What .auDO observes
Direct DNSKEY visibility
.auDO records whether DNSKEY material is visible at collection time. This is supporting direct evidence used within the combined DNSSEC posture view.
Technical fields
Why it is observed
DNSKEY is one visible part of DNSSEC posture
Why it matters
DNSKEY visibility can indicate published DNSSEC key material and supports comparison with registration-side DNSSEC assertions.
What visible change may mean
A change may reflect rollout, key rotation, provider migration, delegation movement, collection timing or maintenance.
Interpretation limits
DNSKEY presence is not the complete chain
DNSKEY visibility alone does not establish a valid DS relationship, successful resolver validation or complete operational quality.
Common retained observations
DNSKEY and assertion-gap movement
Where to use this evidence
Read DNSKEY within combined posture
Related concept
How DNSSEC works
Related signals