For most of the twenty years I've been buying domains, I've picked registrars on price and convenience.
What's the .com renewal? Is the interface tolerable? Can I bulk update nameservers without losing an afternoon? How fast do I get an auth code? Does it play nice with the marketplaces and tools I already use?
Those are fine questions. I still ask them.
But there's another one I didn't start asking until the portfolio got big enough to matter.
Should all of it really be sitting in one account?
The case for consolidating is easy to make. One login. Renewals in one place. Bulk changes that actually work. One API to build against. Clean accounting when it's time to figure out what I spent. I've consolidated plenty myself for exactly those reasons, and I'd probably do it again.
The catch is that convenience is just concentration with better marketing.
Start with the worst case, since that's the one everybody asks about. What happens if your registrar goes under?
For .com, .net and the rest of the gTLDs, you're better protected than you'd expect. If an accredited registrar loses its accreditation or its agreement isn't renewed, ICANN doesn't leave registrants holding nothing. It runs a process to find a qualified registrar to take over the names, then moves them in a bulk transfer. The transfer costs you nothing and it doesn't change your expiration dates.
That's genuinely reassuring. It's also not the whole story.
A normal inter-registrar transfer adds a year to your registration term. A bulk transfer doesn't. So if you've got names coming up for renewal in the middle of all this, that's your problem to solve, not the registry's. The gaining registrar is also allowed to refuse outbound transfers for the first 60 days after the bulk move, at its own discretion, and ICANN specifically permits that. Which means you could spend two months parked at a registrar you never chose, unable to leave.
And this only covers gTLDs. Your ccTLDs live under whatever rules that registry wrote, and they aren't part of the process at all.
Now the boring stuff, which is honestly a lot more likely to actually happen to you.
Account compromise. One login controlling every name you own is a bad night waiting to happen. Unique password, two-factor, current recovery email and phone, all of that should be table stakes by now. But two separate accounts means somebody who gets into one hasn't gotten everything.
Transfer locks are the other one that catches people. As the rules stand today, a domain can't be transferred for 60 days after initial registration or for 60 days after a registrar transfer. A change of registrant triggers its own 60-day lock, and while registrars can offer an opt-out, you have to take it before you make the change. Not after. I've watched more than one investor find that out the hard way.
That last lock is on its way out. The GNSO Council signed off on 47 recommendations from the Transfer Policy Review working group back in March 2025, and the ICANN Board adopted them this past June. The change-of-registrant lock goes away entirely. The registration and post-transfer locks drop to 720 hours, which is 30 days.
Before anybody throws a party, adopted isn't implemented. An Implementation Review Team still has to turn 47 recommendations into actual policy language, and then every registrar has to build it. The registrar stakeholder group asked for an 18-month buffer once that work wraps up. Plan on the 60-day rules being what your registrar enforces for a good while yet.
Pricing is its own argument. A registrar that's cheap this year isn't obligated to stay that way. Renewal prices move. Promo programs quietly disappear. Registrars are stronger on some extensions than others. Keeping a second door open makes it easier to move inventory when the math changes.
Then there's something we deal with now that barely existed ten years ago. API dependency.
A lot of us have registrars wired into portfolio tools, marketplaces, ownership verification, our own scripts. Every one of those integrations makes one company's uptime, policy decisions and rate limits your problem. I've had a Namecheap API key sitting at the center of a script I rely on, and it did occur to me that I'd built a single point of failure and then automated my dependence on it.
None of which means you should scatter a thousand names across fifteen registrars.
That's just a different mess. More logins. More renewal notices that go to the wrong inbox. More payment methods to keep current. More places for something to slip.
There's a middle. For a portfolio worth real money, I like a primary registrar and one meaningful secondary. The primary holds the bulk of it because the pricing and tooling are best. The secondary is a live, funded, established account you can actually transfer into, with a slice of the portfolio sitting there so it isn't cold.
Both accounts get two-factor. Both get current recovery info. Both get a payment method that won't decline at renewal time because you replaced the card two years ago and forgot.
We talk about diversification constantly in this business. By keyword. By industry. By extension, if you're that kind of investor.
The registrar is where the assets themselves live. That's the whole business, sitting behind one password.
Maybe it belongs on the list too.




