Registration and RDAP
Public registration evidence together with the RDAP source context used to obtain it.
- RDAP source context Evidence context
- Registrar Observed evidence
- RDAP status Observed evidence
- RDAP redaction Observed evidence
Signals is the reference library for the public records, fields, derived posture and evidence context .auDO preserves and interprets over time.
Use these pages to understand what the evidence means. Current panel findings remain authoritative in State of .au, Cohorts and dated Reports.
Signal library
Browse by domain-layer family. Labels distinguish direct public evidence, conservative derived posture and best-effort provider inference.
Public registration evidence together with the RDAP source context used to obtain it.
Direct public DNS records describing delegation, resolution destinations and general-purpose text evidence.
Mail-routing evidence and derived authentication posture visible through public DNS.
A combined DNSSEC posture reference supported by direct DNSKEY evidence and a source-specific RDAP assertion.
Best-effort classifications derived from visible name-server and mail-routing patterns.
Supporting reference
These pages explain source lineage, point-in-time metadata, preserved source material and fallback handling. They support trust in the evidence but are not peer domain-posture signals.
How an observation is dated, traced to source material and preserved for later inspection.
How alternate public sources are used and disclosed when the preferred collection path is unavailable or incomplete.
Change-event classification
Tiers classify observed change events. They are separate from the evidence-type labels used to organise this reference library.
Signal tiers are not risk scores. They help readers understand the kind of visible change preserved by .auDO.
Tier 1
Changes that may affect visible domain control, mail posture, DNSSEC posture or registration status.
Tier 2
Visible infrastructure or provider movement that may reflect migration, consolidation or normal operational evolution.
Tier 3
Common, expected or low-confidence changes that are not meaningful without additional context.
Unclassified
Observed event types preserved for future analysis but not yet explicitly classified.
Interpretation limits
Public domain-layer observations describe visible evidence. They do not establish motive, impact, compliance, organisational quality or private operational state.
A public signal does not reveal every internal control, process or decision.
A visible change may be administrative, defensive, accidental, routine or temporary.
Provider labels describe best-effort visible patterns and do not prove a direct customer relationship or service quality.
Technical reference
Technical field names support traceability after the plain-language meaning of each signal is established.
registrar_name, registrar_handle, rdap_status, rdap_source, rdap_fallback_reason, rdap_redacted, nameservers, a_records, aaaa_records, mx_records, txt_records, dnssec_enabled, dnssec_enabled_rdap, dnskey_present, spf_present, dmarc_present, dns_provider, email_provider, rdap_raw, dns_raw, captured_at and run_id.
Use alongside
Use State for current aggregate posture, Reports for dated evidence, Explainers for deeper concepts and Methodology for collection and interpretation rules.