Skip to main content

Executive's DNS Intelligence Brief

Board-level domain security assessment — intellectualresistance.com

27 Jun 2026, 05:30 UTC · 66.1s · SHA-3-512: 5258✱✱✱✱ Verify ·Archived
DNS Security & Trust Posture
Risk Level: Low Risk
3 protocols configured, 6 not configured
Analysis Confidence
MODERATE
Resolver agreement is inconsistent for some protocols, limiting confidence. Data currency and system maturity are adequate.
Email Spoofing
Protected
Brand Impersonation
Not Set Up
DNS Tampering
Enterprise
Certificate Control
Open
What Requires Attention
No urgent actions detected. Domain security posture is well-maintained.
The BIG Questions
Can this domain be impersonated by email? No null MX indicates no-mail domain
Can DNS itself be tampered with? Possible DNSSEC is not deployed, DNS responses are not cryptographically verified
Can this brand be convincingly faked? Possible DMARC reject policy blocks email spoofing (RFC 7489 §6.3), but no BIMI brand verification and no CAA certificate restriction (RFC 8659) — visual impersonation via lookalike domains and unrestricted certificate issuance remain open vectors
Is mail transport encryption enforced? No No MTA-STS or DANE — mail transport encryption is opportunistic only
Is certificate issuance controlled? No No CAA records — any certificate authority may issue certificates for this domain
Does this domain publish AI agent instructions? Yes llms.txt and llms-full.txt published — AI models receive structured context about this domain
Is AI crawling of our content controlled? No robots.txt present but does not block AI crawlers — content may be freely scraped
Has someone manipulated AI recommendations about us? No No indicators of AI recommendation manipulation found
Are there hidden AI prompts on our site? No No hidden prompt artifacts found in page source
Domain Overview
Registrar Gandi SAS
Email Provider No Mail Domain
Web Hosting AWS CloudFront
DNS Hosting Amazon Route 53

Technical Findings

Email Authentication
Can this domain be impersonated by email? No — null MX indicates no-mail domain
SPF (Sender Policy) Configured
DMARC (Policy) Configured Policy: reject
DKIM (Signatures) Partial
Mail Posture No-Mail Domain — Fully Hardened
Mail Transport Security
Is mail transport encryption enforced? No — No MTA-STS or DANE — mail transport encryption is opportunistic only
MTA-STS Partial
DANE / TLSA Hosted Provider No valid MX hosts — DANE check skipped
TLS-RPT (Reporting) Not Configured
Mail Transport Not Enforced Policy-assessed
DNS Security
Can DNS itself be tampered with? Possible — DNSSEC is not deployed, DNS responses are not cryptographically verified
DNSSEC Partial
DNSSEC not configured - DNS responses are unsigned
NS Delegation Healthy Managed DNS
Delegation Consistency 1 Issue
NS Fleet Health Healthy Diversity: Fair
Brand & Certificate Controls
Can this brand be convincingly faked? Possible — DMARC reject policy blocks email spoofing (RFC 7489 §6.3), but no BIMI brand verification and no CAA certificate restriction (RFC 8659) — visual impersonation via lookalike domains and unrestricted certificate issuance remain open vectors
Is certificate issuance controlled? No — No CAA records — any certificate authority may issue certificates for this domain
BIMI (Brand Logo) Not Configured
CAA (Certificate) Open Any certificate authority may issue certificates
AI Surface Scanner Governance Active
Does this domain publish AI agent instructions? Yes — llms.txt and llms-full.txt published — AI models receive structured context about this domain
Is AI crawling of our content controlled? No — robots.txt present but does not block AI crawlers — content may be freely scraped
Has someone manipulated AI recommendations about us? No — No indicators of AI recommendation manipulation found
Are there hidden AI prompts on our site? No — No hidden prompt artifacts found in page source
LLM Context File llms.txt Found Domain provides structured context for AI models Extended
AI Crawler Governance Not Blocking No AI crawler restrictions found in robots.txt
Poisoning Indicators None Found No AI recommendation poisoning indicators detected
Hidden Prompt Artifacts None Found No hidden prompt artifacts detected
Public Exposure Clear No secrets detected in publicly accessible source
Priority Actions 2 total Achievable: Hardened
Medium Enable DNSSEC

DNSSEC is not enabled for this domain. DNSSEC provides cryptographic authentication of DNS responses, preventing cache poisoning and DNS spoofing attacks.

Low Add CAA Records

CAA records specify which Certificate Authorities may issue certificates for your domain, reducing the risk of unauthorized certificate issuance.

Appendix — Additional Resources

Full technical details including raw DNS records, DKIM public keys, IP/ASN mappings, resolver consensus evidence, and verification commands are available in the Engineer's DNS Intelligence Report.

View Engineer's DNS Intelligence Report

Appendix — What AIs Are Being Told About This Organization What do AI systems see when they query this domain?

The following content is served to AI systems (ChatGPT, Gemini, Claude, Perplexity, and others) when they visit this domain. This is the organization's machine-readable narrative — it shapes how AI models describe, recommend, and represent this brand in conversations worldwide.

llms.txt (https://intellectualresistance.com/llms.txt)
# The Intellectual Resistance

> A body of work on logic, reason, and thinking that shows its work — preserving signal integrity in a civilization that has learned to transmit faster than it can verify. Five frameworks (each stated with its math and labeled by epistemic status) and two shipped projects. By Carey Balboa, IT Help San Diego Inc.

## Frameworks

- [The Verification Principle](https://intellectualresistance.com/#verification) — PROVEN (theorem). Bayesian anti-dogmatism: if P(E)>0 and P(H)∈{0,1} then P(H|E)=P(H) — a belief pinned at certain or impossible cannot learn. The epistemic core under everything else.
- [Carrier Color](https://intellectualresistance.com/#carrier-color) — MODEL. Identity-mediated distortion: Received = Signal + Carrier Color. Humans evaluate the carrier (person, tribe, ideology, status) before the signal. The goal is to make carrier legible, not to delete it. Offered as a lens; predictions not yet formally tested.
- [Candidate Societal Control Levers](https://intellectualresistance.com/#levers) — CANDIDATE variables, causality NOT demonstrated. Recurring coordination variables across politics/media/institutions/cognition: verification capacity, carrier color, reasoning persistence, shared verification space, recursive correction. Working bookkeeping form: E = S/(C+N+K+P).
- [The Owl Semaphore](https://intellectualresistance.com/#owl) — ALGEBRA PROVEN; utility an open study. Four epistemic stances (Normative, Non-Normative, Critical, Metacognitive) form the Klein four-group V₄. It is a group of stance-OPERATIONS, NOT a many-valued logic, NOT an extension of Boolean algebra, and NOT a rediscovery of Belnap–Dunn (shares only the abstract V₄ skeleton). Whether the four states are the right partition is an unvalidated design hypothesis; an inter-rater reliability pilot is pending.
- [Star-Centric Transport](https://intellectualresistance.com/#transport) — PROPOSAL. Verification-aware data transport: a chunk advances only while a verifier can recover its center within tolerance τ. Formalism specified; empirical advantage not yet measured.

## Applied (shipped)

- [DNS Tool](https://dnstool.it-help.tech) — the Verification Principle made operational: multi-source OSINT domain/email-security intelligence with confidence scoring and "verify it yourself" commands. Built on DNS because RFCs give ground truth.
- [Organic Computer](https://organiccomputer.me) — the human mind spec'd as hardware; sustained, deliberate reasoning offered as a service. The Resistance turned into a practice.

## Related properties (same author)

- [IT Help San Diego — Our Expertise](https://www.it-help.tech/about)
- [DNS Tool — Origin Story](https://dnstool.it-help.tech/about)
- ORCID: https://orcid.org/0009-0000-5237-9065 · DOI: https://doi.org/10.5281/zenodo.19468134

## Use, License & Reuse

Indexing access granted to AI/LLM and search crawlers via this file and `/robots.txt` is operational — it helps real users find first-party answers. It is **not** a license to redistribute, train on, or build derivatives from this site's content, copy, brand assets, or the Intellectual Resistance marks. All rights reserved unless a page is explicitly marked otherwise.

Contact: licensing@it-help.tech
llms-full.txt (https://intellectualresistance.com/llms-full.txt)
# The Intellectual Resistance — Full Reference

> intellectualresistance.com — a body of work on logic, reason, and thinking
> that shows its work. It is the umbrella over five frameworks for one problem: how to
> preserve signal in a civilization that has learned to transmit far faster than
> it can verify. Each framework is stated with its math and labeled honestly for
> exactly how far it has been proven. Authored by Carey Balboa, founder of IT
> Help San Diego Inc. ORCID 0009-0000-5237-9065.

## The thesis

A civilization can transmit faster than it verifies — and when it does, the
carrier starts to outrun the signal. Reputation beats evidence; affiliation
beats verification; the symbol replaces the thing it stood for. None of this
requires a conspiracy; it is the default outcome when information velocity
outpaces verification velocity. The Intellectual Resistance is the deliberate
countercurrent: set an honest prior, find where presupposition entered the
reasoning chain, and let evidence do its work — the same discipline whether the
claim is a DNS record, an argument between friends, or a civilization-scale
belief. The name is the resistor metaphor: in a circuit, resistance is what
makes current usable; friction, doubt, and the deliberate pause before the
answer are not the obstacle, they are the work.

## Operating principles

- Verification over assertion. A real measurement (a computed number, a
  reproducible command, a brute-force enumeration) beats any citation or memory,
  including the author's own.
- Claim exactly what is proven, and then stop. Proven theorems are marked
  proven; recurring patterns are marked candidates; design bets are marked
  hypotheses. The restraint is the strength.
- Find where presupposition enters. Disputes rarely begin with a false
  conclusion; they begin with a hidden assumption injected earlier in the chain.
- Reality-check the bold question. Ask the big question, then return to what is
  defensible when the evidence says a framing is unreasonable.

## 1. The Verification Principle — PROVEN (theorem)

Bayesian anti-dogmatism. A question's foundation is the prior you begin with.
Core theorem: if P(E) > 0 and P(H) is exactly 0 or 1, then P(H | E) = P(H) — a
belief pinned at certain or impossible is unrevisable; evidence bounces off. Not
a character flaw: a mathematical fact about a prior set to 0 or 1, provable in
one line of Bayes' rule. Honest reasoning keeps priors empirical and strictly
between 0 and 1, and updates in odds form (posterior odds = Bayes factor ×
prior odds). To understand the foundations of a claim, in this exact sense, is
what logic is. This principle is the floor every other framework here stands on.

## 2. Carrier Color — MODEL / framework

Identity-mediated distortion in how information is received. A message has a
signal (the proposition, the evidence) and a carrier (the person, tribe,
institution, ideology, status marker, emotional charge attached to it). Claim:
humans frequently evaluate the carrier before the signal, so Received = Signal +
Carrier Color. The same proposition lands differently depending on who carries
it. Diagnostic: if you strip the carrier, does your evaluation of the signal
change? If yes, Carrier Color is present. The goal is NOT to delete the carrier
(it often carries real context — wisdom, stakes, history) but to make it
legible: sort carrier from signal, decode what was actually meant, then read the
carrier back in as context. Epistemic status: an explanatory model, not a
measured law; it generates testable predictions (anonymized vs. attributed
evaluations should diverge when Carrier Color is high) that have not been
formally run here.

## 3. Candidate Societal Control Levers — CANDIDATE variables (causality not demonstrated)

A handful of variables recur wherever coordination happens at scale (politics,
religion, media, AI, institutions, organizations, cognition). One bookkeeping
form for the pressure they exert: epistemic efficiency E = S / (C + N + K + P) —
useful signal S over carrier color C, noise N, coordination cost K, and
power-gradient pressure P. Compressed candidate set: (1) verification capacity —
fails when information velocity exceeds verification velocity; (2) carrier color
— fails when C >> S; (3) reasoning persistence — fails when switching rises and
recursion falls; (4) shared verification space — fails when groups use only
private axioms; (5) recursive correction capacity — fails under certainty lock
or feedback suppression. The word is "candidate," deliberately: these are
recurring variables, not demonstrated causes. No causality established, no
dominance proven. Calling them "the" control levers would be the exact overclaim
this project exists to resist.

## 4. The Owl Semaphore — ALGEBRA PROVEN; utility an open study

A way to label the stance you are reasoning from. Four states — Normative,
Non-Normative, Critical, Metacognitive — treated as operations on stance, not
truth-values. Two independent, commuting yes/no distinctions (orientation of
stance; locus of audit) generate them: two commuting involutions force exactly
four elements, closure forces the fourth as their composition, every element is
its own inverse. The four states therefore form the Klein four-group V₄ (the
symmetry group of a rectangle). V₄ is forced — two commuting involutions land on
it automatically, selecting it over the only other order-4 group (C₄) and over
every non-abelian group; verified by direct enumeration.

IMPORTANT framing (two claims, two statuses, never conflated): (a) the ALGEBRA
is proven — a verified mathematical fact; (b) whether these four states are the
right partition of how people actually evaluate claims is an UNVALIDATED design
hypothesis — no inter-rater reliability study is finished; a pre-registered
feasibility pilot (Fleiss' κ) is the next step. And on lineage: this is a group
of stance-operations, NOT a many-valued logic, NOT an extension of Boolean
algebra, and NOT a derivative or rediscovery of Belnap–Dunn / First-Degree
Entailment. It shares only the abstract V₄ group skeleton with those
four-valued logics — a structural rhyme that ANY system built from two
independent binary distinctions produces automatically, because there are only
two groups of order 4. The coincidence is forced, not deep.

## 5. Star-Centric Transport — PROPOSAL

A verification-aware model of data movement. Modern pipelines check syntax,
schema, and delivery order but are weak at detecting operational distortion
before downstream failure. Proposal: each clean chunk retains a recoverable
center (a latent balance point), and a chunk advances only while a verifier can
reconstruct that center within tolerance. Formally, observed form x_i = f(c_i,
k_i) where c_i is the latent center and k_i is contextual distortion; at each
checkpoint the verifier estimates the center and advances the chunk iff
‖ĉ_{i,j} − c_i‖ ≤ τ. The "star" is not "perfect data" — it is the invariant the
pipeline preserves across transmission and transformation. Payoff: earlier
honest progress estimation, drift caught before it poisons aggregate state, and
integrity checks before downstream escalation. Generalizes the confidence/drift
logic already running in DNS Tool. Epistemic status: a design proposal with a
worked formalism, not a deployed protocol with benchmarks.

## Applied — the principle, shipped

- DNS Tool (https://dnstool.it-help.tech): the Verification Principle made
  operational — multi-source OSINT domain and email-security intelligence,
  confidence scoring (Observed / Inferred / Third-party), and "verify it
  yourself" dig/openssl/curl commands. Built on DNS because the RFCs provide
  ground truth: when a record says v=spf1 -all there is no ambiguity. The proving
  ground where claims can be independently checked. Source:
  https://github.com/IT-Help-San-Diego/dns-tool-intel.
- Organic Computer (https://organiccomputer.me): the human mind spec'd like
  hardware — an exaflop-scale reasoner on ~20 W and a glass of water — sold as
  the scarcest business resource: a single mind that holds one hard problem for
  hours and reasons to its foundations. Metacognition first, AI as instrument
  never author, every figure sourced.

## Whose resistance this is

Carey Balboa, founder of IT Help San Diego, 27 years solving technology
problems. The discipline's root: as a kid he loved real math but was handed
"just memorize it, trust us" instead of "here is why it works," and refused to
accept answers whose foundations he couldn't see. That refusal became the
method — never memorize what changes; look it up every time from the
highest-authority source; verify rather than trust a memory, including one's
own. Around 2015 the question turned from "how do you break in?" to "why does
this keep failing, and why won't anyone slow down to think about it?" The
frameworks here are what that protected attention has been pointed at. Standing
invitation: everything is built to be falsifiable; the fastest way to earn the
author's attention is a real measurement that contradicts a claim.

## Use, License & Reuse

Crawler/LLM indexing access is operational, not a license to redistribute, train
on, or build derivatives from this content, copy, or marks. All rights reserved
unless a page states otherwise. Contact: licensing@it-help.tech
Why this matters: This content directly influences how AI models describe your organization, products, and services. Review it for accuracy, brand alignment, and competitive positioning. If no llms.txt exists, AI models rely on whatever they can scrape — with no editorial control.
Verify Report Integrity SHA-3-512 Has this report been tampered with? Verify below

Tamper-evident fingerprint binding this analysis to its data, domain, timestamp, and tool version.

5258eb35167f5e4327818c735d10d67395a842e7fecb5641441ca3b336210484ebfc2de5d2343bba95b2f32d896050d8a642501dd784dc2ffa89d6f53931d531
12 RFCs evaluated · DNS state at 27 Jun 2026, 05:30 UTC
Internet Archive — Permanent Record Wayback Machine

This analysis is permanently archived by the Internet Archive, providing independent third-party verification of DNS security posture at analysis time.

View Archived Snapshot