# Domain Name System
## Identification
The three IPs are Cloudflare address-space endpoints historically returned for GoMcGill, not proof of the origin server. `pings` is loose source language because DNS lookup and ICMP reachability are separate operations. [PERSON REDACTED] and [PERSON REDACTED] are minimally identified support representatives. PIN/authentication material is redacted.
## Notebook evidence
- [[Scanned_20260730-1659#PDF page 66 — GoMcGill DNS addresses and GoDaddy support transfer|PDF page 66: GoMcGill DNS addresses and GoDaddy support transfer]] — The three addresses were Cloudflare anycast endpoints for `gomcgill.com` at the time written; Cloudflare’s proxy model intentionally returns Cloudflare addresses rather than the origin. The page’s “pings” are therefore evidence of edge routing, not direct evidence of where the origin server lived. The [PERSON REDACTED]-to-[PERSON REDACTED] transfer records a human support escalation layered onto the DNS investigation. Credential/PIN material remains redacted.
## Relationships and overlays
The source places this record in an evidence cluster with [[Anycast|Anycast]] · [[Cloudflare|Cloudflare]] · [[GoDaddy|GoDaddy]] · [[GoMcGill|GoMcGill]] · [PERSON REDACTED] · [PERSON REDACTED].
The occurrence contributes to the notebook's larger model of [[Identity Continuity|identity continuity]], [[Device Sovereignty|device sovereignty]], and [[Continuity Architecture|continuity architecture]].
## Evidentiary status and open leads
Use historical DNS data to determine proxy/origin configuration; identify [PERSON REDACTED] and [PERSON REDACTED] only as support representatives unless corroborated.
## Source
- [[Scanned_20260730-1659|Scanned_20260730-1659]]
## Scanned_20260730-1913 overlay
[[Scanned_20260730-1913]] connects DNS to email and identity continuity. PDF page 3 records domain/email/account migration; page 37 places DNS beside SPF, AT&T, Microsoft, and Google; page 41 records a local gateway hostname. Together these show that registrar control, DNS records, email authentication, local name resolution, and account recovery are separate but linked authority layers.
The record does not establish a DNS attack or unauthorized modification. Historical zone records, registrar logs, timestamps, and authenticated account history would be required.
## Scanned_20260730-1845 overlay
PDF pages 15–19 and 64 of [[Scanned_20260730-1845]] place DNS between registrar/hosting identity and certificate trust: Tucows/ONE.NET/Onehub, custom domains, Verisign, NS1, DNS apex, Let's Encrypt, ISRG Root X1, RSA, and a later clickjacking/security note.
This clarifies three distinct authorities: registrar ownership, authoritative DNS service, and certificate issuance. The handwritten `NS1 one.net` remains ambiguous, and no DNS modification or attack is established without historical zone, registrar, certificate, and timestamp evidence.