Featured analysis

Observed posture, repeated change: what State and Cohort lenses reveal

Across the fixed 100-domain panel, common mail and registration signals were broadly visible on 15 July. The more useful finding sat in the observation window: material movement was concentrated in a small number of mail-authentication changes, while DNSSEC and registrar posture remained quiet.

Published
15 July 2026
Observation window
30 days
Panel
Fixed 100-domain panel

Featured analysis content

The observation window

The movement was concentrated, not widespread

12 material SPF or DMARC presence observations
4 panel domains affected during the 30-day window
3 domains appearing repeatedly in those observations
0 material DNSSEC or registrar movements retained
  • Common mail and registration signals were broadly visible in the current snapshot, while DNSSEC visibility remained materially narrower.
  • Repeated observation separated a small concentration of mail-authentication movement from quiet DNSSEC and registrar windows.
  • Cohort context adds another reading layer: 96 memberships cover 77 unique domains, with 19 domains intentionally appearing in more than one lens.

What was visible

On 15 July 2026, RDAP and registrar information were visible for all 100 panel domains. SPF was present for 98 domains, DMARC for 97, and public MX records for 94.

DNSSEC evidence was much narrower. Fifteen domains had visible DNSSEC evidence: 13 had secure delegation asserted, eight had a DNSKEY directly observed, and six showed both signals.

Mail posture 98 SPF · 97 DMARC · 94 public MX
DNSSEC visibility 15 visible · 13 asserted · 8 DNSKEY · 6 both
Registration context 100 RDAP-visible · 12 registrars · largest share 36%

These are public observations, not grades. Presence does not establish policy strength, operational maturity, compliance or end-to-end security.

What moved — and what did not

A current lookup can show that a signal is present. It cannot show whether that signal has been stable, newly published, removed and restored, or repeatedly changing.

Across the 30-day mail-authentication window ending 15 July, the State model retained 12 material SPF and DMARC presence observations affecting four domains. Three of those domains appeared repeatedly. During the corresponding State windows, no material DNSSEC or registrar posture movement was retained.

The useful distinction is not “changed” versus “unchanged”. It is whether movement was isolated, repeated or absent within a defined observation window.

A quiet window is evidence of observed stability within the available data. It is not proof that no operational activity occurred behind the public surface.

What cohort context adds

State views organise the full panel by signal. They answer questions such as where DNSSEC, DMARC, registrar or provider posture is visible and where it has changed.

Cohort views organise selected domains by analytical context. The eight published lenses contain 96 memberships across 77 unique domains. Nineteen domains appear in more than one lens, deliberately: a domain may be relevant to more than one public-service, industry or public-interest question.

State lens Where is a public signal visible, concentrated or changing across the fixed panel?
Cohort lens What context becomes visible when selected domains are read together?

Neither lens is a ranking. State counts are not grades, and differences between curated cohorts are not whole-sector assessments.

Why this matters for governance

The practical value is not in declaring a posture good or bad. It is in making better stewardship questions easier to ask and easier to anchor in dated evidence.

  • Is the visible public posture what the responsible owner expects?
  • Has the signal changed once, or has it moved repeatedly?
  • Is a visible registrar or provider dependency understood?
  • Does cohort context reveal concentration or movement that deserves review?
  • Can the observation be traced back to a dated public record?

Those questions connect public evidence to ownership and accountability without pretending that public evidence is the whole operational picture.

Continue into the evidence

Explore the State and Cohort views

The report is the curated interpretation. The underlying pages retain the current counts, observation windows and dated evidence needed to examine the findings further.

Scope and limitations

This analysis uses State and Cohort outputs generated from the canonical observatory dataset on 15 July 2026. The panel contains 100 selected .au domains and is not a representative sample of the whole namespace. Cohorts are curated and may overlap.

Public DNS and registration evidence cannot show private controls, contracts, intent, service quality or organisational maturity. This report records visible posture and observed change; it does not provide scores, rankings, compliance findings, incident findings or assurance.