```
; <<>> DiG 9.8.3-P1 <<>> mail.google.com @112.124.47.27
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 29988
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 0
;; QUESTION SECTION:
;mail.google.com. IN A
;; ANSWER SECTION:
mail.google.com. 600 IN A 203.195.174.41
;; AUTHORITY SECTION:
mail.google.com. 600 IN NS localhost.
;; Query time: 59 msec
;; SERVER: 112.124.47.27#53(112.124.47.27)
;; WHEN: Mon Apr 6 00:29:19 2015
;; MSG SIZE rcvd: 72
```
查了一下, 得到
http://www.ipcheck.cn/203.195.174.41
这个ip所在的地址段属于腾讯。
如果直接访问这个ip, Chrome会警告说这个网站的证书是给google.com的,和地址203.195.174.41不符,而证书本身,Chrome说 is valid.
我没有足够的知识来理解这里发生了什么,腾讯从自己的ip反向代理了google的ip么?或者是个陷阱?
有人能告诉我发生了什么吗?
以及,能建议几个搜索关键词关于实现这个的技术么?
然后不妨看看别的国内DNS的解析结果。
```
; <<>> DiG 9.8.3-P1 <<>> mail.google.com @114.114.114.114
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 60812
;; flags: qr rd ra; QUERY: 1, ANSWER: 6, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;mail.google.com. IN A
;; ANSWER SECTION:
mail.google.com. 376948 IN CNAME googlemail.l.google.com.
googlemail.l.google.com. 40 IN CNAME mail-china.l.google.com.
mail-china.l.google.com. 41 IN A 173.194.72.83
mail-china.l.google.com. 41 IN A 173.194.72.17
mail-china.l.google.com. 41 IN A 173.194.72.18
mail-china.l.google.com. 41 IN A 173.194.72.19
;; Query time: 73 msec
;; SERVER: 114.114.114.114#53(114.114.114.114)
;; WHEN: Mon Apr 6 00:30:47 2015
;; MSG SIZE rcvd: 149
```
173.194.72.83 据 https://ipinfo.io/173.194.72.83 说在Mountain View, 有趣的地方在CNAME是mail-china.l.google.com, 也许Google退出中国之前,mail-china.l.google.com 曾经指向一台国内的服务器?
作为参考,dnscrypt-proxy -> dnscrypt-wrapper -> 8.8.8.8 的结果是这样的
; <<>> DiG 9.8.3-P1 <<>> mail.google.com @127.0.0.1
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 39017
;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;mail.google.com. IN A
;; ANSWER SECTION:
mail.google.com. 21599 IN CNAME googlemail.l.google.com.
googlemail.l.google.com. 299 IN A 173.194.123.53
googlemail.l.google.com. 299 IN A 173.194.123.54
;; Query time: 361 msec
;; SERVER: 127.0.0.1#53(127.0.0.1)
;; WHEN: Mon Apr 6 00:31:12 2015
;; MSG SIZE rcvd: 103
还有更多的google有关的域名,从国内的DNS查询,会得到国内的ip:
"www-google-analytics.l.google.com",
"ssl.google-analytics.com",
"clients1.google.com",
"oauth.googleusercontent.com",
"clients4.google.com",
"googlehosted.l.googleusercontent.com",
"code.google.com",
"ssl-google-analytics.l.google.com",
"ssl.gstatic.com",
"mail.google.com",
"clients2.google.com",
"safebrowsing.cache.l.google.com",
"www.gstatic.com",
"accounts.google.com",
"plus.google.com",
"support.google.com",
"play.google.com",
"translate.google.com",
"clients5.google.com",
"csi.gstatic.com",
"lh3.googleusercontent.com",
"maps.googleapis.com",
"fonts.googleapis.com",
"p4-fjxzzhhbnbftk-wqtl63hegtnygzcr-if-v6exp3-v4.metric.gstatic.com",
"googleadapis.l.google.com",
"fonts.gstatic.com",
"maps.gstatic.com",
"clients3.google.com",
"ajax.googleapis.com",
"chrome.google.com",
"www.googleapis.com",
"gmail.com",
"chatenabled.mail.google.com",
"ci6.googleusercontent.com",
"ci3.googleusercontent.com",
"clients6.google.com",
"mail-attachment.googleusercontent.com",
"lh6.googleusercontent.com"
其中 oauth.googleusercontent.com 有国内的ip让我睡意消退了一些。
; <<>> DiG 9.8.3-P1 <<>> mail.google.com @112.124.47.27
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 29988
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 0
;; QUESTION SECTION:
;mail.google.com. IN A
;; ANSWER SECTION:
mail.google.com. 600 IN A 203.195.174.41
;; AUTHORITY SECTION:
mail.google.com. 600 IN NS localhost.
;; Query time: 59 msec
;; SERVER: 112.124.47.27#53(112.124.47.27)
;; WHEN: Mon Apr 6 00:29:19 2015
;; MSG SIZE rcvd: 72
```
查了一下, 得到
http://www.ipcheck.cn/203.195.174.41
这个ip所在的地址段属于腾讯。
如果直接访问这个ip, Chrome会警告说这个网站的证书是给google.com的,和地址203.195.174.41不符,而证书本身,Chrome说 is valid.
我没有足够的知识来理解这里发生了什么,腾讯从自己的ip反向代理了google的ip么?或者是个陷阱?
有人能告诉我发生了什么吗?
以及,能建议几个搜索关键词关于实现这个的技术么?
然后不妨看看别的国内DNS的解析结果。
```
; <<>> DiG 9.8.3-P1 <<>> mail.google.com @114.114.114.114
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 60812
;; flags: qr rd ra; QUERY: 1, ANSWER: 6, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;mail.google.com. IN A
;; ANSWER SECTION:
mail.google.com. 376948 IN CNAME googlemail.l.google.com.
googlemail.l.google.com. 40 IN CNAME mail-china.l.google.com.
mail-china.l.google.com. 41 IN A 173.194.72.83
mail-china.l.google.com. 41 IN A 173.194.72.17
mail-china.l.google.com. 41 IN A 173.194.72.18
mail-china.l.google.com. 41 IN A 173.194.72.19
;; Query time: 73 msec
;; SERVER: 114.114.114.114#53(114.114.114.114)
;; WHEN: Mon Apr 6 00:30:47 2015
;; MSG SIZE rcvd: 149
```
173.194.72.83 据 https://ipinfo.io/173.194.72.83 说在Mountain View, 有趣的地方在CNAME是mail-china.l.google.com, 也许Google退出中国之前,mail-china.l.google.com 曾经指向一台国内的服务器?
作为参考,dnscrypt-proxy -> dnscrypt-wrapper -> 8.8.8.8 的结果是这样的
; <<>> DiG 9.8.3-P1 <<>> mail.google.com @127.0.0.1
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 39017
;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;mail.google.com. IN A
;; ANSWER SECTION:
mail.google.com. 21599 IN CNAME googlemail.l.google.com.
googlemail.l.google.com. 299 IN A 173.194.123.53
googlemail.l.google.com. 299 IN A 173.194.123.54
;; Query time: 361 msec
;; SERVER: 127.0.0.1#53(127.0.0.1)
;; WHEN: Mon Apr 6 00:31:12 2015
;; MSG SIZE rcvd: 103
还有更多的google有关的域名,从国内的DNS查询,会得到国内的ip:
"www-google-analytics.l.google.com",
"ssl.google-analytics.com",
"clients1.google.com",
"oauth.googleusercontent.com",
"clients4.google.com",
"googlehosted.l.googleusercontent.com",
"code.google.com",
"ssl-google-analytics.l.google.com",
"ssl.gstatic.com",
"mail.google.com",
"clients2.google.com",
"safebrowsing.cache.l.google.com",
"www.gstatic.com",
"accounts.google.com",
"plus.google.com",
"support.google.com",
"play.google.com",
"translate.google.com",
"clients5.google.com",
"csi.gstatic.com",
"lh3.googleusercontent.com",
"maps.googleapis.com",
"fonts.googleapis.com",
"p4-fjxzzhhbnbftk-wqtl63hegtnygzcr-if-v6exp3-v4.metric.gstatic.com",
"googleadapis.l.google.com",
"fonts.gstatic.com",
"maps.gstatic.com",
"clients3.google.com",
"ajax.googleapis.com",
"chrome.google.com",
"www.googleapis.com",
"gmail.com",
"chatenabled.mail.google.com",
"ci6.googleusercontent.com",
"ci3.googleusercontent.com",
"clients6.google.com",
"mail-attachment.googleusercontent.com",
"lh6.googleusercontent.com"
其中 oauth.googleusercontent.com 有国内的ip让我睡意消退了一些。