Featured analysis
Presence is not posture
What 25 days of repeated mail observation made visible.
I expected missing DMARC to be the interesting story. It was not. Once presence became almost universal across determinate evidence, the harder question was what posture the evidence actually described - and how confidently the observatory could describe it.
- Published
- 2 September 2026
- Observation window
- 9 August - 2 September · 25 days
- Panel
- Fixed 100-domain panel
Featured analysis content
The observation window
The strongest finding was persistence - and the boundary of what could be known
p=reject on 24 of 25 dates- Presence stopped being the useful endpoint. The more informative variation sat inside SPF derivation, DMARC policy and evidence state.
- The aggregate series was highly persistent rather than directionally trending. A quiet series is still evidence.
- On 14 August and 1 September, lower DMARC valid counts followed higher
indeterminateevidence whilenot_observedstayed fixed.
I expected absence to be the story
Mail Posture started from a simple problem: presence-only SPF and DMARC observation was not telling enough. A control could be visible without saying much about the posture it expressed. At the same time, I did not want .auDO to become another security scanner.
My working expectation was that richer observation would make absence more interesting. The evidence changed that view. Across all 25 dates, SPF was never determinate-and-not-observed. DMARC not-observed remained exactly one.
Once presence was broad and persistent, the better question was no longer “is it there?” It was “what posture does the public evidence describe?”
That distinction matters because the next layer is not a score. It is a bounded description of visible public posture, with uncertainty preserved where the evidence cannot support a stronger answer.
The same checkbox contained materially different posture
SPF illustrates the point. On 24 of 25 dates, the bounded Mail Posture v1 derivation classified 14 panel domains as malformed. Multiple-SPF and determinate not-observed counts remained zero throughout the window. Depending on evidence determinacy, 82 to 84 domains were classified as a single SPF record.
That malformed label is intentionally narrow. It means the observed record did not satisfy the bounded v1 derivation. It does not mean 14 organisations have “broken email security”, and it is not a maturity or compliance judgement.
DMARC was even more persistent. A valid record was derived for 97 domains on 23 of 25 dates. The dominant policy distribution was 16 none, 13 quarantine and 68 reject. Quarantine stayed at 13 on every date; reject stayed at 68 on 24 of 25.
Repeated observation found persistence rather than trend
The 25-day series does not show a directional improvement or deterioration. Its strongest longitudinal result is persistence, punctuated by small deviations that return quickly to the dominant aggregate distribution.
That can feel less exciting than a trend line, but it is more useful than manufacturing movement where the evidence does not support it. A persistent public posture can prompt a governance question: is what is visible what the responsible owner intends?
It cannot answer that question on the organisation's behalf. Nor does an aggregate series prove that the same individual domains were unchanged. The fixed panel remained stable across the window, but this analysis deliberately stays at panel level.
Knowing less can be the more accurate answer
The clearest example appears on 14 August. DMARC moved from the dominant 98 determinate, 2 indeterminate and 97 valid observations to 96 determinate, 4 indeterminate and 95 valid. Not-observed stayed at one. Malformed and multiple stayed at zero.
A smaller version appeared on 1 September: 97 determinate, 3 indeterminate and 96 valid, again with one not-observed. On 2 September the aggregate returned to 98 determinate, 2 indeterminate and 97 valid.
A changing aggregate does not necessarily mean the underlying posture changed. Sometimes what changed is the quality of the evidence available to describe it.
This is why indeterminate had to become a first-class result. Collapsing it into “absent” would have created a cleaner-looking dataset and a less accurate observatory.
The consequential decision was to fix evidence before interpretation
The technical temptation was to keep adding checks: recurse through SPF, enumerate more mail controls, expose domain-level findings, produce a score. I deliberately kept those things outside the v1 boundary.
The more important lesson was that richer interpretation could not compensate for ambiguous evidence. Evidence quality had to be improved first. That meant distinguishing observed absence from an indeterminate result, retaining provenance, preserving the private/public boundary and accepting that the right answer would sometimes be “the evidence cannot determine this today”.
The resulting boundary is deliberate: ask a better question, fix the foundation, let the evidence challenge the starting hypothesis, preserve uncertainty and stop before useful observation turns into a different product.
- What can the observable evidence actually support?
- Where is uncertainty being hidden for the sake of a cleaner answer?
- Is the visible posture what the responsible owner expects?
- Are we adding interpretation because it is useful, or because the system can produce it?
- Where should the product deliberately stop?
Why repeated observation matters in practice
A separate operational example shared during review reinforced the point. Intermittent SPF lookup failures were visible before a nameserver cutover and stopped afterwards. A point-in-time check taken on either side could easily have missed the pattern.
That example is not evidence for the 100-domain panel and it is intentionally anonymised here. It illustrates the method: repeated observation can make persistence, intermittent behaviour and recovery visible in ways a single lookup cannot.
Continue into the evidence
Read the posture, method and preceding analysis
The article is the interpretation layer. The public State surface and report records retain the current posture and the wider evidence context.
Scope and limitations
This analysis uses panel-level aggregate diagnostics from 25 consecutive dated Mail Posture v1 completion manifests covering 9 August through 2 September 2026. All 25 source manifests passed the publication identity gate, including Mail Posture v1 artefact and contract identity, private flag, run-date/date-key agreement, exact dated rows-key identity, 100 artefact rows, reconciliation controls and zero invalid posture rows. Canonical panel membership remained unchanged across the selected window.
Domain-level private shadow rows are not required for these panel-level findings and are not published here.
The fixed panel is not representative of the whole .au namespace. Public DNS evidence cannot establish private controls, organisational intent, delivery effectiveness, compliance, maturity or assurance. This analysis does not score, rank or publish domain-level findings.