Plain-English explainer

What is domain governance?

Domain governance is how an organisation makes sure its domain names, DNS, email authority and public trust signals are owned, controlled, reviewed and explainable.

It is not just a technical housekeeping task. It is a governance question about identity, accountability, service continuity and public trust.

The short version

Domain governance is the discipline of knowing which domain names an organisation holds, why they exist, who is accountable for them, who can change them, and what happens if something fails.

It also includes the surrounding domain layer: DNS, registrar access, renewal processes, email authentication, supplier dependencies, certificates and the public signals that others can inspect from outside the organisation.

Put simply: your domain layer is already being read from the outside. Domain governance is how you govern it from the inside.

Why domain governance matters

A domain name is often treated as a small administrative asset. In practice, it can carry an organisation’s website, email, identity, service access, fundraising, customer communication, public campaigns and reputation.

If a domain expires, email authentication is weak, registrar access is uncontrolled, or DNS changes are made without review, the impact can move quickly from a technical issue to a public trust issue.

That is why domain governance matters: it turns a hidden technical dependency into something leaders can see, discuss and own.

What domain governance covers

Domain governance is not the same as domain management

Domain management is usually about administration: registering names, renewing them, updating records and operating DNS.

Domain governance asks a broader question: are those names, controls and signals owned, reviewed, explainable and connected to organisational risk?

A domain can be technically working and still poorly governed. It may renew correctly, resolve correctly and send email, while nobody can explain who owns it, why it exists, which suppliers depend on it, or what the incident path is if it fails.

What can be seen from the outside?

Not everything about domain governance is public. Internal ownership, access control, approval paths and accountability usually cannot be seen from outside.

But some signals are visible. Outsiders can often inspect authoritative DNS, nameservers, mail records, DMARC policy, certificate issuance and registration-related metadata.

These signals should not be over-interpreted. A missing signal does not prove irresponsibility, and a passing signal does not prove good governance. But visible signals are useful prompts for better questions.

Who should care?

Domain governance is relevant to technology, cybersecurity, risk, legal, communications, service delivery and executive leadership.

The reason is simple: domain names sit at the boundary between internal control and public trust. When they fail, the consequences are rarely contained inside the technical team.

Questions every organisation should be able to answer

  • Which domain names do we hold, and why?
  • Who is accountable for each one?
  • Who has registrar access?
  • When do they renew, and who receives renewal notices?
  • Which providers host authoritative DNS?
  • Which systems and suppliers rely on each domain?
  • Which domains are authorised to send email?
  • Are SPF, DKIM and DMARC configured and reviewed?
  • Are DNS changes logged, reviewed and recoverable?
  • What is the incident path if a domain, DNS record or email control fails?

Where to start

Start with the ten-question Baseline. It identifies where ownership, evidence, authority or incident readiness is unclear without producing a score.

If you want to see what happens next, the worked walkthrough follows one fictional Australian not-for-profit from uncertain answers through evidence, governance interpretation, accountable decisions, organisational records and recurring review.

Then use the five practical guides to establish the missing practice through the systems, records and governance forums the organisation already operates.

Use the Domain Governance Baseline Open the practical guides