{
  "slug": "thirty-days-pattern-starts-to-emerge",
  "title": "30 days in, the pattern starts to emerge",
  "subtitle": "Week 5 · .au Domain Observatory",
  "published_at": "2026-04-25T09:00:00+10:00",
  "report_type": "featured",
  "series": "observations",
  "status": "published",
  "summary": "After 30 days of continuous observation across a fixed 100-domain .au panel, .auDO recorded 1,122 observable events.",
  "href": "/reports/featured/thirty-days-pattern-starts-to-emerge/",
  "tags": [
    "Featured",
    "Week 5",
    "30 Days",
    "Observatory Activity",
    "Governance",
    ".au",
    "Observations"
  ],
  "hero": {
    "image_path": "/reports/featured/thirty-days-pattern-starts-to-emerge/30-days-pattern-starts-to-emerge.png",
    "image_alt": ".au Domain Observatory Week 5 graphic showing 1,122 observable events over 30 days, activity distribution across a 100-domain panel, provider concentration, and DNSSEC visibility signals.",
    "caption": "30 days in, the pattern starts to emerge. 1,122 observable events across a fixed 100-domain .au panel reveal uneven change, quiet domains, provider concentration, and a gap between asserted and visible trust posture."
  },
  "source": {
    "daily_report_date": "2026-04-24",
    "daily_manifest_path": "/data/report_manifests/2026-04-24.json",
    "analysis_manifest_path": "/data/analysis_manifests/2026-04-24.json",
    "observation_window_start": "2026-03-26",
    "observation_window_end": "2026-04-24",
    "collector_runs": 30,
    "panel_size": 100,
    "cohort_count": 14,
    "note": "The canonical observatory panel remains fixed at 100 domains. The latest posture extract returned 101 rows; panel-level reporting continues to use the fixed 100-domain panel until that extract discrepancy is reconciled."
  },
  "metrics": {
    "observatory_activity": {
      "total_events": 1122,
      "average_daily_events": 37.4,
      "average_active_domains_per_day": 24.3,
      "quiet_domains": 39,
      "low_activity_domains": 26,
      "repeated_activity_domains": 35,
      "highest_single_domain_event_count": 75,
      "material_events": 77,
      "supporting_events": 1045
    },
    "event_materiality": {
      "material_events": 77,
      "supporting_events": 1045,
      "clarification": "Materiality is used to distinguish higher-governance-value changes from routine supporting signal. Supporting events may still become meaningful when repeated or correlated over time."
    },
    "event_types": {
      "a_changed": { "category": "resolution", "severity": "info", "materiality": "supporting", "event_count": 693, "affected_domains": 33 },
      "aaaa_changed": { "category": "resolution", "severity": "info", "materiality": "supporting", "event_count": 263, "affected_domains": 12 },
      "nameservers_changed": { "category": "delegation", "severity": "medium", "materiality": "material", "event_count": 45, "affected_domains": 9 },
      "spf_present_changed": { "category": "mail_hygiene", "severity": "medium", "materiality": "supporting", "event_count": 26, "affected_domains": 6 },
      "mx_changed": { "category": "mail", "severity": "info", "materiality": "supporting", "event_count": 26, "affected_domains": 8 },
      "rdap_status_changed": { "category": "status", "severity": "medium", "materiality": "material", "event_count": 26, "affected_domains": 21 },
      "email_provider_changed": { "category": "provider", "severity": "info", "materiality": "supporting", "event_count": 18, "affected_domains": 13 },
      "dmarc_present_changed": { "category": "mail_hygiene", "severity": "medium", "materiality": "supporting", "event_count": 12, "affected_domains": 4 },
      "dns_provider_changed": { "category": "provider", "severity": "medium", "materiality": "supporting", "event_count": 7, "affected_domains": 7 },
      "hosting_move_signal": { "category": "derived", "severity": "high", "materiality": "material", "event_count": 5, "affected_domains": 5 },
      "registrar_changed": { "category": "registrar", "severity": "high", "materiality": "material", "event_count": 1, "affected_domains": 1 }
    },
    "daily_activity": {
      "window_days": 30,
      "average_daily_events": 37.4,
      "average_active_domains_per_day": 24.3,
      "highest_daily_event_count": 86,
      "highest_daily_event_count_date": "2026-03-30",
      "lowest_daily_event_count": 26,
      "lowest_daily_event_count_date": "2026-04-22"
    },
    "activity_distribution": {
      "quiet_domains": 39,
      "low_activity_domains": 26,
      "repeated_activity_domains": 35,
      "highest_single_domain_event_count": 75,
      "clarification": "Quiet domains are domains with no observable events in the 30-day window. Low-activity and repeated-activity buckets describe observed event frequency only; they are not risk ratings."
    },
    "dnssec": {
      "asserted_domains": 13,
      "dnskey_visible_domains": 8,
      "state_mismatch_domains": 9,
      "clarification": "DNSSEC remains a useful example of the difference between asserted posture and visibly verifiable posture. A mismatch is an observation requiring interpretation, not a standalone finding of failure."
    },
    "email_posture": {
      "spf_present": 100,
      "dmarc_present": 99,
      "panel_size": 100,
      "posture_extract_rows": 101,
      "clarification": "The latest posture extract returned 101 rows while the canonical panel remains 100 domains. The SPF and DMARC counts are retained from the extract and should be reconciled before treating them as final panel-normalised percentages."
    },
    "infrastructure_concentration": {
      "dns_providers": [
        { "provider": "Amazon Route53", "domain_count": 20, "share_pct": 19.8 },
        { "provider": "Akamai / Edge DNS", "domain_count": 19, "share_pct": 18.8 },
        { "provider": "Cloudflare", "domain_count": 11, "share_pct": 10.9 },
        { "provider": "Organisation-managed / Self-hosted DNS", "domain_count": 9, "share_pct": 8.9 },
        { "provider": "Azure DNS", "domain_count": 9, "share_pct": 8.9 }
      ],
      "email_providers": [
        { "provider": "Microsoft 365", "domain_count": 38, "share_pct": 37.6 },
        { "provider": "Proofpoint", "domain_count": 16, "share_pct": 15.8 },
        { "provider": "Google Workspace", "domain_count": 13, "share_pct": 12.9 },
        { "provider": "Mimecast", "domain_count": 11, "share_pct": 10.9 }
      ],
      "registrars": [
        { "provider": "Corporation Service Company (Aust) Pty Ltd", "domain_count": 35, "share_pct": 34.7 },
        { "provider": "Domain Directors Pty Ltd trading as Instra", "domain_count": 12, "share_pct": 11.9 },
        { "provider": "Melbourne IT", "domain_count": 12, "share_pct": 11.9 },
        { "provider": "Education Services Australia Limited", "domain_count": 10, "share_pct": 9.9 }
      ],
      "clarification": "Provider concentration is not a finding of weakness. It is a governance-relevant visibility pattern showing where dependencies cluster across the observed panel."
    },
    "cohort_activity": {
      "highest_events_per_domain": [
        { "cohort": "commercial-watchlist", "sector": "property", "event_count": 103, "active_domains": 2, "panel_domains": 2, "events_per_domain": 51.5 },
        { "cohort": "media-watchlist", "sector": "media", "event_count": 235, "active_domains": 6, "panel_domains": 8, "events_per_domain": 29.38 },
        { "cohort": "commercial-watchlist", "sector": "marketplace", "event_count": 29, "active_domains": 1, "panel_domains": 1, "events_per_domain": 29.0 },
        { "cohort": "critical-infrastructure", "sector": "postal", "event_count": 24, "active_domains": 1, "panel_domains": 1, "events_per_domain": 24.0 },
        { "cohort": "commercial-watchlist", "sector": "industrial", "event_count": 20, "active_domains": 1, "panel_domains": 1, "events_per_domain": 20.0 }
      ],
      "clarification": "Cohort comparisons are based on observed event frequency and panel composition. Small cohorts can produce high events-per-domain results and require careful interpretation."
    },
    "repeat_event_domains": {
      "top_domains_by_event_count": [
        { "domain": "news.com.au", "cohort": "media-watchlist", "event_count": 75, "event_type_count": 4, "event_types": ["a_changed", "aaaa_changed", "nameservers_changed", "rdap_status_changed"] },
        { "domain": "homeaffairs.gov.au", "cohort": "critical-infrastructure", "event_count": 72, "event_type_count": 3, "event_types": ["a_changed", "aaaa_changed", "email_provider_changed"] },
        { "domain": "realestate.com.au", "cohort": "commercial-watchlist", "event_count": 72, "event_type_count": 2, "event_types": ["a_changed", "aaaa_changed"] },
        { "domain": "theaustralian.com.au", "cohort": "media-watchlist", "event_count": 63, "event_type_count": 2, "event_types": ["a_changed", "aaaa_changed"] },
        { "domain": "qantas.com.au", "cohort": "critical-infrastructure", "event_count": 56, "event_type_count": 2, "event_types": ["a_changed", "aaaa_changed"] }
      ],
      "clarification": "Repeat-event domains are listed to show activity distribution. Frequency alone does not indicate elevated risk, incident activity, or poor management."
    }
  },
  "key_points": [
    "1,122 observable events were recorded over the first 30-day observation window.",
    "On an average day, 37.4 events were recorded and 24.3 domains showed some form of observable change.",
    "Activity was uneven: 39 domains were quiet, 26 showed low activity, and 35 showed repeated activity.",
    "Material events were less common than routine supporting signal, but included nameserver changes, RDAP status changes, hosting move signals, and one registrar change.",
    "DNSSEC remains a clear example of the difference between asserted and visibly verifiable trust posture: 13 domains asserted DNSSEC, 8 had visible DNSKEY records, and 9 showed a state mismatch in the latest extract.",
    "Provider concentration is visible across the DNS, email, and registrar layers, including Microsoft 365 at 37.6% of observed email providers and CSC at 34.7% of observed registrars.",
    "The next phase for .auDO is interpretation rather than scale: sharper signal selection, clearer cohort comparison, and more useful daily reporting.",
    "For the wider concentration picture, see the 26 May featured report 'Observed: infrastructure concentration in context'."
  ],
  "callouts": [
    {
      "type": "observation-note",
      "title": "From lookup to observatory",
      "text": "A point-in-time lookup shows posture. Repeated observation starts to show behaviour. Passing 30 days of collection changes the value of .auDO from daily reporting to longitudinal observability."
    },
    {
      "type": "interpretation-note",
      "title": "The signal is distribution, not just volume",
      "text": "The 1,122 events recorded over 30 days are not equally meaningful. The more useful pattern is how activity distributes across domains and cohorts: some domains were quiet, some changed occasionally, and some moved repeatedly."
    },
    {
      "type": "governance-note",
      "title": "Infrastructure exposes trust posture",
      "text": "Digital trust is not only declared in policies, brands, certifications, or assurance statements. It is also exposed through DNS, email, registrar, and provider dependencies that can be observed over time."
    },
    {
      "type": "clarification",
      "title": "Observation is not attribution",
      "text": "The observatory records visible domain-layer changes. It does not attribute activity, infer causality, or rank organisations. Event frequency indicates observed movement only and requires interpretation before it becomes governance insight."
    },
    {
      "type": "panel-note",
      "title": "Why the panel remains fixed",
      "text": "For now, the observatory panel remains fixed at 100 domains. The next phase is not larger collection for its own sake, but better interpretation: sharper signals, clearer cohort comparisons, and more useful reporting from the data already being collected."
    }
  ],
  "sources": [
    {
      "title": "RFC 4033 - DNSSEC Introduction and Requirements",
      "publisher": "IETF",
      "url": "https://datatracker.ietf.org/doc/html/rfc4033",
      "date": "2005-03-01",
      "relevance": "Anchors the asserted-versus-visibly-verifiable DNSSEC framing carried forward from earlier weekly notes and used in this 30-day report's DNSSEC observations."
    },
    {
      "title": ".AU Signed with DNSSEC",
      "publisher": "Internet Society",
      "url": "https://www.internetsociety.org/blog/2014/12/australia-au-and-grenada-gd-are-latest-cctlds-to-sign-with-dnssec/",
      "date": "2014-12-01",
      "relevance": "Establishes the upstream signing condition for .au, the necessary context for any cross-week DNSSEC reading on .au child zones."
    },
    {
      "title": "Root Zone Database - delegation record for .AU",
      "publisher": "IANA",
      "url": "https://www.iana.org/domains/root/db/au.html",
      "date": "2024-08-08",
      "relevance": "Establishes the delegation layer above the panel. The observatory measures within .au; this source describes the layer immediately above it."
    },
    {
      "title": "DNS resolver concentration (OARC measurement)",
      "publisher": "APNIC Labs",
      "url": "https://labs.apnic.net/presentations/store/2023-02-16-OARC-resolver-concentration.pdf",
      "date": "2023-02-16",
      "relevance": "Independent measurement counterpart to this report's observed authoritative-side provider concentration (Route53, Akamai, Cloudflare, Azure DNS). Shows the same clustering pattern at the recursive-resolver layer."
    },
    {
      "title": "RFC 7489 - Domain-based Message Authentication, Reporting & Conformance (DMARC)",
      "publisher": "IETF / dmarc.org",
      "url": "https://datatracker.ietf.org/doc/html/rfc7489",
      "date": "2015-03-01",
      "relevance": "Standards reference behind the report's email posture figures (SPF and DMARC presence at 100 / 99 across the panel)."
    },
    {
      "title": "A Secure .au - auDA Research Report",
      "publisher": "auDA",
      "url": "https://www.auda.org.au/news-insights/research-reports/a-secure-au/",
      "date": "2024-11-01",
      "relevance": "Baseline .au security posture reference. Supports the broader interpretation framing of the 30-day note and the observatory's place alongside auDA's published security work."
    },
    {
      "title": "Measuring the use of DNS over IPv6 (measurement caveat)",
      "publisher": "APNIC Blog",
      "url": "https://blog.apnic.net/2026/03/02/measuring-the-use-of-dns-over-ipv6/",
      "date": "2026-03-02",
      "relevance": "Caveat. Independent discussion of measurement uncertainty in DNS observation, consistent with the report's own posture-extract discrepancy note (101 rows versus a 100-domain panel)."
    }
  ],
  "seo": {
    "title": "30 days in, the pattern starts to emerge | Week 5 | .auDo",
    "description": "Week 5 .au Domain Observatory note on the first 30 days of continuous .au domain-layer observation: 1,122 observable events, uneven activity distribution, provider concentration, DNSSEC visibility gaps, and the shift from collection to interpretation."
  }
}
