The most load-bearing thing a company owns
I bought my first domain name in 1996 and sold it to a competitor two years later. That transaction taught me something most companies never learn until the day it hurts: a domain name is an asset with a market, a history and an attack surface, not a line item on a hosting invoice.
Almost everything a modern business runs on resolves through one name. The website, obviously. But also email, single sign-on, password resets, customer-facing applications, certificate issuance, mobile app configuration, payment notifications, and the trust a customer places in a link somebody sent them. Lose control of the name and the fallbacks fail too, because the fallbacks are addressed at the same name.
That concentration is why domain work deserves more attention than it gets. It is also why the subject splits into two halves that people tend to treat as unrelated: the commercial half — choosing, acquiring and valuing names — and the operational half, which is keeping the one you have. This page is an orientation to both.
How the system is actually organized
Three parties matter, and confusing them is the source of a surprising number of expensive mistakes.
A registry operates a top-level domain — the part after the final dot — and holds the authoritative record for every name within it: creation date, expiration date, sponsoring registrar, nameservers and status codes. There is exactly one registry per extension.
A registrar is an ICANN-accredited company that sells registrations and manages them on your behalf. The registrar holds the account, the billing relationship, the login history and the transfer authorization codes. Resellers sit beneath registrars and add another layer between you and the record, which is why some companies genuinely do not know which registrar holds their own domain.
The registrant is whoever the record says holds the name. Nobody verified that name at registration. It is self-asserted, and since privacy redaction became standard, most public lookups no longer show it at all.
Extensions come in several flavors that behave differently. Legacy generic extensions such as .com, .net and .org are open to anyone. Country code extensions belong to territories and often carry local presence requirements, and search engines do use them as a geographic signal. The newer generic extensions introduced from 2013 onward number in the hundreds; they are crawled, indexed and ranked normally, but they are unevenly recognized by consumers and unevenly accepted by form validators and mail filters, which is a practical problem rather than an algorithmic one.
The lifecycle of a name, and where it goes when it lapses
Domains are leased, not owned outright, and the lease has stages that most registrants have never been told about. Knowing them is the difference between recovering a name and watching it go.
- Registered and active. The normal state. The expiration date is the only thing standing between this and everything below.
- Expired. The name typically stops resolving. It is still recoverable at the ordinary renewal price during a grace period, whose length is set by the registrar rather than by any universal rule.
- Redemption. After the grace period, the name enters a redemption stage of roughly thirty days in most generic extensions, during which only the original registrant can restore it and only by paying a substantial restoration fee.
- Pending delete. A short final window, usually about five days, in which nothing can be done at all.
- Dropped. The name returns to general availability, and in practice it is caught within seconds by automated services that exist to catch drops. Any name with traffic, links or a recognizable string will not simply be sitting there when you get round to it.
Two consequences follow. First, an expired card on a registrar account is a complete business outage waiting for a date. Second, when a name is re-registered after dropping, its creation date usually resets while its accumulated history — the links, the archived content, the reputation — does not. That mismatch is worth remembering the next time someone offers you an aged domain.
What a name is worth
Domain valuation is genuinely difficult, and the confidence with which it is usually asserted is unwarranted. There is no index price. Every sale is a negotiation between one seller and, frequently, exactly one motivated buyer, and the public record of comparable sales is incomplete because a large share of transactions are never disclosed.
The factors that consistently move price are length, memorability, whether the string is a real dictionary word or a natural phrase in a commercially valuable language, the extension, whether the name is already a brand, and how many parties can plausibly use it. Automated appraisal tools apply a model to those attributes. They are useful as a sanity check on order of magnitude and unreliable as a specific figure, and I would not build a damages calculation on one without saying plainly what it is.
The most common commercial mistake here is not overpaying. It is buying without diligence — acquiring a name for its supposed accumulated authority without checking what that authority was accumulated doing. A domain carries its past with it, and the past does not transfer away with the registration.
Control, and how it is lost
Ownership and control are different things, and the public record shows control far more reliably than it shows ownership. A developer, an agency, a former employee or a hosting vendor may sit inside the registrar account with full authority to move a name while every contract says the name belongs to the client. In my experience that gap causes more disputes than anything resembling deliberate theft.
Where names are genuinely taken, the domain is rarely the point of entry. The registrar account is, or the mailbox behind it: an email compromise leading to a password reset, a phone number ported to defeat text-message two-factor authentication, a support agent talked into overriding a lock, or an authorization code sitting in an old ticket. The transfer that follows looks entirely legitimate to everyone processing it, which is precisely why it works.
The controls that prevent this are cheap and unglamorous. Registry lock on the names the business cannot operate without. Hardware-key two-factor authentication rather than text messages. An account email address hosted somewhere other than the domain it protects. Accurate registrant details in the company's name, never an individual's. And a written register of what the company owns, where each name is held, who has access, and what breaks if it lapses. Very few organizations can produce that document when asked.
Disputes, and which mechanism fits which problem
People reach for the wrong instrument here constantly, and choosing wrong costs months.
The UDRP — the Uniform Domain-Name Dispute-Resolution Policy — addresses a specific situation: a name confusingly similar to a trademark, registered and used in bad faith by someone with no legitimate interest in it. That is cybersquatting. It is an administrative proceeding, not a court case, and it can transfer or cancel a name but cannot award money.
The URS, the Uniform Rapid Suspension system, is a faster and cheaper cousin available in many newer extensions. It suspends a name for clear-cut abuse; it does not transfer it to you.
The Transfer Dispute Resolution Policy exists for transfers made without proper authorization. It is filed by a registrar rather than by the registrant, and it is badly underused, mostly because the people it would help have never heard of it.
Court process is what remains when the administrative routes do not fit, and it is the only route that reaches damages. Importantly, a stolen domain is usually a poor fit for the UDRP, because the thief did not register the name in bad faith — you registered it legitimately and it was taken. That mismatch is why such filings fail, and it is the most common strategic error I see in domain theft matters.
Where domains meet search
The two subjects are joined at more points than most people assume. A name's history determines the link profile a new site inherits. A migration to a new name is one of the highest-risk projects an organization can run. Country code extensions carry a geographic signal. Expired-domain acquisition strategies are almost entirely a search idea. And the question people ask most often — whether the choice of extension affects rankings — is a real question with a more interesting answer than either side of the usual argument allows.
Domain name background checks and stolen domain name recovery run through DNAccess, which I founded in March 2023. Consulting engagements are handled through Hartzer Consulting. This site is my professional record; it does not take engagements.