Project overview
For a shorter overview of the observatory, download the .auDO introduction brief. It summarises the project’s purpose, scope and evidence-first reporting posture.
An independent public-interest observatory capturing how visible domain-layer signals change across a fixed set of .au domains over time.
How .auDO preserves public evidence before interpretation and keeps every claim close to its panel, time window, signal definition and limitations.
.auDO independently observes and explains public domain-layer trust signals across the .au ecosystem, preserving evidence over time to support transparency, resilience and better governance.
The method prioritises disciplined collection, stable evidence and bounded public claims. Stronger interpretation is used only where repeated observations, defined windows and supporting evidence justify it.
Operating principles
Preserve observed state and change evidence before applying interpretation.
Expand panel, signal or product scope only where it improves quality, relevance or resilience.
Reliable collection, evidence preservation and dependable reporting take priority over new interfaces or features.
No support arrangement may require weaker methodology, favourable interpretation, suppressed evidence or sponsor approval.
The method is deliberately simple: observe the same panel repeatedly, preserve state before interpretation, compare changes, classify observations, and publish stable reports.
Public DNS, RDAP, mail, registrar and infrastructure state is retained as evidence before report language is applied.
A single lookup can show a moment. Repeated collection gives changes and persistence enough context to be interpreted cautiously.
Publishing model
.auDO separates collection evidence, derived summaries, periodic reporting, longitudinal analysis and explanatory material so readers can move from evidence to context without confusing observations for conclusions.
The five flagship outputs are the Continuous Evidence Archive, State of .au, Monthly Observatory Brief, Quarterly Trust Signals Review and selected featured analysis, and Public Method and Guidance. The surfaces below provide access to and context for those outputs.
Derived public summaries of current posture across DNSSEC, DMARC, registrar, provider and RDAP signal areas.
Dated report artefacts that preserve observed change and support later review.
Canonical definitions for observed fields and human-readable signal tiers.
Curated and sometimes overlapping analytical lenses used to examine aggregate posture and observed change.
Plain-language context for readers who need to understand why a signal matters.
A public operational view of panel composition, signal mix and longitudinal context.
Data governance
.auDO keeps observation evidence, derived summaries, cohort context and external registry reference data separate. The namespace-panel context JSON is the reusable bridge used by public surfaces.
Shared namespace context is loaded when available. Static methodology notes remain valid without it.
| Data category | Role | Interpretation limit |
|---|---|---|
| .auDO observation data | Public DNS, RDAP, mail, DNSSEC, registrar and provider signals collected from the fixed panel over time. | Observation evidence for the panel only. It is not private system evidence or whole-namespace monitoring. |
| Derived State data | Generated summaries used by State pages to describe current visible posture across signal families. | Panel summaries, not registry-wide measurements, scores or assessments. |
| Cohort data | Curated and sometimes overlapping lenses applied to domains already included in the fixed panel. | Cohorts are not exhaustive classifications, organisation comparisons or whole-sector assessments. |
| External auDA registry reference data | Monthly registry statistics used to show wider .au namespace scale and suffix context. | External reference context only. It is not .auDO observation evidence. |
| Namespace-panel context data | Derived JSON that combines panel composition with the latest available auDA registry context for public rendering. | A presentation context layer. It avoids each page independently joining raw reference and panel data. |
Namespace-panel limitations load from the shared context JSON when available.
.auDO is an independent public-interest observatory for the .au domain ecosystem. It observes a fixed panel repeatedly and preserves public evidence of visible DNS, registration, mail and infrastructure change over time.
.auDO began as an R&D observatory in February 2026. The current retained reporting baseline begins on 26 March 2026.
It is not full-coverage or real-time whole-namespace monitoring, a registry authority, vulnerability scanner, incident detector, compliance certifier, rating system or organisational risk assessment.
The operating model remains deliberately lean: enough structure to collect, preserve, explain and publish dependable public evidence without overstating what the panel can represent.
Signal model
.auDO observes public DNS, RDAP, mail posture, DNSSEC, provider inference and provenance signals. These are visible technical signals, not private security findings.
Registrar, RDAP status, domain dates, redaction indicators and related registration metadata where visible.
Name servers, address records, MX records, TXT records, SPF and DMARC presence.
Visible DNSSEC evidence including DNSSEC state, DNSKEY presence and RDAP-derived DNSSEC indicators.
Visible DNS and email provider patterns inferred from public configuration.
Snapshot metadata, raw evidence, source fallback and collection context used to preserve traceability.
Hosting provider and ASN context may appear in specific report artefacts where evidence exists, but they are not currently first-class snapshot signal families.
Read the Signals library for canonical definitions and interpretation limits.
| Area | Current approach |
|---|---|
| Observation scope | A fixed panel of 100 .au domains selected for sector mix, operational relevance, and signal diversity rather than full namespace coverage. |
| Collection cadence | Scheduled recurring collection designed to support repeatable longitudinal observation rather than one-off lookup results. |
| State capture | Public state is captured as snapshots so observed posture can be preserved directly before interpretation is applied. |
| Change detection | Meaningful differences are derived across runs, allowing nameserver, registrar, DNSSEC, mail and related trust-layer changes to be reviewed over time. |
| Report artifacts | Reports are generated from stable exported artifacts so analysis remains inspectable, repeatable, and separate from live collection. |
| Publication model | A lightweight static site publishes method context, daily reports, charts and panel state without pretending to be a real-time monitoring console. |
Operating model
.auDO is owned and editorially controlled by Bryan Chetcuti and runs on a deliberately lean infrastructure model.
External funders, clients, partners, service providers and observed organisations do not approve .auDO methods, findings, language, publication timing or corrections.
The Vigo Group currently provides operational services and bears project costs. Paid advisory work undertaken by Bryan Chetcuti or The Vigo Group is separate and does not purchase influence over .auDO observation or publication.
| Provider | .auDO use | Operating boundary |
|---|---|---|
| Supabase | .auDO uses Supabase as part of its data storage and analysis environment for retained observation data and derived reporting workflows. | Supabase does not supply, review, approve or endorse .auDO observations, classifications or reports. |
| GitHub | .auDO uses GitHub for source control, workflow automation, scheduled processing and management of generated artefacts. | GitHub does not supply, review, approve or endorse .auDO observations, classifications or reports. |
| Cloudflare | .auDO uses Cloudflare for public site delivery, report and asset delivery, and related storage and edge infrastructure. | Cloudflare does not supply, review, approve or endorse .auDO observations, classifications or reports. |
Classification
Signal tiers are interpretive metadata used to describe different kinds of observed change. The canonical human-readable definitions live in the Signals library.
High-signal trust posture change.
Meaningful infrastructure movement.
Routine or low-confidence churn.
Retained evidence not yet explicitly mapped.
Interpretation should be supported by repeated evidence, persistence, volume thresholds or clear context. Single observations are reported without over-claiming.
Counts summarise retained observations. They are not risk scores, ratings, compliance findings or statements about organisational fault.
.auDO observes public technical state. It does not inspect private systems or infer internal intent from public changes alone.
Observed changes are not evidence of compromise, breach, incident or non-compliance unless separate evidence explicitly supports that conclusion.
Use the Observation Guide for a practical walkthrough of how to move from public signal to cautious interpretation.
The observatory is active and can surface useful patterns in visible posture and repeated change, while its public claims remain bounded to the fixed panel and retained evidence.
The continuing priority is collection quality, classification clarity, durable evidence, transparent limitations and interpretation proportionate to the available history.
.auDO records and explains public domain-layer evidence. It does not assess an organisation’s internal governance.
The Domain Governance Baseline is a separate practical self-assessment published by Bryan Chetcuti for organisations that want to review domain ownership, accountability and operating practices
Open the Domain Governance Baseline