What broke
Founder A had Site P1's apex pointed at a CNAME that itself pointed back to the same apex, creating a resolver loop. DNS provider G refused to follow the loop and returned SERVFAIL, so the site looked down for 90 minutes while every browser refused to connect.
How it was fixed
Removed the self-referential CNAME on the apex and replaced it with a flat A-record set to the edge IPs from DNS provider G. Re-ran the resolver from three regions to confirm SERVFAIL was gone, then verified the apex loaded in a fresh browser profile with no cached DNS.
Monitoring rule that would have caught it
Watch your apex AND one level deeper. Any SERVFAIL spike on the apex is a hard incident — alert on it the moment a region sees it, not after the second consecutive failure.