Domain-name inventory
Which domain names does the organisation hold, and why? Forgotten campaign, legacy or defensive domains still carry risk if they are not governed.
Plain-English explainer
Domain governance is how an organisation makes sure its domain names, DNS, email authority and public trust signals are owned, controlled, reviewed and explainable.
It is not just a technical housekeeping task. It is a governance question about identity, accountability, service continuity and public trust.
Domain governance is the discipline of knowing which domain names an organisation holds, why they exist, who is accountable for them, who can change them, and what happens if something fails.
It also includes the surrounding domain layer: DNS, registrar access, renewal processes, email authentication, supplier dependencies, certificates and the public signals that others can inspect from outside the organisation.
Put simply: your domain layer is already being read from the outside. Domain governance is how you govern it from the inside.
A domain name is often treated as a small administrative asset. In practice, it can carry an organisation’s website, email, identity, service access, fundraising, customer communication, public campaigns and reputation.
If a domain expires, email authentication is weak, registrar access is uncontrolled, or DNS changes are made without review, the impact can move quickly from a technical issue to a public trust issue.
That is why domain governance matters: it turns a hidden technical dependency into something leaders can see, discuss and own.
Which domain names does the organisation hold, and why? Forgotten campaign, legacy or defensive domains still carry risk if they are not governed.
Who is the accountable business owner for each domain name? Technical administration is not the same as governance accountability.
Who can change registration settings, transfer a domain, update nameservers or receive renewal notices? Registrar access is authority over public identity.
DNS controls where websites, mail, APIs and other services point. A single record change can affect many systems.
Domains and subdomains can authorise email sending. SPF, DKIM and DMARC help show whether email authority is deliberate and reviewed.
Some domain-layer signals are visible from outside the organisation through DNS, RDAP, email authentication and certificate transparency. They do not tell the whole story, but they shape how others read the organisation.
Domain management is usually about administration: registering names, renewing them, updating records and operating DNS.
Domain governance asks a broader question: are those names, controls and signals owned, reviewed, explainable and connected to organisational risk?
A domain can be technically working and still poorly governed. It may renew correctly, resolve correctly and send email, while nobody can explain who owns it, why it exists, which suppliers depend on it, or what the incident path is if it fails.
Not everything about domain governance is public. Internal ownership, access control, approval paths and accountability usually cannot be seen from outside.
But some signals are visible. Outsiders can often inspect authoritative DNS, nameservers, mail records, DMARC policy, certificate issuance and registration-related metadata.
These signals should not be over-interpreted. A missing signal does not prove irresponsibility, and a passing signal does not prove good governance. But visible signals are useful prompts for better questions.
Domain governance is relevant to technology, cybersecurity, risk, legal, communications, service delivery and executive leadership.
The reason is simple: domain names sit at the boundary between internal control and public trust. When they fail, the consequences are rarely contained inside the technical team.
Start with the ten-question Baseline. It identifies where ownership, evidence, authority or incident readiness is unclear without producing a score.
If you want to see what happens next, the worked walkthrough follows one fictional Australian not-for-profit from uncertain answers through evidence, governance interpretation, accountable decisions, organisational records and recurring review.
Then use the five practical guides to establish the missing practice through the systems, records and governance forums the organisation already operates.
Use the Domain Governance Baseline Open the practical guides
Other parts of this work make domain governance and digital trust easier to inspect and explain.
Governance instrument
A versioned baseline and practical guides for reviewing domain ownership, renewal, DNS, email authority, monitoring and accountability.
Independent observation
Independent, longitudinal observation of visible domain, DNS, registration and email trust signals across a curated .au panel.
Practical inspection
A practical inspection tool for surfacing the visible domain trust signals an organisation already exposes online.
Conceptual model
A model for understanding where digital trust is created, exposed, weakened and governed across systems and dependencies.