{
  "slug": "presence-is-not-posture",
  "title": "Presence is not posture",
  "subtitle": "Featured analysis · .au Domain Observatory · 2 September 2026",
  "prepared_at": "2026-09-02T20:03:53+10:00",
  "published_at": "2026-09-02T20:32:00+10:00",
  "report_type": "featured",
  "series": "observations",
  "status": "published",
  "summary": "Across 25 consecutive Mail Posture observations, broad SPF and DMARC publication persisted while the more useful distinctions sat inside derived posture and evidence quality. The series shows why an observatory must separate what is absent from what it cannot determine.",
  "href": "/reports/featured/presence-is-not-posture/",
  "tags": [
    "Featured",
    "Mail posture",
    "Repeated observation",
    "Evidence quality",
    "Governance"
  ],
  "analysis_baseline": "/docs/strategy/featured-analysis-presence-is-not-posture-baseline.md",
  "metrics": {
    "window": {
      "start": "2026-08-09",
      "end": "2026-09-02",
      "days": 25,
      "panel_size": 100
    },
    "spf": {
      "not_observed_all_days": 0,
      "malformed_typical_count": 14,
      "malformed_typical_days": 24,
      "clarification": "Malformed is the bounded Mail Posture v1 derivation classification. It is not a security, compliance or organisational-maturity judgement."
    },
    "dmarc": {
      "not_observed_all_days": 1,
      "valid_typical_count": 97,
      "valid_typical_days": 23,
      "reject_typical_count": 68,
      "reject_typical_days": 24,
      "quarantine_count_all_days": 13,
      "clarification": "Visible DMARC policy is descriptive public evidence. It does not establish enforcement effectiveness, delivery outcomes, organisational intent or maturity."
    },
    "evidence_state_examples": {
      "2026-08-14": {
        "dmarc_determinate": 96,
        "dmarc_indeterminate": 4,
        "dmarc_valid": 95,
        "dmarc_not_observed": 1
      },
      "2026-09-01": {
        "dmarc_determinate": 97,
        "dmarc_indeterminate": 3,
        "dmarc_valid": 96,
        "dmarc_not_observed": 1
      }
    }
  },
  "key_points": [
    "Presence stopped being the useful endpoint: SPF was never determinate-and-not-observed in the selected window, while DMARC not-observed remained exactly one on every date.",
    "The main longitudinal finding was persistence rather than trend. SPF derivation and DMARC policy distributions repeatedly returned to the same aggregate posture.",
    "On 14 August and 1 September, lower DMARC valid counts tracked higher indeterminate evidence while not-observed remained unchanged, showing that a changing aggregate can reflect changing evidence quality rather than observed absence."
  ],
  "narrative_sections": [
    {
      "title": "Presence stopped being the interesting question",
      "paragraphs": [
        "The original hypothesis was straightforward: richer mail observation might reveal where SPF or DMARC was simply missing. The 25-day series did not support that as the main panel-level story.",
        "SPF not-observed was zero among determinate evidence on every date. DMARC not-observed remained exactly one. Once presence was broad and persistent, the more useful distinctions sat inside derived SPF posture, visible DMARC policy and the quality of the evidence supporting each observation.",
        "That changed the analytical question from whether a control exists to what public posture the evidence can defensibly describe."
      ],
      "blocks": []
    },
    {
      "title": "The same checkbox contains materially different posture",
      "paragraphs": [
        "Across 24 of 25 dates, Mail Posture v1 classified 14 panel domains as SPF malformed under its bounded derivation and 84 or fewer as a single SPF record depending on evidence determinacy. Multiple SPF and determinate not-observed remained zero throughout the window.",
        "DMARC showed a similarly persistent internal distribution. A valid record was derived for 97 domains on 23 of 25 dates. Visible policy was normally 16 none, 13 quarantine and 68 reject; quarantine was 13 on every date and reject was 68 on 24 of 25 dates.",
        "Those values are descriptive. They do not convert public DNS evidence into a security score, compliance finding or assessment of organisational maturity."
      ],
      "blocks": []
    },
    {
      "title": "Repeated observation found persistence rather than trend",
      "paragraphs": [
        "The series does not show a directional improvement or deterioration. Its strongest longitudinal finding is that aggregate mail posture was highly persistent, with small transient deviations that repeatedly returned to the dominant distribution.",
        "Persistence is useful evidence when it is read carefully. It can prompt a stewardship question - is the visible posture the posture the responsible owner intends? - without implying that aggregate stability proves individual-domain stability or that no operational activity occurred behind the public surface.",
        "The discipline is to let a quiet series remain quiet rather than manufacture a trend because a longitudinal analysis is expected to find one."
      ],
      "blocks": []
    },
    {
      "title": "Knowing less can be the more accurate answer",
      "paragraphs": [
        "The clearest example appears on 14 August. DMARC moved from its usual 98 determinate, 2 indeterminate and 97 valid observations to 96 determinate, 4 indeterminate and 95 valid. Not-observed remained one; malformed and multiple remained zero.",
        "A smaller version appeared on 1 September: 97 determinate, 3 indeterminate and 96 valid, again with one not-observed. The following day returned to the dominant 98 determinate, 2 indeterminate and 97 valid distribution.",
        "The defensible conclusion is not that two organisations removed DMARC. It is that the evidence available to describe the panel became less determinate on those dates. A changing aggregate does not necessarily mean the underlying posture changed."
      ],
      "blocks": []
    },
    {
      "title": "What responsible observability requires",
      "paragraphs": [
        "Mail Posture began because presence-only SPF and DMARC observation was not telling enough, but the answer was deliberately not to build another security scanner. Public domain-level findings and scoring remained out of scope.",
        "The more consequential design decision was to improve evidence quality before adding interpretation. That meant treating indeterminate as a first-class result rather than collapsing uncertainty into absence, preserving the private/public boundary, and limiting the derivation vocabulary to claims the observable evidence could support.",
        "The result is intentionally less dramatic than a rating layer. It is also more useful for governance: evidence can challenge the starting hypothesis, uncertainty remains visible, and the system can stop at the point where further technical checks would become a different product."
      ],
      "blocks": []
    },
    {
      "title": "Sources and limitations",
      "paragraphs": [
        "This analysis uses panel-level aggregate diagnostics from 25 consecutive dated Mail Posture v1 completion manifests covering 9 August through 2 September 2026. All 25 source manifests passed the publication identity gate: Mail Posture v1 artefact and contract identity, private flag, run-date/date-key agreement, exact dated rows-key identity, 100 artefact rows, reconciliation controls and zero invalid posture rows. Canonical panel membership remained unchanged across the selected window.",
        "Domain-level private shadow rows are not required for the panel-level findings and are not published here.",
        "The fixed 100-domain panel is not representative of the whole .au namespace. Aggregate persistence does not prove that the same individual domains were unchanged. Public DNS evidence cannot establish private controls, intent, delivery effectiveness, compliance, maturity or assurance."
      ],
      "blocks": []
    }
  ],
  "callouts": [
    {
      "type": "interpretation-note",
      "title": "A changing aggregate can mean the evidence changed",
      "text": "On 14 August and 1 September, DMARC valid counts fell as indeterminate evidence increased while not-observed stayed fixed. The evidence supports an uncertainty finding, not a claim that DMARC was removed."
    },
    {
      "type": "governance-note",
      "title": "The boundary is part of the method",
      "text": "The analysis deliberately stops short of public domain-level findings and scoring. The observatory question is what the public evidence can support, not how many conclusions can be generated from it."
    }
  ],
  "source": {
    "panel_size": 100,
    "analysis_window": {
      "start": "2026-08-09",
      "end": "2026-09-02",
      "days": 25
    },
    "private_manifest_contract": "analysis/mail-posture/v1/year=YYYY/month=MM/day=DD/manifest.json",
    "mail_posture_contract_version": "mail-posture/v1",
    "shadow_artefact_version": "mail-posture-shadow/v1",
    "panel_source": "data/domains/audo_domains_master.csv",
    "panel_source_blob_sha": "b6311b51925deff0d5e4c04c7e54f888e22c7896",
    "publication_identity_validation": {
      "status": "passed",
      "validated_at": "2026-09-02T20:32:00+10:00",
      "passed_units": 25,
      "failed_units": 0
    },
    "note": "The analysis compares daily panel aggregates only. It does not infer domain identity, causation or organisational intent from aggregate movement."
  },
  "seo": {
    "title": "Presence is not posture: Mail Posture observation | .auDO",
    "description": "Featured .auDO analysis of 25 days of Mail Posture observation, showing persistent SPF/DMARC posture and why evidence quality matters."
  }
}
