generated: '2026-09-06' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts (constellis.com, the successor host wired as this record's Website pointer), plus a hand-run probe of Academi's own domain academi.com, which carries no Website pointer because it serves no site hosts: - host: academi.com https: false tls_version: null cert_expires: null hsts: false note: 'TLS handshake failure on 443 (no certificate covering the hostname). Port 80 answers HTTP 409 with a Cloudflare "error code: 1001" body on every path, including the apex - an unconfigured-host response. No HSTS because there is no HTTPS response.' - host: constellis.com https: true tls_version: TLSv1.3 cert_expires: Oct 10 00:02:12 2026 GMT hsts: false domains: - domain: academi.com dnssec: true caa: [] spf: true spf_record: v=spf1 include:spf-004a2a01.pphosted.com -all dmarc: true dmarc_policy: reject dmarc_record: v=DMARC1;p=reject;sp=reject;pct=100;rua=mailto:itsec@constellis.com;fo=1 mx: - mxa-004a2a01.gslb.pphosted.com - mxb-004a2a01.gslb.pphosted.com nameservers: AWS Route 53 registrar: Tucows Domains Inc. created: '1999-08-04' expires: '2027-08-04' note: Registered and actively maintained, but web-retired. The DMARC rua address itsec@constellis.com is first-party evidence that the acquirer administers this domain. - domain: constellis.com dnssec: true caa: [] spf: true dmarc: true dmarc_policy: none note: 'academi.com is the subject domain and is recorded first. It has NO working HTTPS listener - the TLS handshake on port 443 fails outright - while its DNS is fully maintained: DNSSEC signed, Proofpoint MX, an SPF record and a DMARC record at p=reject whose aggregate reports go to itsec@constellis.com. That is a mail-retained, web-retired domain administered by the acquirer. constellis.com is the successor operator''s host and its posture is Constellis'', not Academi''s.'