Methodology

How .auDO observes, preserves, compares and interprets public domain-layer evidence, and the boundaries that keep those observations proportionate.

Start with how the observatory works. Evidence derivation, architecture, governance and version history remain available when you need the detail. For purpose and stewardship, see About .auDO; for wider operating accountability, see Trust and transparency and Security.

Operating cycle

How .auDO works

The observatory repeats a consistent cycle so public observations can be traced to retained evidence and interpreted within explicit limits.

  1. Select a stable panel
  2. Collect public signals
  3. Preserve evidence
  4. Compare observations
  5. Classify change
  6. Publish bounded evidence

Four boundaries shape every publication

Population
A fixed observation panel, not whole-namespace measurement.
Evidence
Public domain-layer signals only; .auDO does not inspect private systems.
Change
Visible change is retained before interpretation and does not establish cause or intent.
Claims
Summaries remain bounded to available evidence, signal definitions and observation windows.

Panel and scope

The observation panel is stable and curated for sector mix, operational relevance and signal diversity; it is not a statistically representative sample of the .au namespace.

auDA registry data is used only as external namespace context and is not .auDO observation evidence. Observation Panel membership and stewardship are governed separately from signal interpretation.

.auDO concept and design work began in February 2026. Repeated data collection began on 26 March 2026, which is the start of the retained reporting baseline used for longitudinal analysis.

Current panel size, composition, wider namespace context and stewardship belong to the Observation Panel. Methodology explains how that population is bounded rather than duplicating its live metrics.

Method principles

Evidence before narrative, continuity before novelty

Evidence before narrative

Observed state and change evidence are retained before analysis or report language is applied.

Continuity before novelty

Reliable collection, preservation and publication take priority over new features.

Definitions before comparison

Signals, cohorts and time windows are explicit before observations are compared.

Claims bounded to evidence

Interpretation remains proportionate to the visible signal, retained history and known limitations.

Interpretation

Move from observation to explanation cautiously

Cautious by default

Stronger interpretation needs repeated evidence, persistence, materiality or clear supporting context.

Evidence summaries, not scores

Counts and distributions are not ratings, compliance findings or statements of fault.

Public-data-first

Visible technical state does not reveal every internal control, process or decision.

No unsupported incident claims

Observed change is not proof of breach, compromise, incident, non-compliance or intent.

Observation Guide

Use the practical guide when moving from a public signal to cautious interpretation.

Evidence model

Know which layer you are reading

The central methodological distinction is between what .auDO observes directly and what it derives from those observations.

Observed evidence

Public DNS, RDAP/registration, mail and DNSSEC observations and query outcomes.

Derived evidence

Provider associations, posture classifications and other deterministic interpretations built from retained public evidence.

Published aggregates

State, cohort and report summaries with explicit denominators, suppression and interpretation limits where applicable.

Provenance and context

Snapshot metadata, source outcomes, fallback information and external namespace context used for traceability and limitations.

Read the Signals library for canonical field and signal definitions.

Collection and preservationHow recurring public observations become retained evidence.
AreaCurrent approach
Collection cadenceScheduled recurring collection supports longitudinal observation rather than one-off lookup results.
State capturePublic state and collection outcomes are captured before interpretation.
Canonical storageSupabase retains canonical observation data used by collection and analytical workflows.
Change derivationMeaningful differences are derived across runs; classification changes are kept distinct from observed infrastructure movement.
Backup and retentionCloudflare R2 retains database backups, exported evidence and published artefacts under explicit retention controls.
PublicationDeterministic static output is deployed through Cloudflare Pages rather than presented as a real-time monitoring console.
Provider ResolutionHow observed infrastructure is separated from provider classification.

Nameserver, MX and selected SPF-reference targets remain direct observed evidence. Provider Resolution applies versioned resolution rules and a versioned Provider Catalogue to derive one or more provider associations.

StageBoundary
Observed targetsDirect public evidence; no supplier, ownership or contractual relationship is inferred from a target alone.
Provider associationDerived evidence under an explicit resolver and catalogue classification context.
Provider movementRequires observed target movement and resolved provider-identity movement under a consistent classification context.
Catalogue-only reclassificationClassification recontextualisation is not treated as observed infrastructure movement.
Historical observationsEvidence and the classification context that existed at observation time are retained; historical snapshots are not silently rewritten.

Provider Catalogue releases do not automatically change the Public Methodology version. A version assessment is required only when Provider Resolution semantics, movement rules, aggregation or interpretation change materially.

The Provider Catalogue is maintained by ThreatScope Check as the canonical published reference for documented infrastructure associations. .auDO records the catalogue version used so provider classifications remain traceable to their classification context.

Mail Posture derivation and publicationDeterminacy, denominators, aggregation and suppression remain inspectable here.

Raw MX, SPF-relevant TXT and DMARC observations are retained first. Evidence classification then determines whether each mail family is usable for bounded derivation. Indeterminate means the evidence is insufficient or unusable; it is not reinterpreted as absence.

LayerRoleBoundary
mail-posture/v1Per-domain deterministic interpretation of classified observed MX, SPF and DMARC evidence.Bounded record interpretation only. It does not test delivery, recursive SPF policy effectiveness or organisational controls.
mail-posture-aggregate/v1Public fixed-panel and eligible-cohort aggregate with evidence accounting, denominators and suppression metadata.No domain-level Mail Posture rows are published through this aggregate.
Public presentationRenders generated aggregate data.The browser does not derive posture from raw DNS material or reconstruct suppressed cells.

Population denominator

The panel or cohort denominator is the population observed for that aggregate unit. Determinate and indeterminate evidence counts are reported separately within it.

Posture denominator

MX, SPF and DMARC posture distributions use the determinate evidence count for that signal family. Indeterminate evidence remains visible in evidence accounting.

Sub-denominators

SPF terminal-qualifier and selected DMARC policy/alignment distributions apply only to the eligible derived subset and therefore use narrower sub-denominators.

Cohort suppression and complementary suppression

Small non-zero cohort cells may be primary-suppressed. Complementary suppression is then applied where needed so a hidden value cannot be recovered by subtraction from the public denominator and remaining visible cells.

If a safe complementary shape is not available, the entire distribution is masked. A suppressed count or share is represented as unavailable, not as zero; safe zeroes remain explicit. Secondary SPF and DMARC distributions may also be withheld when their own sub-denominator is below the publication threshold.

Aggregate categories are derived evidence. They should not be described as though .auDO directly observed the aggregate category on the wire.

Signal tiersHow retained change is classified without becoming a risk score.

Signal tiers classify observed change: Tier 1 high-signal trust-posture change, Tier 2 meaningful infrastructure movement, Tier 3 routine or low-confidence churn, and unclassified retained evidence. They are not organisational risk ratings. Read the canonical signal tier definitions.

High-level architecture

operating boundaries

Collection and automation, canonical observation storage, evidence retention, and public/private delivery are separated so each component has a clear role and failure boundary.

Infrastructure roles and boundariesProvider detail is transparent but secondary to the evidence flow.
Provider or component.auDO roleBoundary
GitHub and GitHub ActionsSource control, orchestration, scheduled processing and versioned publication output.Automation platform only; no analytical or editorial authority.
SupabaseCanonical datastore for retained observations and analytical workflows.Data service only; no role in classification, claims or publication decisions.
Cloudflare R2 and WorkerBackup, evidence and artefact retention.Storage and lifecycle services only.
Cloudflare Pages and Zero TrustPublic static delivery and identity-gated access to approved private evidence views.Delivery and access-control services only.

Publishing model

Separate current posture, dated evidence and explanatory context

State of .au

Current aggregate posture and bounded recent movement.

Evidence and reports

Dated ledger material, monthly briefs, quarterly reviews and featured analysis.

Signals and explainers

Canonical definitions, interpretation limits and durable explanatory context.

Panel and cohorts

Observation population, stewardship and curated analytical lenses.

Method governance

Public Methodology v1.1

Versioning makes material changes to the operating method visible without retrospectively relabelling earlier .auDO evidence or reports.

Current version

Public Methodology v1.1

Effective date

8 September 2026

v1.1 introduces Provider Resolution as the authoritative provider-classification method while preserving the underlying observed infrastructure evidence. Public Methodology v1.0 applies to outputs produced from 25 August through 7 September 2026; outputs before 25 August 2026 remain pre-versioning, and earlier publications remain unversioned rather than being retrospectively assigned v1.0.

Method change record

VersionEffectiveChangeInterpretation impact
1.18 September 2026Provider associations move to versioned Provider Resolution rules and a versioned Provider Catalogue.Provider movement requires observed infrastructure movement as well as resolved provider-identity change. Catalogue-only reclassification is not observatory movement.
1.025 August 2026Initial versioned public methodology.Applies to outputs produced from 25 August through 7 September 2026; earlier publications remain unversioned.

A methodology version changes when a material change to collection, classification, aggregation or interpretation could alter findings or the way results should be compared. Editorial clarification and presentation changes do not require a new version.

Provider Catalogue releases do not automatically change the Public Methodology version. Routine catalogue expansion remains catalogue-versioned; a methodology bump is reserved for material changes to Provider Resolution semantics, movement rules, aggregation or interpretation.

Limits and maturity

An operating observatory with deliberately bounded claims

Maturity
Young but operating, with collection continuity and evidence quality taking priority.
Coverage
A fixed observation panel, not full namespace coverage.
Timeliness
Repeated observations and dated publication, not real-time monitoring.
Purpose
A public trust-signal observatory, not a vulnerability scanner.

.auDO records and explains public domain-layer evidence. It does not assess an organisation's internal governance. The separate Domain Governance Baseline provides a practical self-assessment for ownership, accountability and operating practices.