```html

Cross-Domain GA & GSC Ownership Audit: Fixing Property Contamination in Multi-Site Infrastructure

What Was Done

We conducted a comprehensive Google Search Console (GSC) and Google Analytics (GA) audit across a four-property SailJada portfolio—sailjada.com, queenofsandiego.com, quickdumpnow.com, and dangerouscentaur.com—to identify and remediate cross-domain tracking contamination. The investigation revealed a critical ownership and tagging issue: QuickDumpNow.com's GSC property was being accessed via the JADA Google account, while several QDN subpages were missing their dedicated GA tag entirely.

Technical Details: The Audit Process

Homepage GA Tag Verification

We first established a clean baseline by checking GA tags on all four property homepages:

  • sailjada.com → G-N6HKL4KLKT (JADA Measurement ID)
  • queenofsandiego.com → G-N6HKL4KLKT (same JADA Measurement ID; same business entity)
  • quickdumpnow.com → G-539T97NM1Z (QDN Measurement ID; correctly isolated)
  • dangerouscentaur.com → G-GGP987FJSW (DC Measurement ID)
  • 86from.com → G-YJWFKWVWNQ (correctly isolated)
  • burialsatseasandiego.com → UA-175171552-1 (legacy Universal Analytics—outdated, flagged for migration)

The homepages themselves showed correct tag isolation. The real problem wasn't GA tag cross-contamination but rather ownership and completeness.

Subpage Deep Dive: QDN Property Gaps

Using a Python scanning script, we crawled all sailjada.com and queenofsandiego.com subpages, then spot-checked QDN inner pages. We discovered:

  • QDN subpages /book, /track, and /service-areas/carlsbad/ were missing the QDN GA tag entirely (G-539T97NM1Z)
  • No cross-pollution (JADA tag on QDN pages or vice versa) was detected on production
  • All JADA properties correctly carried the G-N6HKL4KLKT tag across their subpages

The scanning approach: fetch each page's HTML, regex for gtag('config', patterns, and log the Measurement ID found. This allowed us to quickly identify gaps without manual inspection of dozens of pages.

The Real Issue: GSC Ownership vs. GA Tags

The user's screenshot showed QuickDumpNow.com's GSC property being accessed via jadasailing@gmail.com—the JADA account. This reveals a fundamental ownership problem:

  • QDN should have its own GSC property owned by admin@quickdumpnow.com (or QDN's designated account)
  • JADA's GA account holds QDN's GA property ID, creating a dependency risk
  • If JADA's Google account is compromised or ownership changes, QDN loses visibility and control

We documented this finding and queued a separate kanban card for QDN property ownership transfer, which requires browser-based interaction (GSC property addition, verification via GA or domain DNS, and hand-off to QDN's account).

Infrastructure & Command Examples

Verification Commands Used

# Fetch a live sitemap
curl -I https://sailjada.com/sitemap.xml
# Expected: HTTP 200, valid XML

# Check GA tag presence (example with grep)
curl -s https://sailjada.com/ | grep -o "gtag('config'[^)]*)"

# List S3 bucket contents for progress snapshots
aws s3 ls s3://sailjada-progress-bucket/ --recursive

# Query DynamoDB for kanban card state
aws dynamodb get-item --table-name kanban-cards --key '{"card_id":{"S":"t-77babced"}}'

Why We Didn't Script GSC Updates Directly

Google Search Console has no official API for property creation or verification. GSC verification requires either:

  • HTML file upload to the root domain
  • DNS TXT record insertion
  • Meta tag in <head>
  • Google Analytics property link (auto-verify if you own the GA property)

We chose to document the manual steps and create a clear task card rather than build fragile tooling around undocumented APIs.

Key Decisions & Trade-Offs

Why We Didn't Force GA Tag Updates on QDN Pages

Although we identified missing GA tags on three QDN subpages, we halted at documentation instead of pushing a deploy. Reason: QDN is a separate business entity with its own admin account. Changing its infrastructure without explicit approval risks:

  • Breaking QDN's own GA event tracking if they've configured custom rules
  • Creating audit noise if their account admin notices unexpected changes
  • Violating the principle of least privilege—JADA shouldn't unilaterally modify QDN infra

Instead, we created a detailed findings report and queued the work for QDN admin sign-off.

Python Over Shell for Cross-Site Scanning

Our initial shell script (nested subshells with AWS CLI loops) hit sandbox sandboxing limits. We rewrote the logic in Python:

# High-level pseudo-code structure
import requests
import re

sites = ['sailjada.com', 'queenofsandiego.com']
ga_pattern = r"gtag\('config',\s*'([^']+)'"

for site in sites:
    for page in get_subpages(site):
        resp = requests.get(f'https://{site}{page}')
        match = re.search(ga_pattern, resp.text)
        if match:
            log_tag(page, match.group(1))
        else:
            flag_missing_tag(page, site)

Python's requests library is simpler than shell curl loops, regex is more readable, and we could easily persist findings to DynamoDB or JSON for later analysis.

What's Next

Immediate: GSC Property Transfer (Browser-Required)

Kanban card created for manual GSC setup:

  1. Login to Google Search Console as jadasailing@gmail.com
  2. Add new property: https://quickdumpnow.com/ (URL prefix mode)
  3. Verify via Google Analytics property link (auto-passes because JADA owns G-539T97NM1Z)