A domain is infrastructure, not branding
I bought my first domain name in 1996 and sold it to a competitor two years later, which taught me early that a domain is an asset with a market rather than a line item on a hosting invoice. Most companies still treat it as the latter. The name sits in a marketing team's shared account, renewed against a credit card that will eventually expire, with no written record of who controls it.
That matters because so much depends on it. Email, single sign-on, customer-facing applications, certificate issuance, the entire search footprint, and the trust a customer places in a link they were sent all resolve through one name. When it is lost or misconfigured none of the fallbacks work either, because the fallbacks are addressed at the same name.
Domain strategy is therefore two jobs running in parallel: choosing well, and holding on to what you chose.
Choosing a name and a top-level domain
A good domain is short, pronounceable over a phone, unambiguous when spelled aloud, and free of the hyphens and number substitutions that force you to explain it every time you say it. Those are usability criteria, and they are worth more than any ranking consideration.
On the search question specifically: an exact match domain — a domain that is literally the phrase people search for — carries far less inherent advantage than it did in the early 2000s, when it was close to a ranking shortcut. What still helps is indirect. If you build a real brand on that name and use it as your business name, you naturally accumulate links whose anchor text matches the phrase, and that is where the benefit comes from. A parked exact match domain with no brand behind it does nothing at all.
Top-level domain choice is a judgment about audience and trust rather than about algorithms. The newer generic extensions are crawled, indexed and ranked, but they are unevenly recognized by consumers, unevenly accepted by form validators and mail filters, and in some cases associated with abuse in ways that affect deliverability. Country code extensions genuinely help inside their own market and genuinely constrain you outside it.
Acquiring a domain: diligence before price
Buying a domain on the aftermarket without checking its history is the most expensive mistake in this field, because the damage is invisible until after the money has moved. A domain carries its past with it, and the past does not transfer away with the registration.
What I check before a purchase closes:
- WHOIS history — who has held it, how often it has changed hands, and whether ownership ever changed under circumstances suggesting a dispute or a theft.
- DNS history — where it has pointed, which hosts and mail servers it has used, and whether it has operated as part of a network of related sites.
- Archived content — what was published on it, in every language it has ever operated in.
- Link profile — whether the inbound links are editorial or the residue of a link scheme that will need disavowing.
- Blocklist and reputation status — spam blocklists, browser safe-browsing status and mail sender reputation, all of which follow the name rather than the owner.
- Trademark exposure — whether the string reads as somebody else's mark, which is the fastest available route to a dispute you will lose.
In 2013 I created an algorithm and a patent-pending process for performing a background check on an internet domain name, precisely because this work was being done inconsistently and by hand. It became the basis of the domain background check services I have run since.
Portfolio structure and defensive registration
A portfolio should be small, deliberate and documented. The typical corporate portfolio is none of the three: hundreds of names accumulated by different departments across four registrars, some registered to individuals who left the company years ago, several pointing at nothing and one or two pointing at something embarrassing.
Registering your brand across every available extension is usually a waste of money. There are well over a thousand extensions; you cannot cover them, and the ones an infringer would actually use are a short and predictable list. I would rather see a company hold its primary name in its home market extension and in the handful of extensions a customer might plausibly type, plus the obvious typo variants of the main name, and spend what is left on monitoring and enforcement.
What the portfolio does need is a register: which names exist, what each is for, which registrar account holds it, who has access to that account, when it renews, and what breaks if it lapses. Very few companies can produce that document when asked.
Securing what you own
Domain security is where I am least flexible, because the failure mode is catastrophic and the controls are cheap.
- Registry lock on the names the business cannot operate without. This is a hold applied at the registry rather than the registrar, requiring manual out-of-band verification before any change. It is the single most effective control against an unauthorized transfer or a nameserver hijack, and it is the one most companies have never heard of.
- Registrar lock, and transfer authorization codes kept restricted, with the code rotated after any support interaction that exposed it.
- Two-factor authentication on the registrar account, using a hardware key or an authenticator app rather than text messages, which a SIM swap defeats.
- An account email address that is not hosted on the domain being protected, and that is not one employee's personal mailbox.
- DNSSEC — cryptographic signing of DNS responses so a forged answer can be detected — where the registrar and the DNS provider both support it and somebody will actually manage the key rollovers.
- Auto-renew with a calendar reminder behind it, because an expired payment method is an entirely avoidable way to lose a name.
Redirecting, parking and consolidating
Companies routinely own domains they are not using, and handle them badly.
A domain acquired for its traffic or its links should be redirected page by page to the closest equivalent content, in one hop, and only where the old site's subject genuinely relates to the new destination. Pointing an unrelated expired domain at your homepage in the hope of inheriting its authority is a tactic that has been recognized and discounted for years. At best it does nothing.
Typo and defensive domains should redirect to the primary name rather than serving a copy of the site, which creates duplication for no benefit. Domains held for a future launch should serve a minimal holding page or nothing at all, not a parking page full of advertising links, which associates the name with a low-quality neighborhood before you have even used it.
And a domain you have retired should keep redirecting indefinitely, for the same reason old URLs should.
How I advise on domain strategy
Domain work is normally continuing advisory: reviewing what a company owns and where it is held, vetting acquisitions before they close, setting the security baseline and checking it holds, and being reachable when a registrar problem or a dispute appears. It is not a large budget line, and most of its return is in the losses it quietly prevents.
Domain name background checks and related domain services run through DNAccess, which I founded in March 2023. Consulting engagements are handled through Hartzer Consulting.