How to Read a .auDO Observation

.auDO observations are public signals, not findings. This guide helps you move from visible change to cautious interpretation without treating observations as scores, allegations or proof of risk.

Public signals Cautious interpretation Australian .au context Not a score

Before you start

Observations are descriptive records

A visible change is not automatically a risk. Public data cannot prove internal intent, approval, compromise, compliance or governance quality.

Visible, not complete

.auDO reads public DNS, RDAP, mail, DNSSEC and provider signals. Public evidence is useful, but it is not the whole operating picture.

Change needs context

One observation rarely tells the whole story. Repeated patterns can support stronger interpretation, but they still need cautious wording.

Counts are summaries

Panel counts and provider summaries help readers compare context. They are not ratings, rankings, findings or organisation comparisons.

Interpretive cue

Panel observation or namespace context?

First decide whether you are reading a .auDO observation from the fixed panel or external registry context about the wider .au namespace.

Panel observation

Counts, signal changes, State pages and cohort views describe the fixed .auDO panel. Current panel size: - domains.

Namespace context

auDA registry statistics provide wider namespace scale for comparison. Latest reference month: -.

How to use the distinction

Use namespace context to understand scale, not to turn panel observations into registry-wide claims. A panel pattern can be governance-relevant without being representative.

Mail posture reading

Read Mail trust states as evidence classifications

Mail trust posture combines bounded MX, SPF and DMARC derivations. The labels describe what the observed public evidence supports, not the effectiveness of an organisation's mail controls.

Published stateHow to read itWhat it does not establish
Not observedThe relevant public record or configuration was not visible in otherwise determinate evidence at the observation time.It does not prove that the domain does not send email, that a control is ineffective, or that the organisation is non-compliant.
IndeterminateThe retained observation evidence was insufficient or unusable for the bounded derivation.It must not be read as absence. Indeterminate evidence remains separate from “not observed”.
MalformedRelevant record material was visible but did not satisfy the bounded parser and derivation rules.It does not by itself establish operational failure, delivery failure or a governance failure.
Policy and tag valuesValues such as SPF terminal qualifiers and DMARC p, sp, aspf and adkim describe visible configuration within the versioned derivation.They are not ratings and do not establish policy effectiveness, sender coverage, alignment success or compliance.
SuppressedA cohort aggregate value is intentionally withheld under the publication privacy rules.Suppressed does not mean zero, absent or unsupported. Do not infer the hidden value from surrounding cells.

Do not infer compliance or effectiveness. Mail trust posture describes visible public configuration and evidence quality. It does not test delivery, organisational operation of the controls, or whether a policy achieves its intended outcome.

Observation Guide

Read the observation in context

Work through four simple prompts to understand what a visible .auDO observation may suggest, what it cannot show, and what to compare next. This guide does not look up domains or make assessments.

Step 1 of 4

Loading static reading guide content.

Your reading note

Complete the four prompts to see how this observation can be read, where its limits sit, and what to compare next.

Where to go next

Keep reading across .auDO

Use this guide alongside the public surfaces that preserve evidence, define signals and explain collection limits.

Once an observation has been interpreted carefully, the Domain Governance Baseline can help frame the internal ownership and accountability questions that public evidence alone cannot answer.
Open the Domain Governance Baseline.