Version 1.0 - established 9 August 2026

Fixed reference edition

The canonical ten-question baseline.

This page is the stable reference edition for Domain Governance Baseline v1.0. The interactive working edition may improve through the v1.x line, but the substance of these ten questions remains fixed for citation.

Ten canonical questions No score Review aid CC BY 4.0 content
Purpose and boundary

A starting point for governance, not a judgement of maturity

The baseline helps an organisation determine whether the fundamentals of domain ownership, authority, renewal, DNS, email trust, dependencies, change control and incident readiness are understood and governed. If a question cannot be answered clearly, that is where follow-up starts.

What Version 1.0 establishes

The ten questions below are the stable citable core of the v1 line. Supporting explanation, practice guidance and starter records may improve without materially changing these questions.

Output boundary

A baseline review summary, not an assurance report, compliance instrument, maturity score or rating.

Governance boundary

Use existing board, risk, technology, supplier, incident and service-governance processes rather than creating another system to operate.

Evidence boundary

Public signals can inform a review, but only the organisation can answer the internal governance questions.

Canonical baseline

The ten questions

Version 1.0 fixes the following question set for citation and reuse.

01 - Ownership and inventory

Which domains do we own, and why do we own them?

02 - Accountability

Who is the accountable business owner for each domain?

03 - Access control

Who has registrar access, and how is that access controlled?

04 - Continuity

When do the domains renew, and who receives renewal notices?

05 - Infrastructure

Which providers host authoritative DNS?

06 - Dependency mapping

Which systems and suppliers rely on each domain?

07 - Email authority

Which domains are authorised to send email?

08 - Email authentication

Are SPF, DKIM and DMARC configured and reviewed?

09 - Change control

Are DNS changes logged, reviewed and recoverable?

10 - Incident readiness

What is the incident path if a domain, DNS record or email control fails?

Interpretation

Use uncertainty as a governance finding

The baseline is deliberately not scored. A clear answer can be protected and kept current; a partial, absent or uncertain answer identifies where evidence, ownership or action is required.

Observation is not judgement

A missing public signal does not establish poor governance, and a passing public signal does not establish effective internal control.

Local review

The interactive edition is designed without accounts, retained answers, analytics or external assessment processing. Review summaries are generated locally in the browser.

From baseline to practice

Five bounded guides support domain inventory, registrar and DNS authority, email authority, incident readiness and recurring governance.

Citation and reuse

Reference Version 1.0 directly

Preferred citation

Chetcuti, B. (2026). Domain Governance Baseline (Version 1.0). https://baseline.bryanchetcuti.com/

Stable reference URL

https://baseline.bryanchetcuti.com/reference/v1.0/

Reuse

Unless otherwise noted, the authored governance content is available under CC BY 4.0. Adaptation and reuse are encouraged with attribution and an indication of changes.