Members of the Incarnate Word Institute say they don’t know who has access to their websites.
But what does it mean exactly? That they don’t know a password? That they lost contact with a provider? That they can’t identify who manages the main domain of the institution?
We examined public traces of ive.org. We found a current domain, identifiable vendors, configured institutional email, and signs of recent technical activity. The results do not reveal who has the passwords. They do allow us to ask specific questions that the IVE should answer.
The first part explains the findings in everyday language. The second part presents the technical data and their limits, for those who want to examine the basis of the research.
A current domain and identifiable services
The domain ive.org has an expiration date of March 2, 2027. The records consulted show recent administrative changes. This does not allow you to determine the exact date of renewal or who intervened: a change of the record and a renewal are separate operations.
The domain is registered through Network Solutions. Its public internet address allows the hosting infrastructure to be identified. The email logs point to Google servers.
We are not, therefore, dealing with services that are impossible to locate. There are specific providers from which it is possible to investigate who contracted the accounts and what mechanisms exist to recover them. The fact that this information does not appear publicly does not prove that the institution lacks the means to obtain it.
The site features recent technical activity
The October 1, 2026 check found web style files with modification dates of that same day. One of them is associated with the home page. Between the September and October observations, some version identifiers of the resources served by the site also changed.
That doesn’t prove that someone came in that morning to edit the front page. Automatic updates, caching processes, or file regeneration can produce changes without immediate human intervention.
What the answers examined do show is that the infrastructure works and shows recent signs of technical processing. A website can preserve old texts while its components change. The age of its publications is not enough to describe it as completely abandoned.
A support address on the domain itself
The public mail configuration includes soporte@ive.org as the recipient address for technical reports on message authentication.
We do not know if that directorate receives the reports or if anyone reads them. But it is in a specific configuration. It is another clue: who created it, who manages it, can it be used to locate the technical manager?
“We don’t know” needs an explanation
It is possible that certain members of the IVE do not know the credentials. Public research does not allow us to establish what each person knows. But this individual ignorance does not solve the institutional question.
Who contracted the domain? Who receives the hosting bills? What addresses are used to recover the accounts? Who manages the mail? Have the providers been contacted to clarify this?
If the services work automatically, it must be clarified under which accounts and contracts. If they are managed by an external company, it must be identified. If the credentials were lost, it must be explained what steps were taken to recover them and with what result.
There may be real difficulties. What is lacking, in the explanation conveyed to the author, is a verifiable description of those difficulties.
What the data allow us to affirm
The evidence does not prove a deliberate lie by a given person. Nor does it prove that the superiors of the IVE know the passwords. Presenting it like this would go beyond what was observed.
But the findings do allow us to question the sufficiency of the answer. The domain is current, the services have identifiable providers and the site has recent technical activity. There are specific points from which to investigate its administration.
There is no need to divulge passwords or compromise the security of the website. It is enough to identify the responsibilities, specify what control the institution retains and document the steps taken to recover what it says it does not know.
Saying “we don’t know” can be the beginning of an investigation. It shouldn’t be your conclusion.
White Paper: Data, Sources, and Limits
The following observations are from the public consultations conducted on 18 September and 1 October 2026. They are dated observations: the responses of the services may change. The links allow the consultations to be repeated, but they do not guarantee that they will reproduce the historical results.
Examined RDAP and DNS records, HTTP headers, HTML, sitemaps, and public WordPress REST API responses. No credentials were used, no login was attempted, and no attempt was made to circumvent access controls. Times are expressed in UTC unless otherwise stated.
1. Domain registration
The RDAP registry of Public Interest Registry, operator of .org, and the RDAP registry of Network Solutions, registrar of the domain, were consulted.
| Field | Observed Result |
|---|---|
| Domain | ive.org |
| Registrar | Network Solutions, LLC |
| IANA Identifier | 2 |
| Creation, according to the .org registry | 1997-03-01T05:00:00.678Z |
| Expiration | 2027-03-02T05:00:00Z |
| Last modified, according to the .org registry | 2026-08-12T08:58:49.504Z |
| Last modified, per Network Solutions | 2026-09-07T06:37:43Z |
| Status | Client Transfer Prohibited |
| DNSSEC | delegationSigned: false |
Public Interest Registry also indicated an update of its RDAP database to the 2026-10-01T12:59:17.679Z. Network Solutions indicated 2026-09-07T06:37:43Z for its RDAP database update field. These fields should not be confused with an action of the owner.
Interpretation: The domain has a future expiration date, and the records contain recent events. Last modified dates differ between the two sources and are retained as such. Neither allows you to state on its own when the domain was renewed. The transfer restriction status also does not identify the user of the account.
2. Registry privacy
Network Solutions presents the contacts of the owner and the technical manager through PERFECT PRIVACY, LLC. The published addresses are wj8rn3ta992@networksolutionsprivateregistration.com for the owner and zg9ym4nz9wd@networksolutionsprivateregistration.com for the technical contact.
These addresses belong to the privacy service and do not publicly identify the actual controller. The use of registry privacy is common; it does not in itself constitute evidence of misconduct.
3. DNS and domain resolution
| Inquiry | Observed Result |
|---|---|
| A for ive.org | 70.32.23.90 |
| CNAME of www.ive.org | ive.org |
| NS | ns1.supercp.com, ns2.supercp.com, ns3.supercp.com, ns4.supercp.com |
| 70.32.23.90 PTR | mi3-sr28.supercp.com |
| CAA | No CAA record in the examined response |
The SOA information received in the authority section of the DNS query was:
ns1.supercp.com. root.mi3-sr28.supercp.com. 2026081300 3600 1800 1209600 86400
The serial 2026081300 number is formatted as August 13, 2026, followed by a counter. This is an inference based on a common convention, not a demonstrated change date: the administrator can use another convention or set the number manually. The queries were made using Google’s public DNS service.
4. Hosting infrastructure
ARIN’s RDAP query for 70.32.23.90 placed the address in the block70.32.16.0/20, named INTERNET-BLK-A2HOS-14, with A2 Hosting, Inc. as the registrant. Associated contact entities also include WHG Hosting Services Ltd.
The organization’s record included a registration date of March 16, 2004, and a modification date of March 31, 2026. This is vendor data, not events attributable to the ive.org account.
Limit: Assigning an IP address identifies network infrastructure. It does not identify the contractual customer of the hosting or the holder of the credentials.
5. Mail: MX, SPF, DMARC and DKIM
| MX Priority | Server |
|---|---|
| 1 | aspmx.l.google.com |
| 5 | alt1.aspmx.l.google.com |
| 5 | alt2.aspmx.l.google.com |
| 10 | alt3.aspmx.l.google.com |
| 10 | alt4.aspmx.l.google.com |
The published SPF record was:
v=spf1 include:_spf.google.com ~all
The DMARC policy was _dmarc.ive.org :
v=DMARC1;p=quarantine;sp=none;adkim=s;aspf=s;pct=100;fo=0;rf=afrf;ri=86400;rua=mailto:soporte@ive.org
The configuration declares quarantine for the primary domain, a policy none for subdomains, strict SPF and DKIM alignment, 100% enforcement, and sending aggregated reports to soporte@ive.org. A DKIM RSA public key was also found in default._domainkey.ive.org; the full value of the key is not reproduced in this report.
Interpretation and limits: MXs are supported by Google Workspace. The logs show that these settings have been published, but they do not provide evidence of a current subscription, the operation of each mailbox, the receipt of reports, or the actual use of the DKIM key.
6. HTTP Response and WordPress
The HTTPS query on the cover page returned HTTP/2 200. The headers server: LiteSpeed, x-powered-by: PHP/8.5.10 and content-type: text/html; charset=UTF-8, along with HSTS, x-frame-options and x-content-type-options.
The response set a cookie pll_language=es, expiring on October 1, 2027, and posted links to the REST API and the page with ID 2. The headers describe what the server declares; they are not a substitute for an internal inspection of its configuration.
http://ive.org/ and https://www.ive.org/ redirected via 301 to https://ive.org/responses, with attribution of the redirect to WordPress.
https://ive.org/wp-login.php redirected by a 302 response to https://ive.org/iveorg/wp-login.php, where the login page with status 200 and a cookie wordpress_test_cookieresponded. The path https://ive.org/wp-admin/ redirected to /iveorg/wp-admin/ and then to authentication. In this sequence, a cookie mfn-builder, related to BeTheme, was observed.
Limit: An accessible authentication page proves that the mechanism is responsive. It doesn’t prove that a person retains a valid password.
7. Components exposed by the REST API
On October 1, the root of the API published the following namespaces:
chimpmatic-lite/v1 cmatic cmatic/v1 contact-form-7/v1 duplicate-post/v1 elementor-ai/v1 elementor-mcp-composer/v1.0.18 elementor-one/v1 elementor-pro/v1 elementor/v1 elementor/v1/documents elementor/v1/feedback jetpack-boost/v1 Jetpack/v4 Jetpack/V4/Explat jetpack/v4/stats-app my-jetpack/v1 oembed/1.0 PLL/V1 wordfence-login-security/v1 wordfence/v1 wp-abilities/v1 wp-block-editor/v1 wp-site-health/v1 wp/v2 wpcom/v2 wpcom/v3
These paths show components registered to the application. They don’t prove that they are all used, that they have current subscriptions, or that someone has used AI features. elementor-mcp-composer/v1.0.18 it appears in the October observation and did not appear on the list obtained in September; this difference does not allow its installation date to be fixed.
The query returned wp/v2/users a 401 error, code rest_user_cannot_view. The routes wp-site-health/v1/tests/background-updates and wp-site-health/v1/tests/page-cache returned 401, code rest_forbidden. A GET query for a Jetpack cache flush route returned 404, with no matching route; that result does not prove that the function does not exist using another HTTP method.
A list of administrators and access to automatic update settings was not obtained.
8. Observed Version Parameters
| Resources | September 18 | October 1 |
|---|---|---|
| Elementor Resources | 4.2.4 | Values including 4.3.3 and 4.3.1 |
| General Site Resources | 7.1.1 | 7.1.2 |
| Contact Form 7 | 6.1.7 | 6.1.7 |
| BeTheme | 24.0.3.1 | 24.0.3.1 |
In October, the value 8.4.5 also appeared among the parameters examined. In the HTML, eleven occurrences of 4.3.3, eleven of 24.0.3.1, seven of 4.3.1, four of 7.1.2 and four of 6.1.7.
Limit: These are parameter ver= values of the URLs served. They can be used to invalidate caches. They do not constitute an audit of installed versions or allow changes to be attributed to a manual update.
9. Elementor Files with Recent Dates
On September custom-frontend.min.css?ver=178972659218, , located under https://ive.org/iveorg/wp-content/uploads/elementor/css/. The number corresponds to September 18, 2026 at 10:16:32 UTC. Its header Last-Modified indicated that same date and time.
On October 1, the following values were observed in the same directory:
| File and parameter | Last-Modified observed, UTC | Declared size |
|---|---|---|
| custom-frontend.min.css?view=1790849897 | October 1, 2026, 10:18:17 AM | 54,805 bytes |
| post-2931.css?view=1790850085 | October 1, 2026, 10:21:25 AM | 15,282 bytes |
| post-2.css?view=1790850407 | October 1, 2026, 10:26:47 AM | 28,072 bytes |
The file post-2.css contained selectors .elementor-2, consistent with their association with the main page, identified as page 2. It also contained references to images with paths from 2021; a recent date of the CSS does not imply that those images are new.
These other resources appeared with the ver=1790849897: custom-apple-webkit.min.css, custom-pro-widget-call-to-action.min.css, custom-pro-widget-nav-menu.min.css, custom-pro-widget-slides.min.css, custom-pro-widget-testimonial-carousel.min.css, custom-widget-icon-list.min.css, post-2942.css y post-488.css. Your individual headers are not presented as verified in this report.
Interpretation: For the three files checked in October, the time parameters matched the dates declared by the server. This supports a recent rebuild or technical modification. It does not demonstrate content editing, login, or intervention by a specific person. Headers are server-declared data, not internal forensic logs.
10. Content dates and sitemaps
Among the pages returned by the REST queries performed, the most recent modification observed was prueba-popup, 2023-04-24T12:18:51dated . The most recent media files examined were also dated April 24, 2023. This describes the results obtained; it does not attest to a thorough review of all publications and internal statuses.
| Page | Lastmod observed in sitemap |
|---|---|
| Cover | July 19, 2022 |
| /contacto/ | June 5, 2023 |
| /contato/ | 2025-05-23T11:09:52-05:00 |
The sitemap index included versions under /en, /it, /pt, /fr, /nl, /uk, /de, /pl y /ar. The fields lastmod are site declarations: they don’t identify the publisher or describe what changed.
These queries did not find sufficient evidence to affirm that new content had been published in 2026. This result is compatible with the technical activity observed in the style files.
11. Checks without usable result
Querying certificates using crt.sh returned a 502 error. Checking using OpenSSL also did not produce usable information. Therefore, this report does not attribute issue dates, expirations, or certificate issuers to ive.org.
12. Scope of the conclusion
The observations describe a current domain, configured services, an accessible application, and signs of recent technical changes. They don’t identify the administrator, they don’t prove who knows the credentials, and they don’t prove a deliberate lie. Nor do they allow you to establish how much of the activity comes from automations.
Its usefulness is to ask verifiable questions: who maintains the contractual relationship with the suppliers, who manages the recovery accounts and what actions the IVE has taken to clarify the control of its infrastructure.
The final verification of these responsibilities requires contractual or internal information: registrar and accommodation accounts, invoices, authorized contacts, and administration records. Such information was not obtained through this public inquiry.

Leave a Reply