# Domain Name System ## Identification The three IPs are Cloudflare address-space endpoints historically returned for GoMcGill, not proof of the origin server. `pings` is loose source language because DNS lookup and ICMP reachability are separate operations. [PERSON REDACTED] and [PERSON REDACTED] are minimally identified support representatives. PIN/authentication material is redacted. ## Notebook evidence - [[Scanned_20260730-1659#PDF page 66 — GoMcGill DNS addresses and GoDaddy support transfer|PDF page 66: GoMcGill DNS addresses and GoDaddy support transfer]] — The three addresses were Cloudflare anycast endpoints for `gomcgill.com` at the time written; Cloudflare’s proxy model intentionally returns Cloudflare addresses rather than the origin. The page’s “pings” are therefore evidence of edge routing, not direct evidence of where the origin server lived. The [PERSON REDACTED]-to-[PERSON REDACTED] transfer records a human support escalation layered onto the DNS investigation. Credential/PIN material remains redacted. ## Relationships and overlays The source places this record in an evidence cluster with [[Anycast|Anycast]] · [[Cloudflare|Cloudflare]] · [[GoDaddy|GoDaddy]] · [[GoMcGill|GoMcGill]] · [PERSON REDACTED] · [PERSON REDACTED]. The occurrence contributes to the notebook's larger model of [[Identity Continuity|identity continuity]], [[Device Sovereignty|device sovereignty]], and [[Continuity Architecture|continuity architecture]]. ## Evidentiary status and open leads Use historical DNS data to determine proxy/origin configuration; identify [PERSON REDACTED] and [PERSON REDACTED] only as support representatives unless corroborated. ## Source - [[Scanned_20260730-1659|Scanned_20260730-1659]] ## Scanned_20260730-1913 overlay [[Scanned_20260730-1913]] connects DNS to email and identity continuity. PDF page 3 records domain/email/account migration; page 37 places DNS beside SPF, AT&T, Microsoft, and Google; page 41 records a local gateway hostname. Together these show that registrar control, DNS records, email authentication, local name resolution, and account recovery are separate but linked authority layers. The record does not establish a DNS attack or unauthorized modification. Historical zone records, registrar logs, timestamps, and authenticated account history would be required. ## Scanned_20260730-1845 overlay PDF pages 15–19 and 64 of [[Scanned_20260730-1845]] place DNS between registrar/hosting identity and certificate trust: Tucows/ONE.NET/Onehub, custom domains, Verisign, NS1, DNS apex, Let's Encrypt, ISRG Root X1, RSA, and a later clickjacking/security note. This clarifies three distinct authorities: registrar ownership, authoritative DNS service, and certificate issuance. The handwritten `NS1 one.net` remains ambiguous, and no DNS modification or attack is established without historical zone, registrar, certificate, and timestamp evidence.