I took a look at my server logs and they are mostly 404s.
A lot of bots trying to access various admin panels (notably, WordPress) and secrets files. (I should just block anyone trying that.)
And a fair amount of Fedi software trying to access instance info… on the wrong domain!
So if anyone knows anyone writing Fedi software that uses Go-http-client (probably GoToSocial?) or curl, please tell them that the webfinger part is not optional. You cannot assume the domain from the handle.