Evidence before narrative
Observed state and change evidence are retained before analysis or report language is applied.
How .auDO observes, preserves, compares and interprets public domain-layer evidence, and the boundaries that keep those observations proportionate.
Start with how the observatory works. Evidence derivation, architecture, governance and version history remain available when you need the detail. For purpose and stewardship, see About .auDO; for wider operating accountability, see Trust and transparency and Security.
Operating cycle
The observatory repeats a consistent cycle so public observations can be traced to retained evidence and interpreted within explicit limits.
The observation panel is stable and curated for sector mix, operational relevance and signal diversity; it is not a statistically representative sample of the .au namespace.
auDA registry data is used only as external namespace context and is not .auDO observation evidence. Observation Panel membership and stewardship are governed separately from signal interpretation.
.auDO concept and design work began in February 2026. Repeated data collection began on 26 March 2026, which is the start of the retained reporting baseline used for longitudinal analysis.
Current panel size, composition, wider namespace context and stewardship belong to the Observation Panel. Methodology explains how that population is bounded rather than duplicating its live metrics.
Method principles
Observed state and change evidence are retained before analysis or report language is applied.
Reliable collection, preservation and publication take priority over new features.
Signals, cohorts and time windows are explicit before observations are compared.
Interpretation remains proportionate to the visible signal, retained history and known limitations.
Interpretation
Stronger interpretation needs repeated evidence, persistence, materiality or clear supporting context.
Counts and distributions are not ratings, compliance findings or statements of fault.
Visible technical state does not reveal every internal control, process or decision.
Observed change is not proof of breach, compromise, incident, non-compliance or intent.
Use the practical guide when moving from a public signal to cautious interpretation.
Evidence model
The central methodological distinction is between what .auDO observes directly and what it derives from those observations.
Public DNS, RDAP/registration, mail and DNSSEC observations and query outcomes.
Provider associations, posture classifications and other deterministic interpretations built from retained public evidence.
State, cohort and report summaries with explicit denominators, suppression and interpretation limits where applicable.
Snapshot metadata, source outcomes, fallback information and external namespace context used for traceability and limitations.
Read the Signals library for canonical field and signal definitions.
| Area | Current approach |
|---|---|
| Collection cadence | Scheduled recurring collection supports longitudinal observation rather than one-off lookup results. |
| State capture | Public state and collection outcomes are captured before interpretation. |
| Canonical storage | Supabase retains canonical observation data used by collection and analytical workflows. |
| Change derivation | Meaningful differences are derived across runs; classification changes are kept distinct from observed infrastructure movement. |
| Backup and retention | Cloudflare R2 retains database backups, exported evidence and published artefacts under explicit retention controls. |
| Publication | Deterministic static output is deployed through Cloudflare Pages rather than presented as a real-time monitoring console. |
Nameserver, MX and selected SPF-reference targets remain direct observed evidence. Provider Resolution applies versioned resolution rules and a versioned Provider Catalogue to derive one or more provider associations.
| Stage | Boundary |
|---|---|
| Observed targets | Direct public evidence; no supplier, ownership or contractual relationship is inferred from a target alone. |
| Provider association | Derived evidence under an explicit resolver and catalogue classification context. |
| Provider movement | Requires observed target movement and resolved provider-identity movement under a consistent classification context. |
| Catalogue-only reclassification | Classification recontextualisation is not treated as observed infrastructure movement. |
| Historical observations | Evidence and the classification context that existed at observation time are retained; historical snapshots are not silently rewritten. |
Provider Catalogue releases do not automatically change the Public Methodology version. A version assessment is required only when Provider Resolution semantics, movement rules, aggregation or interpretation change materially.
The Provider Catalogue is maintained by ThreatScope Check as the canonical published reference for documented infrastructure associations. .auDO records the catalogue version used so provider classifications remain traceable to their classification context.
Raw MX, SPF-relevant TXT and DMARC observations are retained first. Evidence classification then determines whether each mail family is usable for bounded derivation. Indeterminate means the evidence is insufficient or unusable; it is not reinterpreted as absence.
| Layer | Role | Boundary |
|---|---|---|
mail-posture/v1 | Per-domain deterministic interpretation of classified observed MX, SPF and DMARC evidence. | Bounded record interpretation only. It does not test delivery, recursive SPF policy effectiveness or organisational controls. |
mail-posture-aggregate/v1 | Public fixed-panel and eligible-cohort aggregate with evidence accounting, denominators and suppression metadata. | No domain-level Mail Posture rows are published through this aggregate. |
| Public presentation | Renders generated aggregate data. | The browser does not derive posture from raw DNS material or reconstruct suppressed cells. |
The panel or cohort denominator is the population observed for that aggregate unit. Determinate and indeterminate evidence counts are reported separately within it.
MX, SPF and DMARC posture distributions use the determinate evidence count for that signal family. Indeterminate evidence remains visible in evidence accounting.
SPF terminal-qualifier and selected DMARC policy/alignment distributions apply only to the eligible derived subset and therefore use narrower sub-denominators.
Small non-zero cohort cells may be primary-suppressed. Complementary suppression is then applied where needed so a hidden value cannot be recovered by subtraction from the public denominator and remaining visible cells.
If a safe complementary shape is not available, the entire distribution is masked. A suppressed count or share is represented as unavailable, not as zero; safe zeroes remain explicit. Secondary SPF and DMARC distributions may also be withheld when their own sub-denominator is below the publication threshold.
Aggregate categories are derived evidence. They should not be described as though .auDO directly observed the aggregate category on the wire.
Signal tiers classify observed change: Tier 1 high-signal trust-posture change, Tier 2 meaningful infrastructure movement, Tier 3 routine or low-confidence churn, and unclassified retained evidence. They are not organisational risk ratings. Read the canonical signal tier definitions.
Collection and automation, canonical observation storage, evidence retention, and public/private delivery are separated so each component has a clear role and failure boundary.
| Provider or component | .auDO role | Boundary |
|---|---|---|
| GitHub and GitHub Actions | Source control, orchestration, scheduled processing and versioned publication output. | Automation platform only; no analytical or editorial authority. |
| Supabase | Canonical datastore for retained observations and analytical workflows. | Data service only; no role in classification, claims or publication decisions. |
| Cloudflare R2 and Worker | Backup, evidence and artefact retention. | Storage and lifecycle services only. |
| Cloudflare Pages and Zero Trust | Public static delivery and identity-gated access to approved private evidence views. | Delivery and access-control services only. |
Publishing model
Current aggregate posture and bounded recent movement.
Dated ledger material, monthly briefs, quarterly reviews and featured analysis.
Canonical definitions, interpretation limits and durable explanatory context.
Observation population, stewardship and curated analytical lenses.
Method governance
Versioning makes material changes to the operating method visible without retrospectively relabelling earlier .auDO evidence or reports.
Public Methodology v1.1
8 September 2026
v1.1 introduces Provider Resolution as the authoritative provider-classification method while preserving the underlying observed infrastructure evidence. Public Methodology v1.0 applies to outputs produced from 25 August through 7 September 2026; outputs before 25 August 2026 remain pre-versioning, and earlier publications remain unversioned rather than being retrospectively assigned v1.0.
| Version | Effective | Change | Interpretation impact |
|---|---|---|---|
| 1.1 | 8 September 2026 | Provider associations move to versioned Provider Resolution rules and a versioned Provider Catalogue. | Provider movement requires observed infrastructure movement as well as resolved provider-identity change. Catalogue-only reclassification is not observatory movement. |
| 1.0 | 25 August 2026 | Initial versioned public methodology. | Applies to outputs produced from 25 August through 7 September 2026; earlier publications remain unversioned. |
A methodology version changes when a material change to collection, classification, aggregation or interpretation could alter findings or the way results should be compared. Editorial clarification and presentation changes do not require a new version.
Provider Catalogue releases do not automatically change the Public Methodology version. Routine catalogue expansion remains catalogue-versioned; a methodology bump is reserved for material changes to Provider Resolution semantics, movement rules, aggregation or interpretation.
Limits and maturity
.auDO records and explains public domain-layer evidence. It does not assess an organisation's internal governance. The separate Domain Governance Baseline provides a practical self-assessment for ownership, accountability and operating practices.