{
  "slug": "dnssec-assertion-gaps",
  "title": "Observed: DNSSEC assertion gaps",
  "subtitle": "Week 3 · .au Domain Observatory",
  "published_at": "2026-04-12T09:00:00+10:00",
  "report_type": "featured",
  "series": "observations",
  "status": "published",
  "summary": "Across 100 .au domains, 13 assert DNSSEC through their registration record, but direct DNS observation confirms visible DNSKEY records for only 8 of those asserted domains. Across the panel, 7 domains show DNSSEC state mismatch overall, where asserted and directly observable signals do not align. This featured report predates the 30-day interpretation layer; event distribution, daily activity averages, and repeat-domain rankings were not yet available in the exported report data.",
  "href": "/reports/featured/observed-dnssec-assertion-gaps/",
  "tags": [
    "Featured",
    "Week 3",
    "DNSSEC",
    ".au",
    "Observations"
  ],
  "hero": {
    "image_path": "/reports/featured/dnssec-assertion-gaps/dnssec-claimed-vs-visible.png",
    "image_alt": ".au Domain Observatory chart comparing asserted DNSSEC state with observable DNSKEY records across cohorts, highlighting mismatch in critical infrastructure and other sectors.",
    "caption": "The amber bars show what is asserted. The teal bars show what is verifiable. The gap is the story."
  },
  "source": {
    "daily_report_date": "2026-04-12",
    "daily_manifest_path": "/data/report_manifests/2026-04-12.json",
    "analysis_manifest_path": "/data/analysis_manifests/2026-04-12.json",
    "observation_window_start": "2026-03-28",
    "observation_window_end": "2026-04-12",
    "collector_runs": 16,
    "panel_size": 100,
    "cohort_count": 14
  },
  "metrics": {
    "dnssec": {
      "asserted_domains": 13,
      "observed_dnskey_on_asserted_domains": 8,
      "state_mismatch_domains": 7,
      "clarification": "The mismatch count of 7 refers to total DNSSEC state mismatches across the panel, not simply 13 minus 8. In other words, 8 asserted domains also show visible DNSKEY records, while 7 domains show misalignment between asserted and directly observable DNSSEC state."
    },
    "critical_infrastructure": {
      "cohort_size": 25,
      "asserted_domains": 9,
      "observed_dnskey_domains": 3
    },
    "education": {
      "cohort_size": 10,
      "observable_events": 0
    },
    "dmarc": {
      "domains_with_dmarc": 98,
      "panel_size": 100
    },
    "registrar_concentration": {
      "largest_registrar_share_pct": 35
    },
    "media_activity": {
      "event_rate_vs_critical_infrastructure": ">4x per domain"
    },
    "report_completeness": {
      "observation_phase": "pre-30-day focused observation",
      "available_data": [
        "DNSSEC registration assertion counts",
        "direct DNSKEY visibility counts",
        "critical-infrastructure cohort DNSSEC comparison",
        "DMARC presence",
        "largest registrar share",
        "education observable event count",
        "relative media activity indicator"
      ],
      "not_available_in_this_report": [
        "30-day event distribution",
        "average daily event count",
        "average active domains per day",
        "material versus supporting event breakdown",
        "event type table",
        "repeat-event domain ranking",
        "provider concentration ranking by DNS/email/registrar"
      ],
      "clarification": "This Week 3 featured report was intentionally focused on DNSSEC assertion gaps. Broader longitudinal metrics were not yet produced by the featured-report pipeline at this point in the observation programme."
    }
  },
  "key_points": [
    "Across 100 .au domains - government, health, finance, media, education and more - 13 assert DNSSEC protection through their registration record.",
    "Direct DNS observation confirms visible DNSKEY records for 8 of those asserted domains.",
    "Across the panel, 7 domains show DNSSEC state mismatch overall - where asserted and directly observable signals do not align.",
    "That gap of 7 is not a system error. It's a signal.",
    "The critical infrastructure cohort shows this most sharply: 9 assertions, 3 confirmed.",
    "98 of 100 domains have DMARC present - a stronger result than you'd typically see across a mixed-sector namespace sample.",
    "One registrar holds 35% of the panel. Combined with DNS provider concentration, some sectors have thin infrastructure diversity underneath them.",
    "This report predates the 30-day interpretation layer; broader activity distribution and repeat-domain rankings were not available in the Week 3 source extract."
  ],
  "callouts": [
    {
      "type": "definition",
      "title": "What is DNSSEC?",
      "text": "DNSSEC is a control that works by being verifiable. Asserting it without observable key material is the domain-layer equivalent of asserting a control without making it verifiable."
    },
    {
      "type": "clarification",
      "title": "DNSSEC numbers clarification",
      "text": "The “7” refers to total DNSSEC state mismatches across the panel, not simply 13 minus 8. In other words, 8 asserted domains also show visible DNSKEY records, while 7 domains show misalignment between asserted and directly observable DNSSEC state."
    },
    {
      "type": "cohort-note",
      "title": "Critical infrastructure",
      "text": "The critical infrastructure cohort - which includes government and essential services - shows the sharpest discrepancy: 9 assertions, 3 confirmed."
    },
    {
      "type": "chart-note",
      "title": "Reading the chart",
      "text": "The amber bars show what's asserted. The teal bars show what's verifiable. The gap is the story."
    },
    {
      "type": "data-availability",
      "title": "Data availability for this report",
      "text": "This Week 3 note is a focused DNSSEC observation based on the data available after 16 collector runs. The source extract does not include a complete 30-day activity distribution, daily event averages, materiality split, repeat-event ranking, or full provider concentration table. Those fields are therefore intentionally not inferred here."
    },
    {
      "type": "scope-note",
      "title": "Scope of interpretation",
      "text": "The report should be read as a focused signal note rather than a full observatory baseline. The strongest evidence available in this report is the mismatch between asserted DNSSEC posture and visibly verifiable DNSKEY records."
    }
  ],
  "sources": [
    {
      "title": "RFC 4033 - DNSSEC Introduction and Requirements",
      "publisher": "IETF",
      "url": "https://datatracker.ietf.org/doc/html/rfc4033",
      "date": "2005-03-01",
      "relevance": "Anchors the framing that DNSSEC is a control that works by being verifiable. Defines the security model (origin authentication, data integrity, authenticated denial) against which the report's assertion-vs-visibility gap is read."
    },
    {
      "title": "RFC 4034 - Resource Records for DNSSEC (DS, DNSKEY, RRSIG, NSEC)",
      "publisher": "IETF / NIST",
      "url": "https://www.nist.gov/publications/resource-records-dns-security-extensions-rfc-4034",
      "date": "2005-03-01",
      "relevance": "Defines the DS, DNSKEY, and RRSIG records used to determine whether a domain's asserted DNSSEC posture is also directly observable. Underpins the meaning of asserted vs visibly verifiable."
    },
    {
      "title": ".AU Signed with DNSSEC",
      "publisher": "Internet Society",
      "url": "https://www.internetsociety.org/blog/2014/12/australia-au-and-grenada-gd-are-latest-cctlds-to-sign-with-dnssec/",
      "date": "2014-12-01",
      "relevance": "Confirms that .au itself is DNSSEC-signed. Establishes that child-zone DNSSEC participation is an opt-in choice, which is the condition the observatory measures."
    },
    {
      "title": "Root Zone Database - delegation record for .AU",
      "publisher": "IANA",
      "url": "https://www.iana.org/domains/root/db/au.html",
      "date": "2024-08-08",
      "relevance": "Establishes the chain-of-trust layer above .au against which DS records in the .au zone are validated. Provides the layer above the panel the observatory does not measure directly."
    }
  ],
  "seo": {
    "title": "DNSSEC: claimed vs. visible | Week 3 | .auDo",
    "description": "Week 3 .au Domain Observatory note on DNSSEC assertion gaps across a 100-domain .au panel. This focused report predates the 30-day interpretation layer and calls out unavailable broader activity metrics explicitly."
  }
}