An enterprising scammer has registered replace-this-with-your-hugo-site.com (don't bother trying it, popups, beeping, probably exploits), which I accidentally discovered after deploying a misconfigured website and leading some customers to this very problematic place.
I suggest that if you try to build a site that uses `{{< ref`` anywhere, for which this has not been properly configured that there is some sort of error.
However, if that's too much, at least replacing it with something like replace-this-with-your-hugo-site.example.com will at least protect against this spammer.