Picking a Domain With Email in Mind
Your domain ends up in every address you hand out. How to pick one that is easy to say, hard to spoof, and safe from the registrar mistakes that lose email.

On this page(8 sections)
Most founders choose a domain by how it looks on a landing page. Then they spend the next five years spelling it over the phone, correcting customers who typed it wrong, and explaining why an email "from them" came from a lookalike. Your domain is part of every email address your company will ever use, so it's worth judging it as an email address too.
Test it out loud
Email addresses get dictated: on sales calls, at conferences, to a bank's support line, to the accountant. Before you buy, say the full address out loud to someone who hasn't seen it and ask them to type it.
Common failures:
- Creative spellings. If your product is called "Flowly" but the domain is
flowlee.example, you'll spell it every single time. - Hyphens. "Get dash my dash invoice dot com" is a sentence nobody gets right on the first try. People also forget hyphens when typing from memory.
- Doubled letters at word boundaries. Names like
dealleads.exampleare easy to mistype and hard to read. - Numbers. Is it "4" or "four"? Unless the number is the brand, avoid it.
If the person types it correctly on the first try, it passes. If they ask how it's spelled, think hard.
Watch for confusable characters
Some letter combinations look alike in common fonts: rn and m, l and I, 0 and O, vv and w. A domain that already contains one of these is easy for an attacker to imitate with a near-identical registration, and hard for your customers to spot.
You can't prevent all lookalikes, but you can avoid making them trivially easy. If your preferred name contains rn or vv, consider whether a phishing email from the swapped version would fool your own team.
Practical defenses once you've chosen:
- Register the most obvious typo variants and the main alternative TLD, and redirect them.
- Publish a DMARC policy on your real domain and move it toward enforcement, so mail spoofing your exact domain gets rejected.
- Tell customers, in your onboarding and billing emails, which domain you send from.
DMARC protects your exact domain, not lookalikes, so registering obvious variants still matters. You can check what's published for any domain with our DMARC checker.
Think about the TLD
.com remains the default most people assume when they hear a company name. Other TLDs work well, especially in tech, but plan for the cost of being different:
- Customers who type
.comout of habit will reach someone else's site, or, worse, someone else's mail server. - Some newer TLDs have historically had a poor reputation with spam filters because of abuse. Reputation is mostly earned per domain, so this matters less than it used to, but a new domain on a less common TLD has less benefit of the doubt.
- Country-code TLDs can carry registration requirements and signal a location you may not want.
If you go with a non-.com domain, see whether the .com is available or affordable. If someone else owns it and runs mail on it, misdirected email from your customers will land with them.
Separate domains for different kinds of mail?
Some companies send marketing or bulk email from a separate domain or a subdomain to keep its reputation apart from their main domain. Subdomains are the more common choice: news.yourapp.example stays recognizably yours while letting providers judge it separately.
A completely different domain for bulk mail has drawbacks. Recipients don't recognize it, and it looks like the kind of thing spammers do. For most early-stage companies, one primary domain plus subdomains for distinct streams is the simpler plan.
Secure the registrar account like it holds your company
Because it does. Whoever controls your registrar account controls your DNS, and whoever controls your DNS controls your email, your password reset emails, and anything verified by domain ownership.
| Risk | What happens | Prevention |
|---|---|---|
| Registrar login uses an address on the same domain | Domain expires, email stops, you can't receive the renewal or reset email | Use an address on a different domain for the registrar account |
| Domain expires | Website and email stop, and someone else may register it | Auto-renew on, multi-year registration, a backup payment method |
| Registrar account compromised | Attacker changes MX or nameservers | Strong unique password, 2FA, registrar lock enabled |
| Founder leaves with the account | Nobody can change DNS | Account owned by the company, with at least two admins |
The first row catches more companies than you'd think. If your registrar account email is [email protected], and the domain lapses because the card on file expired, the renewal warnings go to an address that no longer works. Use an address on another domain for the registrar and your DNS host.
Keep the domain separate from the website host
Many registrars and hosting companies bundle email with a domain purchase. That's convenient at first, but it ties your email to whoever hosts your website. When you later redesign the site or switch hosting, the email comes along as an afterthought. Keep DNS somewhere you control directly, and treat web hosting and email as two separate services that both point at the same domain.
A checklist before you buy
- Said aloud to someone who typed it correctly on the first try
- No hyphens, numbers or creative spellings unless they are the brand
- No easily confused letter pairs, or lookalike variants registered
- The
.com(or obvious alternative) checked for availability and current use - Registrar account on an email address at a different domain
- Auto-renew enabled, with a backup payment method
- 2FA and registrar lock turned on
- At least two people at the company can access the registrar
Key takeaways
- A domain is an email address before it's a URL. Test it spoken, not just written.
- Avoid confusable characters and register the obvious variants. DMARC protects only your exact domain.
- The registrar account is the master key to your email. Secure it and never tie its login to the domain it controls.
- Keep DNS independent of your website host so changing one doesn't break the other.
Start with Koltrix
Your domain, one inbox, and an API that sends.
A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.


