August 28, 2026

Want a real short-term AI visibility hack? Or in a bad actor's hands, becomes a real blackhat GEO hack?

I was looking for a Reddit story.

I found hallucinations and parked domains instead.

ChatGPT does not always search the open web once. It writes a few hidden queries first. Those are query fanouts . In late August, a huge share of them started using site:. Pick a domain. Search only that domain.

This is the chart from my previous post: https://www.linkedin.com/pulse/reddit-lost-most-its-visibility-chatgpt-site-filled-gap-ye%C5%9Filyurt--j5aqf/

So I analyzed over 2 million of those site: queries. I listed every host the model named.

Most of it was boring. Live official sites. Fine.

Then the leftovers showed up. Expired names. Parked names. Official URLs that never existed. ChatGPT asking for site: brand-domain.com. The citation still said branddomain.com. The hyphen host was empty.

That leftover list is the short-term hack. In the wrong hands, it is the blackhat version.

If I published the real names, anyone could register them tonight. So I did not. You will see branddomain.com and brand-domain.com in this post. You will not get a shopping list.

While you were all-in on Reddit, someone else closed this gap. They read the fanouts. They followed the site: pattern. They sat on the empty host you left behind.

Own the brand? Register the guess. Publish the page. Get it indexed. Do not own it? Leave it. This is why branddomain.com still matters after a year of Reddit-heavy visibility. And why leaving brand-domain.com empty is not only a missed citation.

Note: I've already seen other posts on LinkedIn that acknowledge this. You can drop those links in comment section.

TL;DR

  • A site: fanout is not a normal search. ChatGPT is saying "only show me pages from this one domain." If that host is empty, the lookup cannot return a page.
  • In Peec's ChatGPT query data, site: went from almost unused (under 0.11 percent of weekly queries from mid May to late July 2026) to 10.2 percent in the week of August 3, then 26.2 percent in the week of August 10 (about 3.9 million of 14.9 million ChatGPT queries). Daily share peaked around 29.2 percent on August 12.
  • Reddit-heavy AI visibility was always shaky. Reddit's share of ChatGPT citations moved around during the year, then fell from about 4.6 percent to 0.2 percent in two weeks in August 2026. The site: wave is the clean reason not to abandon branddomain.com.
  • We then took a wide cut of recent site: fanouts (over 2 million distinct queries from the last 15 days) and counted every domain the model named.
  • Almost every high-volume target is a real official site. That is the main pattern.
  • A thin leftover set is different: hallucinated official URLs (the model invents brand-domain.com while citations still point at branddomain.com) and parked or leftover domains (hyphen variants, expired country sites, old product hosts).
  • In our WHOIS pass, 4 registerable domains showed up 100 or more times, and 104 showed up between 10 and 99 times. The rest of the checked set was already taken.
  • If a bad actor sees that gap, they can register the guessed host and fill it with negative sentiment, a lookalike story, or something worse. The empty site: slot is also a retrieval risk.
  • This is a short-term AI visibility hack, not durable GEO. OpenAI can stop using site:, start checking that the domain exists, or go back to broad search next week. We have already seen ChatGPT change retrieval twice in one month.

Why brand presence still matters

For a long time, a lot of ChatGPT visibility sat on Reddit threads. That felt efficient. One good thread could show up across many prompts. It also made the official site easy to deprioritize. If Reddit was doing the talking, why keep investing in branddomain.com?

The year showed why that was a weak plan. Reddit's share of ChatGPT citations did not stay flat. It moved. In August 2026 it did not just dip. It collapsed, from about 4.6 percent to 0.2 percent in two weeks. Brands that had parked their AI visibility on forum threads lost that channel overnight. Brands that still had a crawlable official site had somewhere to stand.

The site: parameter is the clean explanation, not a side note. ChatGPT is no longer asking "who on the web talks about this?" as often. It is asking "what does this one host say?" When that host is branddomain.com, the page on your domain is the answer. Reddit cannot do that job. A thread you do not control can vanish from retrieval. Your domain cannot, unless you abandon it.

Do not abandon the brand domain. The site: wave is the proof. Forum citations can swing. A named host is a surface you still own.

What site: means inside a fanout

A normal fanout looks like this: the user asks one question, ChatGPT rewrites it into a few more specific searches, then blends whatever it finds. We have covered that mechanic before, including how ChatGPT injects words like "best" and "reviews." For the earlier pattern set, see Patterns we see in ChatGPT query fanouts .

A site: fanout is stricter. The model is not asking "who talks about this?" It is asking "what does this one host say?"

That is why the August rise matters for GEO, not only for SEO trivia. If the model has already decided the source, your ranking on a generic keyword is secondary. Either your pages live on the domain it named, or that lookup comes back empty.

Grok was already doing a version of this earlier. In April 2026, 18.3 percent of Grok chats used site:, often site: reddit.com or review sites. ChatGPT's August move looks broader: brand sites, docs, help centers, government pages, and local official-looking hosts, not just a short trusted-source list.

What we counted

I analyzed over 2 million site parameters fanout data. There are more and more data I still need to dig in.

From there:

  • 134,922 unique hostnames. Every token after site:, after a light cleanup (strip www, drop empty or wildcard hosts).
  • 3,047 hostnames appeared 100 or more times. After dropping .gov, .edu, .mil, and similar restricted suffixes, and rolling subdomains up to the registerable domain, we had 2,633 unique domains in the 100-plus band.
  • 14,839 hostnames in the 10 to 99 band. That rolled up to 13,344 unique registerable domains after the same filters.

We then checked DNS and registry WHOIS. A domain with live nameservers is taken. For the ones without DNS, we asked the registry.

Result, in plain terms: the 100-plus band is almost entirely taken. Four names looked free. The 10 to 99 band had more leftovers. About 104 names looked free on WHOIS at the time we checked (late August 2026).

That is not "half the web is empty." It is the opposite. The model is usually pointing at a real site. The interesting part is the miss rate, because a miss is a site: search that cannot return a page.

Pattern 1: the model wants an official page

Most site: targets in this set are the domains you would expect: branddomain.com, docs hosts, regulators, newspapers, universities (we excluded those from the registerable count). ChatGPT is not swapping Reddit for another forum. It is swapping a broad result list for a named source.

If your real official domain is the one in the fanout, the work is boring and correct: make the page it is looking for. Put the fact, the 2026 figure, the product name, or the policy in plain text. A site: query does not help you if the index has nothing to return.

This is also why brand presence should not have been treated as optional during the Reddit-heavy months. When retrieval swings back to a named host, the brands that kept branddomain.com current are the ones with a page ready. The ones that only fed threads are starting from empty.

Pattern 2: hallucinated official domains

This is the new part.

The model often invents the URL an official source "should" have. It is not copying a link from the prompt. It is guessing a hostname, then locking the search to that host.

The pattern we kept seeing looks like this (real hostnames masked):

  • Citations still go to branddomain.com. The hidden fanout asks for site: brand-domain.com, or a country or .org variant of the same name. That guessed host was never registered.
  • The guess looks official. A hyphen, a different TLD, or an extra word. The model is trying to be careful. The guess is just wrong.

That is a hallucination at the retrieval layer, not only in the final sentence. The answer may still sound confident. The search never hit a real page.

Real leftover hosts from the extract are not named here. Use the pattern, not a shopping list.

Pattern 3: parked, expired, and leftover hosts

A second group is names that look like they used to belong to someone, or like a country or product variant that never got bought.

From the same pass, again masked: branddomain.co.in showed up in the high-100s, including queries that paired it with site: branddomain.com for the same market. brand-domain.com showed up in product-spec queries. Another hyphen variant of a live software brand showed up dozens of times. WHOIS: no match, or available.

Some of these will be expired names. Some will be hyphen or TLD variants of a live brand. Some will be old microsites. We did not classify every leftover as "parked" in the registrar sense. The shared fact is simpler: ChatGPT asked a search index to look on a host that had no registration, or no DNS.

A parked page with ads is not a win. If the fetch happens and the page is junk, you trained the model on junk, or you got nothing. The only useful version of this pattern is a real page that answers the exact fanout.

Real leftover hosts from the extract are not named here. The pattern matters more than the shopping list.

What a bad actor can do with the miss

This is the darker read of the same gap. If you are a marketer reading this as "buy every empty domain in the CSV," stop. Brands should take this version seriously.

ChatGPT can treat branddomain.com as the real source in the answer, while the hidden fanout asks for site: brand-domain.com. If that guessed host is unregistered, anyone can buy it.

Then they can put up a page that matches the fanout: the product name, the 2026 figure, the policy term. They can fill it with negative sentiment, fake complaints, a lookalike support story, a competitor pitch, or something worse. If the model later fetches that host, the lookup is no longer empty. It returns their page.

We are not saying this is happening at scale today. We are saying the window is visible in the data. The cost of leaving brand-domain.com empty is not only a missed citation. It is a retrieval slot someone else can occupy.

If you own branddomain.com, treat brand-domain.com and the other close guesses in your fanouts as brand surface, not leftover inventory. Register the ones that are yours to use. Publish a real page. Get it indexed. Do it before someone else notices the same miss.

The short-term hack (and the line we will not cross)

Here is the version that is a GEO tactic, not a trademark problem:

  1. Open fanouts for your tracked prompts in Peec. Prompts, pick a prompt, Latest Fanout Queries. Or ask the Peec MCP: pull ChatGPT fanouts that contain site: for this project, last 14 days.
  2. Extract every hostname after site:. Group them. Count them. You want repeats, not one-off noise.
  3. Split the list into three buckets. Your real domain and real subdomains (branddomain.com): fix the pages those queries describe. Guessed official URLs for your brand (brand-domain.com, .org vs .com, country TLD, product microsite): if WHOIS is free and the name is yours to use, register it and put the missing content there, then get it indexed. This is defense as much as it is visibility. Someone else's brand, a political party, a bank, a car dealer: leave it. A site: miss is not a license.
  4. Write the page the fanout already specified. The query site: branddomain.com "product name" 2026 is a brief. A homepage that says "Welcome" does not satisfy it.
  5. Watch the same prompts weekly. If site: share drops, the hack shrinks with it.

That is the whole play. You are not beating Google's algorithm. You are sitting on the exact host the model already chose, for as long as it keeps choosing that way, and you are closing the lookalike slot a bad actor could use.

How to do this inside Peec without a 2 million line dump

You do not need our warehouse extract to run the same check on your brand.

Dashboard

Filter to ChatGPT (and Grok, if you want the older site: habit). Open prompts where you are cited, or where a competitor is cited and you are not. Scroll to fanouts. Search the list for site:. Export or copy. Count domains. Look for branddomain.com next to brand-domain.com.

MCP (Claude or any client with Peec connected)

Use a prompt like this:

Using the Peec AI MCP, pull ChatGPT fanout queries from the "[project]" project for the last 14 days that contain "site:". List the domains, how often each appears, and whether the domain is our brand, a partner, a competitor, or unknown. Flag any domain that looks like a guessed official URL for us, including hyphen and TLD variants of branddomain.com.

Then take the unknown and "guessed official" rows to WHOIS. Do not register anything from a single appearance.

Why we are not calling this durable

We need to be blunt, because this post will travel if people read it as a loophole.

  • Retrieval already moved twice in August 2026. No product announcement. site: usage may keep growing, flatten, or disappear.
  • Registration without indexing is still an empty lookup. A site: query only helps if the search index has your URL.
  • Models can start verifying that a domain resolves. If they lock site: only after DNS works, the hallucinated-host window closes.
  • Most site: volume still hits live official sites. The empty-host set is the tail, not the body.
  • Buying a lookalike of another company is a legal problem. It is not a growth channel.

The durable work is unchanged: keep branddomain.com current, cover the fanout angles on properties you already own, and keep measuring. Reddit and other third-party sources will keep swinging. The empty site: host is a patch you apply this month if the name is yours. It is not a replacement for fanout coverage .

What to do this week

If you only have an hour:

  • Pull site: fanouts for your top & worst performing 20 prompts. Start with the prompts that already move citations, not a random sample.
  • Check whether ChatGPT is already aiming at branddomain.com. If yes, match the missing phrases on that domain.
  • Check whether it is aiming at brand-domain.com or another guessed URL that should have been yours. If that name is free and clean to use, register it and publish the page the query asked for. Treat this as defense, not a trick.
  • Recheck in seven days. If the fanouts moved, do not keep buying names.

If you want the wide picture we used, the method is the same at a larger scale: fanout text, site: hosts, counts, WHOIS on the ones without DNS. The conclusion should stay humble. We are looking at one channel, a short window, and a retrieval stack we do not control.

> We will keep watching Peec's ChatGPT query stream. If site: share drops, or if the empty-host tail disappears, that is the update. Until then, this is a real pattern in the data, a reason to keep the brand domain alive, and a small, time-boxed move for brands who already see their own name in those fanouts.

Highly recommended to watch

Jon Clark & Malte Landwehr 's podcast

https://www.youtube.com/watch?si=l9fAKnUc9Hno_u2x&v=ZntIGuNx29c&feature=youtu.be

$subscribe --newsletter

Get new research on AI search, SEO experiments, and LLM visibility delivered to your inbox.

Powered by Substack · No spam · Unsubscribe anytime

Share with AI
Perplexity Gemini
arXiv-Style PDF Download as formatted research paper with complete sources & citations