Skip to content
AAA.win
2026-08-12

IndexNow proof-origin protocol fix

Production Bing validation exposed HTTP 500 at the external root proof because TLS termination was followed by an internal rewrite using the wrong protocol. This release corrects that rewrite boundary, but remains unverified until the external proof returns HTTP 200, the automatic submission runs, a later canary returns HTTP 200, and the idempotent rerun passes.

What changed

01

Recorded the production Bing validation failure as an external root-proof HTTP 500 instead of treating the earlier request result as successful verification.

02

Traced the failure to a protocol mismatch between TLS termination and the internal proof rewrite, rather than to the public root filename or production key.

03

Corrected the internal rewrite protocol boundary while preserving the exact public root-proof contract and keeping the production key server-only.

04

Requires an external proof HTTP 200, the automatic submission, a subsequent changed-URL canary HTTP 200, and an unchanged idempotent rerun before declaring the integration operational; this release makes no advance claim of success, crawling, or indexing.

Version · v4.3.6-indexnow-delivery-verified

Latest releases

IndexNow production delivery verification

Verified production IndexNow receipt with a new key: Microsoft's external proof returned HTTP 200, single-URL GET and POST both returned HTTP 200, and eight batches covering 386 canonical URLs each returned HTTP 200 with zero retries. A second run found the inventory unchanged and sent no request.

IndexNow proof-origin protocol fix

Production Bing validation exposed HTTP 500 at the external root proof because TLS termination was followed by an internal rewrite using the wrong protocol. This release corrects that rewrite boundary, but remains unverified until the external proof returns HTTP 200, the automatic submission runs, a later canary returns HTTP 200, and the idempotent rerun passes.

IndexNow root-proof request compatibility

After v4.3.3, the exact root-level {key}.txt proof returned HTTP 200, but a full request carrying keyLocation still returned HTTP 403; a minimal homepage request with the same production key and no keyLocation returned HTTP 202. This release omits that field, while the automatic full run and idempotent rerun remain deployment checks.

View all releases