Building a Long-Term Trust Score Baseline for Your Domain

Running a business across the eastern seaboard from Brisbane down to Melbourne means juggling AEST one day and AEDT the next, and dealing with spam complaints that can hit your inbox before your morning flat white. Whether you operate a .au domain through auDA or send transactional mail for clients like Telstra, ANZ, or Australia Post, the only way to spot genuine threats is to know what normal looks like first. A steady baseline gives you something to measure against when something goes pear-shaped.

A trust score baseline is essentially a moving average of authentication results, IP reputation, and complaint rates over time. Once you build it, any sudden shift becomes immediately visible, which matters more than ever given the volume of phishing attempts reported to Scamwatch each quarter.

Defining Your Trust Score Baseline

A baseline is the recorded behaviour of your domain across DKIM, SPF, DMARC alignment, sending IPs, and complaint feedback loops over a defined window. Start by choosing a quiet period, perhaps three to four weeks of typical transactional and marketing traffic, and capture the average alignment pass rate, the typical volume per IP, and the historical bounce rate.

Document everything in a single spreadsheet or dashboard so the figures do not drift over time. Treat this snapshot as the reference point every future check is compared against. If you inherit a domain, the same process applies, but expect the first month to be a calibration phase rather than a clean starting line.

Gathering the Right Historical Data

Quality data beats quantity every time. Pull at least 90 days of authentication results from your mail provider, then layer in complaint data from feedback loops with the major mailbox providers. For Australian senders, also include reports logged with ACMA, since regulator-side complaints often precede a reputation dip by several days.

Capture auxiliary signals alongside the core metrics: sending IP changes, new DKIM selectors, and any third-party platforms added to your outbound stream. A new ESP integration can look like suspicious behaviour if your baseline does not already account for it, which is a fair dinkum mistake to avoid when you are trying to detect a genuine hijack.

Choosing Thresholds That Match Your Sending Pattern

A single universal threshold will trigger too many false alarms. Instead, set tiered bands: a soft warning at 10% deviation from baseline, a hard alert at 25%, and an immediate escalation at 40%. This approach keeps the on-call team from being woken up at 2am AEDT for routine noise.

Remember that marketing campaigns can push your volume up sharply without harming your reputation, while a quiet drop in transactional mail might indicate a routing problem. Thresholds should reflect the shape of your sending, not a textbook curve. The how to detect a domain that has been hijacked for spam campaigns checklist walks through the specific warning signs to watch for once your bands are set.

Spotting Anomalies Through Daily Monitoring

Daily checks do not need to be complex. A 15-minute review of your trust score, sending volumes, and authentication pass rates is usually enough to catch early drift. For teams based in Sydney or Perth, scheduling the review for late AEDT means the data covers a full UTC day before you look at it.

Layer your checks with passive monitoring of DNS records. If your SPF record suddenly includes an unfamiliar IP, that is worth investigating before it impacts delivery. The why a domain with an spf fail on its own ip should be investigated immediately checklist is a useful prompt when those alerts fire.

Reading Sudden Drops in Context

A score plunge is rarely random. If your trust score falls sharply on a Tuesday afternoon and you did not send a campaign, look for unauthorised sends, compromised credentials, or a new IP you did not provision. Cross-reference the timing against any platform access logs you keep, since attackers often start with low-volume probes before scaling up.

When the dip coincides with inboxing problems at Optus or Telstra, the cause is often an upstream blocklist hit rather than something you did wrong. Either way, the what a sudden drop in a domain's trust score signals about ongoing abuse checklist helps structure the investigation before you burn cycles on the wrong lead.

Responding to and Documenting Anomalies

Every alert should produce a short incident note: when it fired, what changed, what action was taken, and how the score recovered. Over time, this log becomes its own baseline of expected incidents, which is handy for auditors and for the Notifiable Data Breaches scheme if customer data is involved.

If an anomaly points to a genuine breach involving personal information, remember the OAIC requires notification within 30 days once an eligible breach is confirmed. Documenting the trust score trail makes that conversation much smoother with both regulators and customers.

Comparing Normal and Anomalous Signals

After several months of recording your own numbers, the contrast between steady-state operation and an active incident becomes unmistakable. Once you have a stable dataset, the patterns below usually hold across most sending environments, though your own thresholds will refine them further.

When something looks wrong, run through this comparison before opening a wider investigation. It saves time and helps separate noise from genuine trouble, which matters when you are juggling other priorities through an Aussie afternoon.

Signal Normal baseline Anomaly to investigate
DMARC pass rate 95-99% sustained Sudden drop below 85%
Daily send volume Stable within 15% of average Spike or drop exceeding 40%
SPF alignment Consistent with recorded IPs New IP or unknown mechanism appears
Complaint rate Below 0.05% per send Rises above 0.2% in 24 hours
Blocklist appearances Zero or rare New listing within 48 hours