Why the exact-match .com is an email problem before it is a marketing one
Most companies think of their domain as a web address. The more serious exposure is in the mail that never arrives.
If your company trades as Example and operates from example.co.uk or example-solutions.com, some fraction of the people who write to you will address the message to name@example.com. They do it from memory, from a business card that was misread, or because a mail client auto-completed the wrong entry. The message does not bounce. It is delivered to whoever holds example.com.
What lands there
The misdirected traffic is not marketing noise. It is the mail people send from memory to a company they already deal with: invoices, purchase orders, remittance advice, signed contracts, candidate CVs, and password resets from services where an employee registered with the wrong domain. A catch-all mailbox on the .com collects all of it without anyone at your company knowing.
Why it matters more for regulated businesses
For a healthcare provider, a misdirected referral is a reportable breach. For a supplier to public bodies, misdirected procurement correspondence can fail a security questionnaire. For everyone, a stranger holding a mailbox that receives your customers' remittance advice is a business email compromise waiting to happen.
What to do about it
- Find out whether the .com is registered, and whether it has live mail (MX) records. A name with MX records is receiving mail.
- If it is available, register it. If it is held, acquire it. The cost is almost always less than a single incident.
- Once you hold it, either route its mail into your own system or configure it to reject mail cleanly, so senders learn they have the wrong address.
- Repeat the exercise for hyphenated and common-typo variants, and for the country-code domains of the markets you trade in.