The question nearly always arrives after a scare: somebody registered a variant of your name, or a salesperson sent the email that opens with "we have received a request for your company's domain in Asia".
The short answer: two or three domains, not twenty. The longer answer needs two things separated that usually get confused — protecting a brand, and occupying extensions.
The minimum set, for an Italian company
The .it. It is the extension Italian customers try first and the one that carries local credibility. If the company trades in Italy, this is the primary domain, regardless of which one the website runs on today.
The .com. Less for the traffic than because it is the first variant anyone would try, and the one somebody with bad intentions would register to look like you. It costs little and closes the widest door.
The .eu, if you sell across Europe. Useful if you have customers outside Italy, or expect to. If you sell only locally, it can be skipped without regret.
That is three registrations. Two of them point at the site, which is fine: a domain that redirects to the main one is still yours, and nobody else can use it.
The variants worth considering
Not extensions: the spellings of your name. Those are what get used to impersonate you, and this is where defensive domains earn their cost.
Worth looking at, and deciding case by case:
- with and without a hyphen, if your name contains one:
mario-rossi.comandmariorossi.comare two domains and customers get it wrong; - the most likely typo, the real one, not every imaginable one. Look at a keyboard: the letter next to the right one;
- the form with and without the legal entity:
rossi.comandrossiltd.com; - singular and plural, if the name has both.
The rule for stopping: register a variant if a person acting in good faith might type it by mistake, or if it is the first one somebody would use to imitate you. Not the others.
Why buying twenty protects nothing
The "let's occupy every extension so nobody can use them" reasoning has three problems.
There are hundreds of extensions. You will never hold them all, and whoever wants to impersonate you will use the one you left free — or a domain that looks nothing like yours, because in an email scam the display name matters more than the address.
The cost is annual and never ends. Twenty domains are a perpetual renewal, and the story always ends the same way: after three years nobody remembers why they exist, one expires through inattention, and that is the one somebody else picks up. A forgotten portfolio is worse than a small one.
That is not where the fraud happens. The frauds that really cost money do not come through a lookalike domain: they come through an email that looks like yours and a payment made without verification. Defensive domains do nothing against those.
What actually protects, in order of effectiveness
1. Email authentication. SPF, DKIM and DMARC configured properly make it impossible to use your exact domain in the sender. It costs three records and a few weeks of attention, and it closes the most convincing route a fraudster can take. It is incomparably more effective than ten defensive registrations, and it is done once — it is the substance of business email.
2. A registered trademark. A trademark gives you standing to have a bad-faith domain removed. Without one, the reassignment procedure is far harder. If the company name is worth anything, the trademark protects more than any purchase of extensions.
3. Control over the domains you already hold. Correct ownership, a company email on the holder record, auto-renewal, transfer lock, two-factor authentication. A main domain lost to expiry does more damage than ten variants never bought.
4. Monitoring. Knowing when a domain similar to yours appears, and reacting then, costs less than buying every imaginable variant in advance.
That email from the Asian reseller
It deserves a paragraph because everybody gets it. The text says, politely, that a company in China has applied to register your company's domains with Asian extensions, and that the registrar is giving you first refusal as a courtesy.
It is a sales technique twenty years old. There is no interested third party, and the urgency is the entire message. If you genuinely wanted those extensions, you would register them wherever you liked, calmly, at the ordinary price.
The general rule is the same for every defensive-domain decision: you buy them because you decided to, never because somebody frightened you into it.