Defensive registration is worth doing for a small number of specific names and is a subscription to nothing for the rest. The distinction is whether holding that particular name removes a risk you would otherwise carry.
The ones worth holding
| Name | Why |
|---|---|
| The brand in the TLDs your customers use | Your .com, .net, .org and your home-country ccTLD. Customers type these without thinking. |
| Single-character errors on the primary brand | A small, finite set. These capture real mistyped traffic, which has value beyond defence. |
| Names you have advertised | A campaign URL on a product name is a name customers will type and an attacker knows is being typed. |
| Names a former employee or partner might hold | Cheaper to register now than to recover later. |
| Anything already used against you | If a campaign has burned a name, acquiring it on expiry removes its reuse. |
The ones not worth holding
- Combosquats. Unbounded by construction. You cannot hold
brand-login,brand-secure,brand-billing,brand-verifyand every other word. - The long tail of TLDs. Hundreds exist. Customers transact in a handful.
- Homoglyph variants at scale. Large, and the registry restrictions on mixed scripts already close much of it.
- Bitsquats, below very large query volumes.
If you hold one, use it
A defensively registered domain should: redirect to your real site (captures mistyped traffic) publish v=spf1 -all publish _dmarc p=reject; sp=reject; rua=... publish *._domainkey v=DKIM1; p= publish MX 0 . be on auto-renew, with the rest of the estate A defensive registration left with no records is a domain you are paying for and not protecting.
The renewal is the real cost
A registration is ten dollars once and ten dollars every year afterwards, forever, across an estate that only grows. Fifty defensive names is a permanent line item and fifty more things to keep on auto-renew — and a defensive domain that lapses is worse than never having held it, because it is now available with your brand and some history.