In April 2021, anyone in Argentina who typed google.com.ar into a browser got nothing. The domain had lapsed, and a man outside Buenos Aires registered it for about 270 pesos, roughly three dollars. For a few hours, one of the most sophisticated technology companies on the planet did not control its own address in a country of 45 million people. The registry returned it within hours, and exactly how the lapse happened was never fully explained.
I think about that story more than you might expect, because a smaller version of it walks through our door. A business recently came to us for help with email security, a sensible and increasingly common request. Before we could do anything, we needed to know who owned their domain and whether the registration was current. Nobody could tell us. That is a domain name ownership question, and it deserves an answer long before an IT provider asks it.
Why Domain Name Ownership Matters for Email Security
That is not a trivia question. Protecting email against spoofing and impersonation means publishing a few records, known as SPF, DKIM, and DMARC, in the domain’s DNS settings, which tell the rest of the internet which servers are allowed to send mail on your behalf. Those settings live in an account at a domain registrar or DNS provider, and someone has to be able to log in to change them. When nobody knows whose account that is, an email security project stalls before it starts.
The stakes run well beyond one project. Your domain is not just your website address. Whoever controls it controls where your email is delivered, where your website points, and the verification records that Microsoft 365 or Google Workspace use to confirm the domain belongs to you. In practical terms, the person holding that login holds the keys to your business’s identity online. If the registration lapses because the card on file expired or the renewal notices went to an inbox nobody reads, your email stops arriving. Registrars typically allow a short grace period after expiration, but once it passes, the name can return to the open market, and Argentina showed how quickly someone will claim it. ICANN requires registrars to send renewal reminders about a month and again about a week before expiration, which only helps if they reach an inbox someone actually reads.
How Domain Name Ownership Slips Away
This rarely happens through dramatic negligence. Domains are usually registered once, often years ago, by whoever was handy at the time, and then renew quietly in the background until everyone forgets they exist. Sometimes that works out fine. We worked with another business that knew exactly who controlled its domain: its website designer. That was fine until the two of them fell out. The designer still held the keys, and getting control back turned into a long, frustrating process for a company that had assumed all along that its own name belonged to it. Nothing about that designer’s arrangement was unusual when it was set up. It only became a problem the day the relationship did. Like the vendor contracts I wrote about in July, the arrangement only mattered once someone needed to change it.
A Five-Minute Domain Name Ownership Check
The good news is that finding out takes about five minutes. A public WHOIS lookup will tell you which registrar holds your domain, even if you have long since forgotten. From there, answer four questions. Whose name is on the account? Is the login tied to an email address your company controls, rather than one belonging to a person who might someday leave, and is multi-factor authentication turned on? Is auto-renew enabled, with a payment method that will still be valid next year? And when does the registration expire? If you cannot answer all four with confidence, you have found your project for the week.
Google got its domain back in a matter of hours, because it is Google. Most of us would be waiting considerably longer for that phone call to be returned. Know who owns yours before you need to.
Until next time, keep IT simple.
Dave
