Governance and workforce

What are the Applicant's websites / domains (main website, corporate email domains, subsidiary/franchise sites)?

This list defines what is insured and what gets scanned. Both reasons argue for completeness.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier wants your main website, corporate email domains, and any subsidiary, franchise, or campaign domains. It uses the list for coverage scope and, increasingly, as the input to an external scan.

Why it is underwritten

Coverage for a website usually attaches to the domains disclosed. External scanning also starts here, so the list determines what the underwriter sees before quoting. Domains omitted are both uninsured and unassessed, and the second sometimes helps until the first matters.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Domain ownership is partly discoverable and worth reconciling before answering, because most organisations own more domains than anyone can list from memory.

PlatformWhere the setting livesWhat has to be true
RegistrarAll domains registered to the organisation and to individuals within itA complete list, including defensive registrations and domains held in personal accounts
DNSActive domains with published recordsWhich domains actually resolve and serve content, since dormant ones carry different exposure
Microsoft 365Verified domains in the tenantEvery domain configured to send mail, which is also the list that needs email authentication records
CertificatesCertificate transparency logs for your domainsSubdomains and services you did not know were published
AcquisitionsDomains inherited from acquired entitiesIncluded, since they frequently still serve content and send mail
Domains in personal accounts

Marketing campaign domains and early company registrations frequently sit in an individual employee registrar account, paid on a personal card. They serve real content, they can send mail as your brand, and they are outside every control and every renewal process.

What a defensible yes requires

  • The list is compiled from registrar records rather than from memory.
  • It includes acquisition and subsidiary domains.
  • Domains held in personal accounts are identified and transferred.
  • Every mail-sending domain has authentication records published.
  • Dormant domains carry restrictive records so they cannot be spoofed.

How this answer goes wrong

The main domain is listed and a dozen others are not, several of which send mail on behalf of the business. Those domains are outside the coverage scope and outside the email authentication answer given elsewhere on the form.

Frequently asked

Do we need to list every domain?

List everything active, and defensive registrations too where the form allows. Omission means no coverage for that asset.

What about subdomains?

Usually covered by the parent domain. Certificate transparency logs are the fastest way to find subdomains you had forgotten.

Does the carrier scan these?

Increasingly yes, before quoting. Assume the list you provide is the list that gets scanned.

What about domains we no longer use?

Keep them registered with restrictive email authentication records. A lapsed domain can be re-registered by anyone and used to impersonate you.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture