Chokepoints on the Ecosystem
A chokepoint is not a crime. It is a position. A handful of companies sit at the narrow points through which most of the internet's commerce, messaging, and reachability must pass — the place a domain is resolved, the place a text message is routed, the place a card is charged, the place an email is delivered. Concentration at these points was not plotted; it was earned, by companies that built genuinely good infrastructure and won genuinely large markets. The question this catalog asks is not whether the chokepoints should exist. They will exist, because the economics of scale guarantee that someone will occupy them. The question is what the companies who occupy them owe to the people who must pass through. A chokepoint operated with a published framework, an appeal, and a duty to give warning before it cuts is a piece of civic infrastructure. The same chokepoint operated as an unaccountable gate — one that degrades service while still billing for it, that blocks without notice and without recourse, that denies access as a matter of undisclosed bias — is something else. The power is the same in both cases. The stewardship is not. This is a record of where the chokepoints sit in 2026, which ones are governed and which are not, and what a person passing through one is presently owed and presently denied.
By Odysseus Melchizedek Shiloh, The Wellkeeper ·
Unto whomsoever much is given, of him shall be much required. — Luke 12:48
What a Chokepoint Is, and What It Is Not
A chokepoint is a narrow place that a great deal of traffic must pass through. In a strait, in a mountain pass, in a single bridge across a wide river, the same property holds: whoever controls the narrow place controls, in a real sense, everything that needs to move from one side to the other. The internet has these places too, and they are less visible than a bridge because nothing about them is physical. They are companies, protocols, and policy decisions that sit at the points where one kind of activity must convert into another — where a domain name becomes an IP address, where a message becomes a routed text, where a card number becomes a settled payment, where an email becomes a delivered message in an inbox.
The first thing to say plainly is that these chokepoints are not, in themselves, evidence of wrongdoing. Concentration at the narrow points is the ordinary result of scale economics operating on infrastructure. Building a global email delivery system that maintains sender reputation, fights spam, and lands in the inbox is genuinely hard, and the companies that did it well were rewarded with most of the volume. Building an anycast network that absorbs denial-of-service attacks across hundreds of cities is genuinely hard, and the company that did it best ended up in front of a large fraction of the web. None of this is sinister. It is what happens when a hard problem has a good solution and the good solution scales.
The second thing to say, with equal plainness, is that occupying a chokepoint changes what a company owes. A small business that turns away a customer it does not wish to serve has made a private decision with a limited consequence; the customer goes elsewhere. A company that sits at the narrow point through which a category of activity must pass has no comparable innocence available to it, because for the party it turns away there often is no elsewhere. When the gate is the only gate, closing it is not a private decision. It is an exercise of power over a person who has no alternative, and power exercised over someone with no alternative is the precise circumstance in which the old principle applies without softening: to whom much is given, much is required.
This catalog is built on that distinction and not on hostility to scale. It does not argue that the chokepoints should be broken up, nationalized, or wished away. It argues that a chokepoint is a position of stewardship whether or not the company occupying it has accepted the role, and that the difference between a well-stewarded chokepoint and a badly-stewarded one is observable, nameable, and worth recording while the record is still being written.
The Three Tests of a Governed Gate
Before naming the chokepoints, it is worth fixing the standard against which each is measured, so that the judgments that follow are judgments and not merely complaints. A chokepoint is well-stewarded to the degree that it passes three tests. The tests are not exotic. They are the ordinary features of any fair process, applied to infrastructure.
The first test is notice. Does the company warn before it cuts? A gate that closes without warning forecloses every response the affected party might have made — the correction, the migration, the appeal, the orderly wind-down. A bank that freezes an account gives notice; a landlord that ends a lease gives notice; a utility that disconnects service gives notice, because notice is the difference between an enforcement action and an ambush. A chokepoint that suspends, blocks, or nullroutes without warning has chosen the ambush, and the choice is visible regardless of whatever justification follows it.
The second test is recourse. Is there an appeal, and does a human answer it? A framework that exists only as an automated decision with no path to a person is not a framework; it is a wall with a help article taped to it. The presence of a real appeal — a channel, a response, a named office that can reverse a mistake — is the single feature that most distinguishes a governed chokepoint from an arbitrary one, because every automated system makes errors, and the test of stewardship is not whether errors occur but whether they can be corrected by the person they fall on.
The third test is honesty about the basis of the decision. Does the company disclose the framework by which it decides who passes? A published rule can be examined, criticized, and complied with. An undisclosed rule cannot, and an undisclosed rule is the natural habitat of bias, because bias survives precisely in the conditions where the basis for a decision never has to be stated. The chokepoint that says "we declined you, and we will not say why, and there is no one to ask" has failed this test completely, and the failure is independent of whether the underlying decision happened to be correct.
A gate that gives notice, offers recourse, and discloses its framework is a piece of civic infrastructure even when it is privately owned and operated for profit. A gate that does none of these things is an unaccountable power, and the catalog that follows sorts the chokepoints of 2026 by where they presently stand against these three tests.
The Messaging Gate: 10DLC and the Nullrouted Text
The clearest failure in the catalog is the one with the most complete paper trail, and it sits at the point where a text message becomes a routed text message. In the United States, application-to-person SMS — the messages a business sends to its customers — passes through a registration regime built around the major mobile carriers and the registries they recognize. The regime was assembled under the banner of fighting spam and fraud, which is a real problem and a defensible motivation. What it became in practice is the instructive part.
The pattern that has been documented is specific and worse than ordinary friction. A sender registers, is approved, pays the per-message and per-campaign fees, and then finds that some portion of the messages the sender is paying to deliver are silently discarded in transit — not rejected with an error the sender can see and respond to, but accepted, billed, and then dropped without a delivery and without a notice. The sender pays for a message that the network had already decided not to carry. The combination is the thing that fails every test at once: there is no notice, because the drop is silent; there is no recourse, because the sender is not told the message failed and so has nothing to appeal; and there is no disclosed framework, because the basis on which a given message is carried or discarded is not published and not consistent.
The registration construct that organized this regime has itself shifted and, in the relevant sense, dissolved as a coherent governing framework, even as the fees and the routing behavior it authorized persisted. That is the precise shape of a badly-stewarded chokepoint: the apparatus of control outlives the apparatus of accountability. The carriers occupy the narrow point through which business messaging must pass. They have used the position to charge for a service while reserving an undisclosed and unappealable right not to perform it. This is not a failure of capacity — the networks are entirely capable of delivering the messages. It is a failure of stewardship, and it is the failure against which the rest of the catalog should be read, because it is the one where the gap between the power held and the responsibility exercised is widest and best evidenced.
The Resolution Gate: Domains Blocked Without a Whitelist
The second chokepoint sits at the point where a domain name becomes a reachable destination — the resolution, routing, and protection layer that decides whether a request for a site arrives at the server behind it. A small number of companies occupy this layer at scale, and their position is, on its merits, a genuine public good: the same infrastructure that can make a site unreachable is the infrastructure that keeps it reachable under the denial-of-service attacks that would otherwise take it down. The power to protect and the power to cut are the same power, which is exactly why the stewardship of it matters.
The failure mode here is not silent dropping but blunt categorization. A recently registered domain is treated, by default, as presumptively suspect, on the reasonable-sounding theory that fraud and abuse cluster among new registrations. The theory is not baseless. The execution is where stewardship is tested, because a presumption applied without a corresponding path to rebut it is not a risk model; it is a wall. A domain that has been registered to operate a legitimate civic or commercial service — a clinic's patient portal, a community directory, a merchant's storefront — is indistinguishable, to a system that judges only by registration age, from a domain registered an hour ago to run a phishing campaign. The system that cannot tell them apart, and that provides no efficient means for the legitimate operator to establish the difference, has chosen to treat the false positive as an acceptable cost. For the operator who is the false positive, it is not an acceptable cost; it is the loss of reachability for a service real people depend on, imposed without notice and lifted, if at all, only after an appeal that the system was not designed to make easy.
The missing piece is the affirmative one. A well-stewarded resolution layer would maintain not only a blocklist of bad actors but a workable path by which a responsibly governed operator can be recognized and whitelisted — a framework that distinguishes the new domain run by a real steward from the new domain run by a fraud, on some basis other than the calendar. The absence of that path is the failure. The chokepoint has built the machinery to cut and has not built, with equal seriousness, the machinery to recognize the legitimate party it is cutting. The power to make a site unreachable is among the most consequential a private company holds, and it is presently exercised with a notice-and-recourse posture well below what the consequence warrants.
The Payment Gate: Processing Denied as Undisclosed Bias
The third chokepoint sits at the point where a card becomes a settled payment, and it is the one where the failure is hardest to prove and therefore most important to surface carefully. A merchant who cannot accept payment cannot operate, and the small number of processors and platforms that sit at this point hold, over any given merchant, a power close to the power of permission to exist as a business. When that power is exercised against a merchant operating in good faith, on a basis that is never disclosed, the merchant is left to infer the reason from circumstance — and inference is a weak foundation for an accusation, which is precisely why the chokepoint that declines without explanation is so difficult to hold to account.
The honest version of this entry distinguishes two things that are easy to run together. The first is that processors decline categories of merchants for stated and often legitimate reasons — regulatory exposure, chargeback risk, prohibited products. A processor that declines a category and says so has disclosed its framework; the merchant may disagree, but the merchant can see the rule and seek a processor with a different one. The second, and the actual subject of this entry, is the decline that is dressed in the language of policy but operates on an undisclosed basis — where two merchants with materially identical risk profiles receive different answers, and the difference tracks something the processor will not name. This second thing is the failure, and it is failure precisely because it cannot be examined. The undisclosed basis is the natural hiding place of bias, whether the bias is against a product the processor's staff personally disfavors, a belief the merchant holds, or a category the processor has quietly decided to avoid without saying so.
The reason this entry must be written with more restraint than the others is that systemic bias and individual misjudgment look identical from inside a single case. One merchant declined is a data point, not a pattern, and the temptation to read every adverse decision as proof of animus is a temptation that, indulged, destroys the credibility of the entire catalog. The disciplined claim is narrower and stronger: the payment gate is the chokepoint where the framework is least disclosed, where the appeal is least available, and where the conditions that allow bias to operate undetected are most fully present. The remedy is not an accusation in any single case. The remedy is the surfacing of signal across many cases — the patient accumulation of declined merchants, stated and unstated reasons, and outcomes, until a pattern either appears or does not. A pattern that appears in the aggregate is evidence; a grievance asserted in a single case is not, and the catalog keeps the two apart on purpose.
The Delivery Gate: When All Roads Run to One Engine
The fourth chokepoint is the one that prompted this catalog, and it is interesting less for any present abuse than for the concentration it reveals. A great many of the services that send email on behalf of businesses — the developer-friendly email interfaces, the transactional senders, the newer entrants that present themselves as independent products — do not, underneath, operate their own delivery infrastructure. They route through one of a small number of underlying engines, and a large share of that traffic terminates at a single dominant sending service. The surface shows a marketplace of choices. The layer beneath shows that several of the choices are the same choice wearing different labels.
This matters even when delivery is working, which at present it largely is, because the value of a chokepoint analysis is mostly in mapping the position before it is used rather than after. The dominant sending engine inspects the content it carries, and the link-scanning that follows a send — the automated fetching of URLs in a message to check them for malware — is real and is mostly a service to the recipient, not an abuse of the sender. Safe links are a public good in the same way the protection layer is a public good. The point worth recording is not that inspection is happening but that the inspection, the routing decision, and the reputation judgment all converge on a small number of operators, so that a change in any one of them — a tightened content policy, a reputation threshold, a category quietly disfavored — would propagate through every labeled product sitting on top of it at once. The independence of the products at the surface is, in the respect that counts, an illusion.
The stewardship question for this gate is therefore not a present grievance but a standing one: the engine that carries this much of the world's business email holds, by virtue of the position, the same trio of obligations as the others. If it ever moves from inspecting content for the recipient's safety to gating delivery on the content's acceptability, the tests apply immediately — is there notice, is there recourse, is the framework disclosed. For now the entry in the catalog is a map and a baseline, not a charge: this is where the traffic actually goes, this is how few hands it passes through, and this is the measure against which any future change in behavior should be read. The reason to record the baseline while delivery works is that the only way to demonstrate a later degradation is to have documented the working state first.
The Hosting Gate: One Switch, the Whole Estate
The fifth chokepoint was demonstrated in public on the nineteenth of May, 2026, and it is included because it shows the concentration pattern in a form no one can dispute, having happened on a dated timeline with the affected company's own post-mortem as the source. A widely used developer hosting platform went dark for roughly eight hours after its underlying cloud provider placed its account into a suspended status as part of an automated action, with no advance outreach because the action swept across many accounts at once.
The instructive detail is not that one provider went down. The instructive detail is the cascade. The platform did not run entirely on the cloud that suspended it; it operated its own hardware and burst capacity elsewhere, and those parts stayed running. They became unreachable anyway, because the routing control plane that told the network where to find them lived on the suspended cloud. When the control plane went away, the route caches expired, and the parts of the platform that were never on the affected cloud became invisible regardless. One automated suspension, applied at one provider, nullified an entire platform including the infrastructure the platform owned outright. The single point of dependency was not visible from the outside until the moment it was used, which is the defining property of this kind of chokepoint: it is invisible until it is exercised, and by then the affected party has no time to respond.
The failure of stewardship here belongs primarily to the suspending provider, and it is a familiar one — an automated enforcement action of enormous consequence, applied without the notice that would have let the customer respond, with the recourse arriving only after the damage. The provider has a documented history of comparable actions, including the well-known case of a national pension fund whose infrastructure was erased by a misconfiguration. The platform that was suspended handled the incident about as well as a downstream party can, owning the outage publicly and committing to remove the single dependency, and the entry should credit that. But the deeper lesson is the one that generalizes across the whole catalog: concentration creates hidden single points through which everything passes, and the operator at that point holds a power whose consequence the people downstream cannot see and cannot route around until it is too late to do either. That is the condition that the three tests exist to govern, and it is the condition in which their absence does the most damage.
The Guardrails That Exist, and the Ones That Do Not
A catalog of failures that named no remedies would be a complaint rather than a record, so it is worth being specific about which guardrails are already in place and which are missing, because the gap between the two is the actionable part.
Some guardrails exist and work. Card networks impose chargeback and dispute frameworks that give a wronged consumer a real path to recovery, which is why the payment system, for all the opacity of its merchant-acceptance decisions, treats the cardholder considerably better than it treats the merchant. Domain registration operates under a dispute-resolution framework with named arbitral bodies, so that a contested domain is not simply seized but adjudicated. Email has open authentication standards — the published records that let a sender prove a message is genuinely theirs — which give an honest sender a technical means to establish legitimacy that does not depend on any single carrier's goodwill. These are real guardrails, unevenly distributed, and where they exist the chokepoint they govern is meaningfully less arbitrary.
The missing guardrails are the ones this catalog is organized around. The messaging gate has no published delivery-accountability standard — no requirement that a sender be told, in a form the sender can act on, that a paid-for message was not delivered and why. The resolution gate has no standardized affirmative-recognition framework — no portable way for a responsibly governed operator to be known as such across providers, so that legitimacy established once need not be re-litigated at every gate. The payment gate has no disclosure standard for adverse merchant decisions — no requirement that a decline state its basis in a form that distinguishes a policy from a prejudice. And across all of them, there is no general duty of notice before an automated enforcement action of high consequence, which is the single guardrail that would have changed the outcome of nearly every failure in this catalog.
The surfacing function is the guardrail that can be built from outside, without waiting for the chokepoints to reform themselves, and it is the function this record is part of. A single denied merchant, a single dropped message, a single suspended account is a grievance, and a grievance is contestable and easy to dismiss. The same events, collected at scale and across operators, with their stated and unstated reasons and their outcomes recorded over time, become signal — and signal is the thing that distinguishes a systemic failure of stewardship from an unlucky individual case. The discipline that makes the signal credible is the same discipline that runs through this whole catalog: claim only what the aggregate supports, keep the strong evidence and the weak evidence in separate columns, and let the pattern make the case that no single instance can.
The Standard for the Ones Who Hold the Narrow Places
The companies named and described in this catalog are not, with few exceptions, badly intentioned. They are mostly well-run organizations that solved hard problems, won large markets, and arrived at their chokepoints by merit rather than conspiracy. The argument of this record is not that they are villains. It is that merit in arriving at a position of power does not discharge the responsibility the position carries, and that several of them are presently exercising power at a level of consequence that their notice, their recourse, and their disclosure have not risen to meet.
The standard is not onerous and it is not novel. It is the standard applied to every other party that holds consequential power over people who cannot easily route around it. Give notice before you cut. Provide a real appeal that a human answers. Disclose the framework by which you decide who passes, so that the framework can be examined and complied with and so that bias has nowhere to hide. These three obligations do not require a chokepoint to surrender its position, lower its standards, or carry traffic it has legitimate reason to refuse. They require only that the refusal be visible, contestable, and honest about its basis — which is the difference between an exercise of power and an abuse of it.
The ones who occupy the narrow places have, in 2026, more power over the ordinary conduct of commerce and communication than most governments held over their citizens a century ago, and they hold it with less of the accountability that even a modest government is expected to bear. This is not a call to tear down the narrow places. The traffic has to pass through somewhere, and the companies that built the passages built something genuinely valuable. It is a call to record where the passages are, to measure each one against the plain tests of a governed gate, and to keep the record honestly enough that the difference between the well-stewarded chokepoints and the unaccountable ones stays visible to the people passing through. The power is real and it is concentrated and it is mostly here to stay. What remains open is whether the ones who hold it will accept that to whom much is given, much is required — and the purpose of a catalog like this one is to make the answer to that question a matter of record rather than a matter of trust.
— Odysseus Melchizedek Shiloh, The Wellkeeper, MMXXVI
This catalog is a component of the WellSpr.ing accountability record and is maintained under the NetSentinel legal-hold infrastructure documented at wellspr.ing. The Railway outage of May 19–20, 2026 is drawn from Railway's own published incident report and corroborating contemporaneous reporting; the timeline, the eight-hour duration, the control-plane cascade, and the absence of advance notice are taken from those sources rather than from inference. The 10DLC messaging entry reflects the documented pattern of carrier delivery behavior under the registration regime and is the subject of separate legal-hold notices held under SafeSenders.org. The domain-resolution entry reflects, among other cases, the emergency migration of civic portals away from a major protection provider following takedowns, documented separately in the WellSpr.ing dossier record. The payment-processing entry is stated deliberately at the level of category and standard rather than as an accusation against any named processor in any individual case; the disciplined claim is that the payment gate is the chokepoint where disclosure and recourse are weakest, and the remedy proposed is the aggregation of signal across many cases rather than the litigation of any one. The email-delivery entry is a baseline map of present concentration and is explicitly not a charge of present abuse; delivery is, at the time of writing, functioning, and the entry exists to document the working state against which any future change should be measured. Companies described in this catalog that wish to respond, correct a factual error, or document a change in stewardship posture are invited to do so; the record is intended to be corrigible, and a demonstrated improvement in notice, recourse, or disclosure will be recorded with the same prominence as the failure it remedies. The principle that organizes the entire catalog — that occupying a chokepoint is a position of stewardship whether or not the occupant has accepted the role — is offered not as an indictment of scale but as a standard against which the holders of scale may be fairly and consistently measured. To whom much is given, much is required.