ORENTARA

Insights / Digital Operations

After the trade licence: domain, business email and website for a new UAE company

The trade licence is done. What a new UAE company needs next online: which domain to register, how business email should be set up, and who should own it all.

Michael WagnerMichael WagnerFounder and Lead Engineer, Orentara
Published28 Sept 2026Read7 min
Empty new office floor in a Dubai tower at sunrise, long shadows on a stone floor

Illustration generated with AI.

Key takeaways

  • A plain .ae domain needs no documents; co.ae needs a UAE trade licence, a free zone licence or a UAE trade mark.
  • Register the domain in the company's name and in an account the company controls, not in a freelancer's.
  • Business email is not working until SPF, DKIM and DMARC are published for the domain.
  • Decide on day one where website enquiries go and who answers them, before the site is designed.
  • Keep one written list of every account, its owner and its recovery email.

What does a new UAE company need online after the trade licence?

The licence is issued, the bank account is in progress, and the bank's onboarding form asks for the company email address. Picture the founder typing a Gmail address into that field because nothing else exists yet. For most new companies in the UAE this is the moment the digital setup starts, usually in a hurry and usually in the order in which someone asks for something. That order is the problem. Three decisions come first and are hard to undo later: the domain, the email, and who owns the accounts behind both.

This guide walks through the three in the order they depend on each other. It does not cover company formation itself, free zone choice or licence costs. Your corporate service provider handles those, and they are a different question.

Which domain should a UAE company register: .ae, co.ae or .com?

The UAE country domain is run by the .ae Domain Administration (aeDA), part of the Telecommunications and Digital Government Regulatory Authority. Its domain name policy splits the space into zones with different rules:

  • Directly under .ae (yourcompany.ae) is the unrestricted zone. Section 10 of the policy says applicants "are not required to provide any documentary evidence" beyond the general rules and the registrant warranties.
  • co.ae (yourcompany.co.ae) is restricted to commercial entities trading in the UAE. Under section 11 the registrant needs a valid UAE trade licence, a free zone licence, or a UAE trade mark application or registration, and the name must match, abbreviate or be closely connected to the company, trading name or trade mark.
  • net.ae, org.ae and others have their own restrictions and rarely matter for a new trading company.

The same policy sets the general rules for every name: between 2 and 63 characters, letters, numbers and hyphens only, no hyphen at the start or end. It also states that a domain licence does not by itself give any intellectual property rights in the name, which is worth remembering before building a brand on it. The current versions of all aeDA policies are listed on the TDRA policy page; check there or with your registrar before you apply, because the policy document itself dates from 2010.

In practice: picture a trading company licensed as Example Marine Trading LLC. Search both endings for availability first. It can register `examplemarine.ae` online in minutes with any accredited registrar listed on the TDRA registration page. For `examplemarine.co.ae` the registrar will ask for the trade licence, and the name has to match what is on it.

.ae or .com? If your customers are in the UAE, a .ae address signals that directly. If you sell across the region or internationally, a .com is often the name people type by habit. Many companies register both and point one at the other. What matters more than the ending is that you register it once, correctly, in the right name.

Who should own the domain?

This is the question that costs the most when it is answered by accident. A domain is registered through a registrar, in an account. Whoever controls that account controls the domain, and with it the website address and every email address on it.

Light falling through an open doorway onto a stone floor, a picture of who holds access
Illustration generated with AI.

The common pattern in new companies: a freelancer or an agency registers the domain in their own account "to save time". Picture what happens two years later. The freelancer has moved on, the renewal notice goes to their inbox, the card on file has expired, and one morning the website and every company email address stop working at once. Getting the domain back then means proving to the registrar that the company, not the person in the account, is the rightful registrant. If your domain already sits in someone else's account, ask for a transfer now, while everyone is still reachable: the current registrar issues a transfer code, and the domain moves into a registrar account the company owns.

Before anything is registered, settle four points:

  1. Registrant name: the company as it appears on the trade licence, not a person.
  2. Registrar account: created with a company email address and owned by the company. Give others access as users, not as the owner.
  3. Recovery email and phone: a role address such as it@ or admin@ on the new domain once email works, and a number that stays with the company.
  4. Renewal: automatic, on a company card, with reminders going to more than one person.

The same logic applies to every account that follows: DNS hosting, email, website hosting, the content management system, analytics. A website partner can build and run all of it. The company should still own it. That is the whole principle behind how we structure a website project: the client holds the keys, the partner holds a user account.

How should business email be set up for a new UAE company?

Choosing a provider is the easy part. The mainstream business email services all do the job for a small team. The part that decides whether your first emails reach a customer's inbox or their spam folder is set up in the DNS of your domain, and it is the part most often skipped.

The three records that make email trustworthy

Receiving mail servers ask three questions about every message from your domain. Each answer is a DNS record you publish:

  • SPF lists which servers may send mail for your domain. It is defined in RFC 7208.
  • DKIM adds a cryptographic signature to each message, so the receiver can check it was not altered and really came from your domain. It is defined in RFC 6376.
  • DMARC tells receivers what to do when a message fails those checks, and where to send reports. It is defined in RFC 7489.

This is no longer optional in practice. Google's email sender guidelines require every sender to Gmail accounts to set up SPF or DKIM, and senders of more than 5,000 messages a day to set up SPF, DKIM and DMARC. A new company sends far less than that, but its first contacts are often with larger companies whose filters apply the same logic.

For orentara.com the finished result is short: MX records pointing to `mx.zoho.ae`, one SPF line `v=spf1 include:zohomail.ae ~all`, a DKIM key under `zmail._domainkey`, and a DMARC record now set to `p=quarantine`.

The practical sequence: create the mailboxes with your provider, publish the provider's MX records, then publish SPF, switch on DKIM signing in the provider's admin panel and publish the key it gives you, and finally publish a DMARC record that starts in monitoring mode. Send a test message to an external address and check the headers show SPF, DKIM and DMARC as passed.

A separate guide in this series goes through the provider choice and each record step by step, and another explains why company emails land in spam when one of them is missing.

Role addresses from day one

Create info@, sales@ or hello@ as shared mailboxes or aliases, not as the personal mailbox of whoever joined first. Addresses printed on a trade licence application, a bank form or a business card tend to live for years. If they belong to a person, they leave with the person.

When should the website come, and what should it do first?

A new company does not need a large website. It needs a small one that is clearly its own, loads quickly, says what the company does and for whom, and turns a visitor into an enquiry that someone actually answers.

The last part is where many small sites quietly fail. Take a clinic whose contact form was set up by its web designer: the enquiries go to the designer's own mailbox, who forwards them when they remember. Or the form sends from the web host's server, fails SPF, and lands in the clinic's spam folder. What happens to an enquiry after someone presses send matters more to a new company than the design, because the first enquiries are the ones that decide whether the business gets going.

So before the design starts, decide three things in writing:

  • Where does an enquiry from the website go: which mailbox, or which system?
  • Who answers it, and how quickly?
  • What happens to the enquiry data afterwards: where it is stored and who can see it.

The third point is also where data protection enters. A contact form collects personal data from the first day, and the site needs a privacy notice and a sensible approach to cookies and tracking. How to build that in from the start rather than bolt it on later is covered on our page about privacy-compliant websites for UAE businesses. If you already have a site, the free readiness check shows where it stands.

A one-page checklist for the first month

  • Domain registered in the company's name, in a company-owned registrar account, with auto-renewal.
  • DNS hosted in an account the company owns.
  • Email provider chosen, mailboxes and role addresses created.
  • MX, SPF, DKIM and DMARC published and tested with an external message.
  • Website hosting and content management system in company-owned accounts, with the partner as a user.
  • A written route for website enquiries: destination, owner, response time.
  • One document listing every account, its owner, its admin users and its recovery email, stored where more than one person can find it. One line per account is enough, for example `Domain: registrar account owned by the company, admins: founder and ops, recovery: admin@`.

None of this is complicated. It is simply easier to do in the first month than to untangle in the second year.

Michael Wagner's take

The most common error we see in practice, is that either public email with gmail or similar providers get listed, that hardly signal any trust. On the other side, a lot of companies start with a "quick-and-dirty" approach of getting a website and email adress done in a hurry. Nobody is concerned about proper email delivery which leads to low ranking of the email-adress which leads to the problem, that a lot of emails land in recipients spam folder. And the third most common thing is, that nobody is concerned with data privacy. Which leads to clustered and unmanaged data collection. Until the concern arises or a controller brings this up and people realize, that they are not allowed to use the hard collected client data for further communication. And correcting such problems becomes a nightmare. So our suggestion is to start right with the professional basis and build your business on a solid basis for a thriving future.

Michael Wagner, Founder and Lead Engineer, Orentara

Written by

Michael Wagner

Founder and Lead Engineer, Orentara

Michael Wagner founded Orentara and builds its websites and automations himself. An engineer by training, he has spent his career connecting websites, databases and business processes, and now focuses on automating compliance work under the GDPR, AML rules and the UAE PDPL.

Background and experienceLinkedIn

Related insights

Want this handled properly for your business?

A direct, honest view of what a compliant web presence would take, no reading required.

Book a consultation