{
  "schemaVersion": 1,
  "study": "cold-email-authentication-failure-study",
  "title": "DNS diagnostics: controlled error checks and authentication study protocol",
  "status": "limited-controlled-evidence-available; field-study-pending",
  "scope": "Collection template, not a dataset or completed field study. All null values are intentionally uncollected.",
  "unitOfObservation": "message",
  "requiredInputs": "Owned test domains and original received headers; do not change production DNS.",
  "controls": "Preserve one known-good control; change a single configuration at a time.",
  "primaryAnalysis": "Authentication failures by mechanism and alignment, with unavailable checks separate.",
  "registration": {
    "owner": null,
    "protocolVersion": "1",
    "registeredAt": null,
    "population": null,
    "eligibilityRules": null,
    "primaryOutcomeDefinition": null,
    "denominator": null,
    "observationWindow": null,
    "targetSampleAndJustification": null,
    "assignmentProcedureAndSeed": null,
    "exclusionRules": null,
    "safetyStopConditions": null,
    "missingDataPolicy": null,
    "retentionAndAccessOwner": null
  },
  "collectionRules": [
    "Assign pseudonymous IDs; do not store mailbox passwords, access tokens or unnecessary identifiers.",
    "Freeze the outcome and exclusions before collection; retain exclusions with reasons.",
    "Do not use repeated observations as independent people. Record clustering by person, company or mailbox.",
    "Do not treat a software test, simulated reply or researcher-written example as participant or campaign evidence.",
    "Record complaints and opt-outs and follow the actual suppression workflow.",
    "For interviews obtain permission before recording and respect withdrawal.",
    "Publish aggregate or redacted evidence only after review; keep original private records outside the public website."
  ],
  "fieldDictionary": {
    "envelope_sender_domain": {
      "required": true,
      "type": "string, number or boolean as specified by the registered protocol; null until collected",
      "meaning": "envelope sender domain",
      "missingValue": null
    },
    "visible_from_domain": {
      "required": true,
      "type": "string, number or boolean as specified by the registered protocol; null until collected",
      "meaning": "visible from domain",
      "missingValue": null
    },
    "dkim_domain": {
      "required": true,
      "type": "string, number or boolean as specified by the registered protocol; null until collected",
      "meaning": "dkim domain",
      "missingValue": null
    },
    "spf_result": {
      "required": true,
      "type": "string, number or boolean as specified by the registered protocol; null until collected",
      "meaning": "spf result",
      "missingValue": null
    },
    "dkim_result": {
      "required": true,
      "type": "string, number or boolean as specified by the registered protocol; null until collected",
      "meaning": "dkim result",
      "missingValue": null
    },
    "dmarc_result": {
      "required": true,
      "type": "string, number or boolean as specified by the registered protocol; null until collected",
      "meaning": "dmarc result",
      "missingValue": null
    },
    "receiver": {
      "required": true,
      "type": "string, number or boolean as specified by the registered protocol; null until collected",
      "meaning": "receiver",
      "missingValue": null
    },
    "delivery_path": {
      "required": true,
      "type": "string, number or boolean as specified by the registered protocol; null until collected",
      "meaning": "delivery path",
      "missingValue": null
    },
    "dns_snapshot_at": {
      "required": true,
      "type": "string, number or boolean as specified by the registered protocol; null until collected",
      "meaning": "dns snapshot at",
      "missingValue": null
    }
  },
  "blankRecord": {
    "observation_id": null,
    "envelope_sender_domain": null,
    "visible_from_domain": null,
    "dkim_domain": null,
    "spf_result": null,
    "dkim_result": null,
    "dmarc_result": null,
    "receiver": null,
    "delivery_path": null,
    "dns_snapshot_at": null,
    "excluded": false,
    "exclusion_reason": null,
    "protocol_deviation": null
  },
  "records": [],
  "analysisStatus": "not-run",
  "results": null,
  "interpretationLimits": "A missing header or changed DNS snapshot is an unresolved observation, not proof of failure. Publish results only after the evidence, method and limitations have been reviewed. This protocol provides no benchmark, expected lift or completed-study claim.",
  "procedure": [
    "Record envelope sender, visible From, DKIM d=, receiver Authentication-Results and DNS capture time. Separate direct delivery from forwarding.",
    "Use owned test domains and controlled receivers. Change one configuration at a time; retain a known-good control. Never break production DNS for this study.",
    "Before collection, write the primary outcome, observation window, exclusion rules and stopping conditions. Preserve excluded observations with a reason rather than quietly removing them.",
    "Pilot the procedure with fictional or owned test data, resolve ambiguous fields, and freeze a dated protocol version before the main run."
  ],
  "interviewPrompts": [],
  "controlledEvidence": {
    "url": "https://zintara.io/research-data/2026-09-16/controlled-results.json",
    "limits": "These checks do not validate SPF recursion, DKIM signatures, message alignment, forwarding effects, receiver decisions or the incidence of real authentication failures."
  }
}
