Why Six Domains Answer From One Address

Six of our domains route their mail to one Google Workspace account. Two of them have no website at all — an MX record and nothing else. Why that is a deliberate arrangement, what it costs, and the DNS check worth running on every domain you own.

Ganda Tech Services 7 min read
Why Six Domains Answer From One Address

We own more domains than we run websites on. Most businesses that have been going a while do.

Some were bought for projects that shipped. Some for projects that did not. Some defensively, to stop someone else having the obvious variant of a name. And every one of them can still send and receive email, whether or not anyone has thought about it recently.

Here is how ours are arranged, why, and the check that is worth running on yours this afternoon.

Six domains, one place mail lands

Six domains outside our main brand sites route their mail into a single mailbox. Anyone writing to any of them reaches the same team, and gets an answer from the address that person actually works from.

Four of the six also serve a website. Two of them have no website at all — checked live as we wrote this, they have a mail record and no address record. Type either into a browser and nothing answers.

That is intentional, and the distinction is worth understanding because it is the part most businesses get accidentally.

A domain’s mail routing and its website are configured independently. A domain can:

  • Serve a site and take mail. The normal case.
  • Take mail and serve nothing. A deliberate email-only domain, which is what those two are.
  • Serve a site and take no mail. Common and usually unintentional — mail sent to it bounces or, worse, is accepted by a default that nobody configured.
  • Do neither, while still being registered in your name and still being something anyone can attempt to send as.

Most businesses have at least one domain in each of the last two categories and could not tell you which.

Why route them at all rather than let them lapse

Three reasons, in order of how much they matter.

Someone is still writing to them. A domain from a project that ended still appears on old invoices, in old signatures, in a Google result, on a business card in someone’s drawer. Mail sent there either reaches you or it does not, and “does not” means a customer concluded you ignored them.

A registered domain you do not control is worse than one you never owned. If you let a domain lapse and someone else registers it, they inherit an address that your former customers trust, and any history that attaches to the name. Keeping it is cheap insurance.

Consolidated mail means consolidated protection. One mail provider, one place to configure authentication, one place to apply a policy. Six domains each pointed somewhere different is six configurations to keep correct, and the one nobody remembers is the one that gets abused.

★ Insight ───────────────────────────────────── The security case for routing a dormant domain is stronger than the customer-service one, and it is the reverse of what people assume. A domain with no mail records is not “safe” — it is unclaimed territory. Publishing explicit records for it, including an authentication policy that tells receiving servers to reject anything not sent through your provider, is what makes it hard to impersonate. Silence is not a policy; it is the absence of one, and receiving servers treat those differently. ─────────────────────────────────────────────────

What it costs

Worth being plain, because consolidation is usually sold as free and is not.

Every domain shares one reputation posture. If one of them is used for something that generates complaints, it is the same provider and the same infrastructure carrying your real invoices. This is an argument for care about what goes out under the lesser-used names, not an argument against consolidating.

The reply comes from the wrong domain. Someone who writes to one brand gets an answer from another. That is the trade for one team answering everything, and it is the reason we published a page listing every domain so a customer can confirm it independently rather than guess.

Authentication has to be configured per domain. Consolidating where mail lands does not consolidate the DNS records that prove you are allowed to send as each name. Each domain needs its own, and a domain you forgot to configure is the one an impersonator will choose.

The check worth running this afternoon

List every domain your business owns — registrar account, not memory. Then for each one, answer three questions.

1. Does it accept mail, and where does it go? If it has a mail record, something is receiving mail addressed to that domain. Find out what, and whether a human ever looks at it.

2. Does it have a sending policy, and is it enforcing? The records that tell receiving servers who may send on your behalf, and what to do when something fails that test. A domain with no policy, or a policy set only to “monitor”, is one that can be impersonated with no rejection.

3. Does anything still point at it? Old email signatures, old invoice templates, printed material, third-party listings. This is the one that turns up surprises.

If you are comfortable in a terminal, dig MX yourdomain.com and dig TXT _dmarc.yourdomain.com answer the first two in about ten seconds each. If you are not, your IT provider can produce the whole table for every domain you own in under an hour, and it is a reasonable thing to ask for.

What good looks like

For a business with several domains, the arrangement we would recommend — and run ourselves — is:

  • Every domain routed to one mail provider, so there is one place to configure and one place to look.
  • Every domain, including the ones with no website, carrying its own authentication records with an enforcing policy.
  • The domains with no website left with no website, deliberately, rather than pointed at a parked page full of advertising you do not control.
  • A public page listing all of them, so a customer receiving mail from an unfamiliar one of your names can confirm it without ringing a number from the email.

The last one is the piece almost nobody has, and it is the cheapest of the four.


Ganda Tech Services runs web, cloud, mobile and content operations for a group of Australian brands. Email, DNS and domain security work is handled through Cloud Geeks, and the list of every domain that reaches us is public.

Tags

Business TechnologyEmailDNSOperations