ke. FOFA indexes the manager title ArcGIS on port 6443, esri/admin.css, an ArcGIS response header, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".ke" (12; drop ArcGIS Hub and ArcGIS Data Store), body="esri/admin.css" && host=".ke" (5), port="6443" && title="ArcGIS" && host=".ke" (5), header="ArcGIS" && host=".ke" (8), and title="IIS Windows Server" on gis. / maps. / arcgis / geoportal hostnames (8). title="ArcGIS" && country="KE" (28) and app="ESRI-ArcGIS" && country="KE" (18) are those names plus bare IPs; use ip="..." for a .ke vhost and do not register a bare IP (197.156.139.90 is wwfke-giscoe.wwfkenya.org, not a .ke name; 41.76.172.235 is gishub.petroleum.go.ke; 102.215.40.188 is gis.kplc.co.ke). body="/arcgis/rest/services" && host=".ke" (20) is mostly pages that embed the path. host="gis." && host=".ke" (108) is county and utility hostnames, NexxRetail, and nginx. body="ArcGIS Enterprise" && host=".ke" is personal sites. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Kenya Power, KNBS, Mombasa Water, and the petroleum hub publish under /server/rest/services). Skip token-only folders (gis.nema.go.ke, gis.knbs.or.ke, nwcarcgis.nairobiwater.co.ke, gishub.petroleum.go.ke), Hosted survey and training layers (gis.kplc.co.ke, gis.mombasawater.co.ke), license error 9027 (iggresserver.dkut.ac.ke:6443 and rsrg-iggres.dkut.ac.ke:6443), a broken web adaptor (gis.kwalewater.co.ke returns Application Error), ArcGIS Hub (www.opendata.go.ke, covid19.health.go.ke), a second hostname of the mining cadastre (dashboard.miningcadastre.go.ke, licensing.miningcadastre.go.ke), GeoServer or MapStore sites named gis. (gis.wajir.go.ke, gis.mombasa.go.ke), and hosts that do not answer (gis.gdc.co.ke, gis.garissa.go.ke, gis.tavevowater.co.ke, gis.nairobi.go.ke).
On .lb the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".lb", the body phrase alone, and the same phrase with country="LB" each returned 0 on 26 September 2026, while the registry already had 4 .lb ArcGIS servers (gisportal.ewsp.gov.lb, icilgis.aub.edu.lb, maps.moph.gov.lb, and inactive gis.redcross.org.lb). body="/server/rest/services" && host=".lb", title="Répertoire : /" && host=".lb", title="مجلد: /" && host=".lb", cert="arcgis" && host=".lb", body="ArcGIS Enterprise" && host=".lb", title="Portal for ArcGIS" && host=".lb", host="geoportal" && host=".lb", and port="6080" && title="ArcGIS" && host=".lb" were 0. app="ArcGIS" is 820300. host=".lb" is a substring (arcgis.lb.dartmouth.edu, maps.lb.coltonca.gov, lb.maps.arcgis.com); keep hosts whose name ends in .lb. FOFA indexes the manager title ArcGIS on port 6443, esri in the page, or the IIS welcome page, not /server/rest/services. Use title="ArcGIS" && host=".lb" (7; one name ending in .lb, giscenter.balamand.edu.lb), body="esri/admin.css" && host=".lb" (the same set), body="esri" && host=".edu.lb" (3), body="esri" && host=".org.lb" (1, gim.redcross.org.lb), and body="esri" && host=".gov.lb" (1, already registered maps.moph.gov.lb). port="6443" && title="ArcGIS" && country="LB" and app="ESRI-ArcGIS" && country="LB" are that Balamand manager plus bare IPs; ip="77.42.240.123" is the already registered gisportal.ewsp.gov.lb, and ip="193.227.175.47" is giscenter.balamand.edu.lb. Do not register a bare IP. title="IIS Windows Server" && host=".gov.lb" (40) is mostly mail and hosting; the GIS name in that set is mehegis.mehe.gov.lb. Also probe host="gis." && host=".gov.lb" and host="maps." && host=".gov.lb". title="IIS Windows Server" on gis. / maps. / geoportal / arcgis hostnames with host=".lb" matched maps.lb.coltonca.gov, not this TLD. body="/arcgis/rest/services" && host=".lb" (10) is Dartmouth infix labels, a logistics homepage, and the Balamand manager. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Balamand, the Ministry of Education, and the Red Cross GIM host publish under /server/rest/services). Skip a second port of the same directory (giscenter.balamand.edu.lb:6443 repeats /server/rest/services), token-only folders, school sites named gis. (gis.edu.lb), the AUB interactive-maps SPA (maps.aub.edu.lb), and hosts that do not answer (gis.mehe.gov.lb, drmgis.pcm.gov.lb).
On .hu the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".hu", the body phrase alone, and the same phrase with country="HU" each returned 0 on 26 September 2026, while the registry already had 7 .hu ArcGIS servers. title=="Folder: /" && host=".hu" and title=="Mappa: /" && host=".hu" were 0. title="Folder: /" && host=".hu" (12) and title="Mappa: /" && host=".hu" (18) are stationery and print shops. app="ArcGIS" is 820300. cert="arcgis" && host=".hu", title="Portal for ArcGIS" && host=".hu", body="ArcGIS REST szolgáltatások" && host=".hu", and body="esri" && host=".gov.hu" were 0. host="arcgis" && host=".hu" (1) is wildcard DNS (arcgis.co.beltrami.foodpanda.hu). header="ArcGIS" && host=".hu" (3) and body="/server/rest/services" && host=".hu" (7) are not these servers. title="IIS Windows Server" on gis. / terkep / geoportal / arcgis hostnames was 0. FOFA indexes the manager title ArcGIS on port 6443, or a page that embeds /arcgis/rest/services, not the services-directory HTML. Use title="ArcGIS" && host=".hu" (10; drop ArcGIS Web Application and Web AppBuilder), body="esri/admin.css" && host=".hu" (5), port="6443" && title="ArcGIS" && host=".hu" (5), and app="ESRI-ArcGIS" && host=".hu" (5). title="ArcGIS" && country="HU" (20) is that same .hu set plus non-.hu names. body="/arcgis/rest/services" && host=".hu" (65) is mostly pages that embed the path; the services directories in that set are turistaterkepek.hu, maps.rissac.hu, and emna.hu. Then probe host="gis." && host=".hu" (44) and host="terkep." && host=".hu" (176): those hostname nets are mostly unrelated sites, and the public directories in them are gis.pesterzsebet.hu (/server/rest/services) plus terkep.zuglo.hu and terkep.mekh.hu. port="6443" && host=".hu" (105) and port="6080" && host=".hu" (58) are Kubernetes and other appliances; keep the port only with title="ArcGIS". host=".hu" also matches .hu. inside other names (gis.huse.hu.cn, foodpanda.hu); keep hosts whose name ends in .hu. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (hiking maps, soil maps, and Pesterzsébet publish under /server/rest/services; e-MNA listens on port 6443). Skip the REST directory behind an existing viewer on the same host (map.ksh.hu is KSH TIMEA), a second port of the same directory (www.turistaterkepek.hu:6443 repeats turistaterkepek.hu/server/rest/services; gis.turistaterkepek.hu:6443 repeats the port 443 adaptor), Web AppBuilder shells (turistaterkepek.hu:3344), and hosts that 503 or do not answer (terkep.mki.gov.hu, gis.kormany.hu). gis.turistaterkepek.hu is a separate public root from turistaterkepek.hu (Server 11.5 versus 11.1). maps.rissac.hu:6443/arcgis/rest/services is a separate public root from /server/rest/services: it still publishes Talajinfo and Tokaj soil grids.
On .mn the product-sentence query is thin: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".mn" returned 1 on 26 September 2026 (imagery.ubhub.mn, a second web adaptor of arcgis.ubhub.mn), and the body phrase with country="MN" was 3 rows of that same host, while the registry already had 4 .mn ArcGIS servers (maps.1212.mn, gismap.mris.mn, shonkhor.monmap.mn, titem.tog.mn). header="ArcGIS REST" && host=".mn", title="ArcGIS" && host=".gov.mn", cert="arcgis" && host=".mn", body="/server/rest/services" && host=".mn", and port="6080" && title="ArcGIS" && host=".mn" were 0. app="ArcGIS" is 820300. host=".mn" is a substring of .mn.us (Minnesota); keep hosts whose name ends in .mn. FOFA indexes the manager title ArcGIS on port 6443, not /arcgis/rest/services. Use title="ArcGIS" && host=".mn" (4; drop ArcGIS Urban), body="esri/admin.css" && host=".mn" (3), port="6443" && title="ArcGIS" && host=".mn" (3), and app="ESRI-ArcGIS" && country="MN" (16, mostly bare IPs). title="ArcGIS" && country="MN" (23) is those names plus bare IPs on 6443/6080; use ip="..." for a .mn vhost and do not register a bare IP (202.70.40.236 is uas.mcaa.gov.mn). body="/arcgis/rest/services" && host=".mn" (25) is mostly pages that embed the path; the unregistered services directory in that set is imagery.ubhub.mn, the same portal as arcgis.ubhub.mn. domain="ubhub.mn" lists the UBHUB vhosts. host="gis." && country="MN" (14) is login pages, a 502, and the education-ministry homepage. GET /arcgis/rest/services?f=json and /imagery/rest/services?f=json. Skip a second adaptor of the same owning system (imagery.ubhub.mn and portal.ubhub.mn repeat arcgis.ubhub.mn), a root whose only public service is SampleWorldCities (122.201.23.82), a directory that cannot reach its server machines (mapservice.ubhub.mn), and hosts that time out (arcgis.mykontor.mn, dms.ulaanbaatar.mn). Viewers on explore.mris.mn, publicgeomin.mris.mn, and beta.mris.mn use the already registered gismap.mris.mn server. uas.mcaa.gov.mn:6443 omits a TLS intermediate; the UTM folder still returns public map services.
On .om the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".om" returned 0 on 26 September 2026, and the body phrase alone with host=".om" or country="OM" was 1 (diam.mm.gov.om, titled ArcGIS Server REST API Login). The registry already had 5 .om ArcGIS servers (geoportal.mm.gov.om, gis.dg.gov.om, mzgisportal.mzec.co.om, ncsigeostatportal.ncsi.gov.om, nsaomangeoportal.gov.om). header="ArcGIS" && host=".om", port="6080" && title="ArcGIS" && host=".om", cert="arcgis" && host=".om", host="gisserver" && host=".om", host="gisportal" && host=".om", and title="Portal for ArcGIS" && host=".om" were 0. app="ArcGIS" is 820300. host=".om" is a substring (om.digital.jhhg.com); keep hosts whose name ends in .om. FOFA indexes the manager title ArcGIS, esri/admin.css, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".om" (6; drop Survey123), body="esri/admin.css" && host=".om" (4), port="6443" && title="ArcGIS" && host=".om" (2), and host="arcgis" && host=".om" (1, arcgis.cced.com.om). app="ESRI-ArcGIS" && country="OM" (8) and title="ArcGIS" && country="OM" (12) are those names plus bare IPs; use ip="..." for a .om vhost and do not register a bare IP (77.83.61.205 is edm.gov.om). body="/arcgis/rest/services" && host=".om" (12) is mostly pages that embed the path. body="/server/rest/services" && host=".om" was 1. Also probe host="gis." && host=".om" (19), host="geoportal" && host=".om" (2), and title="IIS Windows Server" on gis. / maps. / geoportal / arcgis hostnames (3). GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Madayn and Muscat Municipality publish under /server/rest/services). Skip a second adaptor of the same directory (diam.mm.gov.om repeats hayawater.mm.gov.om; gis.dg.gov.om:6443 repeats the registered Al Dakhiliyah server), token-only roots (geoportal.mohup.gov.om returns 401), test folders and SampleWorldCities (arc.csds.om:6443), suspended hosts (rindmall.info.fehm.om), and hosts that time out (arcgis.cced.com.om, gis.mm.gov.om, gis.opaz.gov.om, edm.gov.om:6443, gisportal.omangrid.com). gis.bgc.om is a Leaflet land-use dashboard, not a services directory.
On .rw the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".rw", the same phrase with country="RW", title="Folder: /" && host=".rw", and body="/server/rest/services" && host=".rw" each returned 0 in September 2026, while the registry already had 9 .rw ArcGIS servers. body="/arcgis/rest/services" && host=".rw" was 1 (portal.space.gov.rw on port 6443). app="ArcGIS" is 820300. cert="arcgis" && host=".rw" was 0. FOFA indexes the manager title ArcGIS, esri/admin.css, or the IIS welcome page, not /server/rest/services. Rwanda Enterprise sites publish under /server/rest/services (and sometimes /image/rest/services). Use title="ArcGIS" && host=".rw" (4, all portal.space.gov.rw; drop Data Store and Web Application), body="esri/admin.css" && host=".rw" (1), header="ArcGIS" && host=".rw" (2), host="gis." && host=".rw" (46), and host="arcgis" && host=".rw" (1, arcgis.rura.rw). Also probe title="IIS Windows Server" on gis. / geodata / geoportal / arcgis / masterplan hostnames. country="RW" && title="ArcGIS" (29) is mostly bare IPs on 6443/6080; use ip="..." for a .rw vhost and do not register a bare IP. port="6443" && country="RW" is not ArcGIS (FortiGate, GlobalProtect). body="arcgis" && host=".gov.rw" (24) includes KoboToolbox pages. host=".rw" is a substring (rw.china-embassy.gov.cn, .rws, .rwth); keep hosts whose name ends in .rw. GET /server/rest/services?f=json, /arcgis/rest/services?f=json, and /image/rest/services?f=json. Skip empty Hosted/Utilities roots, an image adaptor with no layers, test hosts (gis-vte), login walls, and a second hostname of geodata.rw.
On .cn the product-sentence query is thin: body="ArcGIS REST Services Directory" && host=".cn" returned 4 hosts in September 2026, while the registry already had 34 .cn ArcGIS servers. title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" && host=".cn", body="ArcGIS REST 服务目录" && host=".cn", and header="ArcGIS REST" && host=".cn" were 0. title="文件夹: /" && host=".cn" (352) is folder-encryption tools, movie sites, and stationery, not a services directory. cert="arcgis" && host=".cn" was 2. app="ArcGIS" is 820300. FOFA indexes the manager title ArcGIS (often on port 6080/6443) or esri/admin.css, not /arcgis/rest/services. Esri China ships the same server as GeoScene (/geoscene/rest/services or /server/rest/services). Use title="ArcGIS" && host=".cn" && title!="Hub" && title!="Experience" && title!="Blog" (273), body="esri/admin.css" && host=".cn" (234), port="6080" && title="ArcGIS" && host=".cn" (134), port="6443" && title="ArcGIS" && host=".cn" (34), title="GeoScene" && host=".cn" (22), and body="/geoscene/rest/services" && host=".cn" (10). host="arcgis." && host=".cn" (111) is mostly parked names that contain the product word. host=".cn" is a substring, so keep hosts whose name ends in .cn. Many vhosts on one IP return the same services JSON; keep one hostname. GET /arcgis/rest/services?f=json, /server/rest/services?f=json, and /geoscene/rest/services?f=json. Skip token error 499, dev/test/cpolar tunnels, Esri world-basemap proxies (Canvas / Ocean / Elevation), and roots whose only public folder is Utilities or Hosted. Several .gov.cn managers answer in FOFA and time out from outside China; do not add those until a live services directory responds.
On .uk the product-sentence query is thin: body="ArcGIS REST Services Directory" && host=".uk" matched 3 hosts in September 2026. Use title="ArcGIS" && host=".uk" for Enterprise home pages (drop ArcGIS Hub) and body="/arcgis/rest/services" && host=".uk" for web adaptors. The path query also matches pages that only embed services.arcgis.com; follow the REST host, do not register the referring site. port="6443" alone is not ArcGIS (Portainer, Kubernetes, IIS). Keep it only with title="ArcGIS".
On .fi the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".fi" and body="ArcGIS REST Services Directory" && country="FI" returned 0 in September 2026, and title="Folder: /" && host=".fi" returned 2 hosts that are not these servers. FOFA indexes the IIS welcome page or the manager title ArcGIS, not /arcgis/rest/services. Use title="ArcGIS" && host=".fi" and body="esri/admin.css" && host=".fi", then GET both /arcgis/rest/services?f=json and /server/rest/services?f=json. Also probe title="IIS Windows Server" on kartta / paikkatieto / rajapinta / aineisto / arcgis. hostnames: that is the web-adaptor default page. body="arcgis/rest/services" && host=".fi" (50) is pages that embed a service URL (services.arcgisonline.com, aineistot.esri.fi); register the REST host only when it is a public services directory. port="6443" && host=".fi" is not ArcGIS. Skip folder listings that return token error 499, test hosts, and roots whose only public folders are Hosted and Utilities.
On .se the product-sentence query is also thin: body="ArcGIS REST Services Directory" && host=".se" and the same phrase with title="Folder: /" each returned 1 host in September 2026, while the registry already had 24 .se ArcGIS servers. title="ArcGIS" && host=".se", body="esri/admin.css" && host=".se", and port="6443" && title="ArcGIS" && host=".se" were 1 each. app="ArcGIS" is 820300. title="ArcGIS REST Services Directory", body="/server/rest/services", and the GeoPublisher-style title query were 0. FOFA indexes the IIS welcome page on the web adaptor, not /arcgis/rest/services. Use title="IIS Windows Server" on karta / kartor / geodata / gis. / arcgis. hostnames (39), then host="geodata." && host=".se" (39) and host="geoportal." && host=".se" (5) for hosts whose title is not IIS. header="ArcGIS" && host=".se" (21) is mostly embeds, redirects, and token-required servers. body="/arcgis/rest/services" && host=".se" (69) is pages that mention the path. port="6443" && host=".se" (76) is not ArcGIS. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Kalmar uses /ags/rest/services). Skip token error 499, test hosts, geocode-only Gaida folders, and roots whose only public folders are Hosted and Utilities.
On .li the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".li", the body phrase alone with country="LI", title="Folder: /" && country="LI", title="Ordner: /" && country="LI", body="ArcGIS REST-Services-Verzeichnis" && country="LI", title="ArcGIS" with host=".li" or country="LI", body="esri/admin.css" with host=".li" or country="LI", header="ArcGIS" && country="LI", body="/arcgis/rest/services" with host=".li" or country="LI", body="/server/rest/services" && country="LI", body="servicesDirectory" && country="LI", cert="arcgis" && country="LI", and server="ArcGIS" && country="LI" each returned 0 on 26 September 2026. The registry had 0 .li ArcGIS servers. app="ArcGIS" is 820300. domain=".li" and domain="li" are 0: domain= is the registrable domain, not a TLD. Regex host~="\\.li$" is 820010 on this plan. host=".li" is a substring of .live, .link, .life, .limo, and of a li. label (li.maps.arcgis.com, li.ww7939.com, rt.li.webproxy...); keep hosts whose name ends in .li. country="LI" is IP geolocation (61326 hosts) and includes names that do not end in .li. header="ArcGIS" && host=".li" and host="arcgis" && host=".li" are only li.maps.arcgis.com (ArcGIS Online, portal access private). port="6443" && country="LI" (12) and port="6080" && country="LI" (2) are FortiGate, nginx, and bare IPs. port="6443" && host=".li" (8) names that end in .li (url.wuw.li, grc.tsp.li, web.lom.li, zhenmei.li, whoami.sb2.k8s.deadalus.li) do not answer as a services directory. body="arcgis" && host=".li" (5) and body="esri" && host=".li" (7) are a travel blog, personal sites, and that ArcGIS Online org. FOFA indexes the national geo hostnames, not /arcgis/rest/services. Use host="geo." && country="LI" (geo.llv.li, service.geo.llv.li, map.geo.llv.li, metadata.geo.llv.li, models.geo.llv.li), host="geodaten" && country="LI" (geodaten.llv.li), and domain="llv.li". host="geoportal" && host=".li", host="webgis" && host=".li", and host="gis." && host=".li" (one byu.edu name with .li. in the middle) have no .li GIS host. Municipal domain= queries for Vaduz, Schaan, Balzers, Triesen, Eschen, Mauren, Triesenberg, Ruggell, Gamprin, Schellenberg, Planken, LKW, and the university were 0. GET /arcgis/rest/services?f=json and /server/rest/services?f=json. geodaten.llv.li redirects to the already registered Geodatenportal, which links an Experience Builder app (experience.arcgis.com) whose layers are hosted feature services on services2.arcgis.com, not a .li server. map.geo.llv.li is GeoMapFish. metadata.geo.llv.li returns an empty 200. geo.llv.li is HTTP 503. map.feuer.li is 403. Skip li.maps.arcgis.com and landesverwaltung.maps.arcgis.com (private ArcGIS Online orgs) and do not treat the hosted services2.arcgis.com directory as a .li server.
On .sg the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".sg" returned 0 on 26 September 2026, while the registry already had 3 .sg ArcGIS servers (maps.ura.gov.sg, inactive shgis.nus.edu.sg, inactive trsuat.nparks.gov.sg). app="ArcGIS" is 820300. app="ESRI-ArcGIS" on .gov.sg / .edu.sg / .org.sg / .com.sg was 0. host=".sg" is a substring of a sg. label (sg.varashmtg.gov.ua on port 6443), of .sgc / .sgi / .sgm, and of .sg. inside other names (geo.sg.ch); keep hosts whose name ends in .sg. country="SG" is IP geolocation, not the TLD: title="ArcGIS" && country="SG" (99), header="ArcGIS" && country="SG" (2230), body="/arcgis/rest/services" && country="SG" (925), and port="6443" && title="ArcGIS" && country="SG" (33) are ArcGIS Online, marketing sites, and bare IPs. Do not use country="SG" for this TLD. FOFA indexes the public site, not /arcgis/rest/services: maps.ura.gov.sg is a 301 and shgis.nus.edu.sg is titled Singapore Historical GIS. The manager title, esri/admin.css, and an ArcGIS header on host=".gov.sg" / .edu.sg / .org.sg / .com.sg / .net.sg together returned 0. port="6443" or port="6080" on those suffixes (32) is SSL VPN and webmail. title="IIS Windows Server" on gis. / maps. / geo. / arcgis hostnames was 0; the same title on .gov.sg (13) is job and charity sites. host="gis." && host=".gov.sg" was 0. host="arcgis" && host=".sg" was 0. Use (host=".gov.sg" || host=".edu.sg" || host=".org.sg" || host=".com.sg" || host=".net.sg") && (host="gis." || host="maps." || host="arcgis" || host="geoportal" || host="geospatial") (37; drop mail, VPN, cPanel, and geo.com.sg). host="maps." on those suffixes (19) is maps.ura.gov.sg (already registered), maps.gov.sg (Cloudflare 403), maps.ntu.edu.sg (MazeMap), and maps.smu.edu.sg (Incapsula). body="arcgis/rest/services" && host=".com.sg" (172) is realtor pages that tile the already registered maps.ura.gov.sg directory, plus ahids.willowmore.com.sg tiling server.arcgisonline.com. The same body phrase on .gov.sg, .edu.sg, and .org.sg was 0. body=".gov.sg/arcgis/rest" was 0 even when the live page contains that URL, because the URL sits late in a large script. GET /arcgis/rest/services?f=json and /server/rest/services?f=json. Skip geospatial.sla.gov.sg (CloudFront 403), trsuat.nparks.gov.sg (maintenance; already inactive), libmaps.nus.edu.sg (historical-map viewer, no ArcGIS REST), and gis.a-star.edu.sg (VPN and web filter only).
On .fo the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".fo", the body phrase alone, title="Folder: /" && host=".fo", title="ArcGIS" && host=".fo", title="ArcGIS" && country="FO", body="esri/admin.css" && host=".fo", header="ArcGIS" && host=".fo", body="/server/rest/services" && host=".fo", cert="arcgis" && host=".fo", port="6443" && title="ArcGIS" && host=".fo", and app="ESRI-ArcGIS" && country="FO" each returned 0 on 26 September 2026, while the registry already had 5 .fo ArcGIS servers (agisportal.sev.fo, gis.lv.fo, gis.torshavn.fo, gis.us.fo, srv8.kort.fo). app="ArcGIS" is 820300. title="Faldari" && host=".fo" and title="Mappa: /" && host=".fo" were 0. host=".fo" is a substring (rdgate.fo.pace.edu, fo.egyptair.com, ci-habitat.prodestic.fr.fo); keep hosts whose name ends in .fo. FOFA indexes the IIS welcome page, not /arcgis/rest/services. Use host="arcgis" && host=".fo" (1, arcgis.net.fo, titled IIS Windows Server; the public directory is /server/rest/services), host="gis." && host=".fo" (8; drop gis.fan.fo), and body="arcgis" && host=".fo" (10; the services directories in that set are agisportal.sev.fo and srv8.kort.fo). body="/arcgis/rest/services" && host=".fo" (4) is MUNIN pages (www.kort.fo, srv2.kort.fo, www.hugin.fo) that embed the already registered srv8.kort.fo directory. host="kort." && host=".fo" (28) is those municipal MUNIN viewers. title="IIS Windows Server" && host=".fo" (61) is mostly names that only contain .fo in the middle, plus mail and RDS hosts; the GIS name in that set is arcgis.net.fo. host="gis.torshavn.fo" was 0 even though that server answers. port="6443" && country="FO" (3) and port="6080" && country="FO" (1) had no hostname ending in .fo. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (NET publishes under /server/rest/services). Skip a second adaptor of the same directory (gis02.us.fo repeats gis.us.fo), token-only Utilities folders, and MUNIN viewers whose layers come from srv8.kort.fo.
On .is the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".is", the body phrase alone, title="ArcGIS" && host=".is", and body="esri/admin.css" && host=".is" each returned 0 in September 2026, while the registry already had 7 .is ArcGIS servers. app="ArcGIS" is 820300. title="ArcGIS REST Services Directory" and cert="arcgis" were 0. host="arcgis" && host=".is" (8) is wildcard DNS (arcgis.com.gaur.is, www.arcgis.com.audkenndur.is), not servers. FOFA indexes the IIS welcome page, not /arcgis/rest/services. Use title="IIS Windows Server" on kort / gis. / arcgis / vefsja / luk hostnames (4), then host="kort." && host=".is" (42), host="gis." && host=".is" (35), and host="luk." && host=".is" (5). body="/arcgis/rest/services" && host=".is" (29) is pages that mention the path (Icelandic Volcanoes embeds luk.vedur.is). port="6443" && country="IS" (186) had no .is host. host=".is" also matches .is. inside other domains (luk.is.example.com); keep hosts whose name ends in .is. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (ÍSOR and Skipulagsvefsjá use /server/rest/services). Skip token error 499, broken “could not access any server machines” roots, and a second REST row for Skipulagsvefsjá (luk.skipulag.is and skipulagsvefsja.is are the same product).
On .lt the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".lt", the body phrase alone, title="ArcGIS REST Services Directory" && host=".lt", and the body phrase with country="LT" each returned 0 in September 2026, while the registry already had 46 .lt ArcGIS servers. title="Folder: /" && host=".lt" was 0. title="Aplankas: /" && host=".lt" (10) is folder-gluer vendors and bookshops; title="Katalogas: /" && host=".lt" (818) is the Lithuanian word for a catalog. host="zemelap" && host=".lt", cert="arcgis" && host=".lt", and port="6080" && title="ArcGIS" && host=".lt" were 0. app="ArcGIS" is 820300. FOFA indexes the manager title ArcGIS, esri/admin.css, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".lt" (7; drop ArcGIS Hub and ArcGIS Web Application), body="esri/admin.css" && host=".lt" (1), port="6443" && title="ArcGIS" && host=".lt" (1), header="ArcGIS" && host=".lt" (1), and host="arcgis" && host=".lt" (8). Also probe title="IIS Windows Server" on gis. / maps. / geoportal / arcgis hostnames (7), then host="gis." && host=".lt" (50) and host="geoportal." && host=".lt" (10). host="maps." && host=".lt" (142) is Yandex, real-estate sites, and cPanel; keep names that end in .lt and look like a GIS host. body="/arcgis/rest/services" && host=".lt" (27) is pages that embed the path. title="ArcGIS" && country="LT" (16) is mostly bare IPs on 6443/6080; reverse DNS is a hosting name (static.zebra.lt). Do not register a bare IP. host=".lt" also matches .lt. inside other names; keep hosts whose name ends in .lt. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (LTG and the LTSA Visi maršrutai server publish under /server/rest/services; IRD crime maps publish under /server/rest/services on maps.ird.lt). Skip token error 499 (gis.jonavosst.lt, gis.senergija.lt), test hosts (maps.eptptest.lt), a portal with no services directory (maps.eismoinfo.lt repeats eismoinfo.lt), and a second hostname of an existing directory (gis.zis.lt is ŽISIS). maps.vplanas.lt is a separate public root from gis.vplanas.lt: the open Open_Data folder lists municipal layers.
On .no the product-sentence query is thin: body="ArcGIS REST Services Directory" && host=".no" and title="Folder: /" && body="arcgis/rest/services" && host=".no" each returned 4 hosts in September 2026, while the registry already had about 18 .no ArcGIS servers. app="ArcGIS" is 820300. header="ArcGIS REST", body="/server/rest/services", title="ArcGIS" && host=".kommune.no", and body="arcgis" && host=".kommune.no" returned 0. FOFA indexes the IIS welcome page or the manager title ArcGIS, not /arcgis/rest/services. Use title="ArcGIS" && host=".no" (14) and body="esri/admin.css" && host=".no" (14), then host="arcgis" && host=".no" (22). Probe title="IIS Windows Server" on kart / gis. / arcgis hostnames, and host="kart." && host=".kommune.no" (13): several of those are Kommunekart or VertiGIS viewers already registered on the same host. body="/arcgis/rest/services" && host=".no" (112) and host="cloudgis.no" (64) are mostly embeds, Kubernetes 404s, and private-firm hosts. port="6443" && host=".no" (28) is not ArcGIS. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Allstad uses /server/rest/services). Skip token error 499, utv and test hosts, consultancy project folders, and roots whose only public folders are Hosted, Utilities, and SampleWorldCities.
On .org the product-sentence query is thin: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".org" returned 11 hosts in September 2026 (12 without the title), while the registry already had 444 .org ArcGIS servers. app="ArcGIS" is 820300. title="ArcGIS Server" and the GeoPublisher-style title query were 0. FOFA indexes the Enterprise home page, the manager, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".org" && title!="Hub" && title!="Experience" (134), body="esri/admin.css" && host=".org" (85), port="6443" && title="ArcGIS" && host=".org" (28; port 6080 with the same title was 10), header="ArcGIS REST" && host=".org" (24), and host="arcgis." && host=".org" (100). Also probe title="IIS Windows Server" on gis. / maps. / arcgis. / gisportal / gisserver hostnames (376): that is the web-adaptor default page. body="/arcgis/rest/services" && host=".org" (1864) is pages that embed a service URL. host=".org" also matches .org. inside other domains; keep hosts whose name ends in .org. GET /arcgis/rest/services?f=json and /server/rest/services?f=json. Skip token error 499, test and dev hosts, imagery-only or indoors-only roots, and a second hostname that repeats a services directory already registered.
On .ie the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".ie" returned 0 in September 2026, while the registry already had 18 .ie ArcGIS servers. title="Folder: /" && host=".ie" (2) is not these servers. port="6443" && title="ArcGIS" && host=".ie" was 0. FOFA indexes the manager title ArcGIS or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".ie" (12) and body="esri/admin.css" && host=".ie" (4), then body="/arcgis/rest/services" && host=".ie" (27, mostly pages that embed the path). Probe title="IIS Windows Server" on maps. / gis. / arcgis. hostnames, then host="maps." && host=".ie", host="gis." && host=".ie", host="webservices." && host=".ie", and host="gisserver" && host=".ie". host=".ie" also matches .ie. inside other names (gov.ie.maps.arcgis.com); keep hosts whose name ends in .ie. Enterprise portals may publish under /server1/rest/services or /image1/rest/services (Department of Agriculture); read helperServices on /portal/sharing/rest/portals/self?f=json. Skip token error 499, test and preprod hosts, SampleWorldCities-only roots, ArcGIS Hub and Experience Builder, and ArcGIS Monitor.
On .de the product-sentence query is thin: body="ArcGIS REST Services Directory" && host=".de" returned 3 rows in September 2026 (the same host twice, plus one unrelated page), while the registry already had 55 .de ArcGIS servers. title="Folder: /" paired with that body is the same host. title="ArcGIS REST Services Directory", body="ArcGIS REST-Services-Verzeichnis", and title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" were 0. app="ArcGIS" is 820300. German words Ordner and Verzeichnis are ordinary directory listings (title="Ordner: /" 246, title="Verzeichnis: /" 3128), not the services directory. FOFA indexes the Enterprise home page, the manager title ArcGIS, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".de" (20; drop Hub and the Esri blog), body="esri/admin.css" && host=".de" (11), port="6443" && title="ArcGIS" && host=".de" (8), and host="arcgis." && host=".de" (48). Also probe title="IIS Windows Server" on gis. / geoportal / geodaten / karten / arcgis / geodienste hostnames (35). body="/arcgis/rest/services" && host=".de" (1670) and host="geoportal." && host=".de" (636) are pages that mention a path or any geoportal. host=".de" also matches .de. inside other names; keep hosts whose name ends in .de. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Kreis Gütersloh, Landkreis Aurich, and Stadtwerke Tuttlingen publish under /server/rest/services; Hochschule Worms uses /arcgisserver/rest/services). Skip token error 499, test and staging hosts, consultancy project servers, and roots whose only public folders are Hosted and Utilities.
On .fr the product-sentence query is thin: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".fr" returned 1 host in September 2026, while the registry already had 47 .fr ArcGIS servers. Further FOFA paging stopped on F-point error 820031 (remain_api_data 0), so title="ArcGIS", body="esri/admin.css", and the IIS hostname query were not counted. French-language directories title the root Répertoire : / and label folders Répertoires (services.esrifrance.fr); many municipal servers still use the English Folder: / title and are missing from that one-host FOFA result. Use title="Répertoire : /" && host=".fr", title="ArcGIS" && host=".fr" (drop Hub and Experience), body="esri/admin.css" && host=".fr", and title="IIS Windows Server" on sig. / sig- / carto / portailsig / arcgis / geoportail hostnames. host=".fr" also matches .fr. inside other names; keep hosts whose name ends in .fr. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Aix-Marseille publishes a second public root at /webags/rest/services beside /webags2/rest/services). Skip token error 499, preprod and test hosts, and imagery roots whose public services are samples (Portland_ALL, SampleWorldCities).
On .es the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".es" and the same phrase with title="Folder: /" each returned 0 in September 2026, while the registry already had 19 .es ArcGIS servers. title="Folder: /" && host=".es" (10) is stationery shops. title="Carpeta: /" is a substring match on citizen folders (Carpeta Ciudadana, 62 hosts) and body="Carpetas:" is 3414. body="Directorio de servicios REST de ArcGIS" and body="Directori de serveis REST" were 0. FOFA indexes the Enterprise home title ArcGIS or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".es" && title!="Hub" && title!="Experience" (19), body="esri/admin.css" && host=".es" (14), host="arcgis." && host=".es" (4), and title="IIS Windows Server" on geoportal. / gis. / arcgis hostnames (8 hosts whose name ends in .es). Then host="geoportal." && host=".es" (60, mostly gvSIG and municipal viewers) and empty-titled sig. / gis. / ide. / mapas. hosts: GET /arcgis/rest/services?f=json and /server/rest/services?f=json. body="/arcgis/rest/services" && host=".es" (149) is pages that embed the ArcGIS JavaScript API, including hosts that do not end in .es (*.es.gov.br). host=".es" also matches .es. inside other names; keep hosts whose name ends in .es. port="6443" && title="ArcGIS" && host=".es" was 0. Skip token error 499, -pre and -pru hosts, consultancy multi-client roots, and roots whose only public folders are Hosted and Utilities. sig.mapa.gob.es, sig.mapama.gob.es, and sig.miteco.gob.es publish the same services directory. ide.coruna.es redirects to ide.coruna.gal.
On .cat the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".cat", the body phrase alone, and body="Directori de serveis REST" && host=".cat" each returned 0 in September 2026, while the registry already had 14 .cat ArcGIS servers. title="Carpeta: /" && host=".cat" (18) is Carpeta Ciutadana and other citizen folders. app="ArcGIS" is 820300. port="6443" && title="ArcGIS" && host=".cat", port="6080" && title="ArcGIS" && host=".cat", header="ArcGIS REST" && host=".cat", and body="/server/rest/services" && host=".cat" were 0. host="arcgis" && host=".cat" is arcgis.cat.com (Caterpillar), not this TLD. FOFA indexes the Enterprise home title ArcGIS, esri/admin.css, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".cat" (1), body="esri/admin.css" && host=".cat" (1, the same ACA manager), and host="agportal" && host=".cat" (4, including pre-production). Then host="sig." && host=".cat" (13), host="gis." && host=".cat" (26), host="geoportal" && host=".cat" (21), and host="mapes." && host=".cat" (16). title="IIS Windows Server" on sig. / gis. / mapes. / geoportal / arcgis / geoserveis / ide. hostnames was 4. body="/arcgis/rest/services" && host=".cat" (21 hosts whose name ends in .cat) is pages that embed services.arcgis.com or server.arcgisonline.com. host=".cat" also matches .cat. inside other names (arcgis.cat.com); keep hosts whose name ends in .cat. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (ACA, the Department of Territory, and Viladecans publish under /server/rest/services). Skip preproduccio and pre. hosts, token-only roots, Enmapa / MapServer / GeoServer viewers, and a second hostname of an existing directory (geoportal.tarragona.cat is mapes.tarragona.cat).
On .pl the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".pl" and the same phrase with country="PL" returned 0 in September 2026, while the registry already had 12 .pl ArcGIS servers. title="Folder: /" && host=".pl" (29) is print shops and the Polish word folder. title="Katalog: /" is 6007 generic directory titles. body="Katalog usług REST" and title="Serwer ArcGIS" were 0. app="ArcGIS" is 820300. FOFA indexes the manager title ArcGIS on port 6443/6080, often as a bare IP geolocated in Poland, not /arcgis/rest/services. Use title="ArcGIS" && country="PL" (28) and body="esri/admin.css" && country="PL" (16), then title="ArcGIS" && host=".pl" (8). Reverse DNS or the same-IP vhost (ip="...") supplies the .pl name (ecudo.mir.gdynia.pl for 153.19.105.98, gis.mpu.pl for 150.254.191.196). title="IIS Windows Server" on gis. / mapa / mapy. / geoportal / sip. / arcgis hostnames was 6; mapa.kartuzy.pl is the public services directory in that set. body="/arcgis/rest/services" && host=".pl" (549) is pages that embed the ArcGIS JavaScript API. body="currentVersion" && body="folders" (6) is not ArcGIS. host="gis." (260), host="geoportal." (257), host="mapy." (332), host="mapa." (1168), and host="sip." (756) are too broad to probe. Do not register a bare IP. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Łódź MPU publishes at /server/rest/services on port 443; port 6443 repeats it). Skip token error 499 (mapy.cugis.pl folder contents), license error 500 (geohist.umcs.pl), SampleWorldCities and test roots, Hosted-and-Utilities-only roots, and a second IP that repeats gis.muzeum-wilanow.pl.
On .pt the product-sentence query is thin: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".pt" and the body phrase alone each returned 2 hosts in September 2026 (inspire.lneg.pt already registered, plus servergeo.dgeg.gov.pt), while the registry already had 16 .pt ArcGIS servers. title="ArcGIS REST Services Directory" and title="ArcGIS Server" were 0. app="ArcGIS" is 820300. Portuguese title="Pasta: /" is restaurants and pasta shops (80); body="Diretório de Serviços REST" was 0. host="sig.cm-" returned 0 (the hyphen). FOFA indexes the IIS welcome page or the manager title ArcGIS, not /arcgis/rest/services. Use title="ArcGIS" && host=".pt" (13; drop Hub and Experience), body="esri/admin.css" && host=".pt" (5), host="arcgis" && host=".pt" (12), port="6443" && title="ArcGIS" && host=".pt" (1), and title="IIS Windows Server" on sig. / gis. / geoportal / mapas. / arcgis / ide. hostnames (23). body="/arcgis/rest/services" && host=".pt" (71) is mostly pages that embed the path; servergeo.dgeg.gov.pt is the services directory in that set. body="/server/rest/services" && host=".pt" was 2 and not these servers. host="geoportal." && host=".pt" (112) is mostly ScalarGIS, GeoNetwork, and other viewers. host=".pt" also matches .pt. inside other names; keep hosts whose name ends in .pt. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (DRAP Norte and LNEG publish under /server/rest/services). Skip token error 499, QA and license-error hosts, SampleWorldCities-only roots (Horta), Hosted-and-Utilities-only roots (Mora), and a second REST row on a host whose public catalog is already the Web AppBuilder viewer (Nisa, Fronteira, Penacova).
On .ch the product-sentence query is thin: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".ch" returned 6 rows in September 2026 (4 hosts: gis.cde.unibe.ch and map2.paerke.ch already registered, plus imagery.cde.unibe.ch and map.parcs.ch), while the registry already had 18 .ch ArcGIS servers. The body phrase without the title was the same 6. title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" && host=".ch", title="ArcGIS REST Services Directory", body="Répertoire des services REST" && host=".ch", and port="6080" && title="ArcGIS" && host=".ch" were 0. app="ArcGIS" is 820300. title="Répertoire : /" && host=".ch" (20) is the French word for a directory (music catalogs, the hail-protection register), not a services directory. FOFA indexes the manager title ArcGIS, esri/admin.css, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".ch" (11; drop Hub and Experience), body="esri/admin.css" && host=".ch" (11), and port="6443" && title="ArcGIS" && host=".ch" (4). Also probe title="IIS Windows Server" on gis. / map. / geo. / geoportal / arcgis / webgis hostnames (18). host="arcgis" && host=".ch" (10) and cert="arcgis" && host=".ch" (39) are mostly Astra JS-API hosts behind a BIG-IP logout page. body="/arcgis/rest/services" && host=".ch" (120) is pages that embed the path. host="map." && host=".ch" (601), host="gis." && host=".ch" (103), and host="geo." && host=".ch" (867) are too broad to probe. title="ArcGIS" && country="CH" (44) and port="6443" && title="ArcGIS" && country="CH" (18) are mostly bare IPs; do not register those. host=".ch" also matches .ch. inside other names (ch2.infomaniak.ch); keep hosts whose name ends in .ch. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (ZHAW LSFM, ETH Zurich, ECAB, and SwissMediaCast publish under /server/rest/services; CDE imagery uses /img/rest/services). Skip token error 499, QA and lab hosts (geoserviceqa.fr.ch, arcgis.sitg-lab.ch, arcgis-dev-web.ethz.ch), a second hostname of the same directory (wahgis01.ethz.ch repeats arcgis-prd-web.ethz.ch), SITG vector / raster / thematic hosts already stored as endpoints of sitggech, and consultancy multi-client roots (Cartovision, Geosistema, EW Lachen commune folders, Watergisweb AG project and sample folders).
On .dk the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".dk" and the same phrase with title="Folder: /" each returned 0 in September 2026, while the registry already had 24 .dk ArcGIS servers. body="ArcGIS REST Services Directory" && country="DK" (29) is EEA discomap hosts geolocated in Denmark, not .dk names. title="Mappe: /" && host=".dk" (14) is dk. labels on other sites (folder-gluer vendors), not a Danish services directory. app="ArcGIS" is 820300. title="ArcGIS REST Services Directory", cert="arcgis" && host=".dk", and port="6080" && title="ArcGIS" were 0. FOFA indexes the manager title ArcGIS, esri/admin.css, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".dk" (3) and body="esri/admin.css" && host=".dk" (2), then title="IIS Windows Server" on gis. / kort. / arcgis / webgis hostnames. host="gis." && host=".dk" (53), host="webgis" && host=".dk" (19), host="arcgis." && host=".dk" (7), and host="kort." && host=".dk" (112; 55 names ending in .dk) are the hostname net. body="/arcgis/rest/services" && host=".dk" (52) is mostly server.arcgisonline.com embeds. title="IIS Windows Server" && host=".dk" (3380) is every Danish IIS site. host=".dk" also matches .dk. and a leading dk. label; keep hosts whose name ends in .dk. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Evida publishes under /server/rest/services). Skip token error 499, 401 utility adaptors, test hosts, consultancy multi-client roots (Luva Consult), and cphunigis.ku.dk while its certificate is expired. gis.evida.dk is a second public root beside agis.evida.dk.
On .it the product-sentence query is thin: body="ArcGIS REST Services Directory" && host=".it" and the same phrase with title="Folder: /" each returned 3 hosts in September 2026, while the registry already had 27 .it ArcGIS servers. title="ArcGIS REST Services Directory", header="ArcGIS REST", body="/server/rest/services", and title=="Cartella: /" were 0. app="ArcGIS" is 820300. title="Cartella: /" (91) is the Italian word for a folder (Cartella Sociale), not a services directory. body="Directory dei servizi REST" was a blog. FOFA indexes the manager title ArcGIS, esri/admin.css, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".it" (15), body="esri/admin.css" && host=".it" (12), host="arcgis" && host=".it" (7), port="6443" && title="ArcGIS" && host=".it" (4), and title="IIS Windows Server" on sit. / gis. / geoportale / webgis / mappe. / arcgis / cartografia hostnames (22). body="esri" on those hostname fragments (42) finds servers whose home page is not the manager. host="ags." (42) is the company acronym AGS, not ArcGIS Server. host="servizigis" (155) is a municipal SaaS. body="/arcgis/rest/services" && host=".it" (287) is embed pages. host=".it" also matches .it. inside other names; keep hosts whose name ends in .it. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (ISTAT, the Abruzzo park, ARPA Sardegna, the Central Apennines authority, Perugia, Parma, and Naples publish under /server/rest/services; Iuav listens on port 6443; CNR-ISMAR Bologna on port 6080 over HTTP). Skip token error 499, Hosted-and-Utilities-only roots, and a second hostname that repeats the same directory (geoservizi2025.iuav.it).
On .ca the product-sentence query is thin: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".ca" and the body phrase alone each returned 7 hosts in September 2026, while the registry already had 198 .ca ArcGIS servers. title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" && host=".ca" was 0. app="ArcGIS" is 820300. title="Répertoire : /" && host=".ca" (186) is ordinary French directory listings; the same title with body="arcgis" was 0. FOFA indexes the Enterprise home page, the manager title ArcGIS, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".ca" && title!="Hub" && title!="Experience" (73), body="esri/admin.css" && host=".ca" (41), header="ArcGIS" && host=".ca" (49), host="arcgis." && host=".ca" (55), port="6443" && title="ArcGIS" && host=".ca" (11), and port="6080" && title="ArcGIS" && host=".ca" (2). Also probe title="IIS Windows Server" on gis. / maps. / arcgis. / geoportal / carte / cartes. hostnames (59). body="/server/rest/services" && host=".ca" was 4. host=".ca" also matches .ca. inside other names; keep hosts whose name ends in .ca. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (many municipal Enterprise sites publish under /server/rest/services; Woolwich listens on port 6443 and Lacombe Police on port 6080 over HTTP). Skip token error 499, dev and staging hosts, Esri esriservices.ca infrastructure, consultancy multi-client roots, machine names such as win-*.uwo.ca, and roots whose only public folders are Hosted and Utilities.
On .hr the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".hr", the body phrase alone, body="ArcGIS REST Services Directory" && country="HR", and title="Folder: /" && host=".hr" each returned 0 on 26 September 2026, while the registry already had 4 .hr ArcGIS servers (ags.ribarstvo.hr, arcportal.zagreb.hr, gisportal.pgz.hr, inspire.hakom.hr). title="Mapa: /" && host=".hr" (30) is solar-potential maps and shops, not a services directory. app="ArcGIS" is 820300. app="ESRI-ArcGIS" && host=".hr", title="Portal for ArcGIS" && host=".hr", body="esri/admin.css" && host=".hr", body="ArcGIS Enterprise" && host=".hr", cert="arcgis" && host=".hr", port="6443" && title="ArcGIS" && host=".hr", and port="6080" && title="ArcGIS" && host=".hr" were 0. host=".hr" is a substring (geo.hrsd.com, gisportal.hrsa.gov, and hr. labels on other sites); keep hosts whose name ends in .hr. FOFA indexes the IIS welcome page or a bare IP titled ArcGIS on port 6443, not /arcgis/rest/services. Use title="IIS Windows Server" && host="gis" && host=".hr" (13; the gis. prefix query is only part of that set), title="IIS Windows Server" on gis. / webgis / geoportal / arcgis / karte hostnames (15), host="webgis" && host=".hr" (6), host="arcportal" && host=".hr" (2, already registered arcportal.zagreb.hr), header="ArcGIS" && host=".hr" (1, webgis.hrsume.hr), and body="esri" on gis. / webgis / arcgis / geoportal hostnames (3). title="ArcGIS" && host=".hr" (1) is ArcGIS Data Store on arcgis.potres.hr:2443. app="ESRI-ArcGIS" && country="HR" and title="ArcGIS" && port="6443" && country="HR" are two bare IPs; ip="161.53.15.46" is arcgis.potres.hr / geo46.gfz.hr and ip="85.94.72.84" has no .hr name (PTR brac.toni-informatika.org). Do not register a bare IP. body="/arcgis/rest/services" && host=".hr" (7) is pages that embed the path (vidiplan.netcom.hr and vidiplanmobile.pgz.hr point at the already registered PGZ server). host="gis." && host=".hr" (275) and host="geoportal." && host=".hr" (27) are municipal viewers and catalogs already stored under other software. port="6443" && host=".hr" (68) and port="6080" && host=".hr" (46) are GitLab, Zimbra, and noVNC. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Zagreb, PGZ, and the Hydrocarbons Agency publish under /server/rest/services; Hrvatske šume publishes under /arcgis/rest/services). Skip token error 499 (gis.hcpi.hr, gis.plinara.hr), IIS welcome pages with no REST root (gis.viozz.hr, karte.presecki.hr, webgis.vodovod-labin.hr, hvarskivodovod-gis.hr), a second port of the same directory (gis.zagreb.hr:4433 repeats port 443), and hosts whose certificate is expired (arcgis.potres.hr, geo46.gfz.hr). gis.zagreb.hr is a separate public root from arcportal.zagreb.hr. gis-portal.pgz.hr is a separate public root from gisportal.pgz.hr.
On .gr the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".gr" and the same phrase with title="Folder: /" each returned 0 in September 2026, while the registry already had 22 .gr ArcGIS servers. title="Folder: /" && host=".gr" (3) is a keycard shop. app="ArcGIS" is 820300. cert="arcgis" && host=".gr" was 0. host="arcgis" && host=".gr" (5) is the already registered arcgis.geoapikonisis.gr web adaptor. FOFA indexes the manager title ArcGIS, esri/admin.css, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".gr" (11), body="esri/admin.css" && host=".gr" (8), port="6443" && title="ArcGIS" && host=".gr" (4), and port="6080" && title="ArcGIS" && host=".gr" (4). Also probe title="IIS Windows Server" on gis. / maps. / geoportal / arcgis / webgis hostnames (16), then host="geoportal." && host=".gr" (12) and host="webgis" && host=".gr" (16). body="/arcgis/rest/services" && host=".gr" (69) is pages that embed Esri basemaps. host="gis." && host=".gr" (214) and host="maps." && host=".gr" (109) are too broad to probe. host=".gr" also matches .gr. inside other names; keep hosts whose name ends in .gr. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (ELSTAT and the Region of Attica publish under /server/rest/services; MALWEST listens on port 6080 over HTTP). Skip token error 499, license error 500, Hosted-and-Utilities-only roots, expired certificates, and consultancy multi-client roots (Terra, Prudential). epidemiology.med.uth.gr, elearning.malwest.gr, and www.malwest.gr publish the same services directory.
On .bg the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".bg" and the same phrase with title="Folder: /" or country="BG" each returned 0 in September 2026, while the registry already had 13 .bg ArcGIS servers. title="Folder: /" && host=".bg" (1) is a Joomla error on bg.ac.rs. title="Папка: /" && host=".bg" (6) is stationery. app="ArcGIS" is 820300. body="/server/rest/services" && host=".bg", header="ArcGIS REST" && host=".bg", body="administrator has disabled the Services Directory" && host=".bg", js_name="arcgis.js" && host=".bg", and host="webgis" && host=".bg" were 0. host="geoportal" && host=".bg" (4) is Rila National Park redirects. FOFA indexes the manager title ArcGIS, esri/admin.css, the IIS welcome page, or a gis. hostname, not /arcgis/rest/services. Use title="ArcGIS" && host=".bg" (18; drop Hub, Experience, Web Application, Dashboards, and Web AppBuilder), body="esri/admin.css" && host=".bg" (4), port="6443" && title="ArcGIS" && host=".bg" (3), header="ArcGIS" && host=".bg" (9), host="arcgis" && host=".bg" (5), and title="IIS Windows Server" on gis. / maps. / geoportal / arcgis / webgis hostnames (3). Then probe host="gis." && host=".bg" (128; 39 names ending in .bg). body="/arcgis/rest/services" && host=".bg" (18) is pages that embed the path. title="ArcGIS" && country="BG" (37) and port="6443" && country="BG" (1181) are mostly bare IPs; do not register those. host=".bg" also matches .bg. inside other names (bg.gxly.cn, e-reading.sf.bg.ac.rs); keep hosts whose name ends in .bg. GET /arcgis/rest/services?f=json and /server/rest/services?f=json. Skip token error 499, HTTP 403, Hosted-and-Utilities-only roots, and a services directory that answers on port 6080 for every Host header on the same IP. gis.marad.bg is a public root. gis.mvr.bg lists folders and then requires a token.
On .za the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".za" and the same phrase with title="Folder: /" each returned 0 in September 2026, while the registry already had 21 .za ArcGIS servers. title="Folder: /" && host=".za" (2) is Tender Folder. title="ArcGIS REST Services Directory", header="ArcGIS REST", body="/server/rest/services", cert="arcgis" && host=".za", port="6080" && title="ArcGIS" && host=".za", and host="webgis" && host=".za" were 0. app="ArcGIS" is 820300. port="6443" && host=".za" (42) is PBX, FortiGate, and VPN portals; keep the port only with title="ArcGIS" (1). FOFA indexes the manager title ArcGIS, esri/admin.css, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".za" (4), body="esri/admin.css" && host=".za" (1), header="ArcGIS" && host=".za" (8), host="arcgis" && host=".za" (15), body="ArcGIS Enterprise" && host=".za" (2), and title="IIS Windows Server" on gis. / maps. / geoportal / arcgis / webgis / citymaps hostnames (23). Also probe host="gis." && host=".gov.za" (61), host="maps." && host=".gov.za" (9), host="gisportal" && host=".za" (18), host="citymaps" && host=".za" (4), and host="geoportal." && host=".za" (6). body="/arcgis/rest/services" && host=".za" (58) is pages that embed the path. title="ArcGIS" && country="ZA" (65) includes bare IPs and non-.za names; do not register those. host=".za" also matches .za. inside other names; keep hosts whose name ends in .za. GET /arcgis/rest/services?f=json, /server/rest/services?f=json, and /hosting/rest/services?f=json (Eastern Cape COGTA, Alfred Nzo, Free State Education, and Theewaterskloof publish under /server/rest/services; Gert Sibande, KZN Public Works, and uThukela publish under /hosting/rest/services). Skip token error 499, Hosted-and-Utilities-only roots, and a second REST row on a host whose public catalog is already the Enterprise portal or Web AppBuilder viewer (Ehlanzeni, Mahikeng). gis.overstrand.gov.za does not replace gisportal.overstrand.gov.za.
On .ng the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".ng", the body phrase alone, and the same phrase with country="NG" each returned 0 on 26 September 2026, and the registry had 0 .ng ArcGIS servers. title="ArcGIS REST Services Directory" && host=".ng", title="ArcGIS" && host=".ng", body="esri/admin.css" && host=".ng", body="esri/admin.css" && host=".gov.ng", header="ArcGIS REST" && country="NG", body="ArcGIS Enterprise" && country="NG", host="arcgis" && country="NG", host="arcgis" && host=".gov.ng", cert=".gov.ng" && title="ArcGIS", title="Portal for ArcGIS", body="/server/rest/services" && host=".gov.ng", port="6080" && title="ArcGIS" && country="NG", host="maps." && host=".gov.ng", host="geoportal" && host=".gov.ng", host="gis." && host=".mil.ng", and app="ArcGIS" (820300) were 0. host=".ng" is a substring of .ngo and of labels such as .ngrok; pair it with country="NG" or a real suffix (.gov.ng, .edu.ng, .org.ng, .com.ng, .mil.ng). title="ArcGIS" && country="NG" (8) and port="6443" && title="ArcGIS" && country="NG" (6) are bare IPs. FOFA stamps that title on every name that shares the IP, and several certificates are not .ng names (BEDC-GIS-SVR03.beninelectric.local, STARFIXSERVER / *.starfixgeo.com). app="ESRI-ArcGIS" && country="NG" (7) is that same IP set; app="ArcGIS" is not a rule. header="ArcGIS" && country="NG" (6) adds address.agis.fcta.gov.ng and port 7443 on the same addresses. cert="arcgis" && country="NG" (4) is a Gateway Service hostname plus bare IPs. FOFA indexes body="esri" on government hosts and host="gis." directories, not /arcgis/rest/services. Use body="esri" && host=".gov.ng" (13; drop Enketo, the registered Ogun GeoNode, and SE4ALL), host="gis." && host=".gov.ng" (72; mostly cPanel, webmail, and Yobe staff sites), and title="IIS Windows Server" && host=".gov.ng" (77; the postcode host’s live title is IIS, but FOFA stored an empty title on port 443). body="esri" on .edu.ng (1), .org.ng (3), and .com.ng (33) is college sites, Enketo, and property pages, plus a dead portal.geoai.com.ng. body="/arcgis/rest/services" && host=".gov.ng" (2) is an embed on pci.gov.ng. Keep a services directory only when a public folder lists thematic layers. Hosted and Utilities names alone are not a catalog when every folder returns token required.
On .mz the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".mz", the body phrase alone, title="ArcGIS" && host=".mz", title="ArcGIS" && country="MZ", body="esri/admin.css" with host=".mz" or country="MZ", header="ArcGIS" with either filter, app="ESRI-ArcGIS" with either filter, host="arcgis" && host=".mz", port="6443" && title="ArcGIS" with host=".mz" or country="MZ", port="6080" && title="ArcGIS" && country="MZ", body="ArcGIS Enterprise" && country="MZ", cert="arcgis" && country="MZ", and title="Folder: /" && host=".gov.mz" each returned 0 on 26 September 2026, while the registry already had 5 .mz ArcGIS servers. app="ArcGIS" is 820300. body="serverfederated" && host=".mz" and body="/image/rest/services" && host=".mz" were 0: MozGIS publishes those adaptors, and FOFA does not index the services-directory HTML. port="6443" && country="MZ" (47) and port="6080" && country="MZ" (48) are SoftEther, intranet logins, and Tomcat 404s. title="IIS Windows Server" && country="MZ" (368) is mostly bare IPs. Use title="IIS Windows Server" && host=".gov.mz" (8), host="gis." && host=".gov.mz" (1, gis.fnds.gov.mz), host="mozgis.gov.mz" (20), host="mireme.gov.mz", body="/arcgis/rest/services" && host=".gov.mz" (2), body="/server/rest/services" && host=".gov.mz" (2), body="MapServer" && host=".gov.mz" (2), body="esri" && host=".gov.mz" (7), and body="arcgis" && host=".mz" (15). body="webappviewer" && host=".mz" (7) is pages that embed maps.arcgis.com or Experience Builder (mrv.fnds.gov.mz). host=".mz" is a substring (gis.mz.xinzhidi.cn); keep hosts whose name ends in .mz. GET /server/rest/services?f=json and /arcgis/rest/services?f=json. mis.mireme.gov.mz (title Welcome on 443, IIS on 8443) publishes geological MapServer layers under /server/rest/services. Skip the ANE routing app on catalogo.mozgis.gov.mz and estradasdemocambique.mozgis.gov.mz (same IP; the page embeds a service URL and is not its own services directory), Enketo pages that mention esri, the ADE homepage (it links MozGIS and the registered GeoNetwork), and ArcGIS Online viewers.
On .tr the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".tr" and the same phrase with title="Folder: /" each returned 0 in September 2026, while the registry already had 17 .tr ArcGIS servers. title="Folder: /" && host=".tr" was 1 and not these servers. title="Klasör: /" && host=".tr" (26) is folder-gluer vendors and the Turkish word klasör. app="ArcGIS" is 820300. cert="arcgis" && host=".tr" was 0. FOFA indexes the manager title ArcGIS, esri/admin.css, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".tr" (9; drop the Esri Türkiye blog and ArcGIS Web Application shells), body="esri/admin.css" && host=".tr" (3), host="arcgis." && host=".tr" (8), header="ArcGIS" && host=".tr" (5), and port="6443" && title="ArcGIS" && host=".tr". Provincial special-administration servers often have an empty title; host="cbs." && host=".gov.tr" && (title="ArcGIS" || body="esri") (6) finds them. Also probe title="IIS Windows Server" on cbs. / gis. / harita / arcgis / geoportal / webgis / kentrehberi hostnames (54): many of those are Netcad KEOS or Netigma viewers already registered. body="/arcgis/rest/services" && host=".tr" (84) is pages that embed the path. host=".tr" also matches .tr. inside other names; keep hosts whose name ends in .tr. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Afyonkarahisar, Kadıköy, Nevşehir, Niğde, Rize, and Kahramanmaraş publish under /server/rest/services; Tunceli listens on port 6443; Isparta SUSKI on port 6080 over HTTP). Skip token error 499 (Gümüşhane folders), university lab roots that mix student projects and other cities (Alanya Alaaddin Keykubat), and roots whose only public folders are Hosted and Utilities.
On .at the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".at" and the same phrase with title="Folder: /" each returned 0 in September 2026, while the registry already had 10 .at ArcGIS servers. title="ArcGIS REST Services Directory", title="ArcGIS Server", host="arcgis." && host=".at", header="ArcGIS REST", body="/server/rest/services", body="ArcGIS REST-Services-Verzeichnis", cert="arcgis" && host=".at", and body="ArcGIS Enterprise" && host=".at" were 0. app="ArcGIS" is 820300. title="Folder: /" && host=".at" (3) is print shops. title="Ordner: /" && body="arcgis" && host=".at" was 0. FOFA indexes the manager title ArcGIS or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".at" (4), body="esri/admin.css" && host=".at" (3), port="6443" && title="ArcGIS" && host=".at" (1), host="gisenterprise" && host=".at" (1), host="gis." && host=".gv.at" (14), and host="geodaten." && host=".at" (7). Also probe title="IIS Windows Server" on gis. / geodaten. / geoportal / maps. / gisenterprise / webgis hostnames. title="IIS Windows Server" && host=".gv.at" (56) is mostly schools and mail. body="/arcgis/rest/services" && host=".at" (56) is pages that embed the path. body="currentVersion" && body="folders" && host=".at" (10) is hotel booking pages. host="webgis" && host=".at" (18) and host="geoportal." && host=".at" (22) are WebOffice, Lizmap, and other viewers. title="ArcGIS" && country="AT" (9) includes bare IPs; do not register those. host=".at" also matches .at. inside other names; keep hosts whose name ends in .at. host="gis." && host=".gv.at" missed gis.ktn.gv.at, which is already registered as a STAC catalog and also publishes /arcgis/rest/services. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (the older Burgenland adaptor is /gisbgld/rest/services; GeoSphere uses /maps/rest/services). Skip HTTP 418, license error 500 (ispacevm23.researchstudio.at), unreachable machine names (a772-cvl-sv08.biodiversity.biodiv.univie.ac.at), and a second hostname of an existing directory. gisenterprise.bgld.gv.at is a separate public root from gis.bgld.gv.at: the open public folder includes the zoning map, while several other folders return token error 499.
On .au the product-sentence query is thin: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".au" returned 45 hosts in September 2026, many of them uat-spatial-*.information.qld.gov.au, while the registry already had 40 .au ArcGIS servers. title="ArcGIS REST Services Directory" and title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" && host=".au" were 0. app="ArcGIS" is 820300. port="6080" && title="ArcGIS" && host=".au" was 0 and port="6443" && title="ArcGIS" && host=".au" was 1. body="/server/rest/services" && host=".au" was 6 and cert="arcgis" && host=".au" was 7. FOFA indexes the manager title ArcGIS, esri/admin.css, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".au" (126; drop Hub, Experience, and Web Application), body="esri/admin.css" && host=".au" (87), header="ArcGIS" && host=".au" (84), host="arcgis." && host=".au" (56), and title="IIS Windows Server" on gis. / maps. / arcgis. / spatial / geoportal / mapping. hostnames (38). header="ArcGIS REST" && host=".au" (57) overlaps the services-directory set. host=".au" also matches .au. inside other names; keep hosts whose name ends in .au. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (City of Adelaide, Tweed Shire, UNSW, and the WA Department of Transport publish under /server/rest/services). Skip uat, test, dev, and stg hosts, token error 499, Hosted-and-Utilities-only roots, consultancy multi-client roots (RPS Group), and a second hostname of an existing directory (public-services.slip.wa.gov.au, featureservices.thelist.tas.gov.au, www.data4.actmapi.act.gov.au). mapprod4.environment.nsw.gov.au is a separate public root from mapprod1–mapprod3. image.wsapi.cloud.bom.gov.au publishes AWRA image services; hosting.wsapi.cloud.bom.gov.au is the already registered geofabric and flood catalog.
On .nz the product-sentence query is thin: body="ArcGIS REST Services Directory" && host=".nz" returned 6 hosts in September 2026 (gis.wcc.govt.nz, gis.gns.cri.nz, gisext.wcc.govt.nz, and three Eagle GIS project hosts), while the registry already had 57 .nz ArcGIS servers. title="Folder: /" && host=".nz" (12) adds stationery and a Joomla error. header="ArcGIS REST" && host=".nz" and port="6080" && title="ArcGIS" && host=".nz" were 0. app="ArcGIS" is 820300. FOFA indexes the manager title ArcGIS, esri/admin.css, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".nz" (11; drop Hub, Experience, Web Application, and ArcGIS Monitor), body="esri/admin.css" && host=".nz" (3 hosts), port="6443" && title="ArcGIS" && host=".nz" (1), and host="arcgis." && host=".nz" (2). Also probe title="IIS Windows Server" on gis. / maps. / mapping. / arcgis / geoportal hostnames (18 names ending in .nz), then host="gis." && host=".govt.nz" (20), host="maps." && host=".govt.nz" (30), host="spatial." && host=".nz" (12), and host="geo." && host=".govt.nz" (1). body="/server/rest/services" && host=".nz" was 1 (gis.gns.cri.nz). body="/arcgis/rest/services" && host=".govt.nz" (11) is mostly pages that mention the path. host="eaglegis.co.nz" (22) is hosting, sandboxes, and named project servers. host=".nz" also matches .nz. inside other names; keep hosts whose name ends in .nz. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (NZPAM, New Plymouth, Invercargill, Kāpiti Coast, Herenga ā Nuku, and the Otago spatial host publish under /server/rest/services; Upper Hutt publishes under /arcgis/rest/services). A LocalMaps gallery on the same host stays localmaps; the public services directory is a separate arcgisserver record. Skip token error 499, Hosted-and-Utilities-only roots, SampleWorldCities-only roots, course folders (gis.lincoln.ac.nz), Eagle GIS ncr* project servers, and atlas.npdc.govt.nz while it 404s (geo.npdc.govt.nz is the live directory). spatial.orc.govt.nz is a separate public root from maps.orc.govt.nz.
On .my the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".my", the body phrase alone, title="ArcGIS REST Services Directory" && host=".my", and body="ArcGIS REST Services Directory" && country="MY" each returned 0 in September 2026, while the registry already had 24 .my ArcGIS servers. title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" && host=".my" was 0. title="Folder: /" && host=".my" (30) is ordinary directory listings. app="ArcGIS" is 820300. header="ArcGIS REST" && host=".my", cert="arcgis" && host=".my", title="ArcGIS Server", and title="Portal for ArcGIS" && host=".my" were 0. FOFA indexes the manager title ArcGIS, esri/admin.css, ArcGIS Enterprise, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".my" (8; drop ArcGIS Data Store and Survey123 login), body="esri/admin.css" && host=".my" (4), body="ArcGIS Enterprise" && host=".my" (11), header="ArcGIS" && host=".my" (9), host="arcgis" && host=".my" (6), port="6443" && title="ArcGIS" && host=".my" (3), and port="6080" && title="ArcGIS" && host=".my" (1). Also probe title="IIS Windows Server" on gis. / maps. / arcgis / geoportal / webgis / spatial hostnames (10), then host="gis." && host=".gov.my" (48) and host="geoportal." && host=".my" (26): a 403 or IIS homepage can still publish /server/rest/services. body="/arcgis/rest/services" && host=".my" (123) and body="/server/rest/services" && host=".my" (2) are mostly pages that mention the path. port="6443" && host=".my" (240) is not ArcGIS. title="ArcGIS" && country="MY" (50) includes bare IPs and hosts that do not end in .my; do not register those. host=".my" also matches .my. inside other names (myokaloosa.com); keep hosts whose name ends in .my. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Klang, Pahang, Perak MyGDI, NAHRIM, and Lembaga Getah Malaysia publish under /server/rest/services; Penang SMARTPLAN listens on port 6443). MBPP public maps use /vipserver/rest/services, which FOFA does not title as ArcGIS; follow a services URL cited by a related public app. Skip token error 499 (emap.jln.gov.my, gis.i-aksb.com.my), Hosted-Test-Utilities-only roots (arcgis.utem.edu.my), ArcGIS Data Store on port 2443, Survey123 login (spms.cidb.gov.my), and unreachable hosts (geoportal.planmalaysia.gov.my, gis.tnt.sarawak.gov.my, webgis.ppj.gov.my). gis.mbdk.gov.my repeats gis.mpklang.gov.my (same IP). mygdispatial.perak.gov.my:6443/arcgis/rest/services repeats /server/rest/services. The JPSM portal at gisportal.forestry.gov.my points its helper services at the already registered geoformatik.forestry.gov.my.
On .in the product-sentence query is thin: body="ArcGIS REST Services Directory" && host=".in" returned 3 hosts in September 2026 (two already registered, plus bharatmapsparivesh.parivesh.nic.in, whose /parivesh_bharatmaps/rest/services directory is disabled), while the registry already had 32 .in ArcGIS servers. title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" && host=".in", title="ArcGIS REST Services Directory", title="ArcGIS" && host=".nic.in", and port="6080" && title="ArcGIS" && host=".in" were 0. app="ArcGIS" is 820300. FOFA indexes the manager title ArcGIS, esri/admin.css, the ArcGIS response header, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".in" (13; drop Hub, Experience, Data Store, and Web Application), body="esri/admin.css" && host=".in" (4), header="ArcGIS" && host=".in" (5), port="6443" && title="ArcGIS" && host=".in" (4), and host="arcgis." && host=".in" (3). Also probe title="IIS Windows Server" on gis. / maps. / geoportal / arcgis / webgis hostnames (8). body="/arcgis/rest/services" && host=".gov.in" (14) and body="/server/rest/services" && host=".gov.in" (1) are pages that embed server.arcgisonline.com. title="ArcGIS" && country="IN" (94) and port="6443" && title="ArcGIS" && country="IN" (48) are mostly bare IPs; do not register those. host="gis." && host=".gov.in" (55) is Bhunaksha, Apache defaults, and other viewers. host=".in" also matches .in. inside other names (in.gov, astra.admin.ch); keep hosts whose name ends in .in. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Lucknow Development Authority, Varanasi Nagar Nigam, Orange City Water, NIH Roorkee, and Uttarakhand stamps publish under /server/rest/services; Forest Survey of India listens on port 6080 over HTTP). Skip token error 499, Hosted-and-Utilities-only roots, self-signed machine names (owdapp05.orams.in), ArcGIS Data Store, dev hosts, contractor package roots (gis.jwil.in), and a disabled services directory.
On .sa the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".sa" and the same phrase with country="SA" returned 0 in September 2026, while the registry already had 13 .sa ArcGIS servers. title="Folder: /" && body="arcgis/rest/services" && host=".sa" was 0. title="مجلد: /" && host=".sa" (4) is greeting-card generators. body="خدمات REST" and body="/server/rest/services" && host=".sa" were 0. app="ArcGIS" is 820300. title="ArcGIS" && host=".sa" (11) is mostly the already registered gis2.qassim.gov.sa:6443. port="6443" && host=".sa" (39) is ticketing and appliance consoles; keep the port only with title="ArcGIS" (1). title="ArcGIS" && country="SA" (23) is mostly bare IPs. FOFA indexes the IIS welcome page, not /arcgis/rest/services. Use host="gis." && host=".sa" (109; drop gis.sch.sa school hosts and gis.edu.sa) and host="gis." && host=".gov.sa" (8), then title="IIS Windows Server" on gis. / maps. / geoportal / arcgis hostnames (24) and host="geospatial." && host=".sa" (3). body="/arcgis/rest/services" && host=".sa" (23) is embeds and names that only contain .sa. (sa.gov.au). host=".sa" also matches .sa. inside other names; keep hosts whose name ends in .sa. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (King Abdulaziz Royal Reserve, King Salman Royal Natural Reserve, Taadeen, KAUST, Al-Ahsa, and the Ministry of Education publish under /server/rest/services). Skip token error 499, HTTP 401 (gis.sda.gov.sa), Hosted-and-Utilities-only roots (gis.salam.sa, Chronicle Heritage), a single site-visit map (gis.ardara.sa), and geospatial.gslb.rcu.gov.sa which repeats geospatial.rcu.gov.sa. AlUla thematic folders on geospatial.rcu.gov.sa return token error 499; the public remainder is a basemap and one internal map. Do not register a bare IP.
On .pk the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".pk" and the body phrase alone each returned 0 in September 2026, while the registry already had 3 .pk ArcGIS servers. title="Folder: /" && host=".pk" (3) is APK download shops. title="ArcGIS REST Services Directory", body="/server/rest/services" && host=".pk", cert="arcgis" && host=".pk", host="arcgis" && host=".pk", port="6080" && title="ArcGIS" && host=".pk", and title="ArcGIS" && host=".edu.pk" were 0. app="ArcGIS" is 820300. FOFA indexes the manager title ArcGIS or esri/admin.css, not /arcgis/rest/services. Use title="ArcGIS" && host=".pk" (7) and body="esri/admin.css" && host=".pk" (7, the same hosts), port="6443" && title="ArcGIS" && host=".pk" (4), and header="ArcGIS" && host=".pk" (7), which also finds empty-titled servers on port 6443. title="ArcGIS" && country="PK" (44) is mostly bare IPs whose reverse DNS is an ISP name; do not register those. port="6443" && host=".pk" (26) without the ArcGIS title is Jazz, Daraz, and other non-GIS hosts. body="/arcgis/rest/services" && host=".pk" (15) is pages that embed the path. header="ArcGIS REST" && host=".pk" (2) is the Punjab Land Records Authority website. title="IIS Windows Server" on gis. / gismaps / geoportal / maps. / arcgis hostnames was 1 (gis.mineral.gov.pk, the IIS welcome page). host="gis." && host=".pk" (32) and host="maps." && host=".pk" (57) are schools, companies, and other viewers. host=".pk" also matches .pk. inside other names; keep hosts whose name ends in .pk. GET /arcgis/rest/services?f=json. Skip token error 499 (giss1.mineral.gov.pk), SampleWorldCities-only roots with empty folders (gismaps.punjab-zameen.gov.pk), hosts that do not resolve (gismaps.pulse.gop.pk, arcsrv.pulse.gop.pk), and connect timeouts (emsgis.fesco.com.pk). wris.bwrdsp.gob.pk and ems.iesco.com.pk publish public map services on port 6443; their TLS chains omit an intermediate.
On .eg the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".eg" and the same phrase with title="Folder: /" each returned 0 in September 2026, while the registry already had 7 .eg ArcGIS servers. title="Folder: /" && host=".eg", body="esri/admin.css" && host=".eg", header="ArcGIS" && host=".eg", header="ArcGIS REST" && host=".eg", body="/arcgis/rest/services" && host=".eg", body="/server/rest/services" && host=".eg", host="arcgis" && host=".eg", cert="arcgis" && host=".eg", port="6443" && title="ArcGIS" && host=".eg", port="6080" && title="ArcGIS" && host=".eg", and title="مجلد: /" && host=".eg" were 0. app="ArcGIS" is 820300. port="6443" && host=".eg" (2) matches names that only contain .eg. (eg.bbs.lmjx.net, eg.china-embassy.gov.cn). FOFA indexes the IIS welcome page or the Enterprise title, not /arcgis/rest/services. Use title="ArcGIS" && host=".eg" (1, portal.kfs.gov.eg) and body="ArcGIS Enterprise" && host=".eg" (the same host), then title="IIS Windows Server" on gis. / maps. / geoportal / arcgis hostnames (9) and host="gis." && host=".eg" (14; drop Amazon job hosts and DNS-only names). Also probe host="gis." && host=".gov.eg" (10), host="geoportal." && host=".eg" (7), and host="maps." && host=".eg" (7). title="البوابة الجغرافية" && host=".eg" (2) is the already registered Aswan portal. title="ArcGIS" && country="EG" (7) and body="esri/admin.css" && country="EG" (3) are that portal plus bare IPs (196.221.208.107, 41.33.82.254); do not register those. title="IIS Windows Server" && host=".edu.eg" (185) is student-information systems. host=".eg" also matches .eg. inside other names; keep hosts whose name ends in .eg. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (the Ministry of Civil Aviation publishes under /arcgis/rest/services; Aswan, Kafr El-Sheikh, South Sinai, and the Ministry of Water Resources publish under /server/rest/services). Skip Hosted-and-Utilities-only roots (gis.nwrc.gov.eg), hosts that do not answer (gis.minya.gov.eg, geoportal.capmas.gov.eg, map.sharek.gov.eg, gis.mans.edu.eg), a blocked school portal (geoportal.emis.gov.eg), and a second hostname of an existing directory (www.gis.southsinai.gov.eg). The Mansoura gis.mans.edu.eg title in FOFA is a surveying-program page.
On .ae the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".ae" and the same phrase with title="Folder: /" or country="AE" each returned 0 in September 2026, while the registry already had 15 .ae ArcGIS servers. title="ArcGIS" && host=".ae", body="esri/admin.css" && host=".ae", title="ArcGIS REST Services Directory", header="ArcGIS REST", body="/server/rest/services" && host=".ae", cert="arcgis" && host=".ae", and port="6443" && title="ArcGIS" && host=".ae" were 0. app="ArcGIS" is 820300. title="Folder: /" && host=".ae" (1) is an Android theme page. FOFA indexes an ArcGIS response header or the IIS welcome page, not /arcgis/rest/services. Use header="ArcGIS" && host=".ae" (5; already registered), host="arcgis" && host=".ae" (1), body="esri" on gis. / maps. / geoportal / arcgis hostnames (6), and title="IIS Windows Server" on those hostnames (1, gis.aam.gov.ae). Also probe host="gis." && host=".ae" (24), host="gis." && host=".gov.ae" (14), host="maps." && host=".ae" (32), and host="geoportal." && host=".ae" (8). title="ArcGIS" && country="AE" (6) is bare IPs and mapstags.com. body="/arcgis/rest/services" && host=".ae" (12) is pages that embed the path. port="6443" && host=".ae" (29) is not ArcGIS. host=".ae" also matches .ae. inside other names (ae.maps.me); keep hosts whose name ends in .ae. GET /arcgis/rest/services?f=json, /server/rest/services?f=json, and /gishosting/rest/services?f=json (Abu Dhabi Ports publishes under /gishosting/rest/services). Skip token error 499 (ADREC, Abu Dhabi Ports, and Emarat), geocode-only remainders (Bayanat), and a second hostname of an existing directory. maps.drm.gov.ae is a separate public root from geoportal.drm.gov.ae, which publishes under /arcgis/rest/services.
On .iq the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".iq", the body phrase alone, and the same phrase with country="IQ" each returned 0 in September 2026, while the registry had 0 .iq ArcGIS servers. title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" && host=".iq", title="ArcGIS" && host=".iq", body="esri/admin.css" && host=".iq", body="ArcGIS Enterprise" && host=".iq", body="ArcGIS Enterprise" && country="IQ", title="ArcGIS Server", title="Portal for ArcGIS" && country="IQ", title="مجلد: /" && host=".iq", title="البوابة الجغرافية" && host=".iq", cert="arcgis" && host=".iq", body="/arcgis/rest/services" && host=".iq", body="/server/rest/services" && host=".iq", body="esri-global-nav" && host=".iq", body="webappviewer" && host=".iq", body="jimu-core" && host=".iq", body="MapServer" && host=".gov.iq", body="FeatureServer" && host=".iq", host="geoportal" && host=".iq", host="webgis" && host=".iq", host="spatial" && host=".iq", host="geodata" && host=".iq", host="gisportal", host="gisserver" && host=".iq", port="6443" && title="ArcGIS" && host=".iq", port="6080" && title="ArcGIS" && host=".iq", port="6080" && title="ArcGIS" && country="IQ", title="Folder: /" && country="IQ", and cert="gov.iq" && port="6443" were 0. app="ArcGIS" is 820300. FOFA indexes the IIS welcome page, not /arcgis/rest/services. Use host="arcgis" && host=".iq" (2, arcgis.moh.gov.iq), host="gis." && host=".iq" (4; drop gis.iq.wiki), host="gis." && host=".gov.iq" (2, the same ITPC host), and title="IIS Windows Server" on gis. / maps. / geoportal / arcgis hostnames (4 rows, those two hosts). title="ArcGIS" && country="IQ" (5), body="esri/admin.css" && country="IQ" (2), and port="6443" && title="ArcGIS" && country="IQ" (2) are bare IPs; ip="109.205.112.26" is mopgis.mnpcd.com, not a .iq name. Do not register a bare IP. header="ArcGIS" && host=".iq" and header="ArcGIS REST" && host=".iq" (2) are ur.gov.iq, whose live response has no ArcGIS header. body="arcgis" && host=".iq" (12) is university journals and iq.imsma.org. body="esri" && host=".gov.iq" was 0; body="esri" && country="IQ" && host=".iq" (1) is tas-heel.post.iq on the same address as gis.itpc.gov.iq. host="maps." && host=".iq" (9) and host="map." && host=".iq" (22) are Google, Cloudflare mail, and an advertising site (map.basra.gov.iq). host=".iq" && port="6443" (2) is phycomine.iq.usp.br and iq.zskhlxs.com. host=".iq" also matches .iq. inside other names; keep hosts whose name ends in .iq. title="IIS Windows Server" && host=".gov.iq" (15) is mostly non-GIS IIS sites. GET /arcgis/rest/services?f=json and /server/rest/services?f=json. Both live .iq roots publish under /server/rest/services and list only Hosted and Utilities. Skip token error 499 (arcgis.moh.gov.iq Hosted), and the ITPC root whose only public services are two Survey123 feature services in Hosted.
On .mx the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".mx" and the body phrase alone each returned 0 in September 2026, while the registry already had 12 .mx ArcGIS servers. title="Folder: /" && host=".mx" (4) is a stationery shop. title="Carpeta: /" && host=".mx" (13) is Carpeta Ciudadana and other citizen folders. body="Directorio de servicios REST de ArcGIS" && host=".mx" was 0. app="ArcGIS" is 820300. FOFA indexes the manager title ArcGIS on port 6443/6080 or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".mx" (6; drop ArcGIS Web Application), body="esri/admin.css" && host=".mx" (4, the same CENAPRED managers), port="6443" && title="ArcGIS" && host=".mx" (1), and port="6080" && title="ArcGIS" && host=".mx" (3). title="ArcGIS" && country="MX" (55) is mostly bare IPs; reverse DNS is an ISP name (uninet-ide.com.mx, prod-infinitum.com.mx). A same-IP vhost supplies the .mx name when one exists (maya.cenapred.unam.mx, ssvud.tulancingo.gob.mx). Do not register a bare IP, and do not register a certificate name that is not .mx (*.proyectossop.com). Also probe title="IIS Windows Server" on gis. / sig. / mapas. / geoportal / arcgis hostnames (3). body="/arcgis/rest/services" && host=".mx" (55) is pages that embed the path. host="arcgis" && host=".mx" (4) is vendor DNS and a private SunVizion host. port="6443" && host=".mx" (123) is not ArcGIS. host="sig." && host=".gob.mx" (23) and host="mapas." && host=".mx" (97) are mostly other viewers. host=".mx" also matches .mx. inside other names; keep hosts whose name ends in .mx. GET /arcgis/rest/services?f=json, /ArcGIS/rest/services?f=json, and /server/rest/services?f=json (Morelos and CENAPRED RM-GIR publish under /server/rest/services; servicios2.cenapred.unam.mx listens on port 6080 over HTTP). Skip token error 499, license error 500, SampleWorldCities-only roots, consultancy multi-client roots, hosts that no longer resolve (mapa.catastro.michoacan.gob.mx, sig.ensenada.gob.mx), and a second hostname of the same directory (rmgir.proyectomesoamerica.org repeats maya.cenapred.unam.mx).
On .co the product-sentence query is thin: body="ArcGIS REST Services Directory" && host=".co" returned 7 hosts in September 2026, while the registry already had 26 .co ArcGIS servers. host=".co" is a substring of .com, .co.uk, .co.ke, .co.nz, and .co.th. body="Directorio de servicios REST" && host=".gov.co" was 0. title="Carpeta: /" && host=".gov.co" (3) is Carpeta Ciudadana. app="ArcGIS" is 820300. header="ArcGIS REST" && host=".gov.co" was 0. FOFA indexes the manager title ArcGIS, esri/admin.css, the ArcGIS response header, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".gov.co" (14), body="esri/admin.css" && host=".gov.co" (6), header="ArcGIS" && host=".gov.co" (14), port="6443" && title="ArcGIS" && host=".gov.co" (4), and port="6080" && title="ArcGIS" && host=".gov.co" (1). title="ArcGIS" && host=".co" && host!=".com" && host!=".co.uk" still needs the other country-code second levels dropped, then keep hosts whose name ends in .co. Also probe title="IIS Windows Server" on gis. / sig. / mapas. / geoportal / arcgis / geovisor / ide. hostnames (19), then host="sig." && host=".gov.co" (45), host="mapas." && host=".gov.co" (23), host="geoportal." && host=".gov.co" (31), host="gis." && host=".gov.co" (18), host="geovisor" && host=".gov.co" (11), and host="ide." && host=".gov.co" (5). title="ArcGIS" && country="CO" (60) and port="6443" && title="ArcGIS" && country="CO" (28) are mostly bare IPs whose reverse DNS is an ISP name (tigo.com.co, une.net.co, etb.net.co). Do not register a bare IP. host=".co" also matches .co. inside other names; keep hosts whose name ends in .co. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (the Cundinamarca cadastral agency, Cúcuta, San Andrés, SDIS, the comptroller, Norte de Santander, and Fondo Adaptación publish under /server/rest/services; the Bucaramanga metropolitan area listens on port 6080 over HTTP). Skip token error 499, license error 500 (arcgis.ccb.org.co), Hosted-and-Utilities-only roots (geoportal.ane.gov.co), ArcGIS Data Store, pruebas hosts, Carpeta Ciudadana, and a single untitled image service (imagenes.parquesnacionales.gov.co EarthScanner; the map catalog is already mapas.parquesnacionales.gov.co). mapas.ambientebogota.gov.co is a separate public root from secretariadeambiente.gov.co.
On .il the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".il" and the same phrase limited to Israeli second-level domains (.gov.il, .co.il, .org.il, .ac.il, .muni.il, .net.il, .idf.il) each returned 0 in September 2026, while the registry already had 37 .il ArcGIS servers. body="ArcGIS REST Services Directory" && country="IL" (7) is USGS nationalmap.gov hosts, not .il names. host=".il" is a substring of .il.us, so it returns Illinois (gis.berkeley.il.us, maps.springfield.il.us, geoevent.ci.pekin.il.us). app="ArcGIS" is 820300. title="ArcGIS" && host=".il" (3) is arcgis.dev.idf.il (does not resolve) plus Illinois. title="ArcGIS" on .gov.il / .co.il / .org.il / .ac.il / .muni.il / .net.il / .idf.il / .k12.il was 0. body="esri/admin.css", header="ArcGIS", header="ArcGIS REST", title="Portal for ArcGIS", title="תיקייה: /", and cert="arcgis" on those second-level domains were 0. title="Folder: /" && host=".il" was 0. FOFA indexes the IIS welcome page or an empty-titled web adaptor, not /arcgis/rest/services. Use title="IIS Windows Server" && host="gis" on .gov.il / .muni.il / .org.il / .ac.il / .co.il (4), then host="gis." && host=".gov.il" (4), host="gis." && host=".muni.il" (3), host="gis." && host=".org.il" (2), host="gis." && host=".ac.il" (3), and host="gis." && host=".co.il" (14). host="ags." on .gov.il / .co.il / .org.il is the already registered ags.iplan.gov.il. host="gisviewer" && host=".muni.il" is the already registered Jerusalem viewer. host="gisserver", host="webgis", and host="spatial" on those domains were 0 even though gisserver.haifa.muni.il and webgis.modiin.muni.il are already registered. title="ArcGIS" && country="IL" (5) and port="6443" && title="ArcGIS" && country="IL" (2) are bare Bezeq addresses 84.110.119.69 and 84.110.119.71; reverse DNS is bzq-*.bezeqint.net and the named vhost is palmap.org (Survey123 login, not a .il name). Do not register a bare IP. port="6443" on .co.il / .org.il without the ArcGIS title is PBX and name servers. body="/arcgis/rest/services" on .co.il / .org.il / .ac.il / .muni.il (5) is pages that embed server.arcgisonline.com tiles. host="geo." and host="maps" on Israeli domains are news sites, Yandex, and company homepages. Keep hosts whose name ends in .il, not .il.us. GET /arcgis/rest/services?f=json and /server/rest/services?f=json. Skip 403 (gis.economy.gov.il, gis.tel-aviv.gov.il, gis.eplanner.co.il), WAF denials (gis.haifa.muni.il; the public directory is already gisserver.haifa.muni.il), hosts that do not answer (archmapi.gov.il, gis.mei-lod.co.il, gis.ngm.org.il, mapsrv.map.co.il, geo.mot.gov.il, arcgis.dev.idf.il), and consultancy multi-client roots (gis.ris-eng.co.il mixes Modiin, Ashdod, Herzliya, and local ArcGIS Pro projects; Utilities returns token error 499).
On .nl the product-sentence query is thin: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".nl" returned 8 assets (6 hosts) in September 2026, while the registry already had about 40 .nl ArcGIS servers. title="Folder: /" && host=".nl" (121) is ordinary directory listings; the ArcGIS rows in that set are the same hosts plus GeoPublisher and Overijssel. app="ArcGIS" is 820300. body="/server/rest/services" && host=".nl" was 0. header="ArcGIS REST" && host=".nl" was 3 and already registered. FOFA indexes the manager title ArcGIS, esri/admin.css, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".nl" (26; drop Hub, Experience, and Web Application), body="esri/admin.css" && host=".nl" (2), port="6443" && title="ArcGIS" && host=".nl" (1), header="ArcGIS" && host=".nl" (7), and title="IIS Windows Server" on gis. / geo. / geodata. / geoportaal / geoservices / kaart / maps. / arcgis hostnames (12). Also probe host="geoservices." && host=".nl" (25), host="geodata." && host=".nl" (54), host="geoportaal." && host=".nl" (36), host="arcgis" && host=".nl" (10), and host="geopublisher.nl" (22). host="gis." (88), host="kaart." (169), host="kaarten." (121), and host="maps." (200 in two pages) are tourist maps, shops, and other sites; keep names that end in .nl and look like a GIS host. host=".nl" also matches .nl. inside other names. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Utrecht University Geosciences and Katwijk publish under /server/rest/services; Hoogheemraadschap van Rijnland uses rijnland.enl-mcs.nl). Skip token error 499, Hosted-and-Utilities-only roots, empty roots (geoservices.denhaag.nl, geodata.staatsbosbeheer.nl Archief), test and acceptatie hosts, consultancy multi-client roots (MipMap), and a second REST row on a host whose public catalog is already VertiGIS Studio Web (gis.provincie-utrecht.nl). gis.bar-organisatie.nl is a separate public root from maps.bar-organisatie.nl. ags.rijkswaterstaat.nl is a separate public root from geoservices.rijkswaterstaat.nl and geoweb.rijkswaterstaat.nl.
On .eu the product-sentence query is thin: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".eu" returned 16 hosts in September 2026, all *.discomap.eea.europa.eu, while the registry already had 25 .eu ArcGIS servers (Czech and French city adaptors, danubeforesthealth.eu, and geocoder.esribelux.eu were absent). title="Folder: /" && host=".eu" (37) adds folder-scanner products. title="Répertoire : /" && host=".eu" (5) is the French word for a directory. title="Katalog: /" && host=".eu" (600) is the ordinary word catalog. title="Složka: /" && host=".eu", body="/server/rest/services" && host=".eu", and the GeoPublisher-style title query were 0. app="ArcGIS" is 820300. host=".eu" also matches .eus and .eu. inside other names; keep hosts whose name ends in .eu. FOFA indexes the manager title ArcGIS, esri/admin.css, an ArcGIS response header, or the IIS welcome page, not /arcgis/rest/services. Use host="discomap" && host=".eu" (32), header="ArcGIS" && host=".eu" (14), header="ArcGIS" && host=".europa.eu" (6), and host="arcgis" && host=".europa.eu" (3, arcgis.jrc.ec.europa.eu). title="ArcGIS" && host=".eu" (27) is Esri BeLux and Geographics demo hosts, ArcGIS Data Store on port 2443, and one Web Application. body="esri/admin.css" && host=".eu" (14) and port="6443" && title="ArcGIS" && host=".eu" (10) are those same manager ports. port="6080" && title="ArcGIS" && host=".eu" was 1 (esritest01.esribelux.eu). Also probe title="IIS Windows Server" on gis. / sig. / geoportal / maps. / arcgis / geo. hostnames (4), then host="gis." && host=".eu" (149; page 1 is mostly other viewers), host="geoportal." && host=".eu" (56), and host="arcgis." && host=".eu" (7). body="/arcgis/rest/services" && host=".eu" (187) and host="maps." && host=".eu" (365) are pages that embed the path, Yandex, and other maps. host="webgis" && host=".eu" (29) and host="geodatasrl.eu" (86) are GeoData WebGis and Lizmap viewers. title="IIS Windows Server" && host=".europa.eu" (15) is mostly non-GIS IIS sites; geotool.discomap.eea.europa.eu in that set is a geoprocessing server. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (the JRC publishes under /server/rest/services). Skip token error 499, Hosted-and-Utilities-only roots, ArcGIS Data Store, Esri BeLux and Geographics multi-client demo servers, test and staging hosts, and a second hostname of an existing directory (climate2.discomap.eea.europa.eu repeats climate.discomap.eea.europa.eu; datastore.arcgis.space2you.eu repeats arcgis.space2you.eu). nest.discomap.eea.europa.eu is a separate public root from the thematic air / bio / climate / noise servers: several folders return token error 499, and the open root lists fragmentation, signatory, and protected-area map services. arcgis-maps.jrc.ec.europa.eu is the Enterprise portal for the services directory on arcgis.jrc.ec.europa.eu.
On .edu the product-sentence query is thin: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".edu" returned 12 assets in September 2026, while the registry already had 67 .edu ArcGIS servers. title="ArcGIS REST Services Directory" && host=".edu" and title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" && host=".edu" were 0. app="ArcGIS" is 820300. host!=".edu." also returns 0 and is not a TLD filter. host=".edu" is a substring, so it matches .edu.au, .edu.cn, and other education domains; keep hosts whose name ends in .edu. FOFA indexes the manager title ArcGIS, esri/admin.css, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".edu" && title!="Hub" && title!="Experience" && title!="Web Application" (153), body="esri/admin.css" && host=".edu" (133), header="ArcGIS" && host=".edu" (106), host="arcgis" && host=".edu" (97), port="6443" && title="ArcGIS" && host=".edu" (79), port="6080" && title="ArcGIS" && host=".edu" (10), body="ArcGIS Enterprise" && host=".edu" (8), and title="IIS Windows Server" on gis. / maps. / arcgis / gisserver / geodata / gisportal hostnames (93). body="/server/rest/services" && host=".edu" was 3. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (CSU Dominguez Hills, Arizona State, UC Davis, UC Berkeley, Prince William County Schools, and UNC Wilmington publish under /server/rest/services). Skip dev, test, and preprod hosts, token error 499, ArcGIS Data Store, Survey123, load-balancer and year-stamped twins of the same directory, VCL lab VMs, and roots whose only public folders are Hosted, Utilities, and SampleWorldCities. A directory that answers only on port 6443 with a certificate browsers reject is not a public catalog URL.
On .ee the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".ee" and the body phrase alone each returned 0 in September 2026, while the registry already had 21 .ee ArcGIS servers. title="ArcGIS REST Services Directory", body="esri/admin.css", body="/server/rest/services", body="ArcGIS Enterprise", title="Portal for ArcGIS", cert="arcgis", port="6443" && title="ArcGIS", and port="6080" && title="ArcGIS" were 0. app="ArcGIS" is 820300. title="Folder: /" && host=".ee" (4) and title="Kaust: /" && host=".ee" (9) are folder-gluer vendors on ee. labels of other domains, not a services directory. title="ArcGIS" && host=".ee" (1) is the already registered valgagis.ee web application. header="ArcGIS" && host=".ee" (7) is the Pärnu city homepage, ee.mapsdevext.arcgis.com, and gis.sauevald.ee:6443. host="arcgis" && host=".ee" (2) is that same Esri host. header="ArcGIS" && country="EE" was 0. port="6443" && host=".ee" (232) and port="6443" && country="EE" (541) are Kubernetes and university apps; port="6080" && host=".ee" (10) is ProxySQL. FOFA indexes the IIS welcome page, not /arcgis/rest/services. Use host="gis." && host=".ee" (64), host="kaart." && host=".ee" (60), and host="geoportaal" && host=".ee" (19), then title="IIS Windows Server" on gis. / kaart / maps. / geoportaal / arcgis hostnames (19) and body="esri" && host="gis." && host=".ee" (13). body="esri" && host=".ee" (770) and body="/arcgis/rest/services" && host=".ee" (17) are mostly names that only contain .ee or pages that embed the path. body="js.arcgis.com" && host=".ee" (11) is ArcGIS Hub and story maps. host="webgis" and host="geoinfo" on .ee were 0. host=".ee" also matches ee. labels and .ee. inside other names (ee.mapsdevext.arcgis.com, maps.ee.co.uk); keep hosts whose name ends in .ee. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Põlva publishes under /server/rest/services). Skip token error 499, Hosted-and-Utilities-only roots, demo services (gis.parnuvesi.ee), consultancy multi-client roots (Kobras, AlphaGIS), ArcGIS Hub shells (gis.hiiumaa.ee), and a viewer whose services directory is already another host (gis.elering.ee repeats geoportaal.elering.ee). kaart.harku.ee is a separate public root from the Harku EVALD tenant.
On .th the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".th" returned 0 in September 2026, while the registry already had 24 .th ArcGIS servers. body="ArcGIS REST Services Directory" && country="TH" was 1 (d3l356eihxfp3l.cloudfront.net, a services-directory mirror geolocated in Thailand, not a .th name). title="Folder: /" && host=".go.th", title="ArcGIS" && host=".go.th", host=".ac.th" && title="ArcGIS", host=".mi.th" && title="ArcGIS", and host=".mi.th" && host="gis." were 0. app="ArcGIS" is 820300. host=".th" is a substring of .the and of other names; keep hosts whose name ends in .th, or filter with host=".go.th", host=".ac.th", host=".or.th", host=".in.th", host=".co.th", or host=".mi.th". FOFA indexes the manager title ArcGIS on ports 6443 and 6080, often as a bare IP, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && country="TH" (32; drop ArcGIS Data Store and maps.arcgis.com), body="esri/admin.css" && country="TH" (27), port="6443" && title="ArcGIS" && country="TH" (19), port="6080" && title="ArcGIS" && country="TH" (7), and header="ArcGIS" && country="TH" (13). Also probe host="gis." && host=".go.th" (38), host="gisportal" && country="TH" (19), host="arcgis." && country="TH" (14), host=".co.th" && title="ArcGIS" (2), host=".or.th" && title="ArcGIS" (1), host=".ac.th" && host="gis." (17; mostly university sites that are not servers), and host=".or.th" && host="gis." (7). body="/arcgis/rest/services" && host=".go.th" (13) is pages that embed the path (green-mnre.forest.go.th embeds the already registered gis.forest.go.th). title="IIS Windows Server" && host="gis." && host=".go.th" was 1 (gis.dwr.go.th, already registered). port="6443" && country="TH" without the ArcGIS title is thousands of non-GIS hosts. Do not register a bare IP; 110.164.132.107 is gisportal.fio.co.th. host=".th" also matches .th. inside other names. GET /arcgis/rest/services?f=json and /server/rest/services?f=json. Skip token error 499 when the public remainder is only Hosted and Utilities (Merkator Thailand, whose Hosted folder is Survey123 forms), expired certificates (gisportal.mdes.go.th, expired 2021; the Hosted folder is otherwise a public telecom catalog), ArcGIS Data Store on port 2443, and a second hostname of the same directory (arcgis.erc.or.th:6443 repeats gis.erc.or.th). gisportal.drr.go.th is a separate public root from gis.drr.go.th. gis.mnre.go.th publishes a large public directory; its TLS chain omits the GeoTrust intermediate.
On .vn the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".vn" and the same phrase with country="VN" each returned 0 in September 2026, while the registry already had 20 .vn ArcGIS servers. title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" && host=".vn", header="ArcGIS REST" && host=".vn", body="/server/rest/services" && host=".gov.vn", and cert="arcgis" && host=".vn" were 0. app="ArcGIS" is 820300. title="Folder: /" && host=".vn" (2) is a print shop and an Apache default page. title="Thư mục: /" && host=".vn" (31) is the Vietnamese word for a folder (folder-gluer vendors and file listings), not a services directory. FOFA indexes the manager title ArcGIS, esri/admin.css, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".vn" (26; drop ACTCMS construction portals, ArcGIS Data Store, the UniGIS marketing site, and training pages), body="esri/admin.css" && host=".vn" (15), header="ArcGIS" && host=".vn" (5), host="arcgis" && host=".vn" (34), port="6443" && title="ArcGIS" && host=".vn" (7), and port="6080" && title="ArcGIS" && host=".vn" (2). Also probe title="IIS Windows Server" on gis. / maps. / arcgis / geoportal / webgis / bando hostnames (8). body="/arcgis/rest/services" && host=".gov.vn" (16) is mostly those manager hosts plus login shells. body="ArcGIS Enterprise" && host=".vn" (2) is unigis.vn. title="ArcGIS" && country="VN" (121) is mostly bare IPs; ip= supplies a .vn name when one exists (arcgis.vnmac.gov.vn for 117.4.244.155). Do not register a bare IP. host=".vn" also matches vn. labels and .vn. inside other names; keep hosts whose name ends in .vn. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (VNMAC publishes under /server/rest/services; the Dong Nai land-registration office listens on port 6080 over HTTP; Can Tho listens on port 6443). Skip token error 499 (gisnlg.vn, Portcoast BVTN), license error 500 (xahiem-map-server.fint.vn), empty district folders (qlvbdhvpdkdd.gialai.gov.vn), ArcGIS Data Store on port 2443, ACTCMS construction-portal shells, consultancy multi-client roots (VGIS, GSOT Manrem), a university lab that mixes other countries (ai4sd.vnu.edu.vn), test hosts, and a second hostname of the same directory (vpdkdongnai.org.vn repeats vpdk.stnmt.dongnai.gov.vn; gisapi.cantho.gov.vn, www.gis.cantho.gov.vn, and spp.cantho.gov.vn repeat gisportal.cantho.gov.vn).
On .ph the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".ph", the body phrase alone, and title="Folder: /" && host=".ph" each returned 0 in September 2026, while the registry already had 9 .ph ArcGIS servers. body="/server/rest/services" && host=".gov.ph", cert="arcgis" && host=".ph", body="ArcGIS Enterprise" && host=".ph", and title="ArcGIS" on .edu.ph / .org.ph / .com.ph were 0. app="ArcGIS" is 820300. host=".ph" is a substring (ph.varashmtg.gov.ua); keep hosts whose name ends in .ph, or filter with host=".gov.ph". FOFA indexes an ArcGIS response header, the IIS welcome page, or a controlmap hostname, not /arcgis/rest/services. Use header="ArcGIS" && host=".gov.ph" (4), host="controlmap" && host=".gov.ph" (7), and title="ArcGIS" && host=".gov.ph" (1, ArcGIS Data Store). title="ArcGIS" && country="PH" (8), body="esri/admin.css" && country="PH" (4), and port="6443" / port="6080" with title="ArcGIS" && country="PH" are bare IPs; use ip="..." for the vhost and do not register a bare IP. header="ArcGIS" && country="PH" (137) is mostly maps.arcgis.com. port="6443" && host=".gov.ph" (2), port="6080" && host=".gov.ph" (27), and port="7443" && host=".gov.ph" (96) are Axway, ASTI apps, and Davao webserver titles, not ArcGIS. Also probe host="gis." && host=".gov.ph" (12), host="maps." && host=".gov.ph" (14), host="gisportal" && host=".ph" (3), and title="IIS Windows Server" on gis. / maps. / arcgis / geoportal / webgis / spatial hostnames (1). body="/arcgis/rest/services" && host=".gov.ph" (7) is pages that embed server.arcgisonline.com or an already registered GeoRisk host. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (ERDB and BMB publish under /server/rest/services; /arcgis/rest/services on those hosts returns 500). Skip ArcGIS Data Store on port 2443, Cloudflare and SPA shells (edims.doe.gov.ph), GeoNode (gisportal.bukidnon.gov.ph), hosts that do not answer (controlmap.denr.gov.ph, arcgis.upcebu.edu.ph, Aklan GIS on 180.232.31.154), and a bare IP that repeats a named directory (149.30.133.91 is controlmap-erdb.denr.gov.ph). A Hosted folder that lists operational layers (BMB protected areas and key biodiversity areas) is the catalog; an empty Hosted/Utilities root is not.
On .pe the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".gob.pe", the same phrase with title="Folder: /", and body="ArcGIS REST Services Directory" && country="PE" each returned 0 in September 2026, while the registry already had 18 .pe ArcGIS servers. title="Folder: /" && host=".gob.pe" was 0. title="Carpeta: /" && host=".gob.pe" (6) is Carpeta Ciudadana. body="Directorio de servicios REST" && host=".gob.pe" was 0. app="ArcGIS" is 820300. title="ArcGIS" on .edu.pe, .mil.pe, .org.pe, and .com.pe was 0, as was host="arcgis" && host=".gob.pe" and cert="arcgis" && host=".gob.pe". host=".pe" is a substring of .pekin and of other names; filter with host=".gob.pe" (and .edu.pe, .mil.pe, .org.pe, .com.pe) and keep hosts whose name ends in .pe. FOFA indexes the manager title ArcGIS or esri/admin.css on ports 6080 and 6443, not /arcgis/rest/services. Use title="ArcGIS" && host=".gob.pe" (5; drop ArcGIS Web Application), body="esri/admin.css" && host=".gob.pe" (4), port="6080" && title="ArcGIS" && host=".gob.pe" (3), port="6443" && title="ArcGIS" && host=".gob.pe" (1), header="ArcGIS" && host=".gob.pe" (1), and body="/arcgis/rest/services" && host=".gob.pe" (4, the same PRODUCE and IDEP managers). body="/server/rest/services" && host=".gob.pe" was 0. Also probe (host="gis." || host="geo." || host="geoportal" || host="sigeo" || host="geoserv" || host="catastro" || host="sig." || host="mapas." || host="visor." || host="ide." || host="webgis") && host=".gob.pe" && (body="esri" || title="ArcGIS" || port="6443" || port="6080") (8). title="IIS Windows Server" && host=".gob.pe" (70) is mostly non-GIS IIS. title="ArcGIS" && country="PE" (36) and body="esri/admin.css" && country="PE" (27) are mostly bare IPs; read the certificate name or reverse DNS and keep a .pe hostname. Do not register a bare IP. host=".pe" && port="6443" (71) is not ArcGIS. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (GEOCATMIN 2025 publishes under /server/rest/services; PRODUCE listens on port 6080 over HTTP). Three PRODUCE names (sigeo, geoportal2, catastroacuicola) are one directory. Skip token error 499 (arcgis.volcan.com.pe), a web adaptor whose REST root is HTTP 500 (gis.apn.gob.pe), ArcGIS Data Store and Survey123, and a second hostname of an existing directory (www.idemil.gob.pe is the services root behind the BAGUA.IDEMIL.GOB.PE certificate). Rechecked 25 September 2026: the product-sentence query was still 0, and title="ArcGIS" on .edu.pe, .mil.pe, .org.pe, .com.pe, and .net.pe was still 0. port="6080" && host=".gob.pe" (5) is PRODUCE, IDEP, and GEOCATMIN. port="6443" && host=".gob.pe" (6) is mostly not ArcGIS (OSINFOR’s public site, SMV, San Martín Tomcat, datosabiertos). cert="proviasnac.gob.pe" (9) is the public Provías Nacional services directory at 200.62.243.182:6080 (folders PROVIAS, GEOVIAL, GEOVISOR) plus WEBMAP viewers; the SOAP URL is that IP and no DNS name points at it. 191.98.142.67 is certificate SRVGISPRO.CER.SEDAPAR.COM.PE (does not resolve). 190.216.114.43 is *.contugas.com.pe with reverse DNS outside .pe. 38.250.183.164:6080 is a commercial cadastre with no hostname. Do not register those bare IPs.
On .cz the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".cz" and the same phrase with title="Folder: /" each returned 0 on 25 September 2026, while the dataset export listed 18 .cz ArcGIS servers (the working tree already held six more that were not in that export). title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" && host=".cz", body="Adresář služeb REST" && host=".cz", title=="Složka: /" && host=".cz", title="Portal for ArcGIS" && host=".cz", and port="6080" && title="ArcGIS" && host=".cz" were 0. title="Složka: /" && host=".cz" (27) is the Czech word složka on unrelated sites. app="ArcGIS" is 820300. FOFA indexes the manager title ArcGIS, esri/admin.css, an ArcGIS response header, the IIS welcome page, or an ags. hostname, not /arcgis/rest/services. Use title="ArcGIS" && host=".cz" (16; drop Hub, Data Store, the GISOMAT tutorial, and Web Application), body="esri/admin.css" && host=".cz" (6), header="ArcGIS" && host=".cz" (13), host="arcgis" && host=".cz" (10), host="ags." && host=".cz" (21), cert="arcgis" && host=".cz" (2), and port="6443" && title="ArcGIS" && host=".cz" (1). Also probe title="IIS Windows Server" on gis. / mapy. / geoportal / arcgis / ags. hostnames (25) and body="esri" on gis. / ags. / geoportal. hostnames (20). body="/arcgis/rest/services" && host=".cz" (146) is mostly pages that embed the path. body="/server/rest/services" && host=".cz" (6) includes the KRNAP and CZU servers. title="ArcGIS" && country="CZ" (24) is mostly bare IPs; reverse DNS supplied gislib.upol.cz, gis.fsv.cvut.cz, ags1.kr-ustecky.cz, and sarch.uhk.cz. Do not register a bare IP. host="ags1" && host=".cz" was 0 even though ags1.kr-ustecky.cz is live. host=".cz" also matches .cz. inside other names; keep hosts whose name ends in .cz. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Plzeňský kraj, Ústecký kraj, Liberecký kraj, the Institute of Archaeology, and KRNAP webserv publish under /arcgis/rest/services; CZU and the South Bohemian cycle-route server publish under /server/rest/services; KRNAP webserv listens on port 6443). Skip token error 499 when the public remainder is only Hosted and Utilities (Humpolec, Chodov), empty folders plus SampleWorldCities (UJEP), student folders (Palacký BP_Nedved / DP_Nedved, CTU FSv), indoors-only remainders (Charles University), consultancy multi-client roots (Ekolagroup), a one-layer boundary plus SampleWorldCities (ags.krnap.cz), expired certificates (geoportal.krnap.cz), and a second hostname of an existing directory (ags.cuzk.gov.cz repeats ags.cuzk.cz; wkii-arcgis-pxy.czu.cz repeats gis.czu.cz; gisova.ostrava.cz:6443 repeats mapy.ostrava.cz:6443, the services directory behind the already registered Ostrava map portal). ags1.kr-ustecky.cz is a separate public root from ags.kr-ustecky.cz.
On .sk the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".sk" returned 0 on 25 September 2026, while the registry already had 16 .sk ArcGIS servers. title="Folder: /" && body="arcgis" && host=".sk", title="ArcGIS REST Services Directory" && host=".sk", body="servicesDirectory" && host=".sk", body="/arcgis/rest/info" && host=".sk", body="currentVersion" && body="soapUrl" && host=".sk", cert="arcgis" && host=".sk", banner="ArcGIS REST" && host=".sk", and body="Adresár služieb REST" && host=".sk" were 0. title="Priečinok: /" && host=".sk" (10) is the Slovak word priečinok on stationery and folder-gluer sites. app="ArcGIS" is 820300; app="ESRI-ArcGIS" && host=".sk" was 1. title="ArcGIS" && host=".sk" was 2 (gis.lps.sk is an ArcGIS Web Application already registered; fzki9.uniag.sk:6443 is the manager). FOFA indexes the manager title ArcGIS, esri/admin.css, an ArcGIS response header, or the IIS welcome page, not /arcgis/rest/services. Use country="SK" && body="esri/admin.css" (3) and country="SK" && title="ArcGIS" with Hub, Experience, and Web Application dropped (3): those rows are fzki9.uniag.sk:6443 and 147.175.80.246:6443, whose certificate name is GIS.VM.STUBA.SK. Do not register the bare IP. Also probe title="IIS Windows Server" on gis. / mapa / mapy. / geoportal / arcgis / ags. / geo. hostnames (5), header="ArcGIS" && host=".sk" (2), country="SK" && header="ArcGIS" (4, title Folder: / on the VÚVH adaptors), host="arcgis" && host=".sk" (2), and host="ags." && host=".sk" (4). body="esri" on gis. / arcgis / geoportal / maps. hostnames (4) includes Geodeticca and non-ArcGIS map sites. body="/arcgis/rest/services" && host=".sk" (34) is pages that embed the ArcGIS JavaScript API. body="ArcGIS Server" && host=".sk" (3) is inspire.gov.sk and rpi.gov.sk, which have no services directory. port="6443" && host=".sk" (57) and port="6080" && host=".sk" (271) are not ArcGIS; keep port 6443 only with title="ArcGIS". host="gis." && host=".gov.sk" (6) is GeoServer on gis.geocloud.gov.sk. host=".sk" also matches .sk. inside other names; keep hosts whose name ends in .sk. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (SPU Nitra, STU Bratislava, and the census server publish under /server/rest/services). Skip token error 499 when that folder is not the public catalog (gis.scitanie.sk geodata; the Hosted census layers are open), Kubernetes on 6443 (cp1.geopresovregion.sk), and a second hostname of an existing directory (arcgis.vuvh.sk repeats geoserver.vuvh.sk). Port 6443 on fzki9.uniag.sk and gis.vm.stuba.sk repeats the port 443 web adaptor; the 6443 certificates are self-signed.
On .net the product-sentence query is thin and mostly not these servers: body="ArcGIS REST Services Directory" && host=".net" returned 10 rows in September 2026, while the registry already had 65 .net ArcGIS servers. The same phrase with title="Folder: /" was 2. Of those 10, gis.highlandwater.net was the only services-directory title, and it now returns 404; the rest are Azure API Management hosts, a Tech Maven demo, and a CloudFront mirror. title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" && host=".net" was 0. header="ArcGIS" && host=".net" (521) is pages that embed ArcGIS. host=".net" is a substring, so it also matches .network and .net. inside other names (une.net.co); keep hosts whose name ends in .net. FOFA indexes the manager title ArcGIS, esri/admin.css, ArcGIS Enterprise, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".net" (72; drop Hub, Experience, Web Application, Blog, Data Store, and ArcGIS Monitor), body="esri/admin.css" && host=".net" (43), body="ArcGIS Enterprise" && host=".net" (33), header="ArcGIS REST" && host=".net" (8), port="6443" && title="ArcGIS" && host=".net" (14), and port="6080" && title="ArcGIS" && host=".net" (15). host="arcgis" && host=".net" (45) and cert="arcgis" && host=".net" (25) are mostly azure-api.net and edgekey.net. Also probe title="IIS Windows Server" on gis. / maps. / arcgis / gisserver / geodata / gisportal / geoportal hostnames (53). GET /arcgis/rest/services?f=json and /server/rest/services?f=json (the San Luis Canal Company publishes under /server/rest/services). Skip token error 499, Hosted-and-Utilities-only roots, ArcGIS Data Store, Azure and CDN names, test and pqt hosts, consultancy multi-client roots (GDi, Symology Aurora, and one host that folders many Zhejiang or Guangdong cities), internal mine and dispatch servers, and a second hostname of the same directory (www.flashwind.net repeats flashwind.net). maps.stedin.net is an Enterprise portal that requires a login and has no public services directory.
On .id the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".id", the body phrase with country="ID", and title=="Folder: /" && country="ID" each returned 0 on 25 September 2026, while the registry already had 17 .id ArcGIS servers. title="Folder: /" && host=".id" (25) ignores the colon and slash, so it matches the word Folder (Indonesian stationery shops and id. language labels). app="ArcGIS" is 820300. cert=".go.id" does not match certificate text that the result field still returns. host=".id" is a substring of .id.gov (Idaho) and of id. labels on other domains; keep hosts whose name ends in .id, .go.id, .ac.id, .co.id, .or.id, .mil.id, .sch.id, .my.id, .web.id, or .desa.id. FOFA indexes the manager title ArcGIS or esri/admin.css as a bare IP geolocated in Indonesia, not /arcgis/rest/services. Use body="esri/admin.css" && country="ID" (54) and title="ArcGIS" && country="ID" (63; drop Hub, Experience, and Web Application), then read the certificate common name. header="ArcGIS" && country="ID" was 14. title="ArcGIS" && host=".go.id" was 1, host=".co.id" was 6, and host=".ac.id" was 0. port="6443" && host=".go.id" (11) is OPNsense and closed ports. body="/arcgis/rest/services" && host=".go.id" (140, 92 hosts) is pages that embed server.arcgisonline.com; the same pages also cite self-hosted roots (datamigas.esdm.go.id, peta.big.go.id, portal.ina-sdi.or.id). Do not register a bare IP. GET /arcgis/rest/services?f=json, /server/rest/services?f=json, and /gis/rest/services?f=json. Skip ArcGIS Data Store (dev.gisportal.id), a self-signed port 6443 origin of an existing directory (servergis.lampungprov.go.id repeats geoportal.lampungprov.go.id), and hosts that do not answer (portal.ina-sdi.or.id, mapinvest.sumutprov.go.id, wwf.id). gis.lemhannas.go.id publishes on port 443; its TLS chain omits an intermediate. body="/arcgis/rest/services" on .ac.id (6), .co.id (38), .or.id (11), and .mil.id (3) is pages that embed the path. host="gis." && host=".go.id" && body="esri" (7) includes the already registered BMKG server and gis.lemhannas.go.id. gis.bnn.go.id answers, and its Ganja and Narkotika folders return token error 499. gis.perpusnas.go.id is already a GeoNode record.
On .ec the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".ec", the same phrase with title="Folder: /" or country="EC", title="ArcGIS REST Services Directory" && host=".ec", title="Folder: /" && host=".ec", title="Carpeta: /" && host=".ec", body="Directorio de servicios REST de ArcGIS" && host=".ec", body="esri/admin.css" && host=".ec", body="ArcGIS Enterprise" && host=".ec", header="ArcGIS REST" && host=".ec", cert="arcgis" && host=".ec", and port="6443" && title="ArcGIS" && host=".ec" each returned 0 in September 2026, while the registry already had 15 .ec ArcGIS servers. app="ArcGIS" is 820300. host=".ec" is a substring of .ec.europa.eu and of ec. labels (ec.jrc.ec.europa.eu, ec.dgs.com.tw); keep hosts whose name ends in .ec. FOFA indexes the manager title ArcGIS (DGI-ArcGIS Server, Survey123) or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".ec" (5), header="ArcGIS" && host=".ec" (2), host="arcgis" && host=".ec" (4, the already registered Ambato adaptor), and title="IIS Windows Server" on gis. / sig. / geoportal / arcgis / mapas. / geovisor hostnames (11). title="IIS Windows Server" && host=".gob.ec" (55) is mostly finance and billing sites; keep geoportal, gis, sig, and arcgis names. host="cnelep.gob.ec" (37) is the CNEL EP business-unit adaptors. body="/arcgis/rest/services" && host=".ec" (13) is pages that embed the path. body="esri/admin.css" && country="EC" (176) and title="ArcGIS" && country="EC" (192) are mostly bare IPs; port="6443" && title="ArcGIS" && country="EC" (8) reverse-DNS is an anycast or ISP name except serviciosgis.eerssa.gob.ec and the address of gis.elecgalapagos.com.ec. Do not register a bare IP. An Enterprise portal helperServices URL can name the web-adaptor path (/serviciosgis/rest/services on EERSSA). GET /arcgis/rest/services?f=json and /server/rest/services?f=json. Skip token error 499 (CNEL Manabí, Antonio Ante obras folders, ELEPCOSA Producción), Hosted-and-Utilities-only roots (USFQ maps and p-arcgis-01, geovisor.cnelep.gob.ec), SampleWorldCities with an empty folder (CNEL Milagro; its certificate is expired), a multi-client project server (dgimapserver.com.ec mixes ECU911 cameras, a canal, forest-fire maps, and electric subcircuits), and a second REST row on a host whose public catalog is already the Web AppBuilder viewer (portalarcgis.celec.gob.ec). geoportalgye.cnelep.gob.ec is a separate public root from geoportal.cnelep.gob.ec.
On .br the product-sentence query is thin: body="ArcGIS REST Services Directory" && host=".br" returned 5 hosts in September 2026 (the same 5 with title="Folder: /"), while the registry already had 19 .br ArcGIS servers. title="ArcGIS REST Services Directory", body="Diretório de Serviços REST", and title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" were 0. title="Pasta: /" && host=".br" (336) is the Portuguese word pasta; pairing it with body="arcgis" was 0. app="ArcGIS" is 820300. FOFA indexes the manager title ArcGIS, esri/admin.css, ArcGIS Enterprise, an ArcGIS response header, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".br" (52; drop Hub, Experience, Web Application, and Data Store), body="esri/admin.css" && host=".br" (15), body="ArcGIS Enterprise" && host=".br" (15), header="ArcGIS" && host=".br" (32), header="ArcGIS REST" && host=".br" (8), host="arcgis" && host=".br" (91), port="6443" && title="ArcGIS" && host=".br" (7), and port="6080" && title="ArcGIS" && host=".br" (4). Also probe title="IIS Windows Server" on gis. / sig. / geoportal / mapas. / arcgis / geo. hostnames (31). host="sig." && host=".gov.br" (72), host="geoportal." && host=".br" (96), and host="mapas." && host=".gov.br" (78) are Prodata, SigFap, GeoNode, and other viewers. body="/arcgis/rest/services" && host=".gov.br" (42) is pages that embed the path. title="ArcGIS" && country="BR" (98) includes bare IPs; do not register those. host=".br" also matches .br. inside other names and the start of .bro; keep hosts whose name ends in .br. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (CETESB, Itajaí, Araras, IPAAM, SINFRA-MT, IBRAM-DF, and the Forest Service publish under /server/rest/services; CAEMA, Niterói, Vitória, and EPE publish under /arcgis/rest/services; UnB listens on port 6443). Skip token error 499 when the public remainder is only Hosted and Utilities (SICARF Rondônia, Natura Traceability), SampleWorldCities-only roots, consultancy multi-client roots (Codex Remote, YouX, Ambientare, Urbtec), and a second hostname of an existing directory (bagageiro.epagri.sc.gov.br and cadastroambientalrural.sc.gov.br repeat gis.epagri.sc.gov.br; www.arcgis.barramansa.rj.gov.br repeats arcgis.barramansa.rj.gov.br). Do not add a second REST row on a host whose public catalog is already ArcGIS Hub or Web AppBuilder (Joinville, Londrina, SIGMINE). server.ibram.df.gov.br is a separate public root from the GeoServer on ibram.df.gov.br. gis.vitoria.es.gov.br is a separate public root from geoweb.vitoria.es.gov.br.
On .be the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".be", the same phrase with title="Folder: /" or country="BE", title="ArcGIS REST Services Directory" && host=".be", and title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" && host=".be" each returned 0 in September 2026, while the registry already had 11 .be ArcGIS servers. body="/server/rest/services" && host=".be" was 0. app="ArcGIS" is 820300. title="Map: /" && host=".be" (149) is the Dutch word map on retail folders; pairing it with body="arcgis" was 0. title="Répertoire : /" && host=".be" (17) is ordinary French directories. title="Folder: /" && host=".be" (30) is the same retail folders. title="ArcGIS" on .vlaanderen.be, .wallonie.be, and .fgov.be was 0. host=".vlaanderen.be" (4397), host=".wallonie.be" (917), and host=".fgov.be" (2732) are every site on those domains. FOFA indexes the manager title ArcGIS, esri/admin.css, an ArcGIS response header, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".be" (11; drop ArcGIS Hub, ArcGIS Academy, and ArcGIS Data Store), body="esri/admin.css" && host=".be" (6), port="6443" && title="ArcGIS" && host=".be" (3), port="6080" && title="ArcGIS" && host=".be" (1), header="ArcGIS" && host=".be" (2), header="ArcGIS REST" && host=".be" (2), host="arcgis" && host=".be" (5), body="ArcGIS Enterprise" && host=".be" (1), and cert="arcgis" && host=".be" (2). Also probe title="IIS Windows Server" on gis. / geo. / geoportaal / geoportail / kaart. / arcgis / geodata / geoservices hostnames (11), then body="esri" on those prefixes plus carto (9). body="/arcgis/rest/services" && host=".be" (199), host="gis." && host=".be" (95), and host="geo." && host=".be" (96) are mostly pages that embed the path, GeoServer, and other viewers. title="ArcGIS" && country="BE" (27) and body="esri/admin.css" && country="BE" (15) include bare IPs; reverse DNS is googleusercontent.com, Belgacom, or destiny.be. Do not register a bare IP. port="6443" && host=".be" (67) without the ArcGIS title is not ArcGIS. host=".be" also matches .bel, .beaumont, .berkeley, and .be. inside other names (*.bel.tr); keep hosts whose name ends in .be. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Farys, AIDE, Interleuven, Oost-Vlaanderen, INASEP, and Brandweerzone Centrum publish under /server/rest/services; Limburg, SPAQUE, and the Service public de Wallonie publish under /arcgis/rest/services). Skip token error 499 on every folder (Farys, Natagora), project design drafts (oct.siemens.be), the Esri BeLux test host, 403 adaptors (ags.geo.api.vlaanderen.be), and a second hostname of the same directory (portail-carto.spaque.be repeats carto.spaque.be; gis.farys.be repeats arcgis.farys.be; gis.aide.be:6443 repeats the port 443 adaptor). geoservices.wallonie.be/arcgis/rest/services is a separate public root from the GeoServer catalog on that host. geoservices2.wallonie.be no longer resolves.
On .ar the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".ar", the same phrase with title="Folder: /", title="ArcGIS REST Services Directory" && host=".ar", and title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" && host=".ar" each returned 0 in September 2026, while the registry already had 9 .ar ArcGIS servers. title="Folder: /" && host=".ar" (5) is folder-gluer vendors. title="Carpeta: /" && host=".ar" (6) is the Spanish word carpeta. body="Directorio de servicios REST" was 0. app="ArcGIS" is 820300. body="esri/admin.css" && host=".ar", header="ArcGIS" && host=".ar", header="ArcGIS REST" && host=".ar", port="6443" && title="ArcGIS", port="6080" && title="ArcGIS" && host=".ar", and cert="arcgis" && host=".ar" were 0. FOFA indexes the Enterprise home title ArcGIS, the manager on port 6080 as a bare IP, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".ar" (3; drop ArcGIS Web Application), body="ArcGIS Enterprise" && host=".ar" (3, including a pipeline-integrity marketing page), title="ArcGIS" && country="AR" (7), body="esri/admin.css" && country="AR" (3), and port="6080" && title="ArcGIS" && country="AR" (3). Those country queries are the same three bare IPs (fibertel.com.ar reverse DNS, a DrayTek login, and an empty DPVC folder); do not register a bare IP. header="ArcGIS" && country="AR" (3) is the already registered ENARGAS address plus two “Document Moved” hosts. host="arcgis" && host=".ar" (1) is Aguas Cordobesas. Also probe title="IIS Windows Server" on gis. / sig. / mapas. / geoportal / arcgis / ide. hostnames (3), then empty-titled or IIS7 gis. hosts: title="IIS Windows Server" misses IIS7. host="gis." && host=".gob.ar" (24), host="gis." && host=".gov.ar" (23), host="mapas." (about 30 names ending in .gob.ar or .gov.ar), host="ide." && host=".gob.ar" (49), and host="geoportal" && host=".ar" (24) are GeoNode, GeoServer, and other viewers. body="/arcgis/rest/services" && host=".ar" (75) and body="/server/rest/services" && host=".ar" (3, Villa El Chocón) are pages that mention the path. host=".ar" also matches .ar. inside other names (ar.prefectura.mai.gov.ro); keep hosts whose name ends in .ar. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Buenos Aires security and AGD publish under /server/rest/services; Producción Tucumán publishes under /arcgis/rest/services). Skip token error 499 when nothing else is public (COFFAA SistemaEjercicios and Utilities; the Prefectura Naval portal at 192.231.120.137 did not respond), Hosted-Test-Utilities-only roots (Neuquén Capital), and a second hostname of an existing directory (arcgis.aguascordobesas.com.ar, sig.enargas.gov.ar). gis.producciontucuman.gob.ar is a separate public root from rides.producciontucuman.gob.ar, whose REST path now returns the RIDES WordPress 404.
On .ps the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".ps", the body phrase alone, title="ArcGIS REST Services Directory" && host=".ps", and title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" && host=".ps" each returned 0 in September 2026, while the registry already had 10 .ps ArcGIS servers. title="Folder: /" && country="PS", header="ArcGIS REST" && host=".gov.ps", host="arcgis" && country="PS", body="ArcGIS Enterprise" && country="PS", cert="arcgis" && country="PS", title="Portal for ArcGIS" && country="PS", body="/server/rest/services" && country="PS", port="6080" && title="ArcGIS" && country="PS", and body="esri" on .edu.ps and .org.ps were 0. app="ArcGIS" is 820300. host=".ps" is a substring of .psu, .psc, .psi, and other labels; pair it with country="PS" and keep hosts whose name ends in .ps. FOFA indexes the manager title ArcGIS on port 6443, often as a bare IP, not /arcgis/rest/services. Use title="ArcGIS" && country="PS" (40), body="esri/admin.css" && country="PS" (34), and port="6443" && title="ArcGIS" && country="PS" (33). title="ArcGIS" && host=".gov.ps" was 1 (arcgis02.eapp.gov.ps, already registered). Also probe body="esri" && host=".ps" && country="PS" (24) and host=".pna.ps" && (title="ArcGIS" || body="esri/admin.css" || port="6443") (14): those rows include Experience Builder redirects. Read helperServices on the portal self JSON; mapportal.mtit.pna.ps cites mapserver.mtit.pna.ps/mapsserver/rest/services, which host="mapserver" && country="PS" (6, only PENRA) does not list. Certificate names on the bare 6443 addresses are *.palcp.ps (already mapsserver.palcp.ps), GISPORTAL.MOPWH.PS, MAPSERVER.PENRA.PNA.PS, and non-.ps names (*.palmap.org, *.geostatistics.info, *.wssa-beth.org). Do not register a bare IP. Mail and edge / red names on 213.244.123.237 are the same address and do not answer as a services directory. title="IIS Windows Server" && host=".gov.ps" (4) is ministry mail plus the already registered e-government adaptor. host="gis." && host=".ps" && country="PS" (18) is mostly CMWU plus MegaVertex and XGIS viewers. GET /arcgis/rest/services?f=json, /server/rest/services?f=json, and the adaptor path named by the portal (/mapsserver/rest/services, /maps/rest/services, /security/rest/services). Skip token error 499 on the whole root (plaapp.pla.pna.ps), Survey123 login (mapportal.penra.pna.ps:5443), ArcGIS Data Store, and a second hostname of an existing directory (orthophotos.geomolg.ps is the services root behind geomolg.ps; port 6443 on PENRA, CMWU, PMA, and MoPWH repeats the port 443 adaptor). mapportal.penra.pna.ps is the Enterprise portal for the already registered mapserver.penra.pna.ps. gisportal.gedco.ps and portal.nsf.ps are indexed and time out; maps.nsf.ps is the already registered inactive directory.
On .cr the product-sentence query is empty: title="ArcGIS" && host=".cr", title="ArcGIS" && host=".go.cr", body="ArcGIS REST Services Directory" && host=".go.cr", title="Folder: /" and title="Carpeta: /" on .cr / .go.cr, body="/server/rest/services" && host=".cr", body="esri/admin.css" && host=".cr", host="arcgis" && host=".cr", cert="arcgis" && host=".cr", and port="6443" / port="6080" with host=".go.cr" each returned 0 on 25 September 2026, while the registry already had 9 .cr ArcGIS servers. header="ArcGIS" && host=".cr" was 1 (iucn.cr, already registered). body="arcgis/rest/services" && host=".cr" (5) is an earthquake page and a GeoServer cloud host, not a services directory. app="ArcGIS" was not queried after 820300 on other TLDs. port="6443" && country="CR" (288) and port="6080" && country="CR" (72) are bare IPs (FortiGate, noVNC, cameras); none of those hosts end in .cr. Do not register a bare IP. host=".cr" also matches cr. labels (cr.gis.uz, cr.china-embassy.gov.cn); keep hosts whose name ends in .cr. FOFA does not index several live roots (gis.aya.go.cr is size 0). Use host="gis." && host=".cr" (6), host="sig." && host=".cr" (7), host="mapas." && host=".cr" (25), and title="IIS Windows Server" on gis. / sig. / mapas. / geoportal / arcgis / ide. hostnames (1, sig.icafe.cr). host="geoportal", host="ide.", host="catastro", and host="visor." on .cr are GeoNode, Dobles Visor, and other viewers already registered. body="js.arcgis.com" and body="webappviewer" are municipal homepages. A 403 or IIS homepage can still publish /server/rest/services. GET /arcgis/rest/services?f=pjson and /server/rest/services?f=pjson. Skip a root whose folders all return a portal connection error (sig.icafe.cr) and a root whose only public service is Utilities/PrintingTools (sig.munigarabito.go.cr). gis.muniguarco.go.cr is a separate public root from the El Guarco Web AppBuilder tenant on maps.arcgis.com.
On .cr the product-sentence query is empty: title="ArcGIS" && host=".cr", title="ArcGIS" && host=".go.cr", body="ArcGIS REST Services Directory" && host=".go.cr", title="Folder: /" and title="Carpeta: /" on .cr / .go.cr, body="/server/rest/services" && host=".cr", body="esri/admin.css" && host=".cr", host="arcgis" && host=".cr", cert="arcgis" && host=".cr", and port="6443" / port="6080" with host=".go.cr" each returned 0 on 25 September 2026, while the registry already had 9 .cr ArcGIS servers. header="ArcGIS" && host=".cr" was 1 (iucn.cr, already registered). body="arcgis/rest/services" && host=".cr" (5) is an earthquake page and a GeoServer cloud host, not a services directory. app="ArcGIS" was not queried after 820300 on other TLDs. port="6443" && country="CR" (288) and port="6080" && country="CR" (72) are bare IPs (FortiGate, noVNC, cameras); none of those hosts end in .cr. Do not register a bare IP. host=".cr" also matches cr. labels (cr.gis.uz, cr.china-embassy.gov.cn); keep hosts whose name ends in .cr. FOFA does not index several live roots (gis.aya.go.cr is size 0). Use host="gis." && host=".cr" (6), host="sig." && host=".cr" (7), host="mapas." && host=".cr" (25), and title="IIS Windows Server" on gis. / sig. / mapas. / geoportal / arcgis / ide. hostnames (1, sig.icafe.cr). host="geoportal", host="ide.", host="catastro", and host="visor." on .cr are GeoNode, Dobles Visor, and other viewers already registered. body="js.arcgis.com" and body="webappviewer" are municipal homepages. A 403 or IIS homepage can still publish /server/rest/services. GET /arcgis/rest/services?f=pjson and /server/rest/services?f=pjson. Skip a root whose folders all return a portal connection error (sig.icafe.cr) and a root whose only public service is Utilities/PrintingTools (sig.munigarabito.go.cr). gis.muniguarco.go.cr is a separate public root from the El Guarco Web AppBuilder tenant on maps.arcgis.com.
On .cr the product-sentence query is empty: title="ArcGIS" && host=".cr", title="ArcGIS" && host=".go.cr", body="ArcGIS REST Services Directory" && host=".go.cr", title="Folder: /" && host=".cr", title="Carpeta: /" && host=".go.cr", body="/server/rest/services" && host=".cr", body="esri/admin.css" && host=".cr", host="arcgis" && host=".cr", cert="arcgis" && host=".cr", and port="6443" && host=".go.cr" each returned 0 on 25 September 2026, while the registry already had 9 .cr ArcGIS servers. header="ArcGIS" && host=".cr" was 1 (iucn.cr, already registered). body="arcgis/rest/services" && host=".cr" (5) is informes.lis.ucr.ac.cr and geoservercloud.crossover.co.cr, not services directories. app="ArcGIS" is 820300. port="6443" && country="CR" (288) and port="6080" && country="CR" (72) are bare IPs (FortiGate, noVNC); do not register those. host=".cr" also matches cr. labels (cr.gis.uz, cr.china-embassy.gov.cn); keep hosts whose name ends in .cr. FOFA does not index several live roots (gis.aya.go.cr was 0). Use host="gis." && host=".cr" (6), host="sig." && host=".cr" (7), host="mapas." && host=".cr" (25), host="geoportal" && host=".cr" (4), host="ide." && host=".cr" (5), host="catastro" && host=".cr" (2), and title="IIS Windows Server" on gis. / sig. / mapas. / geoportal / arcgis / catastro / visor / ide. hostnames (1, sig.icafe.cr). GET /arcgis/rest/services?f=json and /server/rest/services?f=json. A 403 homepage can still publish /server/rest/services (gis.muniguarco.go.cr). Skip a root whose folders all return a portal connection error (sig.icafe.cr), Utilities-only roots (sig.munigarabito.go.cr PrintingTools), and hosts that 404 on both REST paths.
On .si the product-sentence query is thin: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".si" returned 2 rows in September 2026, both geohub.webgis.si, which repeats geohub.gov.si. The body phrase alone and body="ArcGIS REST Services Directory" && country="SI" were the same host. title="Folder: /" && host=".si" (8) adds employee folders and a music index. title="Mapa: /" && host=".si" (36) is the Slovenian word mapa (Arnes Mapa, file folders), not a services directory. app="ArcGIS" is 820300. body="esri/admin.css" && host=".si", header="ArcGIS REST" && host=".si", port="6443" && title="ArcGIS" && host=".si", port="6080" && title="ArcGIS" && host=".si", body="/server/rest/services" && host=".si", body="ArcGIS Enterprise" && host=".si", and cert="arcgis" && host=".si" were 0, while the registry already had 9 .si ArcGIS servers. FOFA indexes the IIS welcome page or an empty-titled gis. hostname, not /arcgis/rest/services. Use title="ArcGIS" && host=".si" (2, both ArcGIS Web Application on geo-zs.si), host="arcgis." && host=".si" (3), host="gis." && host=".gov.si" (3), host="gisserver" && host=".si" (1), and (host="gis." || host="gis1." || host="gis2." || host="gis3." || host="gisserver" || host="arcgis.") && host=".si" (140). Also probe title="IIS Windows Server" on gis. / geoportal / arcgis / prostor / webgis / zemljevid hostnames (11). body="/arcgis/rest/services" && host=".si" (31) is pages that embed the path. host="webgis." && host=".si" (39) is Geofoto WebGIS. host="gisportal.si" (88) is an expired-certificate municipal host, not one services directory per name. host="geoportal." && host=".si" (25) is INSPIRE, 3 PORT, and mail. host=".si" also matches .si. inside other names (regione.sicilia.it, siouxfalls.gov); keep hosts whose name ends in .si. GeoHub answers at https://geohub.gov.si/?f=json as well as /ags/rest/services; /ags/rest/services?f=json returns Invalid URL. GET /arcgis/rest/services?f=json and /server/rest/services?f=json. Skip token error 499 when the public remainder is only Hosted and Utilities (arcgis.domplan.si), an Enterprise portal with no services directory (arcgis.elektro-ljubljana.si), expired certificates (gis.gov.si, gisserver.gov.si, *.gisportal.si), and a second hostname of an existing directory (geohub.webgis.si repeats geohub.gov.si; gis2.ljubljana.si repeats gis1.ljubljana.si). gis.arso.gov.si/arcgis/rest/services is a separate public root from the GeoServer catalog on that host.
On .jo the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".jo", the body phrase with host=".gov.jo" or country="JO", title="ArcGIS" && host=".jo", body="esri/admin.css" && host=".jo", body="/arcgis/rest/services" && host=".jo", body="ArcGIS Enterprise" && host=".jo", header="ArcGIS" && country="JO", host="arcgis" && host=".jo", cert="arcgis" && host=".jo", and host=".jo" && port="6080" each returned 0 on 26 September 2026, while the registry already had 8 .jo ArcGIS servers. app="ArcGIS" is 820300. app="ESRI-ArcGIS" && country="JO", title="ArcGIS" && country="JO", body="esri/admin.css" && country="JO", and body="arcgis/rest" && country="JO" are the same bare IP 193.188.71.183:6080 (no certificate name, no reverse DNS, and the REST path timed out). Do not register that IP. country="JO" && port="6080" (81) and port="6443" (132) are FortiGate, IIS welcome pages, and empty titles, not services directories. host=".jo" is a substring of .joburg, .johns, and other names; keep hosts whose name ends in .jo. FOFA does not index several live roots (gis.moa.gov.jo, gis.emrc.gov.jo, memrgis.memr.gov.jo, moemap.moe.gov.jo, and www.ammancitygis.gov.jo were 0). Use body="esri" && host=".jo" (11; drop InfoGraph marketing, Orange coverage, and Jolancer), host="gis." && host=".jo" (4), host="maps." && host=".jo" (6), (host="gis." || host="maps." || host="geoportal" || host="sdi" || host="arcgis") && host=".gov.jo" (5), and title="IIS Windows Server" && host=".gov.jo" (22). title="IIS Windows Server" && host=".jo" (225) is mostly non-GIS IIS. body="webappviewer" && host=".jo" (7) is ministry homepages that link a viewer, including the already registered MEMR server. GET /arcgis/rest/services?f=json. Skip hosts that time out (gis.moh.gov.jo), a custom map gallery with no REST root (maps.hcst.gov.jo), and a second hostname of the same directory (www.josdi.gov.jo repeats josdi.gov.jo). josdi.gov.jo is the public services directory behind an IIS welcome page. The RSCN folder on bims.rscn.org.jo returns token error 499; the root still publishes flora, fauna, reserve, and boundary services.
On .uy the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".uy" returned 0 on 26 September 2026, while the registry already had 7 .uy ArcGIS servers. body="ArcGIS Enterprise" && host=".uy", header="ArcGIS" && host=".uy", body="/server/rest/services" && host=".uy", cert="arcgis" && host=".uy", body="esri/admin.css" && host=".com.uy", port="6080" && host=".gub.uy", and port="6443" && title="ArcGIS" with host=".uy" or country="UY" were 0. app="ArcGIS" is not a FOFA rule. title="Folder: /" && host=".uy" (2) is folder.com.uy, a print shop. title="Carpeta: /" && host=".uy" (8) is Carpeta Verde. port="6080" && country="UY" (101) and port="6443" && host=".gub.uy" (2, DGI e-factura) are not services directories. host=".uy" is a substring (uy.ic9h1.info); keep hosts whose name ends in .uy. FOFA indexes the manager title ArcGIS, esri/admin.css, an arcgis hostname, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".uy" (4; drop ArcGIS Hub; apls3.catastro.gub.uy repeats gis.catastro.gub.uy on 190.64.75.12), body="esri/admin.css" && host=".uy" (1), host="arcgis" && host=".uy" (2), body="arcgis" && host=".uy" (17), and title="IIS Windows Server" on gis. / sig. / mapas. / geoportal / arcgis hostnames (4). Also probe host="gis." && host=".uy" (11), host="sig." && host=".uy" (22), host="mapas." && host=".uy" (13), and host="geoportal." && host=".uy" (8). body="/arcgis/rest/services" && host=".uy" (6) is pages that embed the path (visor.catastro.gub.uy cites the Catastro server). title="ArcGIS" && country="UY" (3) is that same Catastro address, including the bare IP; do not register the IP. body="esri" && host=".gub.uy" (3) is Catastro, the geoCatastro viewer, and Rivera. FOFA does not index several live roots (gis.maldonado.gub.uy, srvgis.igm.gub.uy, web.renare.gub.uy, and visualizadorgeominero.dinamige.gub.uy were 0). mapas.mgap.gub.uy and web.snig.gub.uy are indexed only as a 404 and a 403 homepage. sig.anep.edu.uy appears as IIS7 under host="sig.", not under title="ArcGIS". GET /arcgis/rest/services?f=json and /server/rest/services?f=json. Skip token error 499 on every folder (Montes del Plata), Utilities-only roots (arcgis.upmuruguay.com.uy), 401 adaptors (sig.upmuruguay.com.uy), ArcGIS Hub test hosts (test.ica.com.uy), and a second hostname of the same directory (apls3.catastro.gub.uy repeats gis.catastro.gub.uy). gis.catastro.gub.uy is a separate public root from the geoCatastro viewer on visor.catastro.gub.uy. HTTPS to gis.catastro.gub.uy resets; the public directory is HTTP.
On .cl the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".cl", the body phrase alone, body="Directorio de servicios REST" && host=".cl", and body="Services Directory" && country="CL" each returned 0 on 26 September 2026, while the registry already had 8 .cl ArcGIS servers. title="Folder: /" && country="CL" (4) is e-Folder and Digital Folder, not these servers. title="Carpeta: /" && host=".cl" (17) is not usable: FOFA tokenizes the colon, so it matches unrelated “Carpeta” sites. host=".cl" is fuzzy and also matches a cl label inside other names (cl.example.com) and .cloud. port="6443" && host=".cl" was 43 and mostly those false hosts; port="6080" && host=".cl" was 8, of which only vsitma.maipu.cl was ArcGIS. header="ArcGIS" and cert="arcgis" were 0 on .cl. app="ArcGIS" is 820300. app="ESRI-ArcGIS" && country="CL" (15) is the manager on ports 6443 and 6080, usually a bare IP. FOFA indexes the manager title ArcGIS, esri/admin.css, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && country="CL" (23; drop Web Application), body="esri/admin.css" && country="CL" (15), port="6443" && title="ArcGIS" && country="CL" (7), port="6080" && title="ArcGIS" && country="CL" (8), title="ArcGIS" && host=".cl" (12; the services hosts are ide.temuco.cl:6443 and vsitma.maipu.cl:6080), body="esri/admin.css" && host=".cl" (2), host="arcgis." && host=".cl" && country="CL" (3), and title="IIS Windows Server" on gis. / sig. / ide. / arcgis / geoportal / sit. / mapas. hostnames in country="CL" (5). title="IIS Windows Server" && host=".gob.cl" (5) finds agency IIS hosts such as arcgis.mma.gob.cl. Then ip="{address}" to attach a .cl hostname to a bare manager IP. Keep one GIS hostname per IP. Do not register a bare IP. GET /arcgis/rest/services?f=json and /server/rest/services?f=json. Skip token walls, test folders (prueba, TEST), and a second REST row when the services directory is already an endpoint of a registered catalog (vsitma.maipu.cl is Maipú SITMA).
On .info the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".info", the body phrase alone, title="ArcGIS REST Services Directory" && host=".info", and title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" && host=".info" each returned 0 on 26 September 2026, while the registry already had 7 .info ArcGIS servers. title="Folder: /" && host=".info" (12) is folder-processing software. domain=".info" with title="ArcGIS" or host="arcgis" was 0: domain= is the registrable domain, not a TLD suffix. header="ArcGIS REST" && host=".info", body="/server/rest/services" && host=".info", and body="fullVersion" && body="owningSystemUrl" && host=".info" were 0. app="ArcGIS" is 820300. Regex host~="\\.info$" is 820010 on this plan. host=".info" is a substring, so it also matches an info label (info.zjugis.com, info.maps.trimble.com) and arcgis.com tenants; keep hosts whose name ends in .info. FOFA indexes the manager title ArcGIS on ports 6443 and 6080, or the IIS welcome page, not /arcgis/rest/services. The seven registered servers answer as IIS or a redirect (manitowocmaps.info, edinburghcouncilmaps.info, imagery.oregonexplorer.info), not as title="ArcGIS". Use title="ArcGIS" && host=".info" (13; drop Web Application, Data Store, Experience, and Hub), body="esri/admin.css" && host=".info" (5), port="6443" && title="ArcGIS" && host=".info" (2), port="6080" && title="ArcGIS" && host=".info" (3), and host="arcgis" && host=".info" (7). header="ArcGIS" && host=".info" (22) is hotel sites and geostatistics.info (Experience Builder, no services directory). Also probe title="IIS Windows Server" on gis. / maps. / arcgis / gisserver / geodata / gisportal / geoportal hostnames (2: gis.gopp.info and maps.baydana.info), then host="gis." && host=".info" (91) and host="geoportal." && host=".info" (5). host="maps." && host=".info" (315) and title="IIS Windows Server" && host=".info" (3492) are too broad. body="/arcgis/rest/services" && host=".info" (99) is pages that embed the path. host="gisserver" && host=".info" (7) is the parked name gisserver.info. GET /arcgis/rest/services?f=json and /server/rest/services?f=json. Skip token error 499 when the public remainder is only Hosted and Utilities, SampleWorldCities plus exercise folders (iucagis.sigsa.info also mixes Coronango, Poza Rica, and Saltillo), unreachable managers (esri.sref.info, letitrain.info), ArcGIS Data Store (gisproject.info), Web AppBuilder shells (routemanrms.info, cyclonewatch.geospatialbangladesh.info), and a multi-client GEONIS root (geoportal.netzwerkstadt.info publishes RWB_offen and SWSEE_offen plus test services; the site root is 401). data.edinburghcouncilmaps.info repeats edinburghcouncilmaps.info. gis.gopp.info is a public root: several folders return token error 499, and the open Hosted folder lists urban-boundary and governorate layers.
On .by the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".by", the body phrase alone, and title="Folder: /" && host=".by" each returned 0 on 26 September 2026, while the registry already had 6 .by ArcGIS servers. title="Папка: /" && country="BY" (4) is stationery (arxiv.by); FOFA tokenizes the colon. body="Каталог сервисов" && country="BY" is not a services directory. header="ArcGIS" && country="BY", cert="arcgis" && country="BY", body="ArcGIS Enterprise" && country="BY", body="/server/rest/services" && country="BY", title="ArcGIS" && host=".gov.by", and host="arcgis" && country="BY" were 0. app="ArcGIS" is 820300. host=".by" is a substring (by.gov.cn, made.by., connected.by.); keep hosts whose name ends in .by. port="6443" && host=".by" (18) includes those false hosts; only gisoopt.by, gis.npbp.by, and gis.braslavpark.by are ArcGIS. port="6443" && country="BY" and port="6080" && country="BY" without title="ArcGIS" are mostly non-GIS. FOFA indexes the manager title ArcGIS on port 6443, esri/admin.css, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".by" (3), title="ArcGIS" && country="BY" (9; drop ArcGIS Data Store and bare IPs), body="esri/admin.css" && host=".by" (3), body="esri/admin.css" && country="BY" (8), and app="ESRI-ArcGIS" && country="BY" (8). Also probe host="gismap.by" (Vitebsk only; Gomel and Mogilev are not indexed), host="gis." && host=".by" && country="BY", and title="IIS Windows Server" on gis. / gismap / maps. / geoportal / arcgis hostnames (4). host="arcgis" && host=".by" (2) is by.maps.arcgis.com, an ArcGIS Online organization, not a server. ip="194.158.215.48" is an ArcGIS manager on 6443 and 6080 with no hostname; the live GET timed out. Do not register a bare IP. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (gis.maps.by publishes under /server/rest/services). Skip token error 499 on every folder (gis.maps.by root services are empty). Port 6443 on gisoopt.by, gis.npbp.by, and gis.braslavpark.by repeats the port 443 web adaptor.
On .qa the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".qa", the same phrase with title="Folder: /" or country="QA", body="esri/admin.css" && host=".qa", body="/server/rest/services" && host=".qa", port="6443" && title="ArcGIS" && host=".qa", port="6080" && title="ArcGIS" && host=".qa", and app="ESRI-ArcGIS" && host=".qa" each returned 0 on 26 September 2026, while the registry already had 6 .qa ArcGIS servers. title="مجلد: /" && host=".qa" was 0. app="ArcGIS" is 820300. host=".qa" is a substring, so it also matches a qa. label (massraven.qa.hub.geocloud.com, qa.maps.mail.ru); keep hosts whose name ends in .qa. title="ArcGIS" && host=".qa" (13) is that label plus the already registered geoportal.gisqatar.org.qa Web Application. header="ArcGIS" && host=".qa" (3) and host="arcgis" && host=".qa" (4) do not end in .qa. body="/arcgis/rest/services" && host=".qa" (7) is the open-data portal embedding the path. port="6443" && host=".qa" (93) and port="6080" && host=".qa" (17) are not ArcGIS. FOFA indexes the IIS welcome page or a gisqatar.org.qa hostname, not /arcgis/rest/services. Use host="gisqatar.org.qa" (11), host="gis." && host=".gov.qa" (3), host="geoportal." && host=".qa" (2), and title="IIS Windows Server" on gis. / maps. / geoportal / arcgis hostnames (2 names ending in .qa). title="ArcGIS" && country="QA" (7) and app="ESRI-ArcGIS" && country="QA" (5) are that Web Application plus bare IPs (212.70.96.20, 37.186.58.8, 89.211.33.56, 89.211.33.42, 212.70.106.61). ip="89.211.33.42" is the dev host webdev.gisqatar.org.qa. Do not register a bare IP. An Enterprise portal helperServices URL can name the adaptor (/hosting/rest/services on Al Deera). GET /arcgis/rest/services?f=json, /server/rest/services?f=json, and /hosting/rest/services?f=json. Skip token error 499 on every thematic folder (geoportal.sc.qa leaves only Utilities/Geometry), an IIS welcome page with no adaptor (gis.mme.gov.qa), company homepages (gis.qa, gis.com.qa), and dev or test hosts (webdev.gisqatar.org.qa, gisportaltest.qatarenergy.qa). aldeera.gisqatar.org.qa, 3dgis.gisqatar.org.qa, and thekaa.gisqatar.org.qa are separate public roots from services.gisqatar.org.qa and khazna.gisqatar.org.qa.
On .tw the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".tw", the body phrase alone, title="ArcGIS REST Services Directory" && host=".tw", and title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" && host=".tw" each returned 0 on 26 September 2026, while the registry already had 6 .tw ArcGIS servers. body="ArcGIS REST 服務目錄" && host=".tw", body="servicesDirectory" && host=".tw", body="ArcGIS Enterprise" && host=".tw", cert="arcgis" && host=".tw", header="ArcGIS REST" && host=".tw", and port="6080" && title="ArcGIS" && host=".tw" were 0. title="資料夾: /" && host=".tw" (23) is stationery (資料夾 is the ordinary word for a file folder). app="ArcGIS" is 820300. port="6443" && host=".tw" (257) is GitLab, mail, and Apache test pages. body="/arcgis/rest/services" && host=".tw" (438) and body="/server/rest/services" && host=".tw" (7) are pages that embed the path. country="TW" && title="ArcGIS" (47) is mostly bare IPs; 6 names end in .tw. Do not register a bare IP. FOFA indexes the manager title ArcGIS, esri/admin.css, an ArcGIS response header, an arcgis hostname, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".tw" (6; drop Web Application and Data Store), body="esri/admin.css" && host=".tw" (3), port="6443" && title="ArcGIS" && host=".tw" (2), header="ArcGIS" && host=".tw" (1, pipeline.nantou.gov.tw:6443), host="arcgis" && host=".tw" (15), and host="gisportal" && host=".tw" (5). Also probe title="IIS Windows Server" on gis. / maps. / map. / arcgis hostnames (34), then host="gis." && host=".gov.tw" (61) and host="map." && host=".gov.tw" (22). host=".tw" also matches a tw label inside other names; keep hosts whose name ends in .tw. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (New Taipei planning, the Ministry of Agriculture farmland inventory, and National Ilan University publish under /server/rest/services; the Forestry and Nature Conservation Agency publishes under /arcgis/rest/services). Some .gov.tw certificates omit the subject key identifier; a Python TLS error is not proof the directory is down. Skip token error 499 when that is the only public content, SampleWorldCities-only roots, consultancy multi-client roots (project-code folders on gis.limi.com.tw and gis.liquid.net.tw, mixed client folders on gisportal.triwra.org.tw), numbered tile caches (tiles.map.net.tw), unreachable managers (igisportal.geomatics.ncku.edu.tw:6443, urbandesign.tainan.gov.tw:6443, pipeline.nantou.gov.tw:6443), and a second REST row on a host whose public catalog is already the viewer (map.hl.gov.tw, map.yunlin.gov.tw, eghouse.hccg.gov.tw). map.moa.gov.tw is a separate public root from talis.moa.gov.tw. sgis.forest.gov.tw is the Web AppBuilder shell for gis.forest.gov.tw.
On .lk the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".lk" and the same phrase with title="Folder: /" each returned 0 on 26 September 2026, while the registry already had 5 .lk ArcGIS servers. title="Folder: /" && host=".lk", title="ArcGIS" on .gov.lk / .ac.lk / .org.lk / .com.lk, body="esri/admin.css" && host=".lk", header="ArcGIS REST" && host=".lk", body="/arcgis/rest/services" && host=".lk", body="ArcGIS Enterprise" && host=".lk", cert="arcgis" && country="LK", and app="ESRI-ArcGIS" on .lk and .gov.lk were 0. app="ArcGIS" is 820300. host=".lk" is a substring (geoportal.lk-ni.de, gis.lkleer.de); keep hosts whose name ends in .lk. FOFA indexes an ArcGIS response header, port 6443/6080, an arcgis. or gis. hostname, or an IIS welcome page titled IIS Server (not only IIS Windows Server), not /arcgis/rest/services. Use header="ArcGIS" && host=".gov.lk" (1, lrip.nbro.gov.lk:6443, already registered), port="6443" && host=".gov.lk" (4, that host plus survey.gov.lk, which answers Not Acceptable; the public directory is already arc.survey.gov.lk), port="6080" && host=".gov.lk" (1, crip.irrigation.gov.lk, which did not connect), host="gis." && host=".gov.lk" (2 names: gis.colombo.mc.gov.lk already registered, gis.dmc.gov.lk an IIS welcome page whose HTTPS path is 403), host="arcgis." && host=".lk" (1, arcgis.uom.lk, REST 404), host="geoportal." && host=".lk" (the already registered NSDI geoportal), and title="IIS Server" on gis. / maps. / arcgis / geoportal hostnames (the DMC welcome page). title="IIS Windows Server" && host=".gov.lk" (18) includes gisapps.nsdi.gov.lk (already registered) and ministry sites that are not GIS. body="esri" && host=".gov.lk" (12) is the NSDI catalogue and geoportal plus digitalhealthatlas.lgcc.gov.lk, whose homepage did not return a services directory. body="/server/rest/services" && host=".lk" is that same atlas. title="ArcGIS" && country="LK" (8) and app="ESRI-ArcGIS" && country="LK" (5) are arcgis.gislk.com:6443 plus bare IPs (222.165.187.254, 124.43.192.170, 222.165.186.50). Do not register a bare IP. arcgis.gislk.com is not a .lk name. Port 6443 and 6080 on .ac.lk, .org.lk, and .com.lk were 0. host="gis." && country="LK" also returns gis.hutchison.lk, which timed out. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (NSDI and the Department of Meteorology publish under /server/rest/services; Colombo and the Survey Department publish under /arcgis/rest/services). Skip 403, REST 404, and hosts that do not answer.
On .mk the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".mk", the body phrase alone, and the same phrase with country="MK" each returned 0 on 26 September 2026, while the registry already had 5 .mk ArcGIS servers. title="Folder: /" && country="MK" was 0. title="Папка: /" && host=".mk" (4) is stationery. body="esri/admin.css" && host=".mk", host="arcgis" && host=".mk", cert="arcgis" && host=".mk", body="ArcGIS Enterprise" && host=".mk", header="ArcGIS REST" && host=".mk", body="/server/rest/services" && host=".mk", port="6443" && title="ArcGIS" && host=".mk", and port="6080" && title="ArcGIS" with host=".mk" or country="MK" were 0. host=".mk" is a substring (mk.miljo.stockholm.se, rdg.artsoft.mk.ua); keep hosts whose name ends in .mk. port="6443" && host=".mk" (14) is mostly those mk. labels. FOFA indexes the manager title ArcGIS on port 6443 as a bare IP, an ArcGIS response header, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".mk" (5; drop Dashboards, Web Application, and Hub), title="ArcGIS" && country="MK" (4), body="esri/admin.css" && country="MK" (2), header="ArcGIS" && host=".mk" (2), header="ArcGIS" && country="MK" (3), and port="6443" && title="ArcGIS" && country="MK" (2). Then ip="{address}" to attach a .mk name (80.77.147.247 is gis.aek.mk, 62.162.97.20 is maps.pakomak.mk, 185.177.14.238 is ikat.katastar.gov.mk). Also probe title="IIS Windows Server" on gis. / webgis / gisportal / maps. hostnames (15) and host="gis." && host=".mk" (58). body="/arcgis/rest/services" && host=".mk" (11) is pages that embed the path. host="geoportal" && host=".mk" was 0. Do not register a bare IP. GET /arcgis/rest/services?f=json. Skip a consultancy multi-client root (gisportal.gdi.mk mixes municipalities and companies; its certificate is expired), a second hostname of an existing directory (gisapps.aek.mk and port 6443 on gis.aek.mk repeat the registered AEK catalog; um.pakomak.mk:6443 and app.maps.pakomak.mk:6443 repeat maps.pakomak.mk), a root that cannot reach its server machines (gis.stat.gov.mk), IIS welcome pages with no adaptor (webgis.roads.org.mk, gis.gdi.mk), and hosts that time out (ikat.katastar.gov.mk, appgis.energy.gov.mk). gis.moepp.gov.mk is a separate public root. Municipal *.gis.mk MapServer for Windows hosts and Nexus public portals are not ArcGIS Server.
On .nc the product-sentence query is thin: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".nc" returned 3 hosts on 26 September 2026 (carto.gouv.nc, carto10.gouv.nc, and geosgt.gouv.nc), while the registry already had 5 .nc ArcGIS servers. The body phrase without the title, excluding .nc.gov and .nc.us, adds only sig.noumeaport.nc (title ArcGIS Server REST API Login). body="esri/admin.css" with that host filter, header="ArcGIS REST" && country="NC", body="/server/rest/services" && country="NC", body="ArcGIS Enterprise" && country="NC", body="servicesDirectory" && country="NC", and cert="arcgis" && country="NC" were 0. app="ArcGIS" is 820300. title="Répertoire : /" && country="NC" is the professional-certification directory rcpnc.gouv.nc, not a services directory. host=".nc" is a substring of .nc.gov and .nc.us (North Carolina) and of .ncsu; title="ArcGIS" && host=".nc" (10) is mostly .nc.gov managers. Keep hosts whose name ends in .nc, or pair with country="NC". country="NC" alone is the whole territory (113109). port="6443" && country="NC" and port="6080" && country="NC" are SMSEagle, 3CX, and empty titles, not ArcGIS. FOFA indexes the services-directory title Folder: / for the government web adaptor, an empty title for sig1.gouv.nc, or the IIS welcome page, and it does not index carto.noumea.nc or carto.province-nord.nc (both already registered; host= size 0). geoportail.oeil.nc is indexed as title Geoportal. Use body="ArcGIS REST" && country="NC" (8, the three gouv.nc directories plus the port login), header="ArcGIS" && country="NC" (the same three directories), host="carto." && country="NC" (10), host=".gouv.nc" with body="rest/services" (those directories plus data.gouv.nc), host="arcgis" && country="NC" && host!=".nc.gov" && host!=".nc.us" (arcgis.epi.nc), and title="IIS Windows Server" on arcgis / sig. / mysig hostnames in country="NC" (mysig.cde.nc and arcgis.epi.nc). host=".georep.nc" (31) is the Géorep viewer hostnames; their REST paths 404. body="esri" && country="NC" (53) is mostly geo.nc cPanel names. body="/arcgis/rest/services" && country="NC" (8) is the same services-directory set. GET /arcgis/rest/services?f=json, /public/rest/services?f=json, and /ags/rest/services?f=json (the government directory is /public/rest/services; Calédonienne des Eaux uses /ags/rest/services). Skip token error 499 on every folder (mysig.cde.nc), a REST API login (sig.noumeaport.nc; the live GET timed out), qualification and poc hosts (carteau-qual.cde.nc, poc-mysig.cde.nc), an IIS welcome page that does not connect (arcgis.epi.nc), a cadastre SPA with no services directory (cadastre.gouv.nc), and a second hostname of an existing directory (carto10.gouv.nc and geosgt.gouv.nc /public/rest/services repeat carto.gouv.nc; /arcgis/rest/services on geosgt.gouv.nc is HTTP 401). carto.province-sud.nc answers with an empty title and 404s on the REST paths.
On .gt the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".gt", title="ArcGIS" && host=".gt", title="ArcGIS" && country="GT", body="esri/admin.css" && country="GT", body="ArcGIS REST Services Directory" && country="GT", body="/server/rest/services" && country="GT", host="arcgis" && country="GT", and title="Folder: /" && country="GT" each returned 0 on 26 September 2026, while the registry already had 4 .gt ArcGIS servers. body="/arcgis/rest/services" && country="GT" was 1 (a Metabase host). app="ArcGIS" is 820300. host=".gt" is a substring, so it also matches a gt. label (gt.dnv.org, gt.qq2487.com) and names such as gis.gtcountymi.gov; keep hosts whose name ends in .gt, or filter with host=".gob.gt", host=".edu.gt", host=".org.gt", or host=".com.gt". domain="gob.gt" is 0: domain= is the registrable domain, not the public suffix. port="6443" && country="GT" (76) and port="6080" && country="GT" (33) are FortiGate, SonicWall, and other appliances. title="IIS Windows Server" && country="GT" (730) is mostly non-GIS IIS; the same title on gis. / sig. / mapas. / geoportal / arcgis / ide. hostnames with a .gt suffix was 0. FOFA does not index www.geovisitguatemala.gt or arcgis-server.url.edu.gt (both already registered). Use host=".gob.gt" && body="arcgis" (4), host=".gob.gt" && body="esri" (5), body="arcgis" && country="GT" (7), header="ArcGIS" && country="GT" (1, sig.inab.gob.gt:7443), and host="sig." && host=".gob.gt" (CONRED, INAB, and the PPEM forms app). host="gis." && country="GT" and host="mapas." && country="GT" find Guatemala servers whose names do not end in .gt (gis.empagua.com, mapas.anacafe.org). host="sig." on .com.gt is the IT company sig.com.gt. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (CONRED, INAB, and the INGUAT Enterprise host publish under /server/rest/services). Skip a WordPress site that only mentions ArcGIS (portal.siinsan.gob.gt), Cloudflare 403 (portalvet.svet.gob.gt), a forms app (sig.ppem.gob.gt), names that do not resolve (geoportal.ine.gob.gt, www.jtpdataportal.org.gt), and a root whose only public service is a Hosted form while Utilities returns token error 499 (geovisit.inguat.gob.gt; the tourism directory is already www.geovisitguatemala.gt).
On .sv the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".sv", the body phrase alone, title="ArcGIS REST Services Directory" && host=".sv", title="ArcGIS" && host=".sv", title="ArcGIS" on .gob.sv / .edu.sv / .org.sv, body="esri/admin.css" && host=".gob.sv", header="ArcGIS" && host=".sv", header="ArcGIS REST" && host=".sv", body="ArcGIS Enterprise" && host=".sv", body="Directorio de servicios REST de ArcGIS" && host=".sv", cert="arcgis" && country="SV", and port="6443" / port="6080" with title="ArcGIS" && host=".sv" each returned 0 on 26 September 2026, while the registry already had 4 .sv ArcGIS servers. title="Carpeta: /" && host=".sv" (1) is a government ethics folder, not a services directory. app="ArcGIS" is 820300. host=".sv" is a substring (tre.sv.ugm.ac.id, geo.sv.rostock.de, sv.dconc.gov); keep hosts whose name ends in .sv. FOFA indexes an empty-titled web adaptor, a FeatureLayer title, or the IIS welcome page, not /arcgis/rest/services. Use body="arcgis" && host=".gob.sv" (10), body="/server/rest/services" && host=".sv" (4), body="arcgis" && host=".org.sv" (1, already geovisor.opamss.org.sv), title="IIS Windows Server" && host=".gob.sv" (4), host="geoportal" && host=".gob.sv" (10), host="mapas." && host=".sv" (5), host="sig." && host=".sv" (6), host="geovisor" && host=".sv" (14), and host="visor" && host=".gob.sv" (4). body="arcgis" on .edu.sv and .com.sv was 0. host="gis." && host=".gob.sv", host="arcgis" && host=".gob.sv", and host="ide." && host=".gob.sv" were 0. title="ArcGIS" && country="SV" (1) and body="esri/admin.css" && country="SV" (1) are the bare address 201.247.233.245:6443, whose portal hostname is arcgis.grupocassa.com (not a .sv name). port="6443" && country="SV" (20) is otherwise FortiGate and Pentaho. title="IIS Windows Server" && country="SV" (775) is not a GIS filter. body="services directory" && host=".sv" (8) is WordPress. GET /arcgis/rest/services?f=json and /server/rest/services?f=json. A root whose services array is empty can still publish operational layers under Hosted (observatoriodelagua.anda.gob.sv). Skip 401/403 (bpm.vivienda.gob.sv, geoportal.mag.gob.sv, visor.cnd.gob.sv, geo.bcr.gob.sv), hosts that time out (sig.pnc.gob.sv, geo.educacion.goes.gob.sv), ArcGIS Hub (geoportal.bcr.gob.sv), an ArcGIS JS API page with no REST root (sistemacultivos.goes.gob.sv), Experience Builder on a bare IP (190.86.207.146), and a second hostname of an existing directory (mapas.snet.gob.sv and www.snet.gob.sv embed geoportal.snet.gob.sv; geoserver.ambiente.gob.sv is already an endpoint of geoportalsima.ambiente.gob.sv). Do not register a bare IP or a .com portal found only because the address is geolocated in El Salvador.
On .bd the product-sentence query is empty: body="ArcGIS REST Services Directory" && host=".bd" and the same phrase with country="BD" each returned 0 on 26 September 2026, while the registry already had 4 .bd ArcGIS servers (gis.rhd.gov.bd, masterplan.rajuk.gov.bd, mapgis.lged.gov.bd, gis.bwdb.gov.bd). title="ArcGIS" && host=".gov.bd", host="arcgis" && host=".bd", body="esri/admin.css" && host=".gov.bd", and cert=".gov.bd" && port="6443" were 0. app="ArcGIS" is 820300. host=".bd" is a substring, so title="ArcGIS" && host=".bd" (3) and body="esri/admin.css" && host=".bd" (3) are *.bd.esri.com, and port="6080" && host=".bd" is mostly *.bd.com VPN names. Keep hosts whose name ends in .bd, or filter with host=".gov.bd", host=".org.bd", or host=".ac.bd". FOFA indexes an esri or arcgis mention, an ArcGIS response header, or the IIS welcome page, not /arcgis/rest/services. Use body="esri" && host=".gov.bd" (21), body="arcgis" && host=".gov.bd" (22), host="gisportal" && host=".bd" (8), body="/arcgis/rest/services" && host=".bd" (7, biwtagis.gov.bd plus Esri SaaS), body="/server/rest/services" && host=".bd" (2, the same BIWTA host), header="ArcGIS" && host=".bd" (5, rugisportal.ru.ac.bd:7443 and gis.rhd.gov.bd), and host="gis." && host=".gov.bd" (47). Also probe title="IIS Windows Server" on gis. / maps. / map. / arcgis / geoportal / mapgis hostnames (5). title="ArcGIS" && country="BD" (35) and body="esri/admin.css" && country="BD" (13) are ArcGIS Data Store, bare IPs, lga.icddrb.org, and server.esribangladesh.com. Do not register a bare IP. port="6443" && host=".bd" (26) is mail, NetScaler, and *.bd. labels except gis.rhd.gov.bd:6443. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (BIWTA, DNCC EOC, DGHS, and DWASA publish under /server/rest/services; LGED gisportal and DPE GPSMIS publish under /arcgis/rest/services). A root whose services array is empty can still publish operational layers under Hosted (gis.dghs.gov.bd). Skip token error 499 on every folder (gis.12upazilaudd.gov.bd, serverbori.gov.bd), the Esri Bangladesh marketing site (esribangladesh.com.bd), and hosts that time out (rugisportal.ru.ac.bd, gisportal.bwdb.gov.bd, gisportal.desco.org.bd). gisportal.lged.gov.bd is a separate public root from the SurfGIS site gis.lged.gov.bd and the inactive adaptor mapgis.lged.gov.bd.
On .rs the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".rs", the body phrase alone, title="Fascikla: /" && host=".rs", title="Фасцикла: /" && host=".rs", header="ArcGIS REST" && host=".rs", cert="arcgis" && host=".rs", body="ArcGIS Enterprise" && host=".rs", host="arcgis" && host=".rs", and port="6080" && title="ArcGIS" && host=".rs" each returned 0 on 26 September 2026, while the registry already had 4 .rs ArcGIS servers (gis.mre.gov.rs inactive, www.nrizgis.sepa.gov.rs, gis.ni.rs, gisportal.rs). app="ArcGIS" is 820300. host=".rs" is a substring of .rs.gov.br, .rs.ba, and rs. labels (geo.canoas.rs.gov.br, gistrebinje.rs.ba); keep hosts whose name ends in .rs. FOFA indexes the manager title ArcGIS on port 6443, esri/admin.css, or the IIS welcome page, not /server/rest/services. Use title="ArcGIS" && host=".rs" (2; drop ArcGIS Data Store; both rows are gis.vojvodinasume.rs), body="esri/admin.css" && host=".rs" (1), port="6443" && title="ArcGIS" && host=".rs" (1), and title="ArcGIS" && country="RS" (9). app="ESRI-ArcGIS" && country="RS" (5) and body="esri/admin.css" && country="RS" (5) are that manager plus bare IPs (147.91.212.13 is gis.iaus.ac.rs, 195.178.52.210 is gis.raca.rs, 93.87.67.67 is gis.vojvodinasume.rs). Do not register a bare IP (89.23.75.33 has no hostname). header="ArcGIS" && host=".rs" (5) includes indoo.rs. body="/arcgis/rest/services" && host=".rs" (23) is mostly .rs.gov.br and pages that embed the path. body="/server/rest/services" && host=".rs" (2) is geocensus.stat.gov.rs and vanredniprevoz.putevi-srbije.rs. Also probe host="gis." && host=".gov.rs" (6), host="geoportal." && country="RS" (keep names ending in .rs), and title="IIS Windows Server" on gis. / maps. / geoportal / arcgis hostnames (18 names ending in .rs). Serbian Enterprise sites publish under /server/rest/services. GET /arcgis/rest/services?f=json and /server/rest/services?f=json. Skip a second hostname or port of the same directory (www.gis.vojvodinasume.rs and port 6443 repeat gis.vojvodinasume.rs; vanredniprevoz.putevi-srbije.rs repeats gisportal.rs, whose folders all return token error 499), demo services published from a local machine (gis.es.rs folder edsimovina), 403 (geoportal.srbijasume.rs), and hosts that time out (geoportal.vgi.mod.gov.rs, gis.raca.rs:6443). gis.stat.gov.rs, gis.vojvodinasume.rs, gis.iaus.ac.rs, and gis.zavurbvo.rs are public roots. gis.rdi.gov.rs and geoportal.vojvodina.gov.rs already have Hub records; their /server/rest/services directories are separate public catalogs. GeoServer and MapStore on gis.kragujevac.rs and gis.sremgas.rs are already registered.
On .ba the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".ba", the body phrase alone, and the same phrase with country="BA" each returned 0 on 26 September 2026, while the registry already had 4 .ba ArcGIS servers (gis-server.gisfucz.gov.ba, isvportal.jadran.ba, isvportal.voda.ba, static.katastar.ba). title="Folder: /" && body="arcgis/rest/services" && body!="ArcGIS REST Services Directory" && host=".ba", header="ArcGIS" && host=".ba", header="ArcGIS REST" && host=".ba", body="ArcGIS Enterprise" && host=".ba", body="/server/rest/services" && host=".ba", cert="arcgis" with host=".ba" or country="BA", host="arcgis" && host=".ba", host="geoportal" && host=".ba", host="gisportal" && host=".ba", port="6080" && title="ArcGIS" && host=".ba", and title="Portal for ArcGIS" && country="BA" were 0. app="ArcGIS" is 820300. host=".ba" is a substring of .ba.gov.br and of labels such as maps.ba.com; body="esri" && host=".ba" (64) and body="arcgis" && host=".ba" (61) are mostly Salvador municipal sites. Keep hosts whose name ends in .ba, or add country="BA". FOFA indexes the manager title ArcGIS on port 6443, esri/admin.css, or the IIS welcome page, not /server/rest/services. Use title="ArcGIS" && host=".ba" (2, both isvportal.jadran.ba), body="esri/admin.css" && host=".ba" (2), port="6443" && title="ArcGIS" && host=".ba" (2), title="ArcGIS" && country="BA" (9; drop ArcGIS Data Store), body="esri/admin.css" && country="BA" (7), and app="ESRI-ArcGIS" && country="BA" (7). Those country rows are isvportal.jadran.ba, bhimsma.bhmac.org (not a .ba name), and bare IPs. ip="80.65.73.166" is the already registered gis-server.gisfucz.gov.ba; ip="212.39.120.52" is isvportal.jadran.ba; ip="84.41.117.132" is bhimsma.bhmac.org. Do not register a bare IP. body="/arcgis/rest/services" && host=".ba" (3) is the Jadran manager plus gistrebinje.rs.ba (a WebGIS page, not a services directory). Also probe host="gis." && host=".ba" (64; keep names ending in .ba) and title="IIS Windows Server" on gis. / maps. / webgis / arcgis hostnames with country="BA" (gis.fmpu.gov.ba, gis.mod.gov.ba, webgis.bhtelecom.ba). country="BA" drops gis.ceok-zdk.ba (address geolocated outside Bosnia). host="maps." && host=".ba" includes maps.fzzg.gov.ba. *.gis.ba names in that set are GAUSS WebCity, not ArcGIS Server. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (FMPU, the Ministry of Defence, and the Zenica-Doboj air-quality server publish under /server/rest/services; BH Telecom publishes under /arcgis/rest/services). Skip token error 499 on every folder (maps.fzzg.gov.ba), a second hostname of an existing directory (www.isvportal.jadran.ba and port 6443 repeat isvportal.jadran.ba), and hosts that do not answer (gis.rzzkpn.rs.ba, gistrebinje.rs.ba). gis.ceok-zdk.ba is a public services directory; the site root is an ArcGIS Hub page on the same host.
Skip internal-only servers that return 401/403 for the services list. One record per public services root, not per map service.
On .kr the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".kr" and the body phrase alone each returned 0 on 26 September 2026, while the registry already had 4 .kr ArcGIS servers (www.wamis.go.kr, gis.gjcity.go.kr, gis.kofpi.or.kr, imap.incheon.go.kr). body="ArcGIS REST Services Directory" && country="KR" was 1 (vectortileservices2.arcgis.com, not a .kr name). title="Folder: /" && host=".kr" (5) is not these servers. title="폴더: /" && host=".kr" (15) is folder-lock and folder-gluer shops; FOFA tokenizes the colon. host="arcgis" && host=".kr", cert="arcgis" && host=".kr", and body="/server/rest/services" && host=".go.kr" were 0. app="ArcGIS" is 820300. host=".kr" is a substring (kr-karlovarsky.cz, kreis- labels); keep hosts whose name ends in .kr. FOFA indexes the manager title ArcGIS, esri/admin.css, an ArcGIS response header, or the IIS welcome page, not /arcgis/rest/services. Use title="ArcGIS" && host=".kr" (5; drop ArcGIS Urban and Data Store), body="esri/admin.css" && host=".kr" (4), header="ArcGIS" && host=".kr" (1, gis.icbp.go.kr), port="6443" && title="ArcGIS" && host=".kr" (3), and port="6080" && title="ArcGIS" && host=".kr" (1, fgis.nifos.go.kr). title="ArcGIS" && country="KR" (132), body="esri/admin.css" && country="KR" (89), and app="ESRI-ArcGIS" && country="KR" (89) are mostly bare IPs and *.arcgis.com. port="6443" && title="ArcGIS" && country="KR" (25) and port="6080" && title="ArcGIS" && country="KR" (18) are the same managers. Then ip="{address}" and read the certificate common name (59.27.63.246 is gis.kfca.re.kr, 211.37.10.196 is *.kfpa.or.kr, 210.93.72.171 is *.kadc.or.kr on bigdata.jejunu.ac.kr). Do not register a bare IP. AWS addresses titled ArcGIS on port 443 are *.arcgis.com. Also probe body="esri" && host="gis." && host=".go.kr" (2), body="ArcGIS REST" && host=".go.kr" (5), and title="IIS Windows Server" on gis. / maps. / map. / geoportal / arcgis / geo. hostnames (4). body="/arcgis/rest/services" && host=".go.kr" (3) is pages that mention the path. host="gis." && host=".go.kr" (84) is mostly other viewers. GET /arcgis/rest/services?f=json and /server/rest/services?f=json (Bupyeong and N-Basemap publish under /server/rest/services; the National Institute of Forest Science listens on port 6080 over HTTP). Skip token error 499 when the public remainder is only imagery and a DEM (gis.yeosuic.co.kr 3D구간DB), a multi-client Hosted folder (gis.kfca.re.kr mixes company sites across counties while the program folders require a token), Hosted-and-Utilities-only roots (bigdata.jejunu.ac.kr), ArcGIS Data Store on port 2443, Esri Korea (kgeodata.com, already registered), and a second REST row on a host whose public catalog is already the viewer (gomap.goyang.go.kr is Goyang Gomap; map.gbgs.go.kr returns 404 on both REST paths). gis.myagent.kr, icloudgis.incheon.go.kr, smart.incheon.go.kr, map.gyeyang.go.kr, map.metagis.co.kr, and kgeosolution.co.kr did not answer. The four registered .kr servers were not in title="ArcGIS" && host=".kr".
On .jp the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".jp", the body phrase alone, body="ArcGIS REST サービス ディレクトリ" && host=".jp", title=="Folder: /" && host=".jp", and title=="フォルダー: /" && host=".jp" each returned 0 on 26 September 2026, while the registry already had 4 .jp ArcGIS servers. app="ArcGIS" is 820300. title="Folder: /" && host=".jp" (37) and fuzzy title="ArcGIS" && host=".jp" (12) are not usable: host=".jp" is a substring of names such as folder-lock.jp.malavida.com, and FOFA tokenizes the colon so “Folder” matches download shops. Keep hosts whose name ends in .jp, or filter with host=".go.jp", host=".lg.jp", host=".ac.jp", host=".or.jp", or host=".co.jp". country="JP" && title="ArcGIS" (88) and country="JP" && body="esri/admin.css" (52) are mostly bare IPs, *.arcgis.com, and Survey123 logins. port="6443" && host=".jp" (91) and port="6080" && host=".jp" (22) are VPN, mail, and Kubernetes except where the title is exactly ArcGIS. Do not register a bare IP. FOFA indexes the manager title ArcGIS, esri/admin.css, an arcgis hostname, or the IIS welcome page, not /arcgis/rest/services. The four registered servers (edtt2.drs.dpri.kyoto-u.ac.jp, acpis.jp, trigger-info02.bosai.go.jp, www.sabo-map.pref.hiroshima.lg.jp) were size 0. Use title=="ArcGIS" && host=".jp" (5: gis.smart-river.mlit.go.jp, agedata.smart-river.mlit.go.jp, and routingevacuation.jp on 443 and 6443), body="esri/admin.css" && host=".jp" (the same hosts), host="arcgis" && (host=".go.jp" || host=".lg.jp" || host=".ac.jp" || host=".or.jp") (arcgis.csis.u-tokyo.ac.jp, arcgis.d24h.mhlw.go.jp), and title="IIS Windows Server" on gis. / webgis / arcgis / maps. hostnames (sv-gis.maps.okhotskgis.or.jp, arcgis.okicom.co.jp, gis.midorinet-fukui.jp). body="/arcgis/rest/services" && host=".jp" (32) is pages that embed the path. body="esri" && host=".lg.jp" (10) is prefectural disaster portals, not services directories. Japanese Enterprise sites often publish under /server/rest/services while /arcgis is the portal (web-adaptor 500 or 404). GET both. Skip token error 499 on every folder (gis.smart-river.mlit.go.jp, arcgis.d24h.mhlw.go.jp), Survey123-only Hosted folders (sv-gis.maps.okhotskgis.or.jp), 401 (gis.realtime.bosai.go.jp), an IIS welcome page with REST 404 (arcgis.okicom.co.jp), a Leaflet viewer (gis.midorinet-fukui.jp), a test-host data portal (gisportal.coinext-iwatest.jp), and a story-map shell with no REST root (isrs.bosai.go.jp). www.routingevacuation.jp repeats routingevacuation.jp.
On .et the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".et", the body phrase alone, title="Folder: /" && host=".et", title="ArcGIS" && host=".et", body="esri/admin.css" && host=".et", body="/server/rest/services" && host=".et", header="ArcGIS" && host=".et", host="arcgis" && host=".et", and port="6443" / port="6080" with title="ArcGIS" && host=".et" each returned 0 on 26 September 2026. The registry had 0 .et ArcGIS servers. app="ArcGIS" is 820300. host=".et" is a substring, so it also matches a leading et. label (et.herpatlas.org, et.scjtonline.cn, et.pim.ac.th); keep hosts whose name ends in .et. domain="et" and domain="gov.et" are 0: domain= is the registrable domain, and gov.et, edu.et, com.et, org.et, and net.et are public suffixes (moh.gov.et is not domain="gov.et"). body="/arcgis/rest/services" && host=".et" (2) is et.herpatlas.org, which does not end in .et. FOFA indexes the manager title ArcGIS on ports 6443 and 6080, esri/admin.css, or an IIS welcome page on a gis. hostname, not /arcgis/rest/services. Use title="ArcGIS" && country="ET" (2), body="esri/admin.css" && country="ET" (2), and body="arcgis/rest" && country="ET" (3). Those rows are the bare address 196.188.56.122 (ports 6080 and 6443) plus 196.189.239.114 (title TBRR, no domain). cert="ETH-WEB-LF" is that same address; the certificate common name and DNS name are ETH-WEB-LF only, with no .et name. The live GET timed out. Do not register a bare IP. Also probe host="gis." && country="ET" (4: gis.eeu.et and gis.adc.com.et), host="map." && country="ET" (map.gadasez.et), and host="geo." && country="ET" (geo.portal.ebi.gov.et, already a GeoNode). port="6443" && country="ET" (92) and port="6080" && country="ET" (40) are FortiGate, nginx, and other appliances except that bare manager. body="esri" && country="ET" (45) is Enketo/Kobo and registered GeoNodes. host=".gov.et" && (title="ArcGIS" || body="arcgis") matches those Enketo hosts, not a services directory. GET /arcgis/rest/services?f=json. Skip token error 499 on every folder (gis.eeu.et lists only Hosted and Utilities; the portal name is Ethiopian Electric Utility GIS Portal, and public search for Feature Service and Map Service is 0), an Apache index (gis.adc.com.et), and a site with no REST root (map.gadasez.et).
On .ir the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".ir", the body phrase alone, and the same phrase with country="IR" each returned 0 on 26 September 2026, while the registry already had 1 .ir ArcGIS server (map137.qazvin.ir, and host="map137.qazvin.ir" was 0). header="ArcGIS" && host=".ir", body="ArcGIS for Server", body="/server/rest/services" && host=".ir", cert=".ir" && title="ArcGIS", and title="ArcGIS" / body="esri/admin.css" / port="6080" / port="6443" on .gov.ir were 0. app="ArcGIS" is 820300. host=".ir" is a substring (ir.drugcloud.cn); keep hosts whose name ends in .ir. body="/arcgis/rest/services" && host=".ir" (28) and the same phrase with country="IR" (69) are news sites and pages that embed the path. port="6080" && host=".ir" (12) is noVNC and other appliances except where the title is ArcGIS. port="6080" && country="IR" (1201) and port="6443" && country="IR" (19485) are not ArcGIS. FOFA indexes the manager title ArcGIS or esri/admin.css, often as a bare IP, not /arcgis/rest/services. Use title="ArcGIS" && host=".ir" (5), body="esri/admin.css" && host=".ir" (5), app="ESRI-ArcGIS" && host=".ir" (5), port="6080" && title="ArcGIS" && host=".ir" (2, nlss.ir), and host="arcgis" && host=".ir" (2, arcgis.raromis.ir). title="ArcGIS" && country="IR" (26), body="esri/admin.css" && country="IR" (24), and app="ESRI-ArcGIS" && country="IR" (24) are those names plus bare IPs. Then ip="{address}" for a .ir vhost: 89.43.4.180 is 137.ilam.ir, 194.150.71.30 is tree.falavarjan.ir, 45.135.241.114 is ztclock.ir, and 80.191.103.211 is nlss.ir. Do not register a bare IP. 85.185.4.198 publishes a Maragheh folder, but the indexed names are shahrvandyar.com and an Amard login on port 8080, and host="maragheh.ir" was 0. 79.127.50.12 has no .ir name. Also probe title="IIS Windows Server" on gis. / maps. / map. / arcgis / geoportal / sdi. hostnames (2: gis.spcri.ir and map.damghan.ir:8081, both IIS welcome pages). GET /arcgis/rest/services?f=json. These servers listen on port 6080 over HTTP (nlss.ir, 137.ilam.ir, tree.falavarjan.ir, ztclock.ir); geo.inzamin.ir listens on 6443. Skip empty folders (arcgis.raromis.ir Map1, Maps, and Utilities), a root whose only public service is SampleWorldCities (geo.inzamin.ir), IIS welcome pages with REST 404, and a second hostname of the same directory (www.nlss.ir repeats nlss.ir; app137.ilam.ir repeats 137.ilam.ir).
On .mc the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".mc", the body phrase alone, the same phrase with country="MC", title="ArcGIS" with host=".mc" or country="MC", body="esri/admin.css" with host=".mc" or country="MC", header="ArcGIS" with host=".mc" or country="MC", app="ESRI-ArcGIS" && country="MC", port="6443" && title="ArcGIS" && host=".mc", port="6080" && country="MC", cert="arcgis" && host=".mc", host="arcgis" && host=".mc", title="Répertoire : /" && host=".mc", body="servicesDirectory" && host=".mc", body="arcgis" && host=".gouv.mc", body="esri" && host=".gouv.mc", body="gouv.mc/arcgis", body="montecarto-srv", and host="montecarto" each returned 0 on 26 September 2026. The registry had 0 .mc ArcGIS servers. app="ArcGIS" is 820300. host=".mc" is a substring of .mc.gov.lk (Colombo Municipal Council) and of a mc. label; keep hosts whose name ends in .mc. country="MC" is IP geolocation: port="6443" && country="MC" (43) is Kong, login walls, and Monaco Telecom, not a services directory. FOFA has not indexed montecarto.gouv.mc or montecarto-srv.gouv.mc (the live manager title is ArcGIS). It indexes a page that embeds the REST URL. Use body="/arcgis/rest/services" && host=".mc" (3; the only name ending in .mc is cartoradio.mc) and body="montecarto" && host=".mc" (the same page). body="esri" && host=".mc" (9) is that page plus v2.tam.mc (esri-leaflet on a job board). host="geoportail" && host=".mc" and host="geo-portail" && host=".mc" redirect to urbamonaco.gouv.mc, a planning CMS. host=".gouv.mc" (274) GIS-looking names are those aliases plus map.gouv.mc (Musée d'Anthropologie). title="IIS Windows Server" && country="MC" includes remote.mig.mc (self-signed IIS, REST 404). host="gis." && host=".mc" is gis.colombo.mc.gov.lk, not this TLD. GET /arcgis/rest/services?f=json. The public directory is montecarto-srv.gouv.mc (Server 11.3; folders APPS, Hosted, REF, and URBAMONACO are public; TEMP and Utilities return token error 499). Skip the owning portal on the same system (montecarto.gouv.mc /arcgis/rest/services is 404; owningSystemUrl is https://montecarto.gouv.mc/arcgis), ArcGIS Online (gvt-mc.maps.arcgis.com), the CartoRadio viewer, and the UrbaMonaco CMS.
On .bt the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".bt", the body phrase alone, title="ArcGIS" && host=".bt", body="esri/admin.css" && host=".bt", header="ArcGIS" && host=".bt", body="/arcgis/rest/services" && host=".bt", body="/server/rest/services" && host=".bt", and body="arcgis" && host=".gov.bt" each returned 0 on 26 September 2026. The registry had 0 .bt ArcGIS servers. app="ArcGIS" is not a FOFA rule. host=".bt" is a substring, so it also matches a leading bt. label (bt.jasolar.com, bt.pcauto.com.cn) and British Telecom names (.bt.com, .bt.co.uk). port="6443" && host=".bt" (23) and port="6080" && host=".bt" (8) are those false hosts. host="geo." && host=".bt" and host="map." && host=".bt" are the same. Keep hosts whose name ends in .bt, or filter with host=".gov.bt", host=".edu.bt", host=".org.bt", host=".com.bt", or host=".net.bt". domain=".bt" is not a TLD filter. country="BT" is IP geolocation, not the TLD: port="6443" && country="BT" (27) and port="6080" && country="BT" (11) are mostly Kubernetes, 400 responses, and appliances. FOFA indexes the manager title ArcGIS on port 6443 as a bare IP, or the IIS welcome page on the hostname, not /arcgis/rest/services. Use title="ArcGIS" && country="BT" (4), body="esri/admin.css" && country="BT" (2), header="ArcGIS" && country="BT" (1), and body="rest/services" && country="BT" (2). Then ip="{address}" to attach a .bt name (43.230.208.196 is arcgis.nlcs.gov.bt; 157.10.136.152 is cgi.nlcs.gov.bt). Also probe host="arcgis" && host=".gov.bt" (2, that IIS host), host=".gov.bt" && (host="gis" || host="geo" || host="map" || host="arcgis" || host="spatial" || host="geoportal") (the same host), and title="IIS Windows Server" && host=".gov.bt" (3). host=".gov.bt" alone is 1531. cert="gov.bt" && (title="ArcGIS" || port="6443" || port="6080") was 0. Do not register a bare IP. GET /arcgis/rest/services?f=pjson on port 6443: ports 80 and 443 on arcgis.nlcs.gov.bt are IIS 404. Skip a web adaptor that returns Application Error (cgi.nlcs.gov.bt /portal and /server; the Server 11.1 root on 157.10.136.152:6443 returns license error 9027 and owningSystemUrl is that portal), a Portal for ArcGIS Tomcat error (103.234.126.58:7443; the redirect target gis.bpc.bt does not resolve), a manager that does not answer (103.252.84.77:6443), and a second hostname of the same directory (43.230.208.196:6443 repeats arcgis.nlcs.gov.bt:6443).
On .bh the product-sentence query is empty: body="ArcGIS REST Services Directory" && title="Folder: /" && host=".bh", the body phrase alone, and the same phrase with country="BH" each returned 0 on 26 September 2026, while the registry already had 1 .bh ArcGIS server (www.ma-investment.gov.bh). title="ArcGIS" && host=".bh", body="esri/admin.css" && host=".bh", header="ArcGIS" && host=".bh", host="arcgis" && host=".bh", app="ESRI-ArcGIS" && host=".bh", body="/server/rest/services" && host=".bh", body="ArcGIS Enterprise" && host=".bh", cert="arcgis" && host=".bh", cert=".bh" && title="ArcGIS", title="Portal for ArcGIS" && country="BH", port="6443" / port="6080" with title="ArcGIS" && host=".bh", title="ArcGIS" on .gov.bh / .com.bh / .edu.bh / .org.bh / .net.bh, body="arcgis" and body="esri" on .gov.bh, host="webgis" && host=".bh", host="geo" and host="map" with host=".gov.bh", and title="IIS Windows Server" on gis. / maps. / arcgis / geoportal / webgis hostnames with host=".bh" were 0. app="ArcGIS" is 820300. host=".bh" is a substring, so it also matches a bh. label (bh.ydqh.com.cn, maps.tra.bh.speedchecker.com). port="6443" && host=".bh" (6) is those labels. title="Folder: /" && host=".bh" is cf.ruw.edu.bh (e-Course Folder). Keep hosts whose name ends in .bh. country="BH" is IP geolocation (AWS Bahrain and other local addresses), not the TLD: port="6443" && country="BH" is 678 and mostly logins. FOFA does not index /arcgis/rest/services for the registered server. domain="ma-investment.gov.bh" (4) is that host; the HTML title is مستكشف البحرين الجغرافي البلدي, and the services directory returned 403 from this network. Use title="ArcGIS" && country="BH" (6), body="esri/admin.css" && country="BH" (4), app="ESRI-ArcGIS" && country="BH" (4), and cert="arcgis" && country="BH" (5). Those rows are bare managers on 16.24.105.55 (certificate ARCIMAGE), 16.24.106.196 (ARCGIS), 15.185.246.98 (MICROGISAWS), and 77.69.251.209 (POC.MICROCENTERGULF.COM, not a .bh name). ip= on those addresses does not attach a .bh hostname. Do not register a bare IP. The live GET to port 6443 timed out, and 77.69.251.209:6443 refused the connection. Also probe host="gis." && host=".bh" (nred.gis.rera.gov.bh), host="geoportal" && host=".bh" (geoportal.slrb.gov.bh), body="/arcgis/rest/services" && host=".bh" (infracorp.bh), host=".gov.bh" && (host="gis." || host="arcgis" || host="maps."), and title="IIS Windows Server" && host=".gov.bh" (ewameter.gov.bh, eservices.culture.gov.bh). host="maps." && host=".bh" is Speedchecker and maps.google.com.bh. body="arcgis" across the public suffixes is infracorp.bh plus bh.x7m2c.mobi. GET /arcgis/rest/services?f=pjson and /server/rest/services?f=pjson. Skip 403 (geoportal.slrb.gov.bh on both paths), a page that only embeds server.arcgisonline.com World Street Map tiles (infracorp.bh), token error 499 on every folder (nred.gis.rera.gov.bh and aqari.rera.gov.bh are the same Server 11.5 root: the root services array is empty, Hosted and Utilities require a token, and owningSystemUrl is https://aqari.rera.gov.bh/portal), and hosts that time out (ewameter.gov.bh, the four bare managers).
ArcGIS Experience Builder (experiencebuilder)
Esri configurable web app (Jimu). Product: ArcGIS Experience Builder. Distinct from ArcGIS Hub (arcgishub), ArcGIS Server REST (arcgisserver), ArcGIS Web AppBuilder (webappbuilder), ArcGIS Instant Apps (instantapps), and Esri Finland dmCity (dmcity).
Signals: experience.arcgis.com/experience/{id}; Portal /portal/apps/experiencebuilder/experience/?id=; jimu-core/init.js; title Experience; favicon exb.ico. Swedish county WebbGIS on ext-webbgis.lansstyrelsen.se/{tenant}/ is this product.
Confirm: GET the app URL and match Jimu / Experience Builder. One record per public app (item id or Länsstyrelsen tenant path), not per widget. Do not set experiencebuilder on web.dmcity.fi/{city}/public/ (dmcity), on /apps/webappviewer/ (webappbuilder), or on /apps/instant/ (instantapps). Keep an existing arcgisserver REST directory on the same host as a separate catalog.
| Tool | Query |
|---|---|
site:experience.arcgis.com/experience | |
inurl:/portal/apps/experiencebuilder/experience | |
site:ext-webbgis.lansstyrelsen.se | |
| Censys | web.endpoints.http.body: "jimu-core/init.js" |
| FOFA | body="jimu-core/init.js" |
Skip Experience Builder samples on developers.arcgis.com and login-only drafts.
ArcGIS Web AppBuilder (webappbuilder)
Esri Web AppViewer (predecessor of Experience Builder). Docs: Web AppBuilder. Distinct from Experience Builder (experiencebuilder), Instant Apps (instantapps), and ArcGIS Hub (arcgishub).
Signals: /apps/webappviewer/index.html?id= on *.maps.arcgis.com or /portal/apps/webappviewer/. Exported self-hosted builds load env.js, simpleLoader.js, init.js, and Jimu assets such as jimu.js/css or #jimu-layout-manager.
Confirm: GET the viewer URL. One record per public app id. Do not also register the same host’s REST /arcgis/rest/services as a second Web AppBuilder catalog; keep arcgisserver if that directory is already the catalog.
| Tool | Query |
|---|---|
inurl:/apps/webappviewer/index.html | |
inurl:/portal/apps/webappviewer/ | |
| Censys | web.endpoints.http.body: "/apps/webappviewer/" |
| FOFA | body="/apps/webappviewer/" |
ArcGIS Dashboards (arcgisdashboards)
Esri location-analytics dashboards with maps, indicators, charts, gauges, and lists. Product: ArcGIS Dashboards. Distinct from ArcGIS Hub (arcgishub), Experience Builder (experiencebuilder), Web AppBuilder (webappbuilder), and Instant Apps (instantapps).
Signals: /apps/dashboards/{item-id} on www.arcgis.com, *.maps.arcgis.com, or an ArcGIS Enterprise portal; title ArcGIS Dashboards; dashboard JavaScript application shell.
Confirm: GET the public dashboard and match the exact /apps/dashboards/ route. One record per public dashboard item when it functions as the catalog interface. Keep an existing ArcGIS Server REST directory as a separate catalog only when it exposes a broader service catalog.
| Tool | Query |
|---|---|
inurl:/apps/dashboards/ (GIS OR map OR data) | |
site:maps.arcgis.com/apps/dashboards | |
| Censys | web.endpoints.http.body: "ArcGIS Dashboards" |
| FOFA | body="ArcGIS Dashboards" |
ArcGIS Instant Apps (instantapps)
Esri template-based public map apps (Basic, Sidebar, Lookup, Filter Gallery, Minimalist). Product: ArcGIS Instant Apps. Distinct from Experience Builder (experiencebuilder), Web AppBuilder (webappbuilder), ArcGIS Hub (arcgishub), and ArcGIS Server REST (arcgisserver).
Signals: /apps/instant/{template}/index.html?appid= on *.maps.arcgis.com or Portal /portal/apps/instant/. Templates include basic, sidebar, lookup, filtergallery, minimalist.
Confirm: GET the Instant App URL. One record per public appid. Filter Gallery and org galleries are hunt sources (lists of apps), not a second catalog. Do not set instantapps on /apps/webappviewer/ (webappbuilder) or experience.arcgis.com / jimu-core/init.js (experiencebuilder). Keep an existing arcgisserver REST directory on the same host as a separate catalog.
| Tool | Query |
|---|---|
inurl:/apps/instant/ basic OR sidebar OR lookup site:maps.arcgis.com | |
inurl:/apps/instant/index.html?appid= | |
| Censys | web.endpoints.http.body: "/apps/instant/" |
| FOFA | body="/apps/instant/" |
Lizmap (lizmap)
QGIS Server web client. Signals: /index.php/view/, lizMap, project list. Vendor: lizmap.com. OpenSIS / pgMetadata DCAT wrappers that still serve Lizmap (lizmapPopup, dock CSS, /index.php/view/) stay lizmap; do not invent opensis. Do not set lizmap from /index.php/view/ when the HTML is the same CMS homepage (SIG Cévennes).
lizmap/modules/view/templates/map.tpl includes the custom element lizmap-navbar (47 hosts in September 2026). body="lizMap" matched 4,192 and still covers older clients that do not ship that element.
| Tool | Query |
|---|---|
"Lizmap" (webgis OR geoportail OR "qgis") -site:github.com | |
inurl:lizmap inurl:index.php/view | |
| Censys | web.endpoints.http.body: "lizmap-navbar" |
| FOFA | body="lizmap-navbar" |
| Censys | web.endpoints.http.body: "lizMap" |
| FOFA | body="lizMap" |
Geotrek (geotrek)
French outdoor/trail suite (GeotrekCE). Public catalogs are Geotrek-rando sites (v2 or v3). Docs: geotrek.fr, instance list: Liste des Geotrek connus, map: utilisateurs.geotrek.fr. Distinct from GeoNature-atlas on the same park.
Signals: --color-primary1-default (v3); ng-app="geotrekRando" (v2); title Geotrek-rando; __NEXT_DATA__ / /_next/ (v3); Geotrek-admin /api/v2/trek/. Hosts often rando.*, destination.*, or *rando*.
Confirm: GET the public rando home. One record per public rando portal, not Geotrek-admin /login/, not geotrek.fr, not mobile apps, not Geotrek-rando-widget embeds on a tourism CMS, and not district search URLs of the same hub (Via Columbani, Chemins des Parcs, Rando IdF).
_document.tsx writes --color-primary1-default (322 hosts in September 2026, including rando.parcdumorvan.org and www.rando-aubrac.fr). v2 public/index.html sets ng-app="geotrekRando" (14 hosts, including rando-pnropf.pnr-idf.fr and randotectec.reunion-parcnational.fr). body="Geotrek-rando" matched 181, including www.terresdecorreze.com. body="geotrekApp" matched nothing.
| Tool | Query |
|---|---|
"Geotrek-rando" OR "Geotrek rando" (randonnée OR trek) -site:github.com -site:geotrek.fr | |
inurl:rando geotrek OR "geotrek-rando" site:.fr | |
| Censys | web.endpoints.http.body: "--color-primary1-default" |
| FOFA | body="--color-primary1-default" |
| Censys | web.endpoints.http.body: "geotrekRando" |
| FOFA | body="geotrekRando" |
| Censys | web.endpoints.http.body: "Geotrek-rando" |
| FOFA | body="Geotrek-rando" |
GeoNature (geonature)
French biodiversity suite (PnX-SI). Public catalogs are GeoNature-atlas sites. Docs: geonature.fr, GeoNature-atlas. Distinct from Lizmap cartothèques on the same park.
Signals: /static/css/atlas.css; TaxHub media URLs (/geonature/api/taxhub/); gunicorn + Leaflet species sheets. Title often Biodiv'….
Confirm: GET the public atlas home. One record per public atlas, not the authenticated GeoNature back-office (/geonature/) and not the project site geonature.fr.
assets_header.html links /static/css/atlas.css (409 hosts in September 2026). Indexed pages include GeoNature-atlas homes such as Biodiv'Mercantour.
| Tool | Query |
|---|---|
"GeoNature-atlas" OR "GeoNature atlas" (biodiversité OR biodiv) -site:github.com | |
inurl:biodiversite "atlas.css" site:.fr | |
| Censys | web.endpoints.http.body: "/static/css/atlas.css" |
| FOFA | body="/static/css/atlas.css" |
G3W-SUITE (g3wsuite)
Open-source QGIS WebGIS (G3W-ADMIN + G3W-CLIENT). Site: g3wsuite.it. Distinct from Lizmap (lizmap) and QWC2 (qwc2).
Signals: title or footer “G3W-SUITE”; g3w-client / g3wsdk in JS; path /map/{group}/{project}/; REST /api/ or /group/api/.
Confirm: GET the public portal or /map/ client and match G3W-CLIENT. One record per public portal (tenant), not per QGIS project. Skip /admin login. If QGIS Server on the same host is only the OGC backend, do not also register qgisserver. Do not set g3wsuite from GisClient (widgetGisClient.js, gcTool, ?mapset=) — that is a different product.
index.html serves /static/client/images/g3wsuite_logo.png (12 hosts in September 2026, including map.geo.lea-ti.ch). body="g3w-client" matched 8, the same maps. body="startingspinner" is not usable: the first hits are chocolate shops. body="G3W-SUITE" matched 248, including erp.kartoza.com.
| Tool | Query |
|---|---|
"G3W-SUITE" OR "G3W-CLIENT" (webgis OR geoportale) -site:github.com -site:g3wsuite.it | |
inurl:/map/ g3w (webgis OR qgis) site:.it | |
| Censys | web.endpoints.http.body: "g3wsuite_logo.png" |
| FOFA | body="g3wsuite_logo.png" |
| Censys | web.endpoints.http.body: "g3w-client" |
| FOFA | body="g3w-client" |
NextGIS Web (nextgisweb)
Signals: /resource/0, NextGIS Web UI, /api/resource/.
| Tool | Query |
|---|---|
"NextGIS Web" OR inurl:/resource/0 "nextgis" | |
| Censys | web.endpoints.http.body: "NextGIS" |
| FOFA | body="NextGIS" |
GC2 (gc2)
MapCentia GC2 (GeoCloud 2) spatial-data platform, often with the Vidi viewer. OSGeo: GC2/Vidi. Distinct from Japanese GC Navi (gcnavi) on geocloud.jp.
Signals: title “MapCentia GeoCloud”; path /apps/viewer; /mapcache/{tenant}/wmts; /api/v1/sql/{db}; /api/v2/configuration; hosts *.mapcentia.com or *.gc2.io.
Confirm: GET /apps/viewer or MapCache WMTS GetCapabilities. One record per public tenant, not the MapCentia marketing site or map.gc2.io demo.
index.html sets window.MapCentia (45 hosts in September 2026, including vidi.swarm.gc2.io). The static title MapCentia GeoCloud is not in the indexed HTML. Hosted tenants that drop the viewer script still match mapcentia.com, so keep that query.
| Tool | Query |
|---|---|
"MapCentia" OR GC2 (geoportal OR GeoCloud) (inurl:mapcentia.com OR inurl:gc2.io) -site:github.com | |
inurl:/apps/viewer MapCentia OR inurl:/mapcache/ | |
| Censys | web.endpoints.http.body: "window.MapCentia" |
| FOFA | body="window.MapCentia" |
| Censys | web.names: "mapcentia.com" |
| FOFA | domain="mapcentia.com" |
| crt.sh | %.mapcentia.com OR %.gc2.io |
hale»connect (haleconnect)
wetransform INSPIRE/SDI publishing platform. Product: hale»connect. CSW is often pycsw-backed — still set haleconnect, not pycsw, when hale»connect is the public catalog.
Signals: “hale connect” / hale»connect branding; /csw?service=CSW; /ows/services/org. WMS/WFS; hosts haleconnect.com, GovConnect, Komm.ONE, and other tenants.
Confirm: GET CSW GetCapabilities or the public geoportal home. One record per public cloud or on-prem tenant, not per WMS layer.
| Tool | Query |
|---|---|
"hale connect" OR haleconnect OR "hale»connect" (INSPIRE OR CSW OR geoportal) -site:wetransform.to | |
inurl:haleconnect.com/csw OR "powered by hale" | |
| Censys | web.endpoints.http.body: "hale connect" |
| FOFA | body="hale connect" |
STAC API (stacserver)
Static catalogs (catalog.json) and STAC API. Index: stacindex.org/catalogs.
Confirm: GET https://host/stac or /catalog.json with "type": "Catalog" or STAC API "/conformance" plus /collections. Register the API root, not every collection.
| Tool | Query |
|---|---|
"stac" "catalog.json" OR inurl:/stac filetype:json | |
| Censys | web.endpoints.http.body: "stac_version" |
| FOFA | body="stac_version" |
Do not add STAC items as catalogs.
STAC Browser (stacbrowser)
Radiant Earth STAC Browser (or a fork) as the public catalog UI. Confirm the HTML app title/footer mentions STAC Browser and that it points at a STAC API.
If that API is already registered as stacserver on the same host, do not add a second record unless the browser is the only public product (API is private or on another origin already listed). Prefer stacserver when both are public on the same origin.
GitHub, do both. Code search does not index most forks. Upstream is radiantearth/stac-browser. index.html contains the noscript “STAC Browser doesn't work properly”. config.js holds catalogUrl — that value is the catalog to consider. A null catalogUrl is a generic browser, not a catalog.
| Tool | Query |
|---|---|
| GitHub forks | repos/radiantearth/stac-browser/forks |
| GitHub code | "STAC Browser doesn't work properly" filename:index.html |
"stac-browser" OR "radiantearth" catalog | |
| Censys | web.endpoints.http.body: "stac-browser" |
| FOFA | body="stac-browser" |
| FOFA | body="STAC Browser doesn't work properly" |
openEO (openeo)
EO cloud-processing API with a STAC-compatible collection catalog. Site: openeo.org. Backends include Copernicus Data Space, VITO, EODC, mundialis Actinia, and the Google Earth Engine driver.
Confirm: GET the API landing page (often /openeo/1.2/ or /v1.0/) JSON with api_version plus endpoints for GET /collections and GET /processes. /.well-known/openeo lists versions.
| Tool | Query |
|---|---|
"openeo" ("api_version" OR /collections OR /processes) -site:github.com -site:openeo.org | |
inurl:/openeo/ (collections OR processes) | |
| Censys | web.endpoints.http.body: "openeo" |
| FOFA | body="openeo" |
Register the backend API root, not Hub HTML alone, unless Hub is the public product (hub.openeo.org). Prefer openeo over stacserver when /processes is part of the same API. Skip process-graph playgrounds with no collection list.
Sentinel Hub (sentinelhub)
Earth-observation catalog and processing API (Sinergise / Planet). Docs: docs.sentinel-hub.com. Official STAC: https://services.sentinel-hub.com/api/v1/catalog/1.0.0/. Distinct from generic STAC (stacserver) and from Sentinel Hub openEO backends (openeo).
Signals: hostname *.sentinel-hub.com; STAC /api/v1/catalog; Process API /api/v1/process; EO Browser / Copernicus Browser UI.
Confirm: GET the STAC catalog root JSON (type Catalog/STAC API) or the documented OGC WMS/WMTS. One record per public catalog API (not every collection, not EO Browser as a second catalog if the STAC API is already registered). Prefer sentinelhub over stacserver on Sentinel Hub hosts.
| Tool | Query |
|---|---|
"Sentinel Hub" (STAC OR catalog OR "EO Browser") -site:github.com | |
site:services.sentinel-hub.com catalog | |
| Censys | web.names: "sentinel-hub.com" |
| FOFA | domain="sentinel-hub.com" |
Solargis (solargis)
Commercial solar energy and meteorological data platform (Solargis s.r.o., Bratislava). Docs: solargis.com/solar-data-apis. One global SaaS — register the public maps-and-gis-data download/catalog host once, not per-user Evaluate projects.
Signals: hostname solargis.com (maps-and-gis-data download section); references to Solargis Atlas, Solargis Data API (REST), or Solargis WMS API.
Confirm: GET the maps-and-gis-data download page or the documented Data/WMS API entry points. Do not split Atlas, Evaluate, and the download host into separate records. Vendor-hosted commercial service, not self-hosted installable software.
| Tool | Query |
|---|---|
site:solargis.com ("maps and gis data" OR "data api" OR atlas) | |
| Censys | web.names: "solargis.com" |
| FOFA | domain="solargis.com" |
pygeoapi (pygeoapi)
OGC API Features / Records. Confirm: / or /openapi JSON with pygeoapi in generator/headers; /collections.
The HTML shell pygeoapi/templates/_base.html serves static/img/pygeoapi.png (381 hosts in September 2026). body="pygeoapi" matched 476 and includes documentation hosts (docs.georama.io). Operators copy pygeoapi-config.yml from the repo root. Forks of geopython/pygeoapi are the software, not a portal list.
| Tool | Query |
|---|---|
| GitHub code | filename:pygeoapi-config.yml |
"pygeoapi" (collections OR "ogc api") -site:github.com | |
| Censys | web.endpoints.http.body: "static/img/pygeoapi.png" |
| FOFA | body="static/img/pygeoapi.png" |
| Censys | web.endpoints.http.body: "pygeoapi" |
| FOFA | body="pygeoapi" |
SmartMet Server (smartmetserver)
FMI open-source MetOcean data server (fmidev/smartmet-server). Confirm: HTTP Server header SmartMet Server, plus a live plugin: /wms?service=WMS&request=GetCapabilities titled SmartMet, /edr/collections JSON, /wfs?service=WFS&request=GetCapabilities, or /timeseries (HTTP 400 without params still means the plugin is loaded). Typical catalog_type is Geoportal. Register one public tenant per independently operated host. Do not add a second copy of the same cluster: data.fmi.fi is the API-key twin of opendata.fmi.fi; harmonia.geoss.space and urban.geoss.space alias data.geoss.space. Skip SmartMet Workstation / SmartMet Alert forecast-production installs (no public catalog API). The site root often 404s — probe plugins, not /.
AsyncConnection.cpp sets the Server header to SmartMet Server (48 hosts in September 2026, including opendata.fmi.fi and FMI address-space IPs). The document root on many installs is the plain text SmartMet Server. That body string is what FOFA still sees when nginx replaces the Server header (modelo.aviamet.com.co). Hosts whose root is a 404 HTML page match the header query and not the body query, so run both. body="Web Map Service Powered by SmartMet Server" (the default abstract in docker-smartmetserver wms.conf) returned 0 FOFA hits because GetCapabilities URLs are not crawled.
FMI country installs are GitHub organizations named smartmet-{iso2} (14 orgs in September 2026: bt, co, ee, et, ge, jm, ke, kg, rw, tj, tz, ua, uz, vn) plus meteofi/portainer. The public hostname is the Traefik label traefik.http.routers.smartmetserver.rule=Host(...) in smartmetserver/docker-compose.yml. Code search misses orgs that commit docker-compose.yaml (Uzbekistan); read APPDOMAIN in portainer/docker-compose.yaml (data.${APPDOMAIN} → data.apps.meteo.uz). Forks of fmidev/smartmet-server are the software, not a portal list. Keep a host only when /edr/collections or WMS GetCapabilities lists datasets, or /timeseries returns values (X-TimeSeriesPlugin-Error: The 'param' option is required! on a bare GET only proves the plugin is loaded).
| Tool | Query |
|---|---|
| GitHub code | routers.smartmetserver.rule |
| GitHub orgs | smartmet-{iso2} portainer compose Host() |
"SmartMet Server" (WMS OR EDR OR timeseries OR WFS) -site:github.com | |
| Censys | web.endpoints.http.body: "SmartMet Server" |
| FOFA | header="SmartMet Server" |
| FOFA | body="SmartMet Server" |
| urlscan | page.server:SmartMet |
MapStore (mapstore)
GeoSolutions MapStore. Signals: /mapstore, MapStore2. The splash in web/client/indexTemplate.html uses the class _ms2_init_text (507 hosts in September 2026). body="Loading MapStore" in the same file matched 218.
Do not set mapstore on GAUSS WebCity / WebPresenter tenants ({org}.gis.ba, /webcity/, logo_gauss.png) — use gausswebcity (viewers).
| Tool | Query |
|---|---|
"MapStore" geoportal OR inurl:/mapstore -site:github.com | |
| Censys | web.endpoints.http.body: "_ms2_init_text" |
| FOFA | body="_ms2_init_text" |
| Censys | web.endpoints.http.body: "MapStore" |
| FOFA | body="MapStore" |
QWC2 (qwc2)
QGIS Web Client 2. Signals: qwc2, qwc-services, /theme/ map UI, assets/css/qwc2.css (Schaumburg /maps/). That stylesheet path is the <link> in upstream index.html (430 hosts in September 2026). Do not set qwc2 from {tenant}.tergis.lv (use tergis).
| Tool | Query |
|---|---|
"QWC2" OR "QGIS Web Client" geoportal | |
| Censys | web.endpoints.http.body: "assets/css/qwc2.css" |
| FOFA | body="assets/css/qwc2.css" |
| Censys | web.endpoints.http.body: "qwc2" |
| FOFA | body="qwc2" |
Mapbender (mapbender)
Open-source geoportal framework (WhereGroup). Signals: Mapbender application UI, /mapbender/application/ or /mapbender/app.php/application/, configurable map viewers on OGC services. Symfony publishes src/Mapbender/CoreBundle/Resources/public at /bundles/mapbendercore/ (189 hosts in September 2026, including harmonisiert.geoportal-suedhessen.de). Mapbender.MapModelBase in frontend.js is minified out of the served page. A homepage that JS-redirects to /mapbender/application/{name} (Offenbach) counts. Vendor: mapbender.org. Do not set mapbender on a CMS hub that only links another agency’s Mapbender (Merzig-Wadern → Saarland; Trier-Saarburg → GeoPortal.rlp).
| Tool | Query |
|---|---|
"Mapbender" (geoportal OR Anwendung OR "map application") -site:github.com -site:mapbender.org | |
inurl:/application/ mapbender | |
| Censys | web.endpoints.http.body: "bundles/mapbendercore" |
| FOFA | body="bundles/mapbendercore" |
| Censys | web.endpoints.http.body: "Mapbender" |
| FOFA | body="Mapbender" |
Do not register a Mapbender app that is only a login shell with no public map list.
MapTiler Server (maptilerserver)
Self-hosted tile and map-style catalog. Default port 3650; production sites often sit behind HTTPS on 443. Signals: HTML title MapTiler Server, /admin login, Next.js __NEXT_DATA__ pageProps (serverName, rasterizationEnabled, type). type: list is a public catalog page. type: logoOnly hides that page behind a logo, but the catalog API can still list data.
The homepage does not embed the dataset list. Confirm datasets with GET https://host/api/frontpage, which returns {maps, activeTileSets}. Keep a host when either list is non-empty. Skip staging hostnames (dev, qa, demo) and vendor-sample installs whose only tileset is MapTiler Data (Zurich sample) or MapTiler Satellite Demo Zürich. Register one record per instanceId (Dawonia housing hostnames share e8bce03b with www.maptiler.dawonia.de). Register the public catalog root, not /admin. A logoOnly host with a non-empty frontpage is still a catalog. Bare /api/maps 404s; a style check is GET /api/maps/{mapId}/style.json.
body="rasterizationEnabled" is the stable HTML fingerprint (170 hosts in September 2026, all titled MapTiler Server). body="AUTH_FAKE_TOKEN" matches newer Next.js builds only (185 hosts) and misses older shells such as tiles.atlas.mchs.gov.ru. body="/api/frontpage" is not a fingerprint.
| Tool | Query |
|---|---|
intitle:"MapTiler Server" -site:maptiler.com -site:github.com | |
| Censys | web.endpoints.http.html_title: "MapTiler Server" |
| FOFA | title="MapTiler Server" |
| Censys | web.endpoints.http.body: "rasterizationEnabled" |
| FOFA | body="rasterizationEnabled" |
| Censys | web.endpoints.http.body: "AUTH_FAKE_TOKEN" |
| FOFA | body="AUTH_FAKE_TOKEN" |
| FOFA | body="MapTiler Server" |
| Shodan | http.title:"MapTiler Server" |
MapServer (mapserver)
OGC service middleware (WMS/WFS/WCS from a mapfile). Register it when MapServer is the public catalog (GetCapabilities or a map list as the product), not merely the renderer behind Lizmap, QWC2, GeoNetwork, or p.mapper.
Confirm: WMS GetCapabilities whose service metadata mentions MapServer (cgi-bin/mapserv, mapserv.exe, or a MapServer keyword). Typical paths: /cgi-bin/mapserv, /cgi-bin/mapserv.cgi, or a named .map URL.
maperror.c writes MapServer version into the server message (47 hosts in September 2026, including map.feltgis.no). body="MapServer" is not usable: it matched 30,476 unrelated hosts.
| Tool | Query |
|---|---|
inurl:cgi-bin/mapserv (WMS OR GetCapabilities) | |
"MapServer" GetCapabilities -site:mapserver.org -site:github.com | |
| Censys | web.endpoints.http.body: "MapServer version" |
| FOFA | body="MapServer version" |
| Shodan | http.html:"MapServer version" |
Do not add a second record for MapServer on a host that already has a Lizmap, QWC2, GeoNetwork, or p.mapper catalog pointing at the same services. Do not set mapserver on {city}.geo-portale.it /pmapper-4.2.0/ UIs (pmapper).
QGIS Server (qgisserver)
OGC service middleware from a QGIS project (WMS/WFS/WCS, OGC API). Register it when QGIS Server is the public catalog (GetCapabilities as the product), not merely the renderer behind Lizmap, QWC2, or mviewer.
Confirm: WMS GetCapabilities whose service metadata mentions QGIS Server (qgis_mapserv.fcgi, MAP= .qgs / .qgz, or a QGIS keyword). Typical paths: /cgi-bin/qgis_mapserv.fcgi, /ows, or a named .qgs URL.
| Tool | Query |
|---|---|
inurl:qgis_mapserv.fcgi (WMS OR GetCapabilities) | |
"QGIS Server" GetCapabilities -site:qgis.org -site:github.com | |
| Censys | web.endpoints.http.body: "QGIS Server" |
| FOFA | body="QGIS Server" |
| Shodan | http.html:"QGIS Server" |
Do not add a second record for QGIS Server on a host that already has a Lizmap, QWC2, or mviewer catalog pointing at the same services.
mviewer (mviewer)
GéoBretagne thematic map viewer (OpenLayers). Common in French régions, départements, and communes. Site: mviewer.github.io. Distinct from Lizmap (lizmap) and QWC2 (qwc2).
Signals: mviewer in HTML/JS; config XML under /apps/ (often default.xml); optional mviewerstudio; GéoBretagne / Kartenn branding.
Confirm: GET the viewer URL and match mviewer JS plus a public layer/theme config. One record per public application (config), not per layer.
GitHub, do both. Code search does not index most forks. Upstream is geobretagne/mviewer. index.html links css/mviewer.css (88 hosts in September 2026).
| Tool | Query |
|---|---|
| GitHub forks | repos/geobretagne/mviewer/forks |
| GitHub code | css/mviewer.css filename:index.html |
"mviewer" (géoportail OR geoportail OR "openlayers") -site:github.com -site:mviewer.github.io | |
inurl:mviewer (apps OR config.xml) site:.fr | |
| Censys | web.endpoints.http.body: "css/mviewer.css" |
| FOFA | body="css/mviewer.css" |
| Censys | web.endpoints.http.body: "mviewer" |
| FOFA | body="mviewer" |
Skip mviewerstudio admin and demo configs on mviewer.github.io unless the task is to record them.
Isogeo (isogeo)
French SaaS GIS metadata catalog (OpenCatalog / App). Vendor: isogeo.com. Distinct from IsiGéo (isigeo, Geomatika).
Signals: title or footer “Isogeo” / OpenCatalog; path /api OpenAPI; ISO 19115 inventory; often CSW.
Confirm: GET /api (OpenAPI mentioning Isogeo) or the public OpenCatalog search UI. One record per public catalog, not per metadata sheet.
| Tool | Query |
|---|---|
"Isogeo" (OpenCatalog OR géocatalogue OR "catalogue de données") site:.fr -site:isogeo.com | |
"powered by Isogeo" OR "OpenCatalog Isogeo" | |
| Censys | web.endpoints.http.body: "Isogeo" |
| FOFA | body="Isogeo" |
Do not set isigeo (IsiGéo) for an Isogeo OpenCatalog.
gvSIG Online (gvsigonline)
Municipal / regional SDI built by the gvSIG Association. Demo and docs: demo.gvsigonline.com. GeoServer is required underneath; optionally GeoNetwork.
Signals: path /gvsigonline/; public project picker select_public_project; title or footer “gvSIG Online”.
Confirm: GET https://host/gvsigonline/ (or the catalog link) and match the gvSIG Online UI. Prefer the public viewer root, not /geoserver/web. Skip the demo unless the task is to record it.
base.html links css/gvsigOL.css (63 hosts in September 2026, including visualizador.ide.uy). body="select_public_project" matched 53. body="gvSIG Online" matched 73, the same product, so keep both.
| Tool | Query |
|---|---|
"gvSIG Online" (geoportal OR visor OR IDE) -site:gvsig.com -site:github.com | |
inurl:/gvsigonline/ select_public_project | |
| Censys | web.endpoints.http.body: "gvsigOL.css" |
| FOFA | body="gvsigOL.css" |
| Censys | web.endpoints.http.body: "select_public_project" |
| FOFA | body="select_public_project" |
| Censys | web.endpoints.http.body: "gvSIG Online" |
| FOFA | body="gvSIG Online" |
One record per public SDI UI. Do not also register the bundled GeoServer as a separate catalog on the same host.
deegree (deegree)
Open-source Java SDI stack (WMS, WFS, WMTS, CSW, WPS, and deegree ogcapi). Used as INSPIRE service middleware.
Confirm: GetCapabilities on /deegree-webservices, /services, or a documented service path whose XML mentions deegree. CSW and OGC API Features are enough to treat it as a catalog when that is the public product.
| Tool | Query |
|---|---|
"deegree" (CSW OR WMS OR "ogcapi") GetCapabilities -site:github.com -site:deegree.org | |
| Censys | web.endpoints.http.body: "deegree" |
| FOFA | body="deegree" |
| Shodan | http.html:"deegree" |
VertiGIS WebOffice (weboffice)
Commercial web GIS (formerly SynerGIS WebOffice) on ArcGIS Enterprise. Vendor: vertigis.com. Multi-tenant hosts: wo-hosting.vertigis.com, map.geoportal.at.
Signals: /synserver or /WebOffice/synserver; HTML title VertiGIS WebOffice; weboffice_packed.css; core, flex, or mobile clients. A WebInfo landing that POSTs to ./synserver and loads weboffice_modern_user.css (Landkreis Osnabrück) also counts.
Confirm: GET the synserver URL and match the title plus weboffice_packed.css, or the WebInfo guest landing plus synserver. One record per public client (tenant), not per map project. Do not set weboffice on a CMS Bürgerportal that only links an already-registered wo-hosting.vertigis.com client (Radolfzell).
| Tool | Query |
|---|---|
intitle:"VertiGIS WebOffice" OR inurl:/synserver WebOffice | |
site:wo-hosting.vertigis.com OR site:map.geoportal.at | |
| Censys | web.endpoints.http.html_title: "VertiGIS WebOffice" |
| FOFA | title="VertiGIS WebOffice" |
| Censys | web.endpoints.http.body: "weboffice_packed.css" |
| FOFA | body="weboffice_packed.css" |
Geocortex Essentials (geocortex)
Commercial web GIS (Latitude Geographics, now VertiGIS Studio) on ArcGIS. Vendor: geocortex.com. Hosted tenants: *.geocortex.com. Distinct from VertiGIS WebOffice (weboffice) and VertiGIS Studio Web (vertigisstudioweb).
Signals: title Geocortex Essentials Sites Directory or Geocortex Viewer for HTML5; path /Geocortex/Essentials/ (sometimes /ess/) plus /REST/sites; /Html5Viewer/; footer “licensed Geocortex Essentials”. The HTML5 host page (Index.html) loads Resources/Compiled/loader.js and mentions geocortexUseLocalEsriApi, including when the title is rewritten.
Confirm: GET https://host/Geocortex/Essentials/REST/sites?f=pjson (instance path may include /public/, /EXT/, or a named instance). ViewerSettings.json.js beside the viewer lists site ids when the folder is not /Html5Viewer/. JSON sites array is the catalog. Keep a record only when a public site’s .../sites/{id}/map?f=pjson lists operational layers. HTML5 viewers are the public map UI, not extra catalogs. One record per Essentials instance, not per site or viewer. Do not also register the bundled ArcGIS REST root as a second Geocortex catalog; keep an existing arcgisserver record on the same host if that is already the services directory.
| Tool | Query |
|---|---|
intitle:"Geocortex Essentials Sites Directory" | |
intitle:"Geocortex Viewer for HTML5" -site:github.com | |
inurl:/Geocortex/Essentials/REST/sites OR inurl:/Html5Viewer/ | |
site:geocortex.com Html5Viewer OR Essentials -www -shop -accounts | |
| Censys | web.endpoints.http.html_title: "Geocortex Essentials Sites Directory" |
| FOFA | title="Geocortex Essentials Sites Directory" |
| Censys | web.endpoints.http.html_title: "Geocortex Viewer for HTML5" |
| FOFA | title="Geocortex Viewer for HTML5" |
| FOFA | body="Geocortex Essentials" |
| FOFA | body="/Html5Viewer/" && body="Geocortex" |
| FOFA | body="Resources/Compiled/loader.js" |
| FOFA | body="geocortexUseLocalEsriApi" |
| FOFA | body="Resources/Images/Icons/iOS/apple-touch-icon-ipad-retina.png" |
| FOFA | domain="geocortex.com" |
loader.js and geocortexUseLocalEsriApi are in the HTML5 viewer host page, so they match rewritten titles (50 and 52 hosts in September 2026). The apple-touch icon path is the same page (50). body="Resources/Styles/splash.css" (68) also matches unrelated sites. domain="geocortex.com" (64) is the hosted-tenant list and includes vendor mail, docs, and status hosts.
Skip gedemo.geocortex.com, test and dev hosts, empty Sites Directories, and sites whose map JSON is only 403.
VertiGIS Studio Web (vertigisstudioweb)
Configurable web GIS viewer (formerly Geocortex Web / GXW) on ArcGIS Online or Portal for ArcGIS. Vendor: vertigis.com. SaaS: apps.vertigisstudio.com, apps.vertigisstudio.eu. Distinct from Geocortex Essentials (geocortex) and VertiGIS WebOffice (weboffice).
Signals: /vertigisstudio/web/?app=; /gcx/WebViewer/?app=; /Geocortex/WebViewer/?app= (not /Html5Viewer/ and not /Geocortex/Essentials/REST/sites); HTML #gcx-app; GA title VertiGIS Studio Web; SaaS shells are often ~728 bytes.
Confirm: GET the viewer URL and match #gcx-app plus VertiGIS Studio Web branding. One record per public tenant, not every ?app= GUID. Keep an existing arcgisserver or geocortex record on the same host if that is already the services directory or Html5Viewer.
| Tool | Query |
|---|---|
inurl:vertigisstudio/web/?app= | |
inurl:/gcx/WebViewer/?app= OR inurl:/Geocortex/WebViewer/?app= | |
site:apps.vertigisstudio.com/web OR site:apps.vertigisstudio.eu/web | |
| Censys | web.endpoints.http.html_title: "VertiGIS Studio Web" |
| FOFA | title="VertiGIS Studio Web" |
| FOFA | body="gcx-app" |
| FOFA | body="/vertigisstudio/web/" |
Skip vendor Designer samples, login-only Designer, and extra app GUIDs on a tenant already registered.
GeoMedia WebMap (geomediawebmap)
Hexagon / Intergraph Geospatial Portal (GeoMedia WebMap Publisher Portal). Typical paths: /geoportal01/, /cdngiportal/, /msip/Full.aspx, /Online_Mapping/, /hartagisoradea/.
Signals: Version: and Licensed to: in the UI; Intergraph.WebSolutions; $GP. JavaScript; Compositor.WebClient.ashx, CRSNames.WebClient.ashx, or related WebClient.ashx handlers; title may say Geospatial Portal or GeoMedia WebMap Publisher Portal.
Confirm: GET the portal URL and match at least two of those fingerprints. Skip staff-only intranet portals that require authentication for any map list.
| Tool | Query |
|---|---|
"Geospatial Portal" ("Licensed to" OR Intergraph) -site:hexagon.com | |
"GeoMedia WebMap" (portal OR geoportal) | |
inurl:/geoportal01/ OR inurl:/cdngiportal/ OR inurl:/msip/Full.aspx | |
| Censys | web.endpoints.http.body: "Intergraph.WebSolutions" |
| FOFA | body="Intergraph.WebSolutions" |
Micka (micka)
Czech/Slovak metadata catalog. Signals: /micka, HSLayers, “Micka”.
The catalog layout @layout.latte links micka.css (9 hosts in September 2026, including metadata.vumop.cz). body="micka" is not usable: it matched 3,301 unrelated hosts, including ranstatradgard.se.
| Tool | Query |
|---|---|
"Micka" (metadata OR geoportal OR CSW) site:.cz OR site:.sk | |
| Censys | web.endpoints.http.body: "micka.css" |
| FOFA | body="micka.css" |
HSLayers NG (hslayersng)
Czech open-source web mapping framework (Angular + OpenLayers + CesiumJS) used for map-composition catalogs; usually paired with a Layman backend and often a Micka CSW sibling. Typical deployments: Hub4Everybody-platform hubs (/map/, /mapy/ pages with composition galleries). Signals: hslayers / hslayers-ng JS bundles, layman-proxy or /rest/workspaces/{workspace}/maps composition URLs, “Hub4Everybody” platform links.
Confirm: GET the map app and match hslayers in the page, then verify the Layman REST listing (/rest/workspaces/<workspace>/maps or /layman-proxy/rest/workspaces/<workspace>/maps) returns a JSON array with access_rights. One record per public map hub. Skip ISP network-coverage viewers (HsOptika portals such as hsoptika.* / optika.*), single-map embeds on municipal pages, the dead official demo (ng.hslayers.org redirects to the GitHub wiki), and WordPress front pages that merely link to the platform.
| Tool | Query |
|---|---|
"hslayers" (geoportal OR map OR compositions) -site:github.com | |
inurl:/mapy/ OR inurl:/map/ "hub4everybody" | |
| Censys | web.endpoints.http.body: "hslayers-ng" |
| FOFA | body="hslayers" (expect HsOptika ISP noise) or body="hub4everybody" |
Layman (layman)
Open-source geodata publication server (Layer Manager) by CCSS / Plan4all: REST API for layers and map compositions over GeoServer / PostGIS / QGIS Server with Micka metadata. Almost always reached through an HSLayers NG client, so hunt the client fingerprints above; the server itself answers JSON at /rest/workspaces/... (root /rest/ may 404 while item paths resolve). Signals: /rest/workspaces/, /layman-proxy, “Layman Test Client”.
Confirm: GET /rest/workspaces/<workspace>/maps/<name> or the workspace maps listing and match Layman JSON (access_rights with EVERYONE, bounding_box, file.path). Public workspaces are readable without login.
| Tool | Query |
|---|---|
inurl:/rest/workspaces/ maps layman | |
| Censys | web.endpoints.http.body: "/rest/workspaces/" |
| FOFA | body="/layman/rest" or title="Layman Test Client" |
GeoBlacklight (geoblacklight)
Library geoportals (often US universities). Showcase: geoblacklight.org/showcase. The home partial app/views/catalog/_home_text.html.erb includes id="geoblacklight-version" (62 hosts in September 2026). That div is on the home page, so keep body="geoblacklight" for record pages FOFA indexed without the home markup.
| Tool | Query |
|---|---|
"GeoBlacklight" OR inurl:/catalog geoblacklight site:.edu | |
| Censys | web.endpoints.http.body: "geoblacklight-version" |
| FOFA | body="geoblacklight-version" |
| Censys | web.endpoints.http.body: "geoblacklight" |
| FOFA | body="geoblacklight" |
Oskari (oskari)
Finnish SDI map client. Signals: Oskari, /Oskari/, map full-screen UI.
Confirm: GET the public map UI. One record per independent portal. Reject Oskari RPC embeds of another catalog (Suomi.fi Maps / HKP hkp.maanmittauslaitos.fi embeds on Kalastusrajoitus.fi and similar) and login-walled publishers (API 403).
servlet-map/.../spring-map-jsp/index.jsp links oskari.min.css (39 hosts in September 2026, including kartta.museoverkko.fi). body="Oskari" matched 2,044 hosts, including pages that use the Finnish name and are not the map client.
| Tool | Query |
|---|---|
"Oskari" (geoportal OR kartta) -site:oskari.org | |
| Censys | web.endpoints.http.body: "oskari.min.css" |
| FOFA | body="oskari.min.css" |
| Censys | web.endpoints.http.body: "Oskari" |
| FOFA | body="Oskari" |
Esri Geoportal Server (esrigeo)
Older Esri metadata catalog (not Hub). Signals: /geoportal, Geoportal Server, CSW.
| Tool | Query |
|---|---|
"Geoportal Server" Esri OR inurl:/geoportal/csw | |
| Censys | web.endpoints.http.body: "Geoportal Server" |
| FOFA | body="Geoportal Server" |
disy Cadenza (cadenza)
German public-sector geoanalytics / geoportal (Cadenza Web and Cadenza Workbooks). Vendor: disy.net.
Signals: path /cadenza/, /public/, /pages/map/, or /fachauswertungweb/; HTML/JS contains cadenza and often disy; workbook navigator or JSF *.xhtml map pages; guest login before the public theme tree. Root may return HTTP 401 with an HTML login/guest page — that is still a public catalog if guest access exists.
Confirm: GET the catalog URL and match at least two of: cadenza in HTML, disy branding, Cadenza Web/Workbooks UI, or a working public map permalink. Do not add staff-only Cadenza (police, intranet Energieatlas, bathing-water ops tools). One record per public catalog UI, not per workbook or theme on the same host.
| Tool | Query |
|---|---|
"Cadenza Web" OR "disy Cadenza" (Umwelt OR Kartendienst OR Geoportal) site:.de | |
inurl:/cadenza/ (UDO OR iDA OR Kartendienst) | |
| Censys | web.endpoints.http.body: "cadenza" |
| FOFA | body="cadenza" |
WIS 2.0 Box (wis20box)
WMO WIS2 reference node for publishing meteorological and related geospatial data. Source: wmo-im/wis2box.
Signals: wis2box in HTML or API; pygeoapi / OGC API Features alongside WIS2 messaging; WMO WIS2 branding.
Confirm: GET the public discovery UI or OGC API landing page. Register the node catalog, not an individual dataset or MQTT topic. The WMO WIS2 Global Discovery Catalogue (CMA instance) is a named-list hunt for other WIS2 nodes — duplicate-check before adding.
index.html sets the Open Graph title WIS 2.0 node in a box (321 hosts in September 2026, including wis2.meteo.gov.gh). body="wis2box" matched 445, the same product, so keep both.
| Tool | Query |
|---|---|
"wis2box" OR "WIS 2.0 Box" (pygeoapi OR "OGC API") -site:github.com | |
| Censys | web.endpoints.http.body: "WIS 2.0 node in a box" |
| FOFA | body="WIS 2.0 node in a box" |
| Censys | web.endpoints.http.body: "wis2box" |
| FOFA | body="wis2box" |
GET SDI Portal (getsdiportal)
Geospatial Enabling Technologies SDI client over GeoServer / GeoNetwork. Common in Greek municipal and regional SDIs.
Signals: tabbed UI (map, metadata, files, services); GET SDI / GETMAP branding; CSW plus WMS/WFS.
Confirm: GET the portal home and match the tabbed SDI UI. Do not also register the bundled GeoServer on the same host.
index.php only loads js/loader.js. body="GET SDI" matched 30 hosts in September 2026, and the first hits are www.sdipresence.com and www.getmap.eu. body="GET SDI Portal" matched 3: the vendor site and 84.205.223.98 (Athens GIS). The version banner lives in license.txt, not an HTML template.
| Tool | Query |
|---|---|
"GET SDI Portal" OR "GETMAP" (geoportal OR CSW) -site:getmap.eu |
MapProxy (mapproxy)
Open-source map cache/proxy. Register only when MapProxy is the public catalog (demo viewer + service list), not a silent cache behind another geoportal.
Confirm: GET /demo/ or WMTS/WMS GetCapabilities whose service title mentions MapProxy.
static.html titles the catalog page MapProxy Demo (56 hosts in September 2026, including 188.68.223.69). body="MapProxy" matched 1,990, including tile caches such as tiles.trafimage.ch. Keep both.
| Tool | Query |
|---|---|
intitle:"MapProxy" (demo OR WMTS) -site:github.com -site:mapproxy.org | |
| Censys | web.endpoints.http.body: "MapProxy Demo" |
| FOFA | body="MapProxy Demo" |
| Censys | web.endpoints.http.body: "MapProxy" |
| FOFA | body="MapProxy" |
Terria (terria)
Open-source catalog-driven map portal (TerriaJS). Site: terria.io.
Signals: TerriaJS / National Map-style catalog tree; config.json + catalog.json; Magda or CKAN-backed catalogs behind the viewer.
Confirm: GET the viewer and a working catalog JSON. If the same datasets are already a CKAN/Magda catalog on that host, prefer the dataset CMS unless the map is the primary product.
index.ejs sets class="terria" on the root element (461 hosts in September 2026, including map.geo-rapp.org). body="Terria" matched 1,314. Branded shells can omit the class, so keep both.
| Tool | Query |
|---|---|
"Terria" (catalog OR "National Map") -site:github.com | |
| Censys | web.endpoints.http.body: "class=\"terria\"" |
| FOFA | body="class=\"terria\"" |
| Censys | web.endpoints.http.body: "Terria" |
| FOFA | body="Terria" |
MapBiomas (mapbiomas)
Land-cover collections and map viewers. Country nodes (Brazil, Indonesia, and others) share the MapBiomas web app. Site: mapbiomas.org.
Confirm: GET the country node and match MapBiomas collections UI. One record per public country/program portal.
| Tool | Query |
|---|---|
"MapBiomas" (coleções OR collections OR geoportal) | |
| Censys | web.endpoints.http.body: "MapBiomas" |
| FOFA | body="MapBiomas" |
ERDAS APOLLO (erdasapollo)
Hexagon geospatial content management. Vendor: hexagon.com.
Signals: APOLLO Image Manager / Web Client; ERDAS APOLLO in HTML; WMS/WMTS/CSW from an APOLLO catalog.
Confirm: GET the public discovery client (not an intranet Image Manager). Skip login-only enterprise catalogs.
| Tool | Query |
|---|---|
"ERDAS APOLLO" (WMS OR catalog OR geoportal) -site:hexagon.com | |
| Censys | web.endpoints.http.body: "ERDAS APOLLO" |
| FOFA | body="ERDAS APOLLO" |
pycsw (pycsw)
OGC CSW and OGC API – Records server. Site: pycsw.org. Register when pycsw is the public catalog, not only the CSW backend of GeoNode/GeoNetwork.
Confirm: CSW GetCapabilities or OGC API Records landing page mentioning pycsw.
_base.html loads pycsw-logo-vertical.png (37 hosts in September 2026, including pycsw.studiogis.eu). body="pycsw" matched 700, including MS4W pages that only mention the server. Keep both.
| Tool | Query |
|---|---|
"pycsw" (CSW OR "OGC API" Records) -site:github.com -site:pycsw.org | |
| Censys | web.endpoints.http.body: "pycsw-logo-vertical.png" |
| FOFA | body="pycsw-logo-vertical.png" |
| Censys | web.endpoints.http.body: "pycsw" |
| FOFA | body="pycsw" |
Koordinates (koordinates)
Cloud geospatial data platform. Hosts: *.koordinates.com plus custom government domains. Site: koordinates.com.
Confirm: GET /services/api/v1.x/data/ and keep the host only when X-Resource-Range reports a count above 0. One record per tenant catalog. Publisher pages on koordinates.com (/from/{org}/data/) are the hub, not a second catalog. Login hosts (id.koordinates.com) and Warehouse Not Found redirects are not catalogs.
Every public portal’s HTML preloads https://assets.koordinates.com/fe/boot.js and sets kx_boot_file (19 hosts on 24 September 2026, all already registered, including data.linz.govt.nz and lris.scinfo.org.nz). body="Powered by Koordinates" matched 0. server="Koordinates" matched 363, mostly wildcard-certificate noise, 401s, and dead warehouses. domain="koordinates.com" matched the same 295-host certificate noise and did not include live tenants such as scion.koordinates.com. Keep the boot-script query; use server="Koordinates" only to catch a custom domain the body index missed, then require the data API.
| Tool | Query |
|---|---|
site:koordinates.com (data OR layers) | |
| crt.sh | %.koordinates.com |
| Censys | web.endpoints.http.body: "assets.koordinates.com/fe/boot.js" |
| FOFA | body="assets.koordinates.com/fe/boot.js" |
| FOFA | body="kx_boot_file" |
| FOFA | server="Koordinates" && status_code="200" |
IRI Data Library (datalibrary)
Climate / maproom portals (IRI Columbia and meteorological services). Site: iridl.ldeo.columbia.edu.
Signals: Data Library / maproom; gridded download; IRI-style dataset URLs.
Confirm: GET a public maproom or dataset browser. One record per public library, not per maproom view.
| Tool | Query |
|---|---|
"Data Library" (maproom OR IRI) (climate OR geospatial) -site:columbia.edu | |
| Censys | web.endpoints.http.body: "maproom" |
| FOFA | body="maproom" |
Rasdaman (rasdaman)
Array database with OGC WCS/WMS/WCPS. Site: rasdaman.com. Register the public service/catalog UI, not a silent WCS behind another geoportal.
Confirm: GetCapabilities or WCPS endpoint that names rasdaman.
| Tool | Query |
|---|---|
"rasdaman" (WCS OR WCPS OR petascope) -site:github.com -site:rasdaman.com | |
| Censys | web.endpoints.http.body: "rasdaman" |
| FOFA | body="rasdaman" |
Open Data Cube (opendatacube)
Earth-observation data cube. Site: opendatacube.org. Often paired with STAC or datacubews (OWS). Prefer STAC/stacserver if that is the public catalog; use opendatacube when the cube explorer is the product.
Confirm: GET the explorer or ODC-indexed catalog UI.
base.html writes Open Data Cube v next to <span id="datacube-version"> (36 hosts in September 2026, including explorer.swissdatacube.org and explorer.digitalearth.se). body="opendatacube" is not usable: it matched 71 hosts, including www.opendatacube.org and the AWS open-data registry.
Forks of opendatacube/datacube-explorer keep an empty homepage, and code search skips most of them. Read Ingress host: values (filename:ingress.yaml datacube-explorer). In September 2026 that found explorer.piksel.big.go.id, which the footer query had not indexed. Keep a site only when About or a product page reports datasets (Exploring N datasets). A staging or *-dev host with the same product list is the same catalog.
body="id=\"datacube-version\"", body="datacube-product-name", and body="/audit/dataset-counts" each returned that same 36-host set on 24 September 2026, including twodc.colife.org.tw (twdc.colife.org.tw does not connect). body="cubedash" and the vendored Font Awesome paths are not usable.
| Tool | Query |
|---|---|
"Open Data Cube" (explorer OR datacube) -site:opendatacube.org -site:github.com | |
| Censys | web.endpoints.http.body: "Open Data Cube v" |
| FOFA | body="Open Data Cube v" |
| FOFA | body="id=\"datacube-version\"" |
| FOFA | body="datacube-product-name" |
| GitHub | forks of opendatacube/datacube-explorer; filename:ingress.yaml datacube-explorer |
Datacube OWS (datacubews)
OGC service layer for Open Data Cube (datacube-ows). Docs: datacube-core.readthedocs.io. Use when WMS/WCS OWS is the public product, not the cube explorer (opendatacube) or a STAC API (stacserver).
Signals: datacube-ows / datacube_ows; ODC WMS/WCS GetCapabilities.
Confirm: GET WMS or WCS GetCapabilities that names datacube-ows. Same /collections grain as Open Data Cube when OWS is the public product.
index.html titles the landing page (datacube-ows) (51 hosts in September 2026, including datacube.icc.mn:5000).
| Tool | Query |
|---|---|
"datacube-ows" OR "datacube_ows" | |
| Censys | web.endpoints.http.body: "datacube-ows" |
| FOFA | body="datacube-ows" |
InGrid (ingrid)
German environmental/spatial metadata catalog. Site: ingrid-oss.eu. Source: informationgrid.
Signals: InGrid chrome; CSW and OpenSearch; German environmental SDI.
Confirm: GET CSW GetCapabilities or the InGrid search UI. One catalog per public node.
| Tool | Query |
|---|---|
"InGrid" (CSW OR Geoportal) site:.de | |
| Censys | web.endpoints.http.body: "InGrid" |
| FOFA | body="InGrid" |
GeoPortal.rlp (geoportalrlp)
Rhineland-Palatinate SDI suite (OWS, ISO 19139, map viewer). Source: mrmap-community/GeoPortal.rlp. Help: geoportal.rlp.de.
Confirm: do not re-add known RLP nodes already in the registry. GET CSW or the catalog UI on a distinct node.
| Tool | Query |
|---|---|
geoportal.rlp.de | |
| Censys | web.names: "geoportal.rlp.de" |
| FOFA | host="geoportal.rlp.de" |
ncWMS (ncwms)
WMS for NetCDF / multidimensional environmental data. Docs: ncwms. Register when ncWMS is the public map catalog, not a layer inside THREDDS.
Confirm: WMS GetCapabilities mentioning ncWMS / Godiva.
| Tool | Query |
|---|---|
"ncWMS" OR Godiva (WMS OR NetCDF) -site:github.com | |
| Censys | web.endpoints.http.body: "ncWMS" |
| FOFA | body="ncWMS" |
istSOS (istsos)
OGC Sensor Observation Service (SOS) server for sensor and observation time series (hydrology, meteorology, environmental monitoring), developed by SUPSI Istituto scienze della Terra. Project: istsos.org. Register the public viewer or SOS service root when it is the data catalog, not a login-only /istsos/admin.
Confirm: https://host/istsos/{service}?service=SOS&request=GetCapabilities returns sos:Capabilities titled "IST Sensor Observation Service" (default installs ship a demo service). Web admin / viewer HTML title istSOS or istSOS-viewer; the viewer's /config/config.json reveals apiBaseUrl and service names.
| Tool | Query |
|---|---|
intitle:"istSOS" OR inurl:/istsos/ -site:github.com | |
| Censys | web.endpoints.http.html_title: "istSOS" |
| FOFA | title="istSOS" |
| Shodan | http.title:"istSOS" |
SOS paths carry a per-installation service name (/istsos/{service}), so a root or guessed-path GET may 404/401 while the catalog is alive — check the viewer (/, title istSOS-viewer) before discarding. One SOS server can back several viewer vhosts; register one catalog per server.
ArcGIS StoryMaps (arcgisstorymaps)
Esri's current geospatial storytelling product. Product: ArcGIS StoryMaps.
Signals: storymaps.arcgis.com/stories/{item-id} or an ArcGIS Enterprise equivalent; ArcGIS StoryMaps application shell; a public story item. Register only when the story is the primary interface for discovering or exploring a coherent data collection, not every narrative that embeds a map.
| Tool | Query |
|---|---|
site:storymaps.arcgis.com/stories (data OR atlas OR catalog) | |
| Censys | web.endpoints.http.body: "ArcGIS StoryMaps" |
| FOFA | body="ArcGIS StoryMaps" |
Platforma GeoCloud (geocloud)
Slovak national GeoICT platform of the Ministry of Environment (MŽP SR, ESPUS project). Product: geocloud.gov.sk. Hosts the national INSPIRE applications on shared FastAPI + PostgreSQL/PostGIS backends with GeoServer/MapProxy at gis.geocloud.gov.sk and a Strapi CMS at cms.geocloud.gov.sk. Tenants: Národný geoportál (geoportal.gov.sk, Vue.js/Vuetify), Register priestorových informácií (rpi.gov.sk, Angular), NIPI website (inspire.gov.sk). Distinct from Cegal GeoCloud, US GeoCloud Inc (gpt.geocloud.com, esrigeo), and Chinese 地质云.
Signals: host *.geocloud.gov.sk; /settings.js exposing VUE_APP_API_ENDPOINT_GP: https://api.geocloud.gov.sk/geoportal (Národný geoportál); FastAPI backends on api.geocloud.gov.sk; GeoServer workspace WMS/WFS under gis.geocloud.gov.sk/geoserver/{workspace}/ows.
Confirm: GET the portal home and match the api.geocloud.gov.sk / gis.geocloud.gov.sk references. One record per tenant application (geoportal.gov.sk, rpi.gov.sk, inspire.gov.sk), not per GeoServer workspace. Do not register bare gis.geocloud.gov.sk / cms.geocloud.gov.sk service roots beside their parent tenants, and do not set geocloud on unrelated municipal GeoServer hosts ending in .sk.
| Tool | Query |
|---|---|
"geocloud.gov.sk" site:.sk | |
site:geocloud.gov.sk -gis -cms | |
| Censys | web.endpoints.http.body: "api.geocloud.gov.sk" |
| FOFA | host="geocloud.gov.sk" |
| FOFA | body="VUE_APP_API_ENDPOINT_GP" |