What are the Applicant's websites / domains (main website, corporate email domains, subsidiary/franchise sites)?
This list defines what is insured and what gets scanned. Both reasons argue for completeness.
What the carrier is actually asking
The carrier wants your main website, corporate email domains, and any subsidiary, franchise, or campaign domains. It uses the list for coverage scope and, increasingly, as the input to an external scan.
Why it is underwritten
Coverage for a website usually attaches to the domains disclosed. External scanning also starts here, so the list determines what the underwriter sees before quoting. Domains omitted are both uninsured and unassessed, and the second sometimes helps until the first matters.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Domain ownership is partly discoverable and worth reconciling before answering, because most organisations own more domains than anyone can list from memory.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Registrar | All domains registered to the organisation and to individuals within it | A complete list, including defensive registrations and domains held in personal accounts |
| DNS | Active domains with published records | Which domains actually resolve and serve content, since dormant ones carry different exposure |
| Microsoft 365 | Verified domains in the tenant | Every domain configured to send mail, which is also the list that needs email authentication records |
| Certificates | Certificate transparency logs for your domains | Subdomains and services you did not know were published |
| Acquisitions | Domains inherited from acquired entities | Included, since they frequently still serve content and send mail |
Marketing campaign domains and early company registrations frequently sit in an individual employee registrar account, paid on a personal card. They serve real content, they can send mail as your brand, and they are outside every control and every renewal process.
What a defensible yes requires
- The list is compiled from registrar records rather than from memory.
- It includes acquisition and subsidiary domains.
- Domains held in personal accounts are identified and transferred.
- Every mail-sending domain has authentication records published.
- Dormant domains carry restrictive records so they cannot be spoofed.
How this answer goes wrong
The main domain is listed and a dozen others are not, several of which send mail on behalf of the business. Those domains are outside the coverage scope and outside the email authentication answer given elsewhere on the form.
Frequently asked
Do we need to list every domain?
List everything active, and defensive registrations too where the form allows. Omission means no coverage for that asset.
What about subdomains?
Usually covered by the parent domain. Certificate transparency logs are the fastest way to find subdomains you had forgotten.
Does the carrier scan these?
Increasingly yes, before quoting. Assume the list you provide is the list that gets scanned.
What about domains we no longer use?
Keep them registered with restrictive email authentication records. A lapsed domain can be re-registered by anyone and used to impersonate you.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture