Maybe an html <meta> redirect tag that bounces through a tertiary domain before redirecting to your real one? If they noticed you were doing it they could mitigate it, but they might deem it too much effort and just go away.
You might also start with the hypothesis that they're using regex for JS removal and try various script injection tricks...
You might also start with the hypothesis that they're using regex for JS removal and try various script injection tricks...