This site is a record, not a business. BillHartzer.net publishes Bill Hartzer’s professional history and practice. It sells nothing, quotes nothing and takes no engagements — consulting and expert witness inquiries go to Hartzer Consulting.

BillHartzer.net logo mark — the professional record of Bill HartzerBillHartzer.netThe professional record of Bill Hartzer
Practice area
Engagement: AdvisoryConsultingDomain Names

Domain Name Strategy

Choosing, acquiring, structuring and securing the domain names a business actually depends on

Abstract hexagonal tile illustration representing Domain Name Strategy

A domain is infrastructure, not branding

I bought my first domain name in 1996 and sold it to a competitor two years later, which taught me early that a domain is an asset with a market rather than a line item on a hosting invoice. Most companies still treat it as the latter. The name sits in a marketing team's shared account, renewed against a credit card that will eventually expire, with no written record of who controls it.

That matters because so much depends on it. Email, single sign-on, customer-facing applications, certificate issuance, the entire search footprint, and the trust a customer places in a link they were sent all resolve through one name. When it is lost or misconfigured none of the fallbacks work either, because the fallbacks are addressed at the same name.

Domain strategy is therefore two jobs running in parallel: choosing well, and holding on to what you chose.

Choosing a name and a top-level domain

A good domain is short, pronounceable over a phone, unambiguous when spelled aloud, and free of the hyphens and number substitutions that force you to explain it every time you say it. Those are usability criteria, and they are worth more than any ranking consideration.

On the search question specifically: an exact match domain — a domain that is literally the phrase people search for — carries far less inherent advantage than it did in the early 2000s, when it was close to a ranking shortcut. What still helps is indirect. If you build a real brand on that name and use it as your business name, you naturally accumulate links whose anchor text matches the phrase, and that is where the benefit comes from. A parked exact match domain with no brand behind it does nothing at all.

Top-level domain choice is a judgment about audience and trust rather than about algorithms. The newer generic extensions are crawled, indexed and ranked, but they are unevenly recognized by consumers, unevenly accepted by form validators and mail filters, and in some cases associated with abuse in ways that affect deliverability. Country code extensions genuinely help inside their own market and genuinely constrain you outside it.

Acquiring a domain: diligence before price

Buying a domain on the aftermarket without checking its history is the most expensive mistake in this field, because the damage is invisible until after the money has moved. A domain carries its past with it, and the past does not transfer away with the registration.

What I check before a purchase closes:

  • WHOIS history — who has held it, how often it has changed hands, and whether ownership ever changed under circumstances suggesting a dispute or a theft.
  • DNS history — where it has pointed, which hosts and mail servers it has used, and whether it has operated as part of a network of related sites.
  • Archived content — what was published on it, in every language it has ever operated in.
  • Link profile — whether the inbound links are editorial or the residue of a link scheme that will need disavowing.
  • Blocklist and reputation status — spam blocklists, browser safe-browsing status and mail sender reputation, all of which follow the name rather than the owner.
  • Trademark exposure — whether the string reads as somebody else's mark, which is the fastest available route to a dispute you will lose.

In 2013 I created an algorithm and a patent-pending process for performing a background check on an internet domain name, precisely because this work was being done inconsistently and by hand. It became the basis of the domain background check services I have run since.

Portfolio structure and defensive registration

A portfolio should be small, deliberate and documented. The typical corporate portfolio is none of the three: hundreds of names accumulated by different departments across four registrars, some registered to individuals who left the company years ago, several pointing at nothing and one or two pointing at something embarrassing.

Registering your brand across every available extension is usually a waste of money. There are well over a thousand extensions; you cannot cover them, and the ones an infringer would actually use are a short and predictable list. I would rather see a company hold its primary name in its home market extension and in the handful of extensions a customer might plausibly type, plus the obvious typo variants of the main name, and spend what is left on monitoring and enforcement.

What the portfolio does need is a register: which names exist, what each is for, which registrar account holds it, who has access to that account, when it renews, and what breaks if it lapses. Very few companies can produce that document when asked.

Securing what you own

Domain security is where I am least flexible, because the failure mode is catastrophic and the controls are cheap.

  • Registry lock on the names the business cannot operate without. This is a hold applied at the registry rather than the registrar, requiring manual out-of-band verification before any change. It is the single most effective control against an unauthorized transfer or a nameserver hijack, and it is the one most companies have never heard of.
  • Registrar lock, and transfer authorization codes kept restricted, with the code rotated after any support interaction that exposed it.
  • Two-factor authentication on the registrar account, using a hardware key or an authenticator app rather than text messages, which a SIM swap defeats.
  • An account email address that is not hosted on the domain being protected, and that is not one employee's personal mailbox.
  • DNSSEC — cryptographic signing of DNS responses so a forged answer can be detected — where the registrar and the DNS provider both support it and somebody will actually manage the key rollovers.
  • Auto-renew with a calendar reminder behind it, because an expired payment method is an entirely avoidable way to lose a name.

Redirecting, parking and consolidating

Companies routinely own domains they are not using, and handle them badly.

A domain acquired for its traffic or its links should be redirected page by page to the closest equivalent content, in one hop, and only where the old site's subject genuinely relates to the new destination. Pointing an unrelated expired domain at your homepage in the hope of inheriting its authority is a tactic that has been recognized and discounted for years. At best it does nothing.

Typo and defensive domains should redirect to the primary name rather than serving a copy of the site, which creates duplication for no benefit. Domains held for a future launch should serve a minimal holding page or nothing at all, not a parking page full of advertising links, which associates the name with a low-quality neighborhood before you have even used it.

And a domain you have retired should keep redirecting indefinitely, for the same reason old URLs should.

How I advise on domain strategy

Domain work is normally continuing advisory: reviewing what a company owns and where it is held, vetting acquisitions before they close, setting the security baseline and checking it holds, and being reachable when a registrar problem or a dispute appears. It is not a large budget line, and most of its return is in the losses it quietly prevents.

Domain name background checks and related domain services run through DNAccess, which I founded in March 2023. Consulting engagements are handled through Hartzer Consulting.

Frequently asked questions

Does the domain extension affect search rankings?

Not directly, in the way people usually assume. The newer generic extensions are crawled, indexed and ranked, and no penalty attaches to them for being new. What differs is everything around the algorithm: how readily consumers recognize and trust the extension, whether form validators and mail filters accept it, and the reputation the extension has accumulated through the sites using it. Country code extensions are the real exception, since they carry a geographic signal that helps inside that country and constrains you outside it.

Are exact match domains still worth buying?

Far less than in the early 2000s, when an exact match domain was close to a ranking shortcut. The advantage that remains is indirect. If you build an actual brand on the name and use it as your business name, you accumulate links whose anchor text naturally matches the phrase, and that is where the benefit comes from. A generic exact match domain with no brand behind it, or one used only as a redirect, does very little. Buy it for the marketing value rather than the ranking value.

What should I check before buying a domain on the aftermarket?

WHOIS history, to see who has held it and whether it changed hands under suspicious circumstances. DNS history, to see where it has pointed and what it has been associated with. Archived copies of the content, in every language it has operated in. The link profile, to see whether inbound links are editorial or the residue of a link scheme. Spam blocklist and safe-browsing status, which follow the name. And trademark exposure. The damage is invisible until after the money moves.

How many defensive domains should a company register?

Fewer than most vendors recommend. There are well over a thousand extensions and you cannot cover them, so the goal is not coverage but the short, predictable list an infringer would plausibly use: your primary name in your home market extension, in the handful of extensions a customer might type, and the obvious typo variants of the main name. Money beyond that is better spent on monitoring and enforcement, which catch the registrations you did not anticipate rather than the ones you did.

What is registry lock, and do I need it?

Registry lock is a hold placed on a domain at the registry rather than at the registrar, requiring manual out-of-band verification before any change to the registrant, the registrar or the nameservers. It is the strongest control available against an unauthorized transfer or a DNS hijack, because it moves the change out of a web account that can be phished or compromised. If the domain is one your business cannot operate without — email, authentication, the main site — then yes.
Top