{
  "slug": "namespace-activity-and-visibility-gap",
  "title": "Observed: the namespace moves quietly",
  "subtitle": "Week 4 · .au Domain Observatory",
  "published_at": "2026-04-18T21:00:00+10:00",
  "report_type": "featured",
  "series": "observations",
  "status": "published",
  "summary": "Across 100 .au domains in 24 days of observation, 41 events were recorded across 28 domains - including two high-severity hosting migration signals in the critical-infrastructure and commercial cohorts. homeaffairs.gov.au, the department responsible for Australia's national cyber security strategy, registered two events across two event types during a period of active pro-Iranian threat activity targeting Australian government infrastructure. The domain layer is observable. Most of it is not observed. This report predates the complete 30-day activity distribution; unavailable longitudinal fields are called out explicitly rather than inferred.",
  "href": "/reports/featured/observed-namespace-activity-and-visibility-gap/",
  "tags": [
    "Featured",
    "Week 4",
    "Observatory Activity",
    "Governance",
    ".au",
    "Observations"
  ],
  "hero": {
    "image_path": "/reports/featured/namespace-activity-and-visibility-gap/namespace-moves-who-is-watching.png",
    "image_alt": ".au Domain Observatory chart showing 41 events across 28 domains by cohort and severity, with homeaffairs.gov.au highlighted as a repeat-event domain in the critical infrastructure cohort.",
    "caption": "The namespace moves. Who's watching? 41 events across 28 domains in 24 days - event types by cohort and severity."
  },
  "source": {
    "daily_report_date": "2026-04-18",
    "daily_manifest_path": "/data/report_manifests/2026-04-18.json",
    "analysis_manifest_path": "/data/analysis_manifests/2026-04-18.json",
    "observation_window_start": "2026-03-28",
    "observation_window_end": "2026-04-18",
    "collector_runs": 24,
    "panel_size": 100,
    "cohort_count": 14
  },
  "metrics": {
    "observatory_activity": {
      "total_events": 41,
      "affected_domains": 28,
      "high_severity_events": 2,
      "medium_severity_events": 8,
      "info_severity_events": 31,
      "hosting_move_signals": 2,
      "dns_provider_changed": 2,
      "nameservers_changed": 4,
      "dmarc_present_changed": 1,
      "spf_present_changed": 1
    },
    "dmarc": {
      "domains_with_dmarc": 97,
      "panel_size": 100
    },
    "registrar_concentration": {
      "largest_registrar_share_pct": 35
    },
    "critical_infrastructure": {
      "cohort_size": 25,
      "asserted_domains": 9,
      "observed_dnskey_domains": 3,
      "events_recorded": 10,
      "high_severity_events": 1,
      "medium_severity_events": 2,
      "notable_domain": "homeaffairs.gov.au",
      "notable_domain_events": 2,
      "notable_domain_event_types": 2
    },
    "dnssec": {
      "asserted_domains": 13,
      "observed_dnskey_on_asserted_domains": 8,
      "state_mismatch_domains": 7,
      "weeks_consistent": 2,
      "clarification": "The DNSSEC gap of 7 has held unchanged across Week 3 and Week 4. Consistency across observation periods indicates a structural pattern rather than transient collection noise."
    },
    "email_posture": {
      "spf_present": 99,
      "dmarc_present": 97,
      "panel_size": 100
    },
    "repeat_event_domains": {
      "domains_with_multiple_events": [
        "homeaffairs.gov.au",
        "news.com.au",
        "sydneywater.com.au",
        "qantas.com.au",
        "realestate.com.au",
        "kmart.com.au",
        "crikey.com.au",
        "theaustralian.com.au"
      ],
      "clarification": "Repeat-event domains are those appearing across more than one event type in the current exported delta. Frequency alone does not indicate elevated risk."
    },
    "event_materiality": {
      "high_severity_events": 2,
      "medium_severity_events": 8,
      "info_severity_events": 31,
      "clarification": "Week 4 reported severity distribution, not the later material-versus-supporting classification used in the 30-day interpretation layer."
    },
    "event_types": {
      "hosting_move_signal": {
        "category": "derived",
        "severity": "high",
        "materiality": "material",
        "event_count": 2,
        "affected_domains": null
      },
      "dns_provider_changed": {
        "category": "provider",
        "severity": "medium",
        "materiality": "supporting",
        "event_count": 2,
        "affected_domains": null
      },
      "nameservers_changed": {
        "category": "delegation",
        "severity": "medium",
        "materiality": "material",
        "event_count": 4,
        "affected_domains": null
      },
      "dmarc_present_changed": {
        "category": "mail_hygiene",
        "severity": "medium",
        "materiality": "supporting",
        "event_count": 1,
        "affected_domains": null
      },
      "spf_present_changed": {
        "category": "mail_hygiene",
        "severity": "medium",
        "materiality": "supporting",
        "event_count": 1,
        "affected_domains": null
      }
    },
    "activity_distribution": {
      "affected_domains": 28,
      "total_events": 41,
      "quiet_domains": null,
      "low_activity_domains": null,
      "repeated_activity_domains": null,
      "highest_single_domain_event_count": null,
      "clarification": "The Week 4 source extract reports 41 events across 28 domains, but does not include the later 30-day distribution buckets for quiet, low-activity, repeated-activity, or highest single-domain event count. Those values are intentionally left unavailable rather than inferred."
    },
    "report_completeness": {
      "observation_phase": "pre-30-day activity observation",
      "available_data": [
        "total events",
        "affected domains",
        "severity counts",
        "selected event-type counts",
        "critical-infrastructure cohort summary",
        "DNSSEC consistency note",
        "email posture counts",
        "repeat-event domain list"
      ],
      "not_available_in_this_report": [
        "30-day activity distribution buckets",
        "average daily event count",
        "average active domains per day",
        "highest single-domain event count",
        "full event type affected-domain counts",
        "full provider concentration ranking table"
      ],
      "clarification": "This Week 4 report captured namespace movement before the full 30-day interpretation layer was enabled. The report is complete for its original scope, while later baseline metrics are not backfilled or inferred."
    }
  },
  "key_points": [
    "41 events were recorded across 28 of 100 .au panel domains in the 24-day observation window.",
    "Two high-severity hosting migration signals were detected - one in the critical-infrastructure cohort, one commercial. Neither required public announcement. Neither was publicly noted.",
    "homeaffairs.gov.au - the department responsible for Australia's 2023-2030 Cyber Security Strategy - recorded two events across two event types during a period when ASD and ACSC public reporting described Australian government entities as common targets for malicious cyber activity.",
    "The observatory does not attribute. Domain-layer events are observations of publicly resolvable signals. No inference about cause, threat actor, or incident is made.",
    "The DNSSEC verification gap holds at 7 for the second consecutive week. Consistency across observation periods indicates a structural condition, not noise.",
    "The domain layer is observable. The governance question is whether any organisation - including the one that owns the domain - has a continuous mechanism to notice when it changes.",
    "This report predates the complete 30-day interpretation layer; quiet-domain buckets, daily averages, and full repeat-domain rankings were not available in the Week 4 source extract."
  ],
  "callouts": [
    {
      "type": "observation-note",
      "title": "Observable ≠ observed",
      "text": "The domain layer is publicly resolvable infrastructure. Changes to DNS records, nameservers, hosting architecture, and mail hygiene controls are visible to anyone running continuous collection. Most organisations have no equivalent internal mechanism for their own domains - let alone for infrastructure they depend on."
    },
    {
      "type": "threat-context",
      "title": "Threat environment context",
      "text": "During the observation window, ASD and ACSC public reporting described Australian government entities as common targets for malicious cyber activity and noted that Australian critical infrastructure networks regularly experience targeted and opportunistic malicious activity. The observatory does not attribute. This context is provided to orient the reader to why visibility of domain-layer change in this cohort is worth surfacing."
    },
    {
      "type": "clarification",
      "title": "On hosting migration signals",
      "text": "A hosting_move_signal is detected when correlated changes - nameserver change, DNS provider change, and address record change - occur together within an observation window. Infrastructure migrations do not require public disclosure. Their presence in the event log indicates change, not failure."
    },
    {
      "type": "cohort-note",
      "title": "DNSSEC gap - structural signal",
      "text": "The gap between DNSSEC-asserted domains (13) and those with observable DNSKEY records (8) has held unchanged across two consecutive weekly observation points. A signal that persists across time and does not respond to collection-run variation is more likely to reflect a real posture condition than a transient artefact."
    },
    {
      "type": "data-availability",
      "title": "Data availability for this report",
      "text": "This Week 4 note includes event count, affected-domain count, severity distribution, selected event types, DNSSEC posture, email posture, and repeat-event domains. It does not include the later 30-day activity buckets, average daily event metrics, or full provider ranking tables. Those metrics are intentionally not inferred."
    },
    {
      "type": "scope-note",
      "title": "Pre-baseline observation",
      "text": "The report should be read as a pre-30-day activity note. It shows that the namespace moves quietly, but it does not yet provide the complete longitudinal baseline introduced in the 30-day Week 5 report."
    }
  ],
  "sources": [
    {
      "title": "auDA Rules: Registrant Data Consent and WHOIS Disclosure (s.2.9)",
      "publisher": "auDA",
      "url": "https://www.auda.org.au/au-domain-names/au-rules-and-policies/au-domain-administration-rules-licensing-2/",
      "date": "2021-04-12",
      "relevance": "Backs the report's premise that the .au namespace is structurally observable. Public disclosure of registrant, registrar, and nameserver data is what makes namespace movements visible to a public observatory."
    },
    {
      "title": "auDA Implements RDAP Protocol to Access Public .au Registry Data",
      "publisher": "auDA",
      "url": "https://www.auda.org.au/news-insights/statements/auda-implements-rdap-protocol-to-access-public-au-registry-data/",
      "date": "2026-03-02",
      "relevance": "Documents the structured registry-data path the observatory uses to detect status, nameserver, and registrar changes - the event types this report counts (rdap_status_changed, nameservers_changed, registrar_changed)."
    },
    {
      "title": "RFC 4033 - DNSSEC Introduction and Requirements",
      "publisher": "IETF",
      "url": "https://datatracker.ietf.org/doc/html/rfc4033",
      "date": "2005-03-01",
      "relevance": "Anchors the report's DNSSEC continuity callout (the asserted-versus-visible gap held at 7 for a second consecutive week). Cross-references the Week 3 DNSSEC source set."
    },
    {
      "title": "A Secure .au - auDA Research Report",
      "publisher": "auDA",
      "url": "https://www.auda.org.au/news-insights/research-reports/a-secure-au/",
      "date": "2024-11-01",
      "relevance": "Public baseline for .au security posture and the auDA / ASD framing of namespace governance. Context for the report's argument that namespace movement is observable and worth surfacing."
    },
    {
      "title": "Australian Signals Directorate releases Annual Cyber Threat Report 2024-25",
      "publisher": "ASD",
      "url": "https://www.asd.gov.au/news/2025-10-14-australian-signals-directorate-releases-annual-cyber-threat-report-2024-25",
      "date": "2025-10-14",
      "relevance": "Primary support for the threat-context framing. ASD states that over 2024-25, state-sponsored cyber actors were a serious and growing threat targeting networks operated by Australian governments, critical infrastructure, and businesses."
    },
    {
      "title": "The Commonwealth Cyber Security Posture in 2025",
      "publisher": "ACSC / ASD",
      "url": "https://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/the-commonwealth-cyber-security-posture-in-2025",
      "date": "2026-02-12",
      "relevance": "Supports the wording that Australian government entities are a common target for malicious cyber activity. Reports that in 2025 ASD notified government entities 223 times of potential malicious cyber activity."
    },
    {
      "title": "Critical infrastructure",
      "publisher": "ACSC / cyber.gov.au",
      "url": "https://www.cyber.gov.au/business-government/critical-infrastructure",
      "date": "2026-05-01",
      "relevance": "Supports the wording that Australian critical infrastructure networks regularly experience targeted and opportunistic malicious activity, as published by the ACSC and referencing the Annual Cyber Threat Report 2023-24."
    },
    {
      "title": "ASD Information Security Manual (ISM) - Guidelines for Email",
      "publisher": "ASD / ACSC",
      "url": "https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-email",
      "date": "2025-12-01",
      "relevance": "Backs the report's email posture counts (SPF and DMARC presence) with the formal Australian government compliance reference (ISM-1183, ISM-0861, ISM-1026, ISM-1540, ISM-1799, ISM-1589)."
    }
  ],
  "seo": {
    "title": "The namespace moves quietly | Week 4 | .auDo",
    "description": "Week 4 .au Domain Observatory note on namespace activity and governance visibility. This pre-30-day activity report calls out unavailable longitudinal baseline fields explicitly rather than inferring them."
  }
}