> Traceroute confuses me... i also see it says (fake dns).  What's that
> mean?  that they spoofed an IP?

DNS has two parts:

'regular' or 'forward' DNS, which resolves host names in to IP
'reverse' DNS, which does it the other way around. 

I think your DNS program complains about the two entries not matching
up, which isn't a big deal and actually quite common. In particular for
virtual web servers. For example if you look at 'dshield.org', we have
multiple host names sharing one IP address (www.dshield.org, 
feeds.dshield.org... ). But the IP address reverse resolves to something
our ISP set up, which is fine.

