This site is a record, not a business. BillHartzer.net publishes Bill Hartzer’s professional history and practice. It sells nothing, quotes nothing and takes no engagements — consulting and expert witness inquiries go to Hartzer Consulting.

BillHartzer.net logo mark — the professional record of Bill HartzerBillHartzer.netThe professional record of Bill Hartzer
Pillar

Domain Names

How the domain name system is organized, what a name is worth, how control is lost, and what happens when it is

Abstract prism facet illustration representing Domain Names

The most load-bearing thing a company owns

I bought my first domain name in 1996 and sold it to a competitor two years later. That transaction taught me something most companies never learn until the day it hurts: a domain name is an asset with a market, a history and an attack surface, not a line item on a hosting invoice.

Almost everything a modern business runs on resolves through one name. The website, obviously. But also email, single sign-on, password resets, customer-facing applications, certificate issuance, mobile app configuration, payment notifications, and the trust a customer places in a link somebody sent them. Lose control of the name and the fallbacks fail too, because the fallbacks are addressed at the same name.

That concentration is why domain work deserves more attention than it gets. It is also why the subject splits into two halves that people tend to treat as unrelated: the commercial half — choosing, acquiring and valuing names — and the operational half, which is keeping the one you have. This page is an orientation to both.

How the system is actually organized

Three parties matter, and confusing them is the source of a surprising number of expensive mistakes.

A registry operates a top-level domain — the part after the final dot — and holds the authoritative record for every name within it: creation date, expiration date, sponsoring registrar, nameservers and status codes. There is exactly one registry per extension.

A registrar is an ICANN-accredited company that sells registrations and manages them on your behalf. The registrar holds the account, the billing relationship, the login history and the transfer authorization codes. Resellers sit beneath registrars and add another layer between you and the record, which is why some companies genuinely do not know which registrar holds their own domain.

The registrant is whoever the record says holds the name. Nobody verified that name at registration. It is self-asserted, and since privacy redaction became standard, most public lookups no longer show it at all.

Extensions come in several flavors that behave differently. Legacy generic extensions such as .com, .net and .org are open to anyone. Country code extensions belong to territories and often carry local presence requirements, and search engines do use them as a geographic signal. The newer generic extensions introduced from 2013 onward number in the hundreds; they are crawled, indexed and ranked normally, but they are unevenly recognized by consumers and unevenly accepted by form validators and mail filters, which is a practical problem rather than an algorithmic one.

The lifecycle of a name, and where it goes when it lapses

Domains are leased, not owned outright, and the lease has stages that most registrants have never been told about. Knowing them is the difference between recovering a name and watching it go.

  • Registered and active. The normal state. The expiration date is the only thing standing between this and everything below.
  • Expired. The name typically stops resolving. It is still recoverable at the ordinary renewal price during a grace period, whose length is set by the registrar rather than by any universal rule.
  • Redemption. After the grace period, the name enters a redemption stage of roughly thirty days in most generic extensions, during which only the original registrant can restore it and only by paying a substantial restoration fee.
  • Pending delete. A short final window, usually about five days, in which nothing can be done at all.
  • Dropped. The name returns to general availability, and in practice it is caught within seconds by automated services that exist to catch drops. Any name with traffic, links or a recognizable string will not simply be sitting there when you get round to it.

Two consequences follow. First, an expired card on a registrar account is a complete business outage waiting for a date. Second, when a name is re-registered after dropping, its creation date usually resets while its accumulated history — the links, the archived content, the reputation — does not. That mismatch is worth remembering the next time someone offers you an aged domain.

What a name is worth

Domain valuation is genuinely difficult, and the confidence with which it is usually asserted is unwarranted. There is no index price. Every sale is a negotiation between one seller and, frequently, exactly one motivated buyer, and the public record of comparable sales is incomplete because a large share of transactions are never disclosed.

The factors that consistently move price are length, memorability, whether the string is a real dictionary word or a natural phrase in a commercially valuable language, the extension, whether the name is already a brand, and how many parties can plausibly use it. Automated appraisal tools apply a model to those attributes. They are useful as a sanity check on order of magnitude and unreliable as a specific figure, and I would not build a damages calculation on one without saying plainly what it is.

The most common commercial mistake here is not overpaying. It is buying without diligence — acquiring a name for its supposed accumulated authority without checking what that authority was accumulated doing. A domain carries its past with it, and the past does not transfer away with the registration.

Control, and how it is lost

Ownership and control are different things, and the public record shows control far more reliably than it shows ownership. A developer, an agency, a former employee or a hosting vendor may sit inside the registrar account with full authority to move a name while every contract says the name belongs to the client. In my experience that gap causes more disputes than anything resembling deliberate theft.

Where names are genuinely taken, the domain is rarely the point of entry. The registrar account is, or the mailbox behind it: an email compromise leading to a password reset, a phone number ported to defeat text-message two-factor authentication, a support agent talked into overriding a lock, or an authorization code sitting in an old ticket. The transfer that follows looks entirely legitimate to everyone processing it, which is precisely why it works.

The controls that prevent this are cheap and unglamorous. Registry lock on the names the business cannot operate without. Hardware-key two-factor authentication rather than text messages. An account email address hosted somewhere other than the domain it protects. Accurate registrant details in the company's name, never an individual's. And a written register of what the company owns, where each name is held, who has access, and what breaks if it lapses. Very few organizations can produce that document when asked.

Disputes, and which mechanism fits which problem

People reach for the wrong instrument here constantly, and choosing wrong costs months.

The UDRP — the Uniform Domain-Name Dispute-Resolution Policy — addresses a specific situation: a name confusingly similar to a trademark, registered and used in bad faith by someone with no legitimate interest in it. That is cybersquatting. It is an administrative proceeding, not a court case, and it can transfer or cancel a name but cannot award money.

The URS, the Uniform Rapid Suspension system, is a faster and cheaper cousin available in many newer extensions. It suspends a name for clear-cut abuse; it does not transfer it to you.

The Transfer Dispute Resolution Policy exists for transfers made without proper authorization. It is filed by a registrar rather than by the registrant, and it is badly underused, mostly because the people it would help have never heard of it.

Court process is what remains when the administrative routes do not fit, and it is the only route that reaches damages. Importantly, a stolen domain is usually a poor fit for the UDRP, because the thief did not register the name in bad faith — you registered it legitimately and it was taken. That mismatch is why such filings fail, and it is the most common strategic error I see in domain theft matters.

Where domains meet search

The two subjects are joined at more points than most people assume. A name's history determines the link profile a new site inherits. A migration to a new name is one of the highest-risk projects an organization can run. Country code extensions carry a geographic signal. Expired-domain acquisition strategies are almost entirely a search idea. And the question people ask most often — whether the choice of extension affects rankings — is a real question with a more interesting answer than either side of the usual argument allows.

Domain name background checks and stolen domain name recovery run through DNAccess, which I founded in March 2023. Consulting engagements are handled through Hartzer Consulting. This site is my professional record; it does not take engagements.

Frequently asked questions

Do I own my domain name or am I renting it?

You hold an exclusive right to use the name for the term you have paid for, renewable indefinitely, subject to the registry's rules and the dispute policies you agreed to at registration. In practical commercial terms it behaves like property: it can be sold, transferred, valued, pledged and inherited. But it can also be lost by non-payment, moved by an administrative proceeding, or suspended by a registry, none of which is true of things you own outright. Renew it, lock it, and keep the registration in the company's name.

Does the domain extension affect search rankings?

Not directly, in the sense that no extension carries an inherent ranking bonus, and search engines have said as much about the newer generic extensions. The effects that do exist are indirect and real: country code extensions are used as a geographic targeting signal, extensions with concentrated abuse can affect email deliverability and user trust, and a name people hesitate to click gets fewer clicks regardless of position. Choose for audience recognition, not for an algorithm.

What should I check before buying a domain on the aftermarket?

Registration and ownership history, including whether the name ever changed hands under circumstances suggesting a dispute. DNS history, showing where it pointed and what it was hosted alongside. Archived content in every language the site has ever operated in. The inbound link profile, to see whether it is editorial or the residue of a link scheme. Blocklist, malware and mail reputation status, which follow the name rather than the owner. And trademark exposure, which is the fastest available route to a dispute you will lose.

How quickly can a dropped domain be re-registered by someone else?

Within seconds. Automated drop-catching services monitor the deletion schedule and submit registration requests the moment a name becomes available, and desirable names are frequently caught by multiple services competing for the same instant. If a name matters to your business, the correct response is never to let it reach that stage: keep auto-renew active, keep a valid payment method on file, and put a calendar reminder behind the renewal date rather than trusting the automation alone.

Who actually owns a domain when an agency registered it for us?

That depends on what the record says and what your contract says, and those two things frequently disagree. If the registrar account is in the agency's name, the agency has control regardless of who paid for it, and unwinding that after a relationship ends is slow. The fix is procedural rather than legal: register names in the company's own account under a company email address, grant the agency delegated access rather than ownership, and record in writing that the name is a company asset.

Is a UDRP the right way to get a stolen domain back?

Usually not, and this is the most common strategic mistake in domain theft matters. The UDRP addresses a name registered and used in bad faith by someone with no legitimate interest — cybersquatting. A stolen domain was registered legitimately, by you, and then taken, so the element the policy requires is missing. The faster routes are the losing registrar's compliance desk, the registry, and the transfer dispute process, with court action where those fail.
Top