top of page
Search

Why Should Small Businesses Have to Buy Every Domain Extension Just to Protect Their Name?

Sep 8
6 min read

I recently had a conversation with my domain registrar that raised a much bigger issue than simply deciding which domain names my business should own.

Like many businesses, Covured Inc. owns its primary .com and .ca domains. I also own several related domain variations.

While reviewing those registrations, I was encouraged to purchase additional domain extensions such as .net, .org, .info, .ai and .io because someone else could potentially register those versions of my business name, create a website or email address, and make consumers believe they were dealing with my company.

That concern is real.

But the proposed solution left me asking a much bigger question:

Where does it end?

Suppose a business owns:

Then, to "protect" itself, it purchases:

Is that business now protected?

Not really.

Someone could still register:

They could deliberately misspell the business name, add another word, use another extension, or create countless other variations.

There are hundreds of domain extensions and virtually unlimited variations of a business name.

It is simply not realistic to expect a small business to purchase every conceivable domain that might someday be used to imitate it.

Defensive domain registration has value — but it has limits

There is nothing inherently wrong with purchasing additional domain extensions.

If I purchase mybusiness.net, someone else cannot register that exact domain while I own it.

That can certainly be useful.

But it is important that business owners understand exactly what they are buying.

Purchasing .net does not make an existing .com more secure.

Purchasing .ai does not provide some additional layer of protection against artificial intelligence.

Purchasing .io does not prevent someone from creating another misleading variation of the company name.

It simply prevents another person from registering those particular domain addresses.

That distinction matters when these products are being sold to businesses as "protection."

The registrar is standing at the front door

The part of this issue that concerns me most is the amount of responsibility being placed on the legitimate business owner while relatively little preventative responsibility appears to exist at the point where these domains are actually being registered.

A domain registrar is the company facilitating the registration.

That registrar knows the domain being requested.

Modern systems can determine whether the same distinctive name already exists under major extensions.

Corporate registries exist.

Trademark databases exist.

Technology capable of identifying similar names certainly exists.

So why is virtually all of the responsibility placed on the established business after the fact?

If someone attempts to register a domain that exactly matches or closely resembles an established corporation, registered business or trademark, I believe there should at least be circumstances where that registration triggers additional verification.

I am not suggesting that every matching domain automatically be prohibited.

There may be perfectly legitimate reasons why two unrelated parties use similar names.

What I am suggesting is that an obvious potential conflict should sometimes require a closer look.

If the risk is obvious enough to sell protection, why isn't it obvious enough to trigger verification?

This is what really struck me during my conversation.

A registrar can explain to an established business owner:

"Someone could register your company name under another extension, create a website or email address and potentially impersonate you. You should purchase those extensions to protect yourself."

If the registrar can identify that risk well enough to sell defensive registrations because of it, why shouldn't the same risk matter when an unrelated person attempts to purchase that domain?

Why couldn't the registration system say:

"This distinctive name is already associated with an established business. Please provide additional information demonstrating your legitimate reason for registering this domain."

That doesn't mean automatically refusing the registration.

It means applying reasonable due diligence before potentially handing someone a powerful tool for impersonation.

We shouldn't wait until after someone becomes a victim

Canada already has mechanisms for dealing with bad-faith domain registrations.

For .ca domains, the Canadian Internet Registration Authority, or CIRA, operates a dispute-resolution process for certain bad-faith registrations. CIRA also has procedures for reporting malicious or abusive .ca domains.

Those protections are important.

But they largely address the problem after the suspicious domain has already been registered.

By then, a fake website may have been created.

An email account may already exist.

Customers may already have received messages.

A business owner may then have to discover the problem, gather evidence, report it, pursue a dispute, and potentially obtain legal assistance.

Why shouldn't at least some effort be made to prevent obvious cases before they reach that point?

This isn't only about protecting businesses

This is ultimately a consumer-protection issue.

Imagine receiving an invoice from:

one month and then receiving another from:

Would every customer notice?

What if the email looked professional?

What if it contained the company's logo?

What if the website looked almost identical?

What if the message instructed the customer to send payment to a different bank account?

The legitimate business suffers reputational damage, but the customer can suffer the actual financial loss.

As websites, email templates, automated content and artificial intelligence become easier to use, creating something that looks legitimate is becoming easier too.

That makes identity verification increasingly important.

Registrars should have some responsibility too

I do not believe a registrar should automatically be blamed every time someone later misuses a domain.

That would be unreasonable.

But I also don't believe its responsibility should end at:

"The domain is available, so here you go."

There should be some level of preventative responsibility where clear warning signs exist.

Possible safeguards could include:

  • automated checks for exact or very close matches to registered corporations, business names or trademarks;

  • enhanced verification when a proposed domain presents an obvious impersonation risk;

  • additional checks when the proposed domain will be used for commercial or financial activity;

  • clearer disclosure to businesses explaining exactly what defensive domain registration does and does not protect;

  • faster mechanisms for legitimate businesses to challenge domains being used for impersonation; and

  • greater responsibility for registrars to respond when their systems identify an obvious conflict.

The objective shouldn't be to give a company ownership of every possible combination of words on the internet.

The objective should be to make deliberate impersonation more difficult.

Small businesses should not have to buy the entire internet

Small businesses already pay for websites, hosting, cybersecurity, email systems, insurance, accounting software, license's, marketing, taxes and countless other operating expenses.

Telling them that they should also continuously purchase every new domain extension that becomes available is not a sustainable answer to online fraud.

Today it might be .net.

Then .org.

Then .info.

Then .ai.

Then .io.

And there will always be another one.

Defensive registration can be part of a company's strategy.

It should not be treated as the primary solution to a systemic impersonation problem.

I have written to both the Alberta and federal governments

I have now raised this issue with both the Government of Alberta and the federal government.

I have asked them to consider whether:

  • domain registrars should have greater preventative responsibilities;

  • enhanced verification should occur in higher-risk registrations;

  • defensive domain products should be explained more clearly to consumers;

  • businesses should have quicker ways to stop clear impersonation; and

  • governments, registrars, registries and organizations such as CIRA should work together on better preventative safeguards.

I don't expect one letter to rewrite the domain-name system.

But these conversations have to start somewhere.

Other Canadians can write too

If you are a business owner or consumer and believe this issue deserves attention, you can write as well.

At the federal level, the current Minister of Industry, Mélanie Joly, can be reached at:

The federal Minister of Artificial Intelligence and Digital Innovation, Evan Solomon, can also be contacted at:

Those addresses are currently listed by Innovation, Science and Economic Development Canada.

In Alberta, consumer-protection concerns can be directed to:

Service Alberta and Red Tape Reductionservice.alberta@gov.ab.ca1-877-427-4088

The federal Office of Consumer Affairs also maintains a directory of consumer-protection offices for every province and territory, so Canadians outside Alberta can find the appropriate office in their own jurisdiction.

People with concerns specifically involving .ca domains can also contact CIRA or use its procedures for reporting abusive domains and resolving certain bad-faith registrations.

What should you say?

You don't need to write a complicated legal letter.

Explain:

What concerns you. For example, legitimate businesses can be impersonated through similar domain names.

Why the current solution isn't enough. A business cannot realistically purchase every domain extension and every possible variation of its name.

What you would like changed. Ask government to consider greater verification and responsibility at the point of domain registration.

A simple letter could say:

I am writing to ask that government examine whether domain registrars should have greater responsibility when registering domains that exactly match or closely imitate established businesses. Legitimate businesses cannot realistically purchase every possible domain extension or variation of their names simply to prevent impersonation. I believe enhanced verification should be considered where a proposed registration creates an obvious risk of fraud or consumer confusion. Registrars should also clearly explain the difference between defensive domain registration and actual security protection for an existing domain. I would appreciate having this issue reviewed as a matter of consumer protection and fraud prevention.

The more business owners and consumers who raise an issue, the harder it becomes for policymakers to assume nobody is concerned about it.

The question is worth asking

If we can identify the possibility of business impersonation before a domain is sold, why should our system rely so heavily on fixing the damage afterward?

Businesses have a responsibility to protect themselves.

Consumers have a responsibility to be cautious.

But the companies that control the gateway through which domain names are registered should have responsibilities too.

Protecting consumers from online impersonation shouldn't require legitimate businesses to buy every dot on the internet.

 
 
 

Recent Posts

See All

Comments


covured logo transparent png.png

Privacy and Security Statement
Covured Inc. is a federally incorporated Canadian business providing tax and bookkeeping services nationwide. We collect personal information solely for the purpose of preparing tax returns, managing client accounts, and complying with CRA regulations. All data is collected through encrypted forms and stored securely. We do not share or sell client data. We are committed to upholding strict privacy and confidentiality standards in accordance with Canadian federal law.

  • LinkedIn

1-800-944-1960 

covured logo transparent png.png

©2017 by insyncbookkeepingandtaxprep

bottom of page