From the essay · Domain governance as a trust surface

A lightweight companion to the essay, not another assessment platform.

The ten-question starting-point checklist for domain governance.

This is the checklist from Domain Governance as a Trust Surface, made interactive so you can work through it privately and use the result in an existing governance process.

10 checklist questions Intentionally minimal Private in-browser review Copy or print notes

No account. No retained answers. No external assessment platform. Use it locally, take away the summary, and place priorities and actions into the governance processes your organisation already operates.

See a worked walkthrough About the baseline
Use it in existing governance

Use the checklist at moments where domain governance already matters

Use it to prepare evidence, identify gaps and choose the practical guide that matches the work required. It does not create a new programme or forum.

Before a board, executive or risk update

Identify evidence gaps, accountable owners, decisions and escalation points that belong in the brief.

After a domain, DNS or email incident

Test whether the incident exposed unclear accountability, access, dependencies or recovery paths.

During supplier assurance

Review registrar, DNS, email and digital-service responsibilities before accepting that a supplier has the domain layer covered.

At a recurring domain review

Reconfirm that ownership, renewal, public signals and incident paths still reflect how the organisation operates today.

Starting point · From the essay

The ten-question checklist

These are the ten trust-surface questions from the source essay. They are intentionally basic, not a comprehensive control framework: if the organisation cannot answer one clearly, that is where follow-up starts. Items marked externally observable form part of the public trust surface.

0 of 10 answered
Optional follow-on

Go further only where useful

The ten questions are the complete starting point. These six themes are optional prompts for organisations that want to carry the findings into broader recurring governance. You do not need to answer them to generate a review summary.

0 of 6 considered
Your baseline review

Review summary

Priorities for follow-up

Baseline questions you marked as partial, not in place, or not sure - ordered so the most open questions come first. Each is shown at three levels: board / exec / risk, technical, and public trust / service impact.

Your public trust surface

The externally observable items - the parts of your domain layer anyone can inspect from outside via DNS, RDAP, DMARC or certificate transparency.

Practical next steps

Guide links based on the questions that need follow-up. These are not scores, findings of fault or automated assurance recommendations.

What is already in place

Baseline items you can answer clearly today. Worth protecting - the recurring-review guide is how you keep them true.

Optional follow-on themes

Only the broader themes you chose to consider in this pass.

A missing signal does not mean an organisation is irresponsible, and a passing signal does not mean everything behind it is well managed. Observation is not judgement - but it can strengthen governance decisions, evidence and follow-up. Use this as a starting point to bring the domain layer into broader digital governance.
Move from review to practice. See the worked walkthrough for one fictional organisation's path from uncertainty to evidence, decisions and records, then use the five practical guides to establish and sustain domain visibility, privileged authority, email trust, incident readiness and recurring governance.
About this checklist

A lightweight companion to the source essay

It exists to make the essay's ten starting-point questions easier to use. It is not intended to become another assessment platform, governance system or product workflow.

Source and boundaries

Source
Domain Governance as a Trust Surface
Checklist
Ten starting-point questions reproduced from the essay
Optional guidance
Six follow-on themes for broader domain-governance review
Output
Baseline review summary - not a score, rating or assurance report
Processing
Generated locally in the browser. No answers are sent to a backend.

What it is

A small, self-contained way to work through the checklist from Domain Governance as a Trust Surface. Use it individually or with a team, then move priorities, evidence needs and actions into the governance artefacts and processes you already maintain.

Position

Most organisations do not govern the domain layer until something breaks. The checklist makes the questions visible before that moment.

Boundary

The output is a baseline review summary, not an assurance report, compliance instrument, maturity score or rating.

Relationship

The checklist is the practical companion to the essay; the essay remains the fuller argument and source context.

Why it deliberately stays local

Organisations should be able to review ownership gaps, supplier dependencies and incident readiness without placing those answers into another external assessment system.

No account or retained record

Your answers remain in the browser tab and disappear when the page is closed or reloaded.

Priorities over scoring

The useful output is a set of governance-ready priorities, evidence needs and next actions, not a maturity number or comparative rating.

Use existing governance

Use the practical guidance to establish missing practices, then maintain the resulting records in the organisational systems you already operate.

Public domain-layer observation, including .au Domain Observatory (.auDO) and ThreatScope Check, can provide external evidence. Only the organisation can answer the internal governance questions.