generated: '2026-08-26' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts hosts: - host: musaffa.com https: true tls_version: TLSv1.3 cert_expires: Oct 16 06:06:35 2026 GMT hsts: false - host: api.musaffa.com https: true tls_version: TLSv1.3 cert_expires: Oct 9 17:42:31 2026 GMT hsts: true hsts_max_age: 31556926 - host: platform.musaffa.com https: false probe_note: >- Recorded as https:false because neither `openssl s_client` nor curl could complete a clean TLS session with this host on 2026-08-26 (curl reported HTTP status 000, no certificate could be read). The host DOES serve content over https — a 938KB Next.js SPA shell came back for every path tried — but the connection terminates abnormally, so no TLS version, certificate expiry or HSTS value could be measured. Treat this as an unmeasured host, not as a plaintext one. domains: - domain: musaffa.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: none