generated: '2026-08-23' method: probed source: live DNS/TLS/HTTP probes of apis.yml + production API hosts, 2026-08-23 note: >- The headline finding is that the canonical marketing site is DOWN over HTTPS. www.jitjatjo.com resolves to the Webflow edge (proxy-ssl.webflow.com) and that edge aborts the TLS handshake with alert 40 (handshake_failure) on all three of its IPs and at every offered TLS version, so no HTTPS request completes at all. The apex jitjatjo.com 301s to it, and news.jitjatjo.com and www.networkplatform.com sit behind the same Webflow edge with the same failure. The Internet Archive's last successful capture of the site is 2026-06-08, which brackets when it broke. The product hosts are healthy — the CloudFront apps and the production API host all negotiate TLS cleanly and the API host sets HSTS. hosts: - host: www.jitjatjo.com https: false note: >- TLS handshake aborted by the Webflow edge (SSL alert 40) at TLS 1.1/1.2/1.3 and from every resolved IP. Canonical marketing site is unreachable. - host: ondemandapi.dayforceflexwork.com https: true hsts: true hsts_max_age: 15768000 hsts_include_subdomains: true note: >- Production API host for the Jitjatjo "Ondemand" web app, read from the app's own JS bundle. On the acquirer's domain following the September 2025 Dayforce acquisition of JJJ International. - host: jobs.jitjatjo.com https: true hsts: true hsts_max_age: 15768000 hsts_include_subdomains: true - host: help.jitjatjo.com https: true hsts: false note: Intercom-hosted help center on a Jitjatjo custom domain; no HSTS header. domains: - domain: jitjatjo.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: reject - domain: dayforceflexwork.com dnssec: false caa: [] spf: true spf_record: >- v=spf1 include:spf.protection.outlook.com ip4:67.231.152.177 ip4:208.84.65.220 ip4:67.231.158.158 ip4:67.231.151.29 -all dmarc: true dmarc_policy: reject note: >- Successor domain carrying the production API hosts. Included because the Jitjatjo apps call it directly; not a separate company.