UTS Standard: Internet Domain Name

Overview

The Internet domain name standard establishes requirements for the use of the Oakland University domain names. 

Scope

This standard applies to all Internet domain names registered, used, or managed on behalf of Oakland University, including subdomains, regardless of who manages the domain or its hosting environment.

Standard

The purpose of this standard is to establish processes for the acquisition, use, management, and retirement of Internet domain names representing Oakland University. The standard ensures consistency in naming, enhances the institution’s branding, and reduces risks associated with improper or insecure domain management. 

Approval of domain names may require consultation with, or approval by, relevant University areas, including but not limited to University Communications and Marketing (UCM).

Domain Names

Official Oakland University domains will be .edu.  Auxiliaries (e.g., Golf & Learning Center, Meadow Brook Hall, etc) will use an industry-recognized Top-Level Domain (TLD) (e.g., .org or .com).   

Uploaded Image (Thumbnail)
 

  • Domains must be UTS reviewed and approved; 
  • Domains must be registered through domain registrars that support security features (e.g., multi-factor authentication, DNSSEC, and WHOIS privacy protection).

Only an academic or administrative unit of the University (e.g., a school, department, center, institute or administrative organizational unit of the University) may request a third-level domain; third-level domain names will not be created for individuals or student groups. (what is a third-level domain name)

  • UTS and UCM can assist in selecting an appropriate domain name.

Fourth- and Lower-Level Domain Names

The use of fourth-level and lower-level domains will be reviewed and approved on a case-by-case basis. 

External \ Non EDU Domain Names

External domain names (e.g., .com, .org, or country-code TLDs) must be justified and approved by the Information Security Office and University Communications and Marketing.  

Examples of circumstances of authorized external domain names:

  • Contracted Software as a Service (SaaS) application or service. (I have a question about SaaS apps)
  • Personal/Student-organization websites; UTS does not support or guarantee availability.
  • Research projects.

The individual/group obtaining approval for an external domain name is responsible for any costs associated with establishing and maintaining the domain name, including initial and renewal registration fees and the costs of any external services needed to maintain the domain name service.

Use of Domain Names

The University official responsible for the academic or administrative unit with a third-level or an external domain name must ensure the web content associated with the domain name neither misuses nor misrepresents the University’s brand name and logos, and that neither copyrighted material is distributed nor trademarks are used without proper authorization from the copyright or trademark owner.  See University Brand Guidelines for more information.

Usage Requirements

  • The content being used must be in line with Oakland University brand guidelines; any unauthorized use of trademarks, logos, or copyrighted materials is prohibited.
  • The domain owner (unit head) is responsible for ensuring content accuracy and brand compliance.
  • Consult the University Brand Guidelines for detailed instructions.

Security Requirements

The following requirements will ensure the security of Oakland University domains:

  • All domains must enforce HTTPS using TLS certificates.
  • DNS records must be hosted on institutionally approved DNS providers.
  • DNSSEC is encouraged where supported.
  • DNS over TLS (DoT) is not a supported configuration
  • External hosting providers must meet institutional security requirements.
  • Other than No email (wording)

Domain Auditing & Inventory

The Information Security Office will facilitate periodic audits of official domains (e.g., oakland.edu) to ensure compliance with this standard. Domains no longer in use or conflicting with these standards must be decommissioned securely. 

Non-Compliance & Exceptions

If this standard cannot be met, a Security Exception Request must be submitted for review and approval.  

Roles & Responsibilities

Chief Information Officer (CIO)

  • Approves changes to this standard

Chief Information Security Officer (CISO)

  • Administers and enforces this standard
  • Oversees annual review and domain compliance efforts

University Communications & Marketing (UCM)

  • Ensures domain name use aligns with University branding
  • Reviews naming conventions for appropriateness

Information Security Office (ISO)

  • Reviews all domain requests
  • Conducts annual audits of all Oakland University domains
  • Advises on secure DNS and hosting requirements

Network & Infrastructure Teams

  • Support DNS configuration and infrastructure needs
  • Maintain institutionally approved DNS platforms

Definitions

  • TLD: Top-Level Domain (e.g., .edu, .com).
  • DNSSEC: Domain Name System Security Extensions.
  • HTTPS: Hypertext Transfer Protocol Secure.
  • Registrar: An entity authorized to register domain names.

Related Documents & Resources

  • 860 Information Security Policy
  • University Brand Guidelines
  • Software, Applications, and Website Purchasing Checklist Request

Additional Support

  • OU Technology Center
  • 44 Oakland Center
  • Rochester, MI 48309-4479
  • Phone: (248) 370-4357
  • Email: support@oakland.edu
  • Office Hours: M-F 8:00am - 5:00pm

Last Modified: 8/26/2026
Authority: Approved by University Technology Services (UTS) Chief Information Officer
Category: Security Standards
Status: Approved