Methodology

An independent public-interest observatory capturing how visible domain-layer signals change across a fixed set of .au domains over time.

How .auDO preserves public evidence before interpretation and keeps every claim close to its panel, time window, signal definition and limitations.

Fixed panel Repeated collection Snapshot preservation Cautious interpretation

Purpose

.auDO independently observes and explains public domain-layer trust signals across the .au ecosystem, preserving evidence over time to support transparency, resilience and better governance.

The method prioritises disciplined collection, stable evidence and bounded public claims. Stronger interpretation is used only where repeated observations, defined windows and supporting evidence justify it.

Project overview

For a shorter overview of the observatory, download the .auDO introduction brief. It summarises the project’s purpose, scope and evidence-first reporting posture.

Operating principles

Evidence before narrative, method before scale

Evidence before narrative

Preserve observed state and change evidence before applying interpretation.

Method before scale

Expand panel, signal or product scope only where it improves quality, relevance or resilience.

Continuity before novelty

Reliable collection, evidence preservation and dependable reporting take priority over new interfaces or features.

Independence before funding

No support arrangement may require weaker methodology, favourable interpretation, suppressed evidence or sponsor approval.

Observation model

The method is deliberately simple: observe the same panel repeatedly, preserve state before interpretation, compare changes, classify observations, and publish stable reports.

Select panel Collect public signals Preserve snapshots Compare changes Classify observations Publish reports

State before interpretation

Public DNS, RDAP, mail, registrar and infrastructure state is retained as evidence before report language is applied.

Repeated evidence over single lookups

A single lookup can show a moment. Repeated collection gives changes and persistence enough context to be interpreted cautiously.

Publishing model

Flagship public outputs and supporting surfaces

.auDO separates collection evidence, derived summaries, periodic reporting, longitudinal analysis and explanatory material so readers can move from evidence to context without confusing observations for conclusions.

The five flagship outputs are the Continuous Evidence Archive, State of .au, Monthly Observatory Brief, Quarterly Trust Signals Review and selected featured analysis, and Public Method and Guidance. The surfaces below provide access to and context for those outputs.

State pages

Derived public summaries of current posture across DNSSEC, DMARC, registrar, provider and RDAP signal areas.

Reports

Dated report artefacts that preserve observed change and support later review.

Signals

Canonical definitions for observed fields and human-readable signal tiers.

Cohorts

Curated and sometimes overlapping analytical lenses used to examine aggregate posture and observed change.

Explainers

Plain-language context for readers who need to understand why a signal matters.

Observation Panel

A public operational view of panel composition, signal mix and longitudinal context.

Data governance

Data categories and context artefacts

.auDO keeps observation evidence, derived summaries, cohort context and external registry reference data separate. The namespace-panel context JSON is the reusable bridge used by public surfaces.

Shared namespace context is loaded when available. Static methodology notes remain valid without it.

Data categoryRoleInterpretation limit
.auDO observation dataPublic DNS, RDAP, mail, DNSSEC, registrar and provider signals collected from the fixed panel over time.Observation evidence for the panel only. It is not private system evidence or whole-namespace monitoring.
Derived State dataGenerated summaries used by State pages to describe current visible posture across signal families.Panel summaries, not registry-wide measurements, scores or assessments.
Cohort data Curated and sometimes overlapping lenses applied to domains already included in the fixed panel. Cohorts are not exhaustive classifications, organisation comparisons or whole-sector assessments.
External auDA registry reference dataMonthly registry statistics used to show wider .au namespace scale and suffix context.External reference context only. It is not .auDO observation evidence.
Namespace-panel context dataDerived JSON that combines panel composition with the latest available auDA registry context for public rendering.A presentation context layer. It avoids each page independently joining raw reference and panel data.
-fixed panel domains
-external namespace scale
-registry reference month
-context generated

Namespace-panel limitations load from the shared context JSON when available.

Current scope

.auDO is an independent public-interest observatory for the .au domain ecosystem. It observes a fixed panel repeatedly and preserves public evidence of visible DNS, registration, mail and infrastructure change over time.

Provenance

.auDO began as an R&D observatory in February 2026. The current retained reporting baseline begins on 26 March 2026.

Boundaries

It is not full-coverage or real-time whole-namespace monitoring, a registry authority, vulnerability scanner, incident detector, compliance certifier, rating system or organisational risk assessment.

The operating model remains deliberately lean: enough structure to collect, preserve, explain and publish dependable public evidence without overstating what the panel can represent.

Signal model

Signals collected

.auDO observes public DNS, RDAP, mail posture, DNSSEC, provider inference and provenance signals. These are visible technical signals, not private security findings.

Registration and RDAP

Registrar, RDAP status, domain dates, redaction indicators and related registration metadata where visible.

DNS and mail posture

Name servers, address records, MX records, TXT records, SPF and DMARC presence.

DNSSEC

Visible DNSSEC evidence including DNSSEC state, DNSKEY presence and RDAP-derived DNSSEC indicators.

Provider inference

Visible DNS and email provider patterns inferred from public configuration.

Provenance

Snapshot metadata, raw evidence, source fallback and collection context used to preserve traceability.

Not first-class signals

Hosting provider and ASN context may appear in specific report artefacts where evidence exists, but they are not currently first-class snapshot signal families.

Read the Signals library for canonical definitions and interpretation limits.

Data collection and preservation

AreaCurrent approach
Observation scopeA fixed panel of 100 .au domains selected for sector mix, operational relevance, and signal diversity rather than full namespace coverage.
Collection cadenceScheduled recurring collection designed to support repeatable longitudinal observation rather than one-off lookup results.
State capturePublic state is captured as snapshots so observed posture can be preserved directly before interpretation is applied.
Change detectionMeaningful differences are derived across runs, allowing nameserver, registrar, DNSSEC, mail and related trust-layer changes to be reviewed over time.
Report artifactsReports are generated from stable exported artifacts so analysis remains inspectable, repeatable, and separate from live collection.
Publication modelA lightweight static site publishes method context, daily reports, charts and panel state without pretending to be a real-time monitoring console.

Operating model

Operating infrastructure and independence

.auDO is owned and editorially controlled by Bryan Chetcuti and runs on a deliberately lean infrastructure model.

Editorial independence

External funders, clients, partners, service providers and observed organisations do not approve .auDO methods, findings, language, publication timing or corrections.

Operational support and advisory separation

The Vigo Group currently provides operational services and bears project costs. Paid advisory work undertaken by Bryan Chetcuti or The Vigo Group is separate and does not purchase influence over .auDO observation or publication.

Provider .auDO use Operating boundary
Supabase .auDO uses Supabase as part of its data storage and analysis environment for retained observation data and derived reporting workflows. Supabase does not supply, review, approve or endorse .auDO observations, classifications or reports.
GitHub .auDO uses GitHub for source control, workflow automation, scheduled processing and management of generated artefacts. GitHub does not supply, review, approve or endorse .auDO observations, classifications or reports.
Cloudflare .auDO uses Cloudflare for public site delivery, report and asset delivery, and related storage and edge infrastructure. Cloudflare does not supply, review, approve or endorse .auDO observations, classifications or reports.

Classification

Signal tiers

Signal tiers are interpretive metadata used to describe different kinds of observed change. The canonical human-readable definitions live in the Signals library.

Tier 1

High-signal trust posture change.

Tier 2

Meaningful infrastructure movement.

Tier 3

Routine or low-confidence churn.

Unclassified

Retained evidence not yet explicitly mapped.

Read the canonical signal tier definitions.

Interpretation principles

Cautious by default

Interpretation should be supported by repeated evidence, persistence, volume thresholds or clear context. Single observations are reported without over-claiming.

Evidence summaries, not scores

Counts summarise retained observations. They are not risk scores, ratings, compliance findings or statements about organisational fault.

Public-data-first

.auDO observes public technical state. It does not inspect private systems or infer internal intent from public changes alone.

No compromise claims

Observed changes are not evidence of compromise, breach, incident or non-compliance unless separate evidence explicitly supports that conclusion.

Observation Guide

Use the Observation Guide for a practical walkthrough of how to move from public signal to cautious interpretation.

Limits and maturity

The observatory is active and can surface useful patterns in visible posture and repeated change, while its public claims remain bounded to the fixed panel and retained evidence.

The continuing priority is collection quality, classification clarity, durable evidence, transparent limitations and interpretation proportionate to the available history.

Young but operating Not full namespace coverage Not real-time monitoring Not a vulnerability scanner

.auDO records and explains public domain-layer evidence. It does not assess an organisation’s internal governance. The Domain Governance Baseline is a separate practical self-assessment published by Bryan Chetcuti for organisations that want to review domain ownership, accountability and operating practices
Open the Domain Governance Baseline