Diagnose a network that blocks the platform

Prompt:

My app loads at home but not on the office Wi-Fi. Is the platform down, or is it the network?

Also works:

  • "A tester says the sign-in page never opens for them."
  • "Your MCP server stopped connecting when I moved to the cafĂ©."

What your tool does

  • Runs two Domain Name System (DNS) lookups of the same name from your machine: one through the network's own resolver, and one over HTTPS through a public resolver (step 1).
  • Compares the two results and tells you whether the network is filtering the name (step 2).
  • Calls read_status with the application's identifier, where it can reach the platform, to read the application's state and version.
  • Drafts the request for the network's administrator, listing the hosts to allow (step 3).
  • Changes no setting on your machine or the network, and asks for no browser approval.

What you need

  • A computer on the network that has the problem, so checks can run there.
  • If possible, a second network to compare against, such as your phone's mobile data.

Before your AI starts

This section is for your AI tool: what it checks and gathers before it begins. You don't need to do these steps yourself.

  • The application's production hostname, <label>.ai.host, or its development hostname, <label>-dev.ai.host. list_applications returns the label.

Steps

The platform uses two domains. turnzero.ai hosts the site, this documentation, your account's sign-in, the Model Context Protocol (MCP) endpoint https://turnzero.ai/mcp, and the platform's routes, including file storage. ai.host hosts every application: each one responds at <label>.ai.host and <label>-dev.ai.host, including its end users' sign-in pages.

Some networks filter names by category. Such a filter responds to a lookup for a blocked domain with the filter vendor's own name, or with no answer at all. The browser then reports that the site cannot be reached, or shows the network's block page.

1. Run the two lookups

Ask the network's resolver first:

nslookup <label>.ai.host

Then ask a public resolver over HTTPS, which bypasses the network's resolver:

curl -s -H "accept: application/dns-json" "https://cloudflare-dns.com/dns-query?name=<label>.ai.host&type=A"

For the platform itself, run both lookups again with turnzero.ai as the name.

2. Read the responses

Where the two lookups agree and both end in an address, the name resolves and the network is not filtering it. Open the hostname from the second network too. Where it fails on both networks, the cause is not the network: read the application's state with read_status.

Where the network's resolver returns another company's name, or nothing, and the lookup over HTTPS returns an address, the network is filtering the domain. The platform and the application are up. Changing networks lets you keep working while you wait for the administrator.

A certificate error is a third case. A network that inspects encrypted traffic can present its own certificate authority for a blocked domain. The browser then rejects the connection with an error such as NET::ERR_CERT_AUTHORITY_INVALID. The padlock shows the network's authority as the issuer, not the platform's.

3. Ask the network's administrator

Only the administrator can change what the network allows. Send the two domains and what each one is for:

Please allow turnzero.ai and ai.host, with every name under ai.host, in the network's DNS and URL filter.
turnzero.ai is the Turn Zero Cloud platform: its site, documentation, sign-in, and developer tools.
ai.host is where applications built on Turn Zero Cloud are served, each at its own name under ai.host.
Opening https://ai.host shows a page that describes the domain and who operates it.

A filter usually blocks by the category its vendor assigned to the domain. Palo Alto Networks, for example, treats a domain as newly registered for its first 32 days, then crawls it. Where the crawl finds too little to read, the vendor keeps the domain in a category it calls insufficient-content. Its recommended rules block both categories.

The administrator can add the two domains to the filter's allow list. They can also ask the vendor to correct the category, which a customer of the vendor can do and we cannot.

4. Give the production page something to read

The same vendor defines insufficient-content to include a host that offers only an application programming interface (API), and a site whose first page asks for a sign-in. That is its written definition; we have not observed it applied to an application. A production application whose first page describes the application in plain text gives such a crawl something to read.

Every application uses a name under ai.host; you cannot attach a domain of your own.

Expected result

On a network that filters the domain, nslookup returns a name that belongs to the filter's vendor, or returns no address. The lookup over HTTPS returns JSON whose Status is 0 and whose Answer list ends in an address. On a network that does not filter, the two results list the same records.

read_status returns the application's state and each environment's deployed version, as Read logs and counters shows.

Opening https://ai.host or https://www.ai.host shows a short page about the domain. It gives the operator's name, links to https://turnzero.ai, and links to the acceptable-use section of the terms for reporting an abusive application. Those two names show only that page. They set no cookie and never reach an application.

Refusals

A refusal changes nothing on the platform. Refusals lists every refusal the platform returns.

Refusal Status Cause Remedy
method_not_allowed 405 A request other than GET or HEAD of / reached ai.host or www.ai.host. Those names serve the page about the domain and nothing else. Send the request to the application's own hostname, <label>.ai.host or <label>-dev.ai.host.
unknown_application 404 The hostname's label matches no application. Use the label list_applications returns for the application.
no_such_application 404 read_status gave an application the account does not have. Use the identifier list_applications returns.