✉️ MapleMail
Email fundamentals

Why use email on your own domain instead of a free address?

A free consumer mailbox is not wrong. It just cannot be authenticated, cannot be delegated, cannot be taken with you, and makes Canada's anti-spam identification rules harder to satisfy credibly.

The short answer

A domain you own is the difference between renting your business identity and holding it. It lets you satisfy CASL's sender-identification and 60-day contact rules credibly, publish SPF, DKIM and DMARC records so your mail can be authenticated, add and remove staff mailboxes, and keep your address if you ever change providers.

The usual argument for a business email address on your own domain is that it looks more professional. That is true, and it is the least interesting thing about it. Plenty of successful trades businesses in New Brunswick have run for a decade off a free address and nobody thought less of them. If professionalism were the whole case, the honest advice would be to ignore it.

The case is stronger than that, and it is mostly made of things that are invisible until they bite: what the law asks you to put in a commercial email, what the mail-receiving world checks before deciding whether your message is real, and what happens to your identity when a relationship with a provider or an employee ends.

What CASL actually requires, and why a domain makes it easier

Canada's anti-spam law prohibits sending a commercial electronic message to an electronic address unless the recipient has consented and the message complies with section 6(2) [1]. Section 6(2) has three parts: the message must set out prescribed information identifying the person who sent it and the person on whose behalf it was sent, must set out information enabling the recipient to readily contact one of those persons, and must set out an unsubscribe mechanism [1].

The prescribed information is defined in the CRTC's Electronic Commerce Protection Regulations. It is the name under which the sender carries on business (or their name, if there is no separate business name), a statement identifying anyone the message is sent on behalf of, and a mailing address plus at least one of a telephone number reaching an agent or voice messaging system, an email address, or a web address [2]. All of it, plus the unsubscribe mechanism, must be set out clearly and prominently, and the unsubscribe must be able to be readily performed [2]. If it is not practicable to fit it all in the message, it can live on a readily accessible web page linked clearly and prominently from the message [2].

Then come the two 60-day rules that people miss. The contact information required by paragraph 6(2)(b) must remain valid for a minimum of 60 days after the message has been sent [1]. Separately, the unsubscribe address or web page must also stay valid for a minimum of 60 days [1], and a request to unsubscribe must be given effect without delay and in any case within 10 business days, with no further action required from the person [1].

None of that says "use a custom domain". You can comply from a free address. But look at what you are asserting: this is the business, here is how to reach us, and this route will still work two months from now. An address that lives on a domain matching the business name, with a web address on the same domain, makes that assertion self-evidencing. An address on a consumer service is an assertion the recipient has no way to check, tied to an account that can be suspended, locked out, or lost with a phone number. The stakes are not trivial either: section 20 makes contravention of sections 6 to 9 a violation attracting an administrative monetary penalty, with a maximum of $1,000,000 for an individual and $10,000,000 for any other person [1].

Authentication is a domain-level thing, and it decides delivery

This is the argument that convinces technical people and gets skipped in most consumer-facing writing. Email as originally specified places no restriction on what a sending host can claim as the envelope sender or in the SMTP HELO command, which is why email on the internet can be forged in a number of ways [4]. Three protocols were built to patch that, and all three hang off a domain name.

  • SPF lets an administrative domain explicitly authorize the hosts allowed to use its domain names, so a receiving host can check that authorization [4].
  • DKIM lets a person, role or organization that owns a signing domain claim responsibility for a message by associating a domain with it; the claim is validated cryptographically by querying that domain for the public key [5].
  • DMARC lets a mail-originating organization express domain-level policies for message validation, disposition and reporting, which a mail-receiving organization can use to improve mail handling, ranging from no action through altered delivery up to outright rejection [6].

Read those three descriptions again and notice the word that appears in every one: domain. The party who gets to make these statements is the party who controls the domain. On a free consumer address, that party is the provider, and the policy they publish is written for their millions of users, not for you. You cannot authorize your invoicing tool to send as your address. You cannot sign your own mail. You cannot see a DMARC report telling you someone is spoofing you. When a recipient's mail server evaluates your message, the answers it gets back describe somebody else's infrastructure.

Worth being straight about the limit here, because it gets oversold: DMARC explicitly does not produce or encourage elevated delivery privilege for authenticated email [6]. Passing authentication is not a fast lane. It removes a reason to distrust you. That is all, and it is still the difference between a quote landing in an inbox and landing nowhere.

You own the address, so leaving does not cost you your identity

A domain is an asset with your name on it. Every address at that domain is yours, and the provider behind it is a supplier you can replace. If the service gets worse, gets more expensive, or gets bought by someone you would rather not deal with, you change where the domain's mail records point and every mailbox continues working. Nobody has to be told anything.

On a free address, the situation is reversed. The address belongs to the provider's domain, so it is theirs. Moving means a new address and a migration project that runs through every customer, supplier, bank, insurer, marketplace and login recovery path you have accumulated. Ten years of business history is attached to a string of characters you do not own. That is not usually described as lock-in, but that is exactly what it is, and it deepens every year you stay.

The same logic applies to your accumulated mail. Correspondence sitting in a personal consumer account is bound to a person, not to the business. If that person is you, fine. If it is a bookkeeper or a salesperson who leaves, the business record leaves with them, and there is no administrative route to get it back.

Staff, records, and who is accountable for what

A free consumer account has no notion of an organization above it. There is no administrator, so you cannot create a mailbox for a new hire, cannot disable one for someone who has left, cannot reset a password on an account you nominally paid for, cannot enforce two-factor authentication, and cannot retain or export mail as a business record. Every account is a private relationship between one individual and the provider, and the business is not a party to it.

That matters beyond convenience. PIPEDA's Accountability principle makes an organization responsible for personal information under its control and requires it to designate someone accountable for compliance [3]. It goes further: the organization is responsible for personal information in its possession or custody, including information transferred to a third party for processing, and must use contractual or other means to provide a comparable level of protection [3]. The Safeguards principle requires protection appropriate to the sensitivity of the information, against loss, theft, unauthorized access, disclosure, copying, use and modification, regardless of the format it is held in [3]. The Openness principle expects you to make available the name or title and address of the person accountable for your privacy practices, and to whom complaints and inquiries can be forwarded [3].

Now picture your customer list, quotes, addresses and payment discussions distributed across three personal accounts belonging to three individuals, with no way for the business to reach any of them. The obligations above are still yours. The access needed to meet them is not.

When you honestly do not need this

If you are a sole proprietor just starting out, with no staff, no marketing email, and no bulk sending, you are not doing anything wrong with a free address. It is reliable, it is free, your customers already have it, and nothing above is currently biting you. Switching has a real cost that nobody selling email likes to mention: you will spend an evening changing the address on your bank, your CRA account, your accounting software, your suppliers and your platform logins, and some contacts will keep using the old address for a year. That is a genuine expense of your time, not a rounding error.

The sensible read is that this is a threshold, not a rule. Cross it when you hire your first person, when you start emailing a list rather than individuals, when you begin sending mail through a tool that is not your inbox, or when the business needs to outlive one person's personal account. Before any of those, "later" is a defensible answer.

Do this this week

Whichever side of that threshold you are on, spend twenty minutes on one thing: register the domain that matches your business name, even if you do nothing with it yet. Domains are cheap, they are first-come, and the one thing you cannot fix later is somebody else having taken yours. Point it at nothing, park it, leave it. Then, if you already send anything that looks like marketing, open your last such message and check it against section 6(2): is the business named, is there a mailing address, is there a way to reach you that will still work in 60 days, and is there an unsubscribe a person could actually use [1]? Fix whichever of those four is missing. That is the compliance work, and it is worth doing before the domain work.

Frequently asked questions

Is it illegal to run a Canadian business from a free Gmail address?

No. Nothing in Canadian law requires a business to use a custom domain. CASL regulates commercial electronic messages, not which mailbox you use. What CASL does require is that a commercial electronic message identify who sent it, give contact information that stays valid for at least 60 days, and carry an unsubscribe mechanism. You can satisfy that from a free address; it is just harder to do credibly.

What exactly does CASL make me put in a commercial email?

Section 6(2) requires the message to set out prescribed information identifying the sender, information letting the recipient readily contact that sender, and an unsubscribe mechanism. The CRTC regulations spell out the prescribed information: the name you carry on business under, and a mailing address plus one of a phone number, an email address or a web address. All of it must be set out clearly and prominently.

What is the 60-day rule in CASL?

Two separate 60-day rules. Section 6(3) says the contact information in a commercial electronic message must stay valid for a minimum of 60 days after the message was sent. Section 11(2) says the same about the unsubscribe address or web page. So an address you might abandon, or one tied to an account you could lose access to, is a compliance problem as well as an inconvenience.

Why can I not set up SPF, DKIM and DMARC on a free email address?

All three are published in DNS under a domain name, and you can only publish DNS records for a domain you control. SPF lets a domain owner authorize which hosts may use the domain in mail. DKIM lets the owner of a signing domain sign messages so receivers can verify them. DMARC lets a domain owner publish a policy for what to do with mail that fails. None of that is available to you on a domain someone else owns.

Does having my own domain guarantee my email lands in the inbox?

No, and anyone who promises that is overselling. DMARC itself states that it does not produce or encourage elevated delivery privilege for authenticated email. Authentication removes a common reason to reject or spam-folder your mail; it does not buy you reputation. Sending relevant mail that people asked for is still what builds that.

What happens to my email if I leave my provider?

If the address ends in a domain you own, you point the domain's MX records somewhere else and every address keeps working. If it ends in a provider's domain, the address is theirs, and leaving means telling every customer, supplier, bank and platform that you have a new one. That switching cost is the real reason free addresses feel sticky.

I am a sole proprietor with no staff. Do I actually need this?

Not urgently. If you have no employees, send no marketing email, and your customers already have your address, a free mailbox is doing the job and switching has a genuine cost in updated logins and confused contacts. The point at which it stops being fine is when you hire, when you start sending anything promotional in bulk, or when you need records to outlive one person's personal account.

How does PIPEDA relate to which mailbox I use?

PIPEDA does not name mailboxes, but its Accountability principle makes an organization responsible for personal information under its control, including information transferred to a third party for processing, and its Safeguards principle requires protection appropriate to the sensitivity of the information. Customer email held in an employee's personal consumer account is information your organization is answerable for but cannot actually reach.

Sources

  1. Canada's Anti-Spam Legislation (CASL) - full text — S.C. 2010, c. 23 - ss. 6(1)-(6), 11(1)-(3), 20(1)-(4)
  2. Electronic Commerce Protection Regulations (CRTC), SOR/2012-36 — Prescribed sender-identification and contact information (s. 2), form requirements (s. 3)
  3. PIPEDA, Schedule 1 (Principles set out in the National Standard of Canada) — Clauses 4.1 Accountability, 4.1.3, 4.7 Safeguards, 4.8 Openness
  4. RFC 7208 - Sender Policy Framework (SPF) for Authorizing Use of Domains in Email, Version 1 — IETF Standards Track, April 2014 - domain owners authorize sending hosts
  5. RFC 6376 - DomainKeys Identified Mail (DKIM) Signatures — IETF Standards Track, September 2011 - signing domain claims responsibility
  6. RFC 7489 - Domain-based Message Authentication, Reporting, and Conformance (DMARC) — RFC Editor, March 2015 - domain-level policy expression and failure handling

All sources verified 2026-08-28.

MapleMail runs business email on your own domain, hosted in Canada, with SPF, DKIM and DMARC set up as part of the move.

See plans and pricing