HACKER Q&A
📣 wanderingmind

How do you solve the domain registration, custom email circular problem


I'm looking to transition from gmail to a paid vendor (ex: Fastmail). However, as suggested in HN multiple times, I want an email with a custom domain name. However, the domain registrars like Namecheap will require an email for registration. What email to use for registration and what if I lose that email access (Gmail block). Ideally, looks like I will need 2 domains registered at 2 separate registrars and 2 separate email providers for cross-registering. Is there a simpler/cheaper way to solve this problem?


  👤 mtz_federico Accepted Answer ✓
You could get a free email from a provider you trust. I have my domain's email in protonmail and use an email from another provider for my domain registration. I only use that email for important accounts, specially ones that I need to be able to access to control my domain (domain registration, bank, DNS/VPS hosting, etc)

👤 ok_dad
I use Fastmail with my own domain then I use a masked email using the Fastmail.com domain for my registrar account email. Because I login to Fastmail via Fastmail.com, it works fine. Masked emails are tied to a users account forever, too, so I think this method is pretty safe.

I used to just use my gmail account and forward it, but recent stories caused me to evaluate how to eliminate the Gmail weakness.


👤 newscracker
I'm not sure about cheaper, but you could use an email address from another provider without a custom domain. That could be an @fastmail.com (or other domains Fastmail supports) address or an email address from Posteo.de (paid) or Tutanota.com (free/paid) or Mailfence.com (free/paid) or ProtonMail.com (free/paid). The risk of getting locked out is negligible with these providers. Fastmail and Posteo have been around for a very long time and it's not likely they'd shutdown in the next decade or two (giving you plenty of time to re-plan as time passes).

You may change the email address with your domain registrar at any point in time to manage future risks.

My suggestions:

* stick with a (preferably paid) email account on a domain that's not yours but is likely to be around for a long time

* choose one of the common TLDs like .com or .net or .org for the email address (these TLDs have the least likelihood of disappearing or being blocked by anyone)

* make sure you keep the email address active (by logging in and/or paying on time)


👤 jhoelzel
Its allwayas a problem in the beginning but yes email is the defacto -auth- mechanism out there.

I have been and will always be using exchange from a reputable source (in my case OVH). I pay money for my email because its now their problem to keep it running. After that I add dns protection to my domain so it can not be changed on a whim. For it i have like 100 aliases setup which I give out to the vendors I use.

But yes, after initially signing up with a freemail, I changed my main email to the one provided by OVH. Why? because I can verify myself with my invoices even if two FA and everything else has been taken over.

There really is no ideal setup, because email was not designed for it. Its a messaging protocol and not an auth mecahnism, that it can be used that way is coincedence.

USE 2FA. Use a dedicated device for auth, because those are designed to be with you at all times. Like actual keys.

The probability that someone will actually hack your icloud backup with your 2fa app backed up into it, are way less likely then one of your passwords leaking.


👤 danwee
Cant' you just change the email you used for registration later on?

👤 egberts1
That’s why your domain provider should allow your account to have:

- backup emails and/or

- editable email field(s) that is secured by your 2FA/MFA/SMS/TOTP


👤 jrootabega
Anybody know any good, tested practices for reducing the risk of your Gmail/whatever getting blocked? Do you think if you don't use it for social purposes, don't buy or sell from Google services with it, always log in from nonsuspicious IPs in the same country, etc, that your chances of a ban will be significantly reduced?

👤 bombcar
What I have is two domains that have differing expiration times. But it hasn’t really been a problem.

👤 bell-cot
Do you have a "default" e-mail account like "your_name123@your_isp.net"?

Obvious downside: you gotta keep real careful track of where you use an e-mail address like that. If it's your "final/reset" contact, and you change ISP's...


👤 whatatita
If you decide to use a webmail site, you can use the default email they provide as the registration email for the domain. Then, use the same webmail with the custom email too.

I use Protonmail for both and it works perfectly.


👤 pid-1
You can edit your primary email in namecheap, as well as all contacts.