Home › Insights

Insights

Six short notes on the questions that come up once a domain purchase reaches a board, a finance team or an IT lead. They are written to be forwarded.

Strategy Six minute read

Exact-match .com or the country code you already have?

A country-code domain is a perfectly good address for a company that sells in one country. The question is what happens the year that stops being true.

A .co.uk, .de or .com.au tells the reader where you are, which is useful, and it is usually cheap and available, which is why most companies start there. Search engines treat a ccTLD as a strong signal of the market you serve, so a British firm on a .co.uk ranks well in Britain and, deliberately, less well elsewhere.

When the country code is enough

If your customers, suppliers and staff are all in one market and will stay there, the ccTLD does the job. Register the matching .com defensively if it is available, point it at the main site, and move on. The .com in that case is insurance, not identity.

When it is not

Three things tend to change the answer. The company starts selling or hiring outside its home market, and international contacts assume the .com. The company raises money or is acquired, and the buyer asks why the obvious name is held by someone else. Or the .com is already in use by a competitor, a parking page or a lookalike, and the misdirected traffic and mail become visible in the support queue.

At that point the .com is no longer insurance. It is the address the world already believes you have, and the cost of not holding it is paid in small, invisible increments: a lost enquiry, a supplier invoice sent to a stranger, a candidate who applied to the wrong place.

What we advise

Keep the country code; it still serves the home market. Acquire the exact-match .com before the moment you need it, because the price rises the day your expansion becomes public. Then run both, with the .com as the primary identity for email and the ccTLD redirecting or serving local content.

Security Five minute read

The mail you are not receiving

A company that trades on example.net has an inbox it does not control. It belongs to whoever holds example.com, and it has been quietly filling up.

How the mail gets there

Nobody types your domain carefully. Customers guess the .com because that is what a domain is, to them. Mail clients autocomplete the wrong address from a previous typo. A supplier's accounts system was set up years ago by someone reading your name off a business card. Forms on hotel wifi, conference badges, LinkedIn messages: the .com is the default, and every one of these produces a message addressed to it.

If the holder of the .com has no mail server, those messages bounce and the sender may or may not notice. If the holder has a catch-all mailbox, the messages are delivered, read or not, and sit there. Contracts, invoices, password resets, HR correspondence, all of it.

Why it matters more for regulated businesses

A clinic, a law firm or a financial adviser has obligations about where client information goes. A patient who emails their consultant at the wrong domain has disclosed medical information to a third party, and the practice will struggle to explain that the third party was simply whoever registered the .com first.

The two ways to stop it

The first is to acquire the name. Once the .com is yours, you decide what happens to mail sent to it: forward it, reject it cleanly, or make it the primary address. This is the only complete fix.

The second, when the name cannot be acquired, is hygiene on the names you do hold: publish SPF, DKIM and DMARC so that mail claiming to come from you can be verified; print and link the correct address consistently; and train the people who answer the phone to spell it out. This reduces the volume but does not stop it.

A protection review tells you which of your names are leaking, and by roughly how much, before you decide which route to take.

Finance Six minute read

How a domain price is reasoned

There is no list price for a domain name, and automated appraisal tools disagree with each other by an order of magnitude. A defensible price comes from three inputs, shown to the buyer.

Comparable sales

Domain sales are recorded, in aggregate, by escrow agents, marketplaces and industry databases. For any name there are recorded sales of names with the same structure: two dictionary words in the same sector, a city plus a service, a company-style name with a common suffix. We start from those, adjusted for date and for how closely they resemble the name in question. This is the same logic a surveyor applies to a house.

The structure of the name

Shorter is worth more, other things being equal. Dictionary words are worth more than invented ones. A name that describes what the company does, in the words a customer would search, is worth more than one that has to be explained. Hyphens, numbers and unusual spellings all take value away, because every one of them is a chance for a customer to reach the wrong site.

What it does for the buyer

This is the input most sellers overstate and most buyers understate. A name that stops a clinic leaking patient email, or lets a software vendor retire six country sites, or removes a lookalike from a bank's search results, is worth more to that buyer than the comparables alone suggest. We ask what the name will do, and we say plainly how much of the price rests on that answer.

What we do not do

We do not quote a range, because a range is an invitation to start at the bottom and a signal that the top was never real. We do not raise the price because you replied quickly, or because someone else asked. And we do not decline to explain a number. If a figure cannot be reasoned to a finance director in a paragraph, it is not the right figure.

Operations Five minute read

One registrar, one account

Most companies of any age hold domains in four or five places, several of them in the names of people who no longer work there. Consolidation is dull, and it is the single most effective thing you can do for the security of your names.

How portfolios fragment

The first domain was registered by a founder on a personal card. The agency that built the second website registered three more under its own account. A product launch needed a campaign domain and marketing bought it on a company card that has since expired. An acquisition brought a portfolio of twenty names at a registrar nobody had heard of. None of this was wrong at the time; it simply never got tidied.

What goes wrong

A renewal fails because the card behind it was cancelled, and the name lapses into an auction where a competitor or a squatter picks it up. A departed employee still holds the login to the account that contains the main brand. A password reset for the registrar account goes to a mailbox that no longer exists. Each of these is survivable once; together, over years, one of them will bite.

The consolidated state

Every name in one registrar account owned by the company, not a person. Two-factor authentication with the recovery route documented. Registrar lock on everything and registry lock on the names that matter most, so that a transfer or a nameserver change needs a human at the registrar to approve it. Multi-year renewals on core names, funded from a company payment method with a second one on file. And a register, one page, listing each name, its purpose, its internal owner, its expiry and where its DNS lives.

We run this as a custody engagement, but the standard is the point, not the supplier. Any company can do this itself in a fortnight.

Legal Seven minute read

When a UDRP is the better route

The Uniform Domain-Name Dispute-Resolution Policy lets a trademark owner recover a domain through arbitration rather than litigation. It is faster and cheaper than court, and it is the wrong tool for most acquisitions.

What a complaint has to prove

All three of the following, not two: that the domain is identical or confusingly similar to a trademark in which you have rights; that the registrant has no rights or legitimate interests in the name; and that the domain was registered and is being used in bad faith. The panel does not weigh them against each other. Fail one and the complaint fails.

Where complaints fail

The most common failure is the third element. If the registrant acquired the name before your trademark existed, they could not have registered it in bad faith towards you, whatever they are doing with it now. Descriptive names fail on the second element: a registrant holding a dictionary phrase and using it descriptively has a legitimate interest. And a complaint brought against a name that was simply available, and that the registrant bought first, tends to be found as an attempt to use the policy to acquire a name the complainant could have bought, which panels call reverse domain name hijacking and record against the complainant.

When to file

File when your mark predates the registration, the name is being used to impersonate you, sell counterfeit goods or capture your customers, and the registrant is either hidden or has quoted a price that is plainly extortionate. In those circumstances a UDRP costs a few thousand dollars in fees and counsel, takes about two months, and ends with the name transferred to you.

When to negotiate instead

Negotiate when any of the three elements is uncertain, when the registrant has a plausible story, or when the price they are likely to accept is lower than the cost and risk of a complaint. Most exact-match names held by a small business, a parking company or an investor fall into this category. An anonymous approach through a representative usually produces a number that makes the legal route unnecessary, and it does so without the registrant learning who wanted the name. Where a complaint would fail, the approach is the only route; where it would succeed, the approach is often still cheaper.

None of this is legal advice. It is the framework we use to tell a client whether to call their lawyer or call us.

Operations Four minute read

The first week after acquiring a name

The transfer is the easy part. What you do in the seven days after it decides whether the name works for you or simply sits there.

Day one: lock it and record it

Turn on the registrar transfer lock, confirm two-factor authentication on the account, and add the name to the company register with its purpose, owner and expiry. Set the renewal to multi-year and auto-renew from a company payment method.

Day two: decide what mail does

Before any MX record exists, decide whether mail to the new name is forwarded to the existing domain, rejected, or becomes the primary. Publish SPF, DKIM and DMARC for the new name whichever you choose, so nobody else can send as it.

Days three to five: move web traffic

If the new name will be primary, replicate the DNS zone at your provider, lower the time-to-live on the old records a day in advance, then switch nameservers. Redirect the old domain to the new one with permanent redirects, page for page, and update the canonical tags. If the new name is secondary, redirect it to the old one and stop.

Days six and seven: tell people

Update email signatures, letterhead, invoices, social profiles and the business listings that search engines read. Tell the bank, the accountants and the largest customers. Keep the old domain for as long as anyone might still be using it, which is longer than you think.

We walk every buyer through this on the day of release. It takes half an hour and it saves the month of confusion that follows a name going live before the redirects do.

Want a view on your own situation?

Write with the name and a sentence on the problem. Sarah will reply with the route she would take, whether or not it involves us.