NotesTools
Owning your domain and email: a plain guide for a small business
Your domain name is the one piece of your online presence that everything else depends on: the website, the email address, the sign-in to half your accounts. Who actually holds it, what the DNS records do, how renewals go wrong, and what to keep a record of.
A small business can change its website, its email provider and its accounting software and survive. Losing its domain name is different. The website stops loading, email stops arriving, and every account that sends password resets to that address is suddenly out of reach. It happens more often than it should, and usually for boring reasons: a renewal email went to an old address, the card on file expired, or the domain was registered by someone who no longer works with the business.
This note explains the parts, in plain words, and gives a short list of what to check and write down. It is written for anyone who has a domain, or is about to buy one, and wants to keep it safe without becoming an expert.
Four jobs that are easy to confuse
When you "have a website at yourbusiness.ca", up to four different services may be involved. Sometimes one company does all four; often it does not.
The registration. ICANN, the body that co-ordinates the global domain name system, calls the person or organization that holds the rights to a domain the registrant. That should be your business. You register through a registrar, the company you pay each year. Behind the registrar sits a registry, which runs each top-level domain (.com, .ca and so on) and publishes its records. Some companies that sell domains are resellers: ICANN notes that resellers are not accredited by it, and that the registrar remains responsible for services a reseller provides. Your fees, renewals and transfers are governed by your agreement with your registrar.
DNS hosting. The domain's DNS records are the public directions that tell the internet where your website and email live. They are kept by whichever company runs your domain's name servers. That is often the registrar, but it can be your web host or a separate DNS provider.
Web hosting. The server or service that actually serves your website.
Email hosting. The service that receives and stores your mail, such as a workspace provider or the email product bundled with your host.
The reason to know the difference: when something breaks, or when you want to move, you need to know which of the four to log in to. And when you leave a web designer or a hosting company, the registration is the part you must not leave behind.
DNS records, in plain words
You do not need to edit DNS records often, but you should recognise the main types when you see them. In Cloudflare's plain definitions:
| Record | What it does |
|---|---|
| A | Holds the IP address (IPv4) a name points to; usually where your website lives |
| AAAA | The same, for an IPv6 address |
| CNAME | Points one name, such as www, at another name instead of an address |
| MX | Directs mail for the domain to your email server |
| TXT | Stores text; often used for email security and to prove you own the domain |
The two you most need to protect are MX, because changing it changes where your email goes, and the TXT records that hold your email authentication settings, below. Before anyone changes your DNS, take a screenshot or export of the current records. It is the quickest way to undo a mistake.
Email that arrives: SPF, DKIM and DMARC
Three TXT-based settings tell other mail systems which servers are allowed to send email as your domain, and what to do with messages that fail the check.
- SPF lists the servers that may send mail for your domain.
- DKIM adds a cryptographic signature to your messages so receivers can check they were not altered or forged.
- DMARC tells receivers what to do with mail that fails: deliver it and report (a policy of "none"), mark it as suspicious ("quarantine"), or refuse it ("reject").
The Canadian Centre for Cyber Security's guidance on email domain protection says that for complete protection you must implement all three, and that only a DMARC policy of reject at 100 per cent will prevent illegitimate messages from being delivered. It also flags a practical limit: an SPF record can involve no more than 10 DNS lookups, which matters once you use several services that send mail for you, such as a newsletter tool, an invoicing app and your email provider.
There is also a delivery reason to do this. Google's email sender guidelines, in force since February 2024, require everyone sending to Gmail accounts to set up SPF or DKIM, and larger senders to set up SPF, DKIM and DMARC. A small business sending invoices and replies is unlikely to hit the bulk thresholds, but it still benefits from having all three in place.
If you own a domain you never send mail from, such as a spare spelling or an old brand, the Cyber Centre's guidance is to publish records that say so, so that nobody can send convincing mail from it.
Renewal traps, and what the rules guarantee
Most lost domains are not stolen. They expire. ICANN's rules give you some protection, but not unlimited time:
- Reminders. Under ICANN's Expired Registration Recovery Policy, registrars must send renewal reminders approximately one month and one week before expiry, and another notice within five days after it. They go to the contact details on your registration, which is why those must be current.
- The website goes dark first. After expiry, the policy requires that the domain stop resolving for at least the last eight consecutive days during which you can still renew it, as a final warning that is hard to miss.
- A last chance, at a price. Registries must offer a Redemption Grace Period of 30 days after a registration is deleted. Recovering a domain at that stage usually costs more than a renewal.
ICANN's statement of registrant responsibilities adds two rules worth knowing: you must keep your registrar account data current and respond to your registrar's inquiries within 15 days, and if you use auto-renewal you must keep your payment information up to date.
The simplest defences: turn on auto-renewal, renew for several years at a time if your registrar allows it, keep a working card on file, and put the expiry date in your own calendar with a reminder a month before.
Moving to another registrar
You can move a domain to another registrar, but there are two rules to plan around. Under ICANN's Transfer Policy, a registrar may refuse a transfer within 60 days of the domain's registration or of a previous transfer, and a change of registrant can trigger a 60-day transfer lock. To move, you request a transfer code (the "AuthInfo" code) from your current registrar, which the policy says must be provided within five calendar days. ICANN has published an updated version of the policy; check your registrar's current terms before you start.
What to keep a record of
Keep one page, stored where at least two people in the business can find it, with:
- the domain name, the registrar, and the expiry date;
- who the registrant is (it should be the business, not a former designer or employee);
- the email address the registrar sends notices to, and confirmation that someone reads it;
- where DNS is hosted, where the website is hosted, and where email is hosted;
- an export or screenshot of the current DNS records, dated;
- where the sign-in details are kept, and that two-factor sign-in is on for the registrar account.
Check it once a year, on a date you choose. Ten minutes a year is the whole cost of never losing the name your business is known by.
Drafted with AI assistance.
Sources
- ICANN — The Domain Name Registration Process icann.org
- ICANN — Registrant Benefits and Responsibilities icann.org
- ICANN — Transfer Policy icann.org
- ICANN — Expired Registration Recovery Policy icann.org
- Cloudflare Learning Center — What is a DNS record? cloudflare.com
- Google — Email sender guidelines support.google.com
- Canadian Centre for Cyber Security — Implementation guidance: email domain protection (ITSP.40.065) cyber.gc.ca