Skip to content
PageSpeed 100 as the delivery default
Technik

Domain and Business Email: Getting the Basics Right

Domain name, ownership and your own email address: what businesses get wrong at the base, and how SPF, DKIM and DMARC keep quotes out of the spam folder.

15 min read DomainE-MailZustellbarkeitMarkenrecht

Two things are created within minutes at the start of every business's online presence, and then stay with the company for years: the domain name and the business email address. Both are often set up in passing — ordered alongside a hosting package, registered by an acquaintance, grown out of a private free-mail account. That is precisely why they are the two building blocks whose correction later costs the most effort. A domain name nobody understands on the phone quietly costs a few contacts every week. A domain registered in the name of a former service provider turns into a bargaining chip the moment you want to move. And quotes that sit in the recipient's spam folder are missing from revenue without anyone noticing the cause. This article works through both blocks in order: from choosing the name, through trademark and name rights and the question of ownership, to the three records that decide whether your mail arrives.

Domain and business email: one base, two blocksName, ownership and deliverability — the parts that get expensive later18,053,047 .de domains (DENIC)Block 1: The domain namehttps://yourbusiness.deShortunder 20 charactersSayableclear on the phoneDistinctno mix-upsCheck trademark and name rights first909,659 registered trademarks on file (DPMA)Who owns the domainThe business is the holder, not the agencycontract partner of the registry (DENIC)The AuthInfo code sits in your own folderwithout it no provider change is possibleRenewal and billing path stay in viewtermination is possible at any time (DENIC)Block 2: Your own email addressinfo@accounting@jobs@Role addresses instead of personal namesthey stay valid when someone leaves the businessAccess for at least two peopleno mailbox that nobody ever opensDeliverability: three DNS recordsSPF: who may sendlist of permitted sending pathsDKIM: the sealthe signature proves the originDMARC: the rulewhat happens in doubt, plus a reportBSI TR-03182: email authentication against spoofing3/3recordsset and verified

Why the basics cost so much later

The name space is well filled. 18,053,047 (DENIC) .de domains are currently registered; at the end of 2025 the figure stood at roughly 17.7 million (DENIC). A substantial share of the growth comes from abroad: around 2.15 million and therefore 12.2 percent (DENIC) of all .de domains belong to holders outside Germany, with the United States as the largest single group at 31.3 percent (DENIC) of foreign registrations. For an individual business this means one thing in daily practice: the obvious, short, descriptive name for your trade in your town is quite likely taken. And it is exactly during the search for a still-available variant that most poor decisions are made.

The regional figures show how densely populated the space is. Hamburg counts 329 (DENIC) .de domains per 1,000 inhabitants, Berlin 246 (DENIC) and Hesse 203 (DENIC). In absolute terms Berlin leads with 929,612 (DENIC) domains, ahead of Hamburg with 627,674 (DENIC) and Munich with 524,028 (DENIC). Anyone registering today is not searching an empty shelf but a very well stocked one.

At the same time a domain is far more than a line in the address bar. Germany's Federal Office for Information Security counted around 13.2 million (BSI) .de domains reachable from the internet in the second quarter of 2025 and explicitly describes them as attack surface; 61 percent (BSI) of them were reachable only over the older IPv4 protocol. A domain carries the website, the mailboxes, the invoice dispatch and frequently the logins to external portals. It is therefore the one technical building block that touches practically every customer contact — and the one a business can only set comfortably once.

The difference between annoyance and damage

An awkward domain name is an annoyance: you spell it out a few more times and some callers end up on a stranger's page. A domain that belongs to someone else is damage: it blocks the provider change, delays the relaunch and, in a dispute, can affect the entire email traffic. Both can be settled cleanly in half an hour at the beginning — and later only with time, money and patience.

Choosing the domain name: the phone test

The most reliable test for a domain name is not a spreadsheet but a phone call. Say the name out loud, the way you would at the end of a conversation: „just write to me at ...". If the other person has to ask whether that is with a hyphen, a double letter or a silent character, the name has failed the test. The test works so well because it checks the three requirements that matter in daily practice at once: length, sayability and distinctiveness.

Sayable on the phone

The name should be dictatable in a single breath, without a follow-up question and without a memory aid. Combinations of two familiar words work well; invented words with foreign spelling and local pronunciation rarely do. A name that can only be passed on with the addition „with a k at the end" loses a few seconds in every call and occasionally a contact.

Short enough to remember

Technically .de allows between one and 63 characters (DENIC); in practice memorability ends much sooner. A useful rule of thumb is to stay under 20 characters and use at most two word components. Every additional syllable increases the number of typing errors on vehicle lettering, business cards and invoices.

No risk of confusion

Check which domains exist when a single character changes: singular instead of plural, the missing hyphen, a different ending. If another business sits there, part of your calls and mail will move there permanently. This check takes a few minutes and can hardly be made up for later.

A second consideration is durability. A name that describes the current service very narrowly becomes a constraint as soon as the business widens its offer. Naming a single trade is impractical if two further trades join in five years. A regional reference, by contrast, is usually harmless and often helpful, as long as the region stays the same. If you are currently thinking about how the offering should be structured, our article on the pages a business website really needs offers a useful cross-check.

  • The name can be said once on the phone without being spelled out
  • It is shorter than 20 characters and consists of at most two components
  • It contains no digits that could be written either as a word or as a figure
  • It does not describe so narrowly that a later extension of the offer would look odd next to it
  • The obvious typo variants do not belong to another business
  • It can be read on vehicle lettering without stepping closer
  • It sounds the same in a voice message and in dictation

The test with unfamiliar ears

Record three name suggestions one after another on the voicemail of someone who does not know the business, and ask what they understood. What arrives there is what arrives with customers. Those five minutes replace any discussion about taste — and they reliably show which variant will work later at the reception desk, in a radio spot and on the company van.

Hyphens, special characters and other pitfalls

As soon as the preferred name is taken, the phase of workarounds begins. A hyphen here, a „24" there, an umlaut written out, a suffix such as „-gmbh" attached. Each of these variants is technically permitted, and each has its price in daily use. For .de the rules are clear: digits, hyphens and letters are allowed, but a hyphen may sit neither at the beginning nor at the end and not at the third and fourth position at the same time; upper and lower case are not distinguished (DENIC).

WorkaroundWhat happens in practiceThe better route
Hyphen chains such as „master-trade-hildesheim"Three separators have to be announced on the phone; in voice messages and dictation they regularly get lostA single hyphen, if it noticeably improves readability — or one short compound name
Umlaut written out, for example „muellermetall"Some callers type the umlaut version, land nowhere and do not try againRegister the umlaut variant as well and redirect it permanently to the main address
Umlaut domain as the main addressSome older systems, forms and address fields import it incompletelyKeep the ASCII spelling as the main address and use the umlaut variant as a feeder
Suffixes such as „-online", „24" or „-gmbh"The suffix is dropped when people remember it, and the enquiry reaches another businessDrop the suffix and choose a second word component that genuinely belongs to the business
Invented foreign words with local pronunciationEvery handover needs spelling out, and every spelling costs attentionWords that are unambiguous on the phone in your customers' language

The pragmatic way to handle spelling variants is unglamorous: define one main address, register the two or three obvious deviations alongside it and redirect them permanently to the main address. The direction matters — all secondary forms point to one single address, not the other way round. How to build such a redirect structure without losing rankings is described in detail in the article on redirects during a relaunch.

Before registering: check trademark and name rights

Registering a domain is a technical act that takes two minutes. Whether you may keep it is a legal question. The name space is narrowed not only by other domains but also by trademarks: the German Patent and Trade Mark Office counted 93,291 (DPMA) national trademark applications in 2025, after 77,224 (DPMA) the year before — an increase of roughly 20.8 percent (DPMA). 55,863 (DPMA) trademarks were registered in 2025, and the register held 909,659 (DPMA) trademarks at year-end.

The domain holder warrants that the registration and the intended use of the domain infringe neither the rights of third parties nor general law.

Paraphrased from the DENIC domain terms and conditions (DENIC)

That sentence assigns responsibility unambiguously: the registry does not check rights, it assigns names in order of arrival. Likewise, the German Patent and Trade Mark Office examines only absolute grounds for refusal such as lack of distinctiveness during a trademark application, not the likelihood of confusion with earlier trademarks (DPMA). Anyone relying on the idea that a successful registration must therefore be fine is relying on a check that nobody carried out.

  1. Search the German trademark register for the preferred name and for similar-sounding spellings, in the goods and services classes that match your own offering
  2. Include the EU trademark register as well, because EU trademarks take effect in Germany too
  3. Check the commercial register and trade directories for a company already operating under the same name — name rights arise even without a trademark registration
  4. Check whether the name is already in use as a business designation, for instance as a shop name or an established short form
  5. Where there is visible proximity to an existing sign, take legal advice before vehicles are lettered and print materials ordered
  6. Document the result of the search with a date and file it with the domain records

A DISPUTE entry cuts both ways

Anyone asserting rights to a name can apply for a DISPUTE entry with the registry; this requires a prior enquiry no older than one month and evidence of name or trademark rights (DENIC). The domain remains usable for the current holder but can no longer be transferred, and the DISPUTE holder automatically becomes the new holder if the domain is deleted. The entry initially runs for one year and can be renewed (DENIC). That protects your own rights — and it applies just as much to whoever skipped the research.

Whether your own trademark makes sense depends on the business. An electronic application with the German Patent and Trade Mark Office costs 290 euros (DPMA) including up to three classes, 300 euros (DPMA) on paper, with 100 euros (DPMA) for each further class. Protection lasts ten years (DPMA) and can be renewed for 750 euros (DPMA); after five years (DPMA) without use a trademark becomes vulnerable. For a regionally active business this is rarely the first step — but for a name that appears on vehicles, workwear and a growing website it becomes a serious consideration over time.

Dot de, dot com or an industry ending

The discussion about domain endings is often conducted with more passion than the matter deserves. For a business with German customers, .de is the obvious choice because it is expected: someone who hears the name and types it out will add .de almost automatically in Germany. Everything else has to be stated explicitly. That is the real difference between endings — not the technology, but the expectation.

EndingIn favourTo consider
.deAdded automatically in Germany; 18,053,047 (DENIC) registered domains show how anchored it is in the market; clear rules on ownership and transferIf the holder is based abroad, the registry may require a service agent resident in Germany (DENIC)
.comSensible if customers or suppliers are international, or if the name is built from English words anywayHas to be named explicitly on the phone; the good short form is often taken and traded
Industry and topic endingsCan carry the purpose in the name and are often still free for short wordsLess familiar; people substitute .de when recalling them, and pricing depends on the respective operator
Regional endingsEmphasise local roots, which can suit businesses working in one areaAdditional explanation needed on the phone and in printed material

The supply of endings is growing rather than shrinking. The Internet Corporation for Assigned Names and Numbers has opened a submission window from 30 April to 12 August 2026 (ICANN) for its next round of new generic endings. For an individual business that changes little about the starting position: a main address that sticks in the mind beats any ending that needs explaining. Anyone who does secure several endings should treat them like spelling variants — one is the address, all the others point to it.

One address is the address

Registering several endings is inexpensive and sensible, as long as it stays clear which of them is the main address. That one address appears on print materials, in the email signature, in the legal notice and in all directories. Every further ending points there via a permanent redirect. Promoting two addresses in parallel halves recognition and splits your visibility across two accounts.

Who owns the domain

The most expensive mistake in this field has nothing to do with the name. It consists of the business not being the holder of its own domain. For .de the domain holder is the registry's contract partner; the application is submitted either through a member or directly, and the contract comes into being with the registration (DENIC). If an agency, a hosting provider or a private individual is named there, the domain formally belongs to that party — with all the consequences for transfer, sale and dispute.

Domain holder

This is where the company's legal name belongs, exactly as it appears in the commercial register or trade licence, with an address for service. The details must be accurate and complete and corrected without delay when something changes (DENIC). For a holder based outside Germany, a service agent resident in Germany may be required within two weeks (DENIC).

Administrative contact

A service provider may fill this role, because it reflects technical support. It does not replace ownership. A role address belonging to the business works best as the stored contact address, so that notices still arrive when the supporting person changes.

Billing and payment path

Renewal should run through an account the business knows and monitors. If the debit goes to a card assigned to someone who has left, the renewal fails silently — and the domain drops out at a moment nobody can choose.

  • The public database entry for the domain names the business as holder, not the service provider
  • The stored address is the current business address, not the private address of someone who has left
  • The stored contact address is a role address of the business that someone reads regularly
  • The login details for the domain's administration area sit with the business, not only with the provider
  • The AuthInfo code is known or can be requested at any time by the business itself
  • The domain's expiry date is a recurring appointment in the calendar
  • Payment path and invoice recipient are clearly assigned to the business

The question that settles it

Can your business move the domain to a different provider today, without a third party's consent? If the answer is yes, ownership is in order. If it is no, or „I would have to ask", it belongs on the task list — before any relaunch, any provider change and any larger investment in visibility.

AuthInfo, transfer and renewal

Moving a .de domain to another provider is deliberately straightforward: the holder can transfer administration from the registry to a member, back again, or from one member to another; a password previously stored or requested is needed for this (DENIC). That password is the AuthInfo code. It is the key to your own domain, and it should be filed where the trade licence is: within reach, up to date, and not solely in one person's mailbox.

  1. Request the AuthInfo code from the current provider; it is sent to the holder's stored contact address
  2. Instruct the new provider to carry out the transfer with the domain name and AuthInfo code, keeping the holder details unchanged
  3. Before the change, record which records are currently set — in particular those for the website and for mail delivery
  4. Prepare those records with the new provider so they take effect immediately after the transfer
  5. Confirm the transfer and afterwards spot-check that website, mailboxes and form dispatch are working
  6. Only then terminate the old contract, so that no mailbox is switched off in the meantime

Cancelling is easier than repairing

The domain holder may terminate the contract at any time without notice period (DENIC). What sounds convenient is the flip side of the duty of care: a domain cancelled by mistake or left unrenewed becomes free and can be registered by third parties. So end the old contract only once the transfer is complete and verified — and set the expiry date as a recurring calendar entry rather than a reminder in a mailbox.

One special case deserves attention: when a domain changes holder as part of a handover, for instance in a succession, that is a separate procedure and not a technical transfer. Change of holder and change of provider should happen one after the other and be documented separately. Starting both at once tends to blur the picture of which contract currently sits where.

Your own email address as a trust signal

The second building block hangs on the first: once the domain is in place, so is the email address. The difference between an address on your own domain and a free-mail address is less technical than commercial. An address on your own domain states in a few characters that this business genuinely exists, that it runs its own infrastructure and that the enquiry will not land with a private individual. For quotes in the four-figure range, that signal is worth its effort.

AspectFree-mail addressAddress on your own domain
First impressionReads as private; a disadvantage in tenders and enquiries from companiesMatches the company name and confirms the details on the website
CommitmentThe address belongs to the person who created the accountThe address belongs to the business and survives staff changes
Sender verificationThe business has no influence over the records of the external domainSPF, DKIM and DMARC can be set and checked for your own domain
Splitting by taskEverything converges in one mailboxSeparate addresses for enquiries, accounting and applications at no extra cost
HandoverDuring illness or after a departure, access is missingAccess rights can be granted, withdrawn and documented

In practice the switch is less demanding than feared. The old address stays reachable as a forward for a while; the new address appears immediately in the signature, the contact form, quotes and directories. After a few months practically all traffic runs through the new address. The one thing that matters is not to switch the old address off quietly while it is still printed on material in circulation.

Ordering mailboxes, aliases and forwards

A common misconception: every address needs its own mailbox. That is rarely the case. An alias is simply another name for an existing mailbox — it usually costs nothing, can be created in minutes and removed just as quickly. That is exactly why it pays to work with clear role addresses from the start rather than one catch-all address for everything.

info@ for first contact

The address that appears on the website, the van and the business card. At least two people should read it, so that holidays and illness leave no gap. If you collect enquiries here, add an acknowledgement of receipt — it noticeably reduces the number of follow-up calls.

accounting@ for documents

Invoices, reminders and receipts belong in a separate inbox because they follow different deadlines than enquiries. This address appears on invoices and in supplier master data and becomes a fixed part of the filing system — changing it later is laborious, so a clean choice at the start pays off.

jobs@ for applications

Applications contain particularly sensitive data and should sit apart from general mail. A dedicated address makes access rights unambiguous and deletion periods traceable. It belongs on the careers page, not in the footer of every page.

  • Every publicly stated address is assigned to a task, not to a person
  • For every role address it is settled who reads it and who steps in as a substitute
  • Forwards are documented: which address points to which mailbox, since when and why
  • Personal addresses in the form firstname@ exist in addition but do not replace a role address
  • When someone leaves, the personal address is turned into a forward rather than deleted straight away
  • There is no address pointing to a mailbox that nobody opens any more
  • The addresses on the website match those in quotes, invoices and directories

Keep forwards clean

Forwarding to a private address is convenient and creates two problems: replies leave with the private address, and business correspondence sits outside the company. If a forward is needed as an interim solution, it should have an end date and replies should go out through the business address. For the time after that the rule is: an additional mailbox beats a permanent diversion into someone's private account.

SPF, DKIM and DMARC in plain language

When a carefully written quote stays in the spam folder, the text is rarely the reason. In most cases it is because the receiving side could not verify that the message really came from the stated domain. Three records handle exactly that, and they belong to the domain rather than to the mailbox. Germany's Federal Office for Information Security covers them in its technical guideline TR-03182 on email authentication, complemented by TR-03108 on secure email transport; the stated aim is protection against attacks that fake the identity of trustworthy senders (BSI).

SPF: the guest list

SPF is a list of the servers permitted to send in your domain's name — comparable to the list at reception showing who may enter the building today. If the sending server is not on it, the message is treated as suspicious. Important: newsletter dispatch, accounting software and the website's contact form must appear on that list too, otherwise they are missing at the check.

DKIM: the seal

DKIM places a digital signature on every outgoing message, much like a seal on an envelope. The receiving side checks the seal against a key published in the domain. If it matches, it is evidenced that the message comes from the stated domain and was not altered in transit. The key belongs to the domain, not to the individual mailbox.

DMARC: the house rule

DMARC defines what should happen when SPF or DKIM do not work out: only observe, move to the spam folder or reject. In addition, DMARC delivers reports on who has been sending in your domain's name. Those reports are the real gain — they reveal forgotten sending paths and abuse attempts before they turn into a problem.

The order of introduction is proven and unspectacular: first set up SPF completely, then activate DKIM, then set DMARC to observation mode only. The rule is tightened once the reports show over several weeks that all legitimate sending paths run cleanly — first to sorting into the spam folder, later to rejection. Anyone starting straight away with the strictest setting risks their own invoices going missing.

Forwards are the most common stumbling block

An automatic forward changes the sending path: the message arrives at its destination from a server that is not on your domain's SPF list. The check fails although nobody did anything wrong. So use forwards sparingly, know how many exist and account for them explicitly when building the records. Setting a strict DMARC rule without that view loses exactly those messages that travel via a diversion.
  • Several SPF records side by side: exactly one record per domain is valid, more than one invalidates the check
  • Sending paths added after setup — invoicing software, booking system, newsletter — that are missing from the record
  • DKIM activated, but the associated key was not carried over during a provider change
  • DMARC set to rejection without evaluating the reports beforehand
  • The sender name deviates from the domain because a piece of software sends with an external address
  • The reports land in a mailbox that nobody has opened for months

The effort for these three records amounts to a manageable half day, usually spread across a few weeks of observation. The return is deliverability that becomes more predictable, and considerably harder misuse of your own sender address. Anyone working on the attack surface of their own website at the same time is working on the same site — both topics hang on the domain.

Five traps that regularly cost money

The following five constellations appear strikingly often in project work (project experience). What they have in common is that they stay unnoticed for a long time and then surface at the least convenient moment: in the middle of a tender, just before a season, or on the day of a relaunch.

TrapHow it surfacesWhat helps beforehand
The expired domainWebsite and mailboxes are gone one morning without warning; the domain may not be recoverable straight awayExpiry date as a recurring calendar entry, payment through a company account, invoices to a role address
The former employee as contactNotices about renewal, transfer and security go to a mailbox nobody reads any moreReview the stored contact address regularly and switch it to a role address that is read inside the business
The mailbox nobody opensEnquiries sit unanswered for weeks; prospects read the silence as a rejectionDefine a substitution rule for every publicly stated address and spot-check the inbox
The domain held by the providerA change turns into a negotiation, and the AuthInfo code arrives late or not at allCheck ownership in the public database entry and keep the AuthInfo code inside the business
The silent spam folderQuotes count as ignored although they were sent; without a check the cause stays invisibleSet SPF, DKIM and DMARC, evaluate the reports and record the sending path of every application

That these oversights are not without consequence is shown by the security situation. In the reporting period from 1 July 2024 to 30 June 2025, Germany's Federal Office for Information Security counted around 280,000 (BSI) new malware variants per day and an average of 119 (BSI) newly disclosed vulnerabilities daily. Of the ransomware attacks reported to the authorities, 80 percent (BSI) targeted small and medium-sized enterprises; 950 (BSI) such attacks were reported in total. 22 percent (BSI) of the consumers surveyed said they had already been affected by cybercrime, 7 percent (BSI) within the past twelve months. A well-maintained domain with clean sender verification is not a shield — but it takes part of the effect out of one of the most common forms of attack.

When your own address is misused

If messages go out in your business's name without your involvement, you notice it through undeliverable bounces and irritated callbacks. A DMARC rule that is set and whose reports are evaluated makes that misuse visible and limits it. Complaints about unsolicited advertising and about the misuse of phone numbers are received by the Federal Network Agency through its consumer portal, which maintains running statistics on them (Bundesnetzagentur); the agency is also the competent coordinating body for the supervision of digital services in Germany (Bundesnetzagentur).

Sorted out in twelve steps

Implementation needs neither a project plan nor a budget. It consists of a series of short checks, most of which are done in a few minutes. Anyone who works through them once completely and files the results in one place buys years of quiet in an area that otherwise produces regular surprises.

  1. Open the public database entry for your own domain and check who is registered as holder
  2. Bring the stored address and contact address up to date
  3. Request the AuthInfo code and file it, together with the login details, in a place more than one person knows
  4. Set the domain's expiry date as a recurring calendar entry with four weeks' lead time
  5. Check the payment path: does the renewal run through a company account?
  6. Register the obvious spelling variants and the most important second ending and redirect them to the main address
  7. List every publicly stated email address and assign each one a task and a responsible person
  8. Create role addresses for enquiries, accounting and applications and define the substitutes
  9. Write down existing forwards, remove the unnecessary ones and note an end date for those that remain
  10. Record every application that sends in the domain's name — website form, invoicing software, booking system, newsletter
  11. Set up SPF completely, activate DKIM and put DMARC into observation mode first
  12. After four to six weeks, evaluate the DMARC reports and tighten the rule step by step

For the website side of this task, the route in XICflow is deliberately short: an existing domain is connected, the required records are shown step by step, the SSL certificate is set up, and delivery is static. The domain contract stays where it belongs — with the business. Existing mailboxes remain untouched, because only the records for the website are changed. What the feature set covers in detail, how the route from setup to publication works and which domains are included in which plan can each be read up in one place; the demo websites show the finished result.

One final point reaches beyond both building blocks: an address and a mailbox are only as good as what passes through them. A precise domain name and a reliably delivered message help little if the quote is full of technical terms nobody unpacks. How to avoid that is covered in the article on writing clear website copy. And if you are unsure whether your existing setup will hold, a look at the comparison of approaches or a short conversation about your starting position will help.

Two questions that reveal the state of play

First: can you move your domain today without anyone else's consent? Second: do you know which applications send emails in your domain's name? Anyone who answers both without looking anything up has the basics under control. Anyone who hesitates on one of them already knows the next task — and it is smaller than it feels.

Sources and studies

This article is based on data from: the domain statistics and annual statistics of DENIC eG on the stock of .de domains, their regional distribution and the share of foreign domain holders; the DENIC domain terms and domain guidelines on ownership, permitted characters, provider changes and termination, as well as the DENIC DISPUTE procedure; the trademark statistics and fee schedule of the German Patent and Trade Mark Office (DPMA) on applications, registrations, the trademark stock, application and renewal fees and the scope of examination in trademark applications; the report on the state of IT security in Germany published by the Federal Office for Information Security (BSI) for the reporting period 1 July 2024 to 30 June 2025, including the figures on reachable .de domains, malware variants, vulnerabilities and reported ransomware attacks; the technical guidelines BSI TR-03182 on email authentication and BSI TR-03108 on secure email transport; the publications of the Internet Corporation for Assigned Names and Numbers (ICANN) on the application window for the 2026 round of new generic domain endings; the consumer portal of the Federal Network Agency (Bundesnetzagentur) on complaints about unsolicited advertising and phone number misuse; and our own project experience.