{
  "slug": "what-state-and-cohort-pages-make-visible",
  "title": "What the State and Cohort pages make visible",
  "subtitle": "Featured article \u00b7 .au Domain Observatory",
  "published_at": "2026-06-17T09:00:00+10:00",
  "report_type": "featured",
  "series": "observations",
  "status": "published",
  "summary": "The new State and Cohort pages do not make .auDO louder; they make accumulated observations easier to read. They turn public domain-layer evidence into careful summaries of current visible posture, curated cohort context, and recent movement worth review.",
  "href": "/reports/featured/what-state-and-cohort-pages-make-visible/",
  "tags": [
    "Featured",
    "State of .au",
    "Cohorts",
    "Observations",
    "Governance"
  ],
  "article_focus": {
    "primary_purpose": "Walk through the new State and Cohort pages and explain what they make visible.",
    "supporting_context": "Use recent daily report manifest summaries to show why these new reading layers are worth paying attention to.",
    "reading_position": "A reading layer, not a rating layer."
  },
  "narrative_sections": [
    {
      "title": "Why this view matters",
      "paragraphs": [
        "The State and Cohort pages are a reading layer for public domain-layer trust signals. They turn repeated DNS, RDAP, mail, registrar, and provider observations into stable views that help readers understand what is visible now and what has moved recently.",
        "The pages should be read as observatory summaries, not as scores, rankings, compliance findings, or determinations. Their value is in making public evidence easier to inspect consistently across the fixed .auDO panel."
      ],
      "blocks": []
    },
    {
      "title": "How to read the State pages",
      "paragraphs": [
        "State pages group the current 2026-06-17 snapshot by signal lens. Each page answers a different governance question: what can be seen publicly, where signals are concentrated, and which visible posture patterns may deserve routine review."
      ],
      "blocks": [
        {
          "title": "DNSSEC posture",
          "what_it_shows": "Visible DNSSEC-related evidence, including secure delegation assertions and directly observed DNSKEY evidence.",
          "why_it_matters": "DNSSEC posture helps readers see whether domain-authentication signals are visible at the delegation and DNS record layers.",
          "current_observation": "In the 2026-06-17 snapshot, 15 domains had visible DNSSEC evidence, 13 had secure delegation asserted, and 8 had DNSKEY observed.",
          "read_carefully": "Read this as public posture evidence only. It is not a statement that a domain is compliant, protected, or misconfigured."
        },
        {
          "title": "DMARC posture",
          "what_it_shows": "Visible mail-authentication posture, including DMARC alongside SPF and MX visibility where available.",
          "why_it_matters": "DMARC and SPF visibility help readers understand whether common mail trust signals are publicly published for observed domains.",
          "current_observation": "In the 2026-06-17 snapshot, 98 domains had DMARC present, 99 had SPF present, and 95 had MX records present.",
          "read_carefully": "Presence is not the same as policy strength, operational maturity, or enforcement quality. The State page records visible public signals."
        },
        {
          "title": "RDAP and registration signals",
          "what_it_shows": "Public registration visibility, including RDAP availability and registrar visibility across the panel.",
          "why_it_matters": "Registration signals help readers understand whether basic public registration context is consistently available for observed domains.",
          "current_observation": "In the 2026-06-17 snapshot, RDAP was available for 100 observed domains and registrar information was known for 100 observed domains.",
          "read_carefully": "Optional RDAP fields are not inferred when unavailable. Missing optional counts should be treated as data limits, not conclusions about domain governance."
        },
        {
          "title": "DNS providers",
          "what_it_shows": "Observed DNS provider patterns and provider diversity across the fixed panel.",
          "why_it_matters": "DNS provider summaries help readers inspect concentration and dependency patterns that may be relevant to resilience planning and governance review.",
          "current_observation": "In the 2026-06-17 snapshot, 24 distinct DNS providers were represented across 100 observed domains.",
          "read_carefully": "Provider concentration is not a quality judgement. A large or small provider footprint does not by itself indicate good or poor practice."
        },
        {
          "title": "Email providers",
          "what_it_shows": "Observed email-provider patterns for domains with visible mail routing evidence.",
          "why_it_matters": "Email-provider summaries help readers see where mail infrastructure dependencies cluster across public-facing domains.",
          "current_observation": "In the 2026-06-17 snapshot, 14 distinct email providers were represented across 95 domains with observed email-provider visibility.",
          "read_carefully": "Provider inference depends on visible public records and naming patterns. It should support questions for review, not definitive assessments of service arrangements."
        },
        {
          "title": "Registrar signals",
          "what_it_shows": "Registrar visibility and registrar concentration across the observed panel.",
          "why_it_matters": "Registrar signals provide context for registration-layer dependencies and changes in registration stewardship.",
          "current_observation": "In the 2026-06-17 snapshot, 12 distinct registrars were represented and registrar information was known for 100 observed domains.",
          "read_carefully": "Registrar choice is not a ranking or risk score. Changes and concentration patterns are prompts for context-aware review."
        }
      ]
    },
    {
      "title": "How to read the Cohort pages",
      "paragraphs": [
        "Cohort pages group selected domains into readable public contexts. They are useful for comparing patterns within an observation group, but they are curated cohorts, not complete sector maps or league tables."
      ],
      "blocks": [
        {
          "title": "Government",
          "why_watched": "Government domains are watched because public services rely on stable domain, registration, DNS, and mail signals that citizens can recognise and revisit.",
          "current_scope": "The current public cohort detail covers 14 panel domains.",
          "reader_question": "Which visible trust-posture and infrastructure signals are changing across the observed government group?",
          "limitation": "This is a curated observation cohort, not complete coverage of Australian government domains."
        },
        {
          "title": "Not-for-profit",
          "why_watched": "Not-for-profit domains are watched because public trust, donations, member services, and community communications often depend on recognisable domain and mail posture.",
          "current_scope": "The current public cohort detail covers 16 panel domains.",
          "reader_question": "Are visible mail, DNS, registrar, or provider signals changing across the observed not-for-profit group?",
          "limitation": "The cohort is selected for observability and context; it should not be read as sector-wide measurement."
        },
        {
          "title": "Education",
          "why_watched": "Education domains are watched because schools, universities, and related bodies often support high-volume public communication and identity-sensitive services.",
          "current_scope": "The current public cohort detail covers 10 panel domains.",
          "reader_question": "Which public DNS, mail, registration, or provider signals are visible for the observed education group?",
          "limitation": "The page does not represent all education providers and does not assess institutional security or compliance."
        },
        {
          "title": "Media",
          "why_watched": "Media domains are watched because public information access, brand trust, and publishing continuity depend on recognisable domain-layer signals.",
          "current_scope": "The current public cohort detail covers 8 panel domains.",
          "reader_question": "Where are visible infrastructure or mail-routing signals moving across the observed media group?",
          "limitation": "The cohort is a public observatory sample, not a completeness claim about the media sector."
        },
        {
          "title": "Commercial",
          "why_watched": "Commercial domains are watched because large public-facing services can make provider concentration, mail posture, and registration movement easier to understand in everyday contexts.",
          "current_scope": "The current public cohort detail covers 14 panel domains.",
          "reader_question": "Which visible dependencies and posture signals are shared or changing across the observed commercial group?",
          "limitation": "The cohort is not a ranking of companies and does not imply relative trustworthiness."
        },
        {
          "title": "Public-interest placeholder",
          "why_watched": "The placeholder keeps space for a future public-interest grouping where the observatory can explain why domains are grouped before showing detailed evidence.",
          "current_scope": "The current public page is present as a placeholder and does not yet have backing detail JSON.",
          "reader_question": "What public-interest grouping would make repeated observations easier to inspect without over-claiming?",
          "limitation": "Until backing detail data is present, the page should be treated as a signpost rather than an evidence view."
        }
      ]
    },
    {
      "title": "What recent observations add",
      "paragraphs": [
        "The 2026-05-19 to 2026-06-17 manifest window adds context for reading the current pages. It contains 30 daily manifests, but the movement-theme totals below are based only on the 27 manifests in that window that include summary objects.",
        "The 2026-05-19, 2026-05-20, and 2026-05-21 manifests still record input_summary.event_rows of 38, 28, and 34 respectively. Because those manifests do not include summary objects, those rows are acknowledged as unsummarized context rather than inferred into the 837-event or theme totals.",
        "Across the 27 summarized manifests, daily summaries recorded nameserver movement, RDAP status movement, MX movement, SPF visibility movement, and email provider movement. These are observation themes worth review, not standalone findings."
      ],
      "blocks": [
        {
          "title": "Name server movement",
          "current_observation": "Across the 27 summarized manifests, the recent high-signal summary recorded 42 nameserver changes.",
          "read_carefully": "Nameserver movement can reflect routine administration, provider changes, consolidation, or other stewardship activity. The count provides context for review."
        },
        {
          "title": "RDAP status movement",
          "current_observation": "Across the 27 summarized manifests, the recent high-signal summary recorded 22 RDAP status changes.",
          "read_carefully": "RDAP status changes are registration-layer signals. They need date, registrar, and domain context before any stronger interpretation."
        },
        {
          "title": "MX movement",
          "current_observation": "Across the 27 summarized manifests, the recent high-signal summary recorded 12 MX changes.",
          "read_carefully": "MX movement indicates visible mail-routing change. It does not by itself say whether mail service quality or control changed."
        },
        {
          "title": "SPF visibility movement",
          "current_observation": "Across the 27 summarized manifests, the recent high-signal summary recorded 6 SPF presence changes.",
          "read_carefully": "SPF visibility movement shows a public TXT-record posture change. It should be read alongside DMARC, MX, and provider evidence."
        },
        {
          "title": "Email provider movement",
          "current_observation": "Across the 27 summarized manifests, the recent meaningful infrastructure movement summary recorded 3 email-provider changes.",
          "read_carefully": "Provider movement can be ordinary migration or service-management activity. It is useful governance context, not an assessment."
        }
      ]
    },
    {
      "title": "How to use these pages carefully",
      "paragraphs": [
        "Use State pages to understand the signal lens first, then use Cohort pages to place selected domains in context. A useful reading path is: check the current posture, inspect whether a cohort has repeated movement, then follow evidence links before drawing conclusions.",
        "Avoid reading counts as grades. Prefer governance questions: Is the public signal expected? Has it changed repeatedly? Is provider concentration understood? Are registration and mail-posture signals consistent with the organisation's own stewardship expectations?"
      ],
      "blocks": []
    },
    {
      "title": "Sources and limitations",
      "paragraphs": [
        "This article uses the 2026-06-17 State and Cohort derived JSON as the current snapshot and the daily report manifests from 2026-05-19 to 2026-06-17 as recent-observation context.",
        "Recent movement totals are calculated from the 27 manifests in that window that include summary objects. The three earlier manifests in the window without summary objects are disclosed separately rather than folded into summarized movement themes.",
        "The pages describe the fixed observed panel and curated public cohorts. They do not provide complete namespace coverage, sector-wide measurement, scores, rankings, compliance findings, incident findings, or private operational context."
      ],
      "blocks": []
    }
  ],
  "source": {
    "snapshot": {
      "date": "2026-06-17",
      "basis": "Latest available public State and Cohort derived JSON generated from the canonical observatory dataset.",
      "state_index_path": "/data/state/index.json",
      "cohort_index_path": "/data/cohorts/index.json",
      "state_detail_paths": [
        "/data/state/dnssec.json",
        "/data/state/dmarc.json",
        "/data/state/registrars.json",
        "/data/state/dns-providers.json",
        "/data/state/email-providers.json",
        "/data/state/rdap.json"
      ],
      "cohort_detail_paths": [
        "/data/cohorts/government.json",
        "/data/cohorts/nfp.json",
        "/data/cohorts/education.json",
        "/data/cohorts/media.json",
        "/data/cohorts/commercial.json"
      ]
    },
    "recent_observation_window": {
      "start": "2026-05-19",
      "end": "2026-06-17",
      "days": 30,
      "basis": "30 daily report manifests available locally; 27 include summary objects used for event and movement-theme totals; 2026-05-19, 2026-05-20, and 2026-05-21 have input_summary.event_rows but no summary object; insights JSON artifacts referenced but not locally present",
      "daily_manifest_count": 30,
      "insights_availability_note": "Daily manifests referenced insights JSON artifacts, but dated insights JSON files were not present locally for 30-day aggregation in this repository checkout.",
      "summarized_manifest_count": 27,
      "unsummarized_manifest_count": 3,
      "unsummarized_input_summary_event_rows_total": 100
    },
    "latest_daily_observation": {
      "date": "2026-06-17",
      "daily_manifest_path": "/data/report_manifests/2026-06-17.json",
      "analysis_manifest_path": "/data/analysis_manifests/2026-06-17.json"
    },
    "panel": {
      "observed_panel_domains": 100,
      "collector_runs_on_snapshot_date": 7,
      "observed_cohort_group_count": 14,
      "public_cohort_page_count": 6,
      "public_cohort_detail_json_count": 5,
      "clarification": "The observed cohort group count describes the underlying observatory grouping model. The public article should emphasise the six public Cohort pages, of which five currently have backing detail JSON and one is a placeholder."
    },
    "note": "This article uses the 17 June 2026 State and Cohort JSON as the current snapshot for posture counts, then uses the latest 30 daily report manifests as supporting recent-observation context. State pages are summaries, not scores. Cohort pages are curated observation groups, not complete sector coverage or rankings."
  },
  "metrics": {
    "current_snapshot": {
      "date": "2026-06-17",
      "panel_size": 100,
      "state_pages": [
        {
          "label": "DNSSEC posture",
          "href": "/state/dnssec/",
          "data_path": "/data/state/dnssec.json"
        },
        {
          "label": "DMARC posture",
          "href": "/state/dmarc/",
          "data_path": "/data/state/dmarc.json"
        },
        {
          "label": "Registrar signals",
          "href": "/state/registrars/",
          "data_path": "/data/state/registrars.json"
        },
        {
          "label": "DNS providers",
          "href": "/state/dns-providers/",
          "data_path": "/data/state/dns-providers.json"
        },
        {
          "label": "Email providers",
          "href": "/state/email-providers/",
          "data_path": "/data/state/email-providers.json"
        },
        {
          "label": "RDAP and registration signals",
          "href": "/state/rdap/",
          "data_path": "/data/state/rdap.json"
        }
      ],
      "dnssec": {
        "secure_delegation_asserted": 13,
        "dnskey_observed": 8,
        "dnssec_visible": 15,
        "both_dnssec_signals": 6,
        "no_current_dnssec_evidence": 85,
        "clarification": "DNSSEC posture is presented as visible delegation and DNSKEY evidence across the observed panel. It is not a compliance judgement."
      },
      "email_posture": {
        "spf_present": 99,
        "dmarc_present": 98,
        "mx_present": 95,
        "email_provider_known_count": 95,
        "clarification": "Mail posture figures describe public SPF, DMARC, MX, and provider signals. They do not prove operational maturity, control quality, or compliance."
      },
      "rdap_registration": {
        "rdap_available": 100,
        "registrar_known": 100,
        "authoritative_source_count": null,
        "fallback_source_count": null,
        "redaction_count": null,
        "domain_created_date_count": null,
        "domain_expiry_date_count": null,
        "clarification": "RDAP availability and registrar visibility describe public registration signals. Optional RDAP fields are left null where the current derived data does not support a reliable count."
      },
      "provider_concentration": {
        "dns_providers": {
          "distinct_provider_count": 24,
          "observed_domain_count": 100,
          "observed_domain_share_pct": 100
        },
        "email_providers": {
          "distinct_provider_count": 14,
          "observed_domain_count": 95,
          "observed_domain_share_pct": 95
        },
        "registrars": {
          "distinct_provider_count": 12,
          "observed_domain_count": 100,
          "observed_domain_share_pct": 100
        },
        "clarification": "Provider counts show concentration and diversity patterns across the fixed panel. Provider choice is not a quality judgement."
      },
      "cohort_pages": {
        "public_page_count": 6,
        "backed_detail_json_count": 5,
        "placeholder_page_count": 1,
        "available_pages": [
          {
            "cohort": "government",
            "sector": "government",
            "href": "/cohorts/government/",
            "data_path": "/data/cohorts/government.json",
            "panel_domains": 14,
            "status": "backed-by-detail-json"
          },
          {
            "cohort": "nfp",
            "sector": "not-for-profit",
            "href": "/cohorts/nfp/",
            "data_path": "/data/cohorts/nfp.json",
            "panel_domains": 16,
            "status": "backed-by-detail-json"
          },
          {
            "cohort": "education",
            "sector": "education",
            "href": "/cohorts/education/",
            "data_path": "/data/cohorts/education.json",
            "panel_domains": 10,
            "status": "backed-by-detail-json"
          },
          {
            "cohort": "media",
            "sector": "media",
            "href": "/cohorts/media/",
            "data_path": "/data/cohorts/media.json",
            "panel_domains": 8,
            "status": "backed-by-detail-json"
          },
          {
            "cohort": "commercial",
            "sector": "commercial",
            "href": "/cohorts/commercial/",
            "data_path": "/data/cohorts/commercial.json",
            "panel_domains": 14,
            "status": "backed-by-detail-json"
          },
          {
            "cohort": "public-interest",
            "sector": "public-interest",
            "href": "/cohorts/public-interest/",
            "data_path": null,
            "panel_domains": null,
            "status": "placeholder-page"
          }
        ],
        "latest_observation_labels": [
          {
            "cohort": "government",
            "latest_snapshot_observation_count": 1
          },
          {
            "cohort": "education",
            "latest_snapshot_observation_count": 1
          },
          {
            "cohort": "commercial",
            "latest_snapshot_observation_count": 0
          },
          {
            "cohort": "media",
            "latest_snapshot_observation_count": 0
          },
          {
            "cohort": "nfp",
            "latest_snapshot_observation_count": 0
          }
        ],
        "clarification": "Cohort pages are curated presentation groups. They make selected domain-layer observations easier to read in context, but they are not complete sector coverage, league tables, or rankings."
      }
    },
    "recent_observations": {
      "window": {
        "start": "2026-05-19",
        "end": "2026-06-17",
        "days": 30
      },
      "basis": "Aggregated summary fields from the 27 daily report manifests in the 2026-05-19 to 2026-06-17 window that include a summary object; the 2026-05-19, 2026-05-20, and 2026-05-21 manifests record input event rows but do not include summary objects, so they are not included in the 837-event or movement-theme totals.",
      "daily_manifest_count": 30,
      "active_panel_domains_each_day": 100,
      "observed_cohort_group_count_each_day": 14,
      "collector_run_rows_total": 210,
      "event_summary": {
        "total_events": 837,
        "average_daily_events": 31,
        "material_events": 91,
        "high_signal_trust_posture_changes": 82,
        "meaningful_infrastructure_movement": 9,
        "routine_or_low_confidence_churn": 744,
        "unclassified_events": 2,
        "clarification": "These labels help organise the 27 summarized daily manifests in the window. They do not grade, rank, or assess domains. The three unsummarized manifests are kept visible separately rather than inferred into theme totals."
      },
      "high_signal_change_themes": [
        {
          "event_type": "nameservers_changed",
          "public_theme": "Name server movement",
          "count": 42
        },
        {
          "event_type": "rdap_status_changed",
          "public_theme": "RDAP status movement",
          "count": 22
        },
        {
          "event_type": "mx_changed",
          "public_theme": "Mail routing movement",
          "count": 12
        },
        {
          "event_type": "spf_present_changed",
          "public_theme": "SPF visibility movement",
          "count": 6
        }
      ],
      "meaningful_infrastructure_movement_themes": [
        {
          "event_type": "email_provider_changed",
          "public_theme": "Email provider movement",
          "count": 3
        }
      ],
      "routine_churn": {
        "routine_or_low_confidence_churn_events": 744,
        "routine_churn_domain_day_count_sum": 573,
        "repeated_address_churn_domain_day_count_sum": 161,
        "clarification": "Routine churn domain counts are summed daily counts from summarized manifests, not deduplicated domain counts across the whole 30-day window. A and AAAA movement remains preserved as evidence, but is not the focus of this article."
      },
      "limitations": [
        "The 2026-05-19 to 2026-06-17 window contains 30 daily manifests, but only 27 include summary objects used for the 837-event and movement-theme totals.",
        "The 2026-05-19, 2026-05-20, and 2026-05-21 manifests have input_summary.event_rows of 38, 28, and 34 respectively; those rows are acknowledged separately and not inferred into the summarized theme totals.",
        "The recent window uses daily report manifest summaries because local dated insights JSON artifacts were not present in the repository checkout.",
        "Daily routine churn domain counts are summed daily counts, not deduplicated domain counts across the whole window.",
        "The aggregate describes observed movement in the fixed panel and does not rank or assess domains.",
        "Recent observations are supporting context for the State and Cohort walkthrough, not a replacement for the underlying evidence."
      ],
      "summarized_manifest_count": 27,
      "unsummarized_manifest_count": 3,
      "unsummarized_manifests": [
        {
          "date": "2026-05-19",
          "input_summary_event_rows": 38,
          "summary_available": false
        },
        {
          "date": "2026-05-20",
          "input_summary_event_rows": 28,
          "summary_available": false
        },
        {
          "date": "2026-05-21",
          "input_summary_event_rows": 34,
          "summary_available": false
        }
      ],
      "unsummarized_input_summary_event_rows_total": 100
    },
    "latest_daily_observation": {
      "date": "2026-06-17",
      "source_manifest_path": "/data/report_manifests/2026-06-17.json",
      "total_events": 28,
      "tier_1_count": 4,
      "tier_2_count": 0,
      "tier_3_count": 24,
      "unclassified_count": 0,
      "routine_churn_domain_count": 18,
      "repeated_address_churn_domain_count": 6,
      "high_signal_changes": [
        {
          "event_type": "rdap_status_changed",
          "public_theme": "RDAP status movement",
          "count": 3
        },
        {
          "event_type": "nameservers_changed",
          "public_theme": "Name server movement",
          "count": 1
        }
      ],
      "meaningful_infra_movement": [],
      "clarification": "The latest daily manifest is retained as a point-in-time observation only. It should be read beneath the State and Cohort snapshot and the recent 30-day context."
    }
  },
  "key_points": [
    "The State and Cohort pages do not make .auDO louder; they make accumulated observations easier to read.",
    "This article walks through the State and Cohort pages using the 2026-06-17 State/Cohort snapshot for current posture counts, then uses the latest 30 daily report manifests as supporting recent-observation context.",
    "The State pages summarise current visible signals across the fixed 100-domain panel: DNSSEC posture, DMARC posture, registrar signals, DNS providers, email providers, and RDAP and registration signals.",
    "State pages are summaries, not scores. Counts describe observed public evidence and missing optional fields are counted as missing rather than inferred.",
    "The Cohort pages group selected domains for readable public context: government, not-for-profit, education, media, commercial, and a public-interest placeholder.",
    "Cohort pages are curated observation groups, not complete sector coverage or rankings.",
    "The 2026-06-17 State snapshot shows 15 domains with visible DNSSEC evidence, 13 with secure delegation asserted, 8 with DNSKEY observed, 98 with DMARC present, 99 with SPF present, 95 with MX present, and 100 with RDAP available.",
    "Provider summaries make concentration easier to inspect: 24 distinct DNS providers, 14 distinct email providers, and 12 distinct registrars are represented across the observed panel.",
    "Across the 2026-05-19 to 2026-06-17 report-manifest window, 27 of 30 manifests include summary objects. Those summarized manifests recorded 837 events: 82 high-signal trust posture changes, 9 meaningful infrastructure movement events, 744 routine or lower-confidence churn events, and 2 unclassified events.",
    "The 2026-05-19, 2026-05-20, and 2026-05-21 manifests have no summary object, but they still record 38, 28, and 34 input_summary.event_rows respectively; this article keeps them visible as unsummarized context rather than inferring them into theme totals.",
    "Within the 27 summarized manifests, the high-signal summary was led by name server movement, RDAP status movement, mail routing movement, and SPF visibility movement.",
    "Within the 27 summarized manifests, tier-2 meaningful infrastructure movement was represented by email provider changes.",
    "The latest 2026-06-17 daily manifest remains useful as a point-in-time check: it recorded 28 events, including 3 RDAP status changes and 1 nameserver change in the high-signal group.",
    "Routine A and AAAA movement remains preserved as evidence, but this article keeps the emphasis on DNSSEC posture, DMARC and mail posture, registrar and nameserver movement, RDAP visibility, provider movement, and provider concentration."
  ],
  "callouts": [
    {
      "type": "governance-note",
      "title": "A reading layer, not a rating layer",
      "text": "State pages collect visible public signals into stable summaries. They help readers ask better governance questions without turning observations into scores, grades, or rankings."
    },
    {
      "type": "interpretation-note",
      "title": "Cohorts need context",
      "text": "Cohort pages are intentionally curated. They make repeated observation easier to compare, but they do not represent whole sectors and should not be read as league tables."
    },
    {
      "type": "clarification",
      "title": "Limits kept visible",
      "text": "The source JSON explicitly limits the reading: counts describe the observed .auDO panel, missing optional fields are not inferred, RDAP optional date counts are unavailable where those fields are absent, and provider inference is based on visible public patterns."
    },
    {
      "type": "observation-note",
      "title": "Recent movement worth review",
      "text": "The 2026-05-19 to 2026-06-17 window contains 30 daily manifests. Movement-theme totals are based on the 27 manifests with summary objects; the three manifests without summaries are disclosed separately as unsummarized input-row context."
    }
  ],
  "sources": [
    {
      "title": "State of .au index JSON",
      "publisher": ".auDO",
      "url": "https://audo.bryanchetcuti.com/data/state/index.json",
      "date": "2026-06-17",
      "relevance": "Lists available State pages and panel-level summary counts."
    },
    {
      "title": "Observed cohorts index JSON",
      "publisher": ".auDO",
      "url": "https://audo.bryanchetcuti.com/data/cohorts/index.json",
      "date": "2026-06-17",
      "relevance": "Lists available Cohort pages, cohort sizes, and cohort limitations."
    },
    {
      "title": "Daily report manifest window, 2026-05-19 to 2026-06-17",
      "publisher": ".auDO",
      "url_pattern": "https://audo.bryanchetcuti.com/data/report_manifests/YYYY-MM-DD.json",
      "date": "2026-06-17",
      "relevance": "Provides the 30-manifest window and identifies which manifests include summary objects for recent observation counts and movement themes."
    },
    {
      "title": "Daily report manifest for 2026-06-17",
      "publisher": ".auDO",
      "url": "https://audo.bryanchetcuti.com/data/report_manifests/2026-06-17.json",
      "date": "2026-06-17",
      "relevance": "Provides the latest point-in-time daily observation used beneath the broader State/Cohort snapshot and 30-day window."
    }
  ],
  "seo": {
    "title": "What the State and Cohort pages make visible | .auDO",
    "description": "A careful .auDO featured article explaining the State and Cohort pages, recent DNSSEC, DMARC, RDAP, provider and cohort observations, and the limits of public domain-layer summaries."
  },
  "evidence_pack": {
    "source_files_reviewed": [
      "audo-site/state/index.html",
      "audo-site/state/dnssec/index.html",
      "audo-site/state/dmarc/index.html",
      "audo-site/state/registrars/index.html",
      "audo-site/state/dns-providers/index.html",
      "audo-site/state/email-providers/index.html",
      "audo-site/state/rdap/index.html",
      "audo-site/cohorts/index.html",
      "audo-site/cohorts/government/index.html",
      "audo-site/cohorts/nfp/index.html",
      "audo-site/cohorts/education/index.html",
      "audo-site/cohorts/media/index.html",
      "audo-site/cohorts/commercial/index.html",
      "audo-site/cohorts/public-interest/index.html",
      "audo-site/data/state/index.json",
      "audo-site/data/state/dnssec.json",
      "audo-site/data/state/dmarc.json",
      "audo-site/data/state/registrars.json",
      "audo-site/data/state/dns-providers.json",
      "audo-site/data/state/email-providers.json",
      "audo-site/data/state/rdap.json",
      "audo-site/data/cohorts/index.json",
      "audo-site/data/cohorts/government.json",
      "audo-site/data/cohorts/nfp.json",
      "audo-site/data/cohorts/education.json",
      "audo-site/data/cohorts/media.json",
      "audo-site/data/cohorts/commercial.json",
      "audo-site/data/report_manifests/2026-05-19.json through audo-site/data/report_manifests/2026-06-17.json",
      "audo-site/data/report_manifests/2026-06-17.json",
      "data/analysis_manifests/2026-06-17.json"
    ],
    "snapshot_date": "2026-06-17",
    "latest_observation_report_date_used": "2026-06-17",
    "recent_observation_window": {
      "start": "2026-05-19",
      "end": "2026-06-17",
      "basis": "30 daily report manifests available locally; insights JSON artifacts referenced but not locally present"
    },
    "state_pages_available": [
      "/state/dnssec/",
      "/state/dmarc/",
      "/state/registrars/",
      "/state/dns-providers/",
      "/state/email-providers/",
      "/state/rdap/"
    ],
    "cohort_pages_available": [
      "/cohorts/government/",
      "/cohorts/nfp/",
      "/cohorts/education/",
      "/cohorts/media/",
      "/cohorts/commercial/",
      "/cohorts/public-interest/"
    ],
    "key_counts_or_observations_used": [
      "100 observed panel domains in the 2026-06-17 State/Cohort snapshot",
      "15 DNSSEC visible; 13 secure delegation asserted; 8 DNSKEY observed",
      "98 DMARC present; 99 SPF present; 95 MX present",
      "100 RDAP available; 100 registrar known",
      "24 distinct DNS providers; 14 distinct email providers; 12 distinct registrars",
      "6 public Cohort pages, 5 with backing detail JSON and 1 public-interest placeholder",
      "30 daily report manifests reviewed for 2026-05-19 through 2026-06-17; 27 include summary objects used for the recent movement totals",
      "2026-05-19, 2026-05-20, and 2026-05-21 have no summary object but record input_summary.event_rows of 38, 28, and 34 respectively",
      "Recent summarized manifest totals across 27 manifests: 837 events, 82 high-signal trust posture changes, 9 tier-2 meaningful infrastructure movement events, 744 tier-3 routine or lower-confidence churn events, and 2 unclassified events",
      "Recent high-signal change summary across 27 summarized manifests: 42 nameserver changes, 22 RDAP status changes, 12 MX changes, and 6 SPF presence changes",
      "Recent tier-2 movement summary: 3 email provider changes",
      "Latest daily manifest on 17 June 2026: 28 events, including 3 RDAP status changes and 1 nameserver change in the high-signal group"
    ],
    "missing_or_incomplete_optional_fields": [
      "Public-interest cohort has an HTML page and index entry but no data/cohorts/public-interest.json backing detail file in the current data set.",
      "RDAP current metrics include null optional counts for authoritative source, fallback source, redaction, domain created date, and domain expiry date.",
      "Daily manifests reference insights JSON artifacts, but those dated insights JSON files are not present locally for 30-day aggregation in this repository checkout."
    ],
    "limitations_to_mention": [
      "Counts describe the observed .auDO panel, not the whole .au namespace.",
      "State pages are summaries, not scores.",
      "Cohort pages are curated observation groups, not complete sector coverage or rankings.",
      "Missing optional fields are counted as missing rather than inferred.",
      "Provider inference is based on visible public DNS and mail routing patterns.",
      "Routine A/AAAA movement is retained as evidence but should not dominate public interpretation.",
      "Recent observation aggregates are based on daily manifest summaries, not local dated insights JSON aggregation."
    ]
  }
}