The short answer
A domain you own is the difference between renting your business identity and holding it. It lets you satisfy CASL's sender-identification and 60-day contact rules credibly, publish SPF, DKIM and DMARC records so your mail can be authenticated, add and remove staff mailboxes, and keep your address if you ever change providers.
The usual argument for a business email address on your own domain is that it looks more professional. That is true, and it is the least interesting thing about it. Plenty of successful trades businesses in New Brunswick have run for a decade off a free address and nobody thought less of them. If professionalism were the whole case, the honest advice would be to ignore it.
The case is stronger than that, and it is mostly made of things that are invisible until they bite: what the law asks you to put in a commercial email, what the mail-receiving world checks before deciding whether your message is real, and what happens to your identity when a relationship with a provider or an employee ends.
What CASL actually requires, and why a domain makes it easier
Canada's anti-spam law prohibits sending a commercial electronic message to an electronic address unless the recipient has consented and the message complies with section 6(2) [1]. Section 6(2) has three parts: the message must set out prescribed information identifying the person who sent it and the person on whose behalf it was sent, must set out information enabling the recipient to readily contact one of those persons, and must set out an unsubscribe mechanism [1].
The prescribed information is defined in the CRTC's Electronic Commerce Protection Regulations. It is the name under which the sender carries on business (or their name, if there is no separate business name), a statement identifying anyone the message is sent on behalf of, and a mailing address plus at least one of a telephone number reaching an agent or voice messaging system, an email address, or a web address [2]. All of it, plus the unsubscribe mechanism, must be set out clearly and prominently, and the unsubscribe must be able to be readily performed [2]. If it is not practicable to fit it all in the message, it can live on a readily accessible web page linked clearly and prominently from the message [2].
Then come the two 60-day rules that people miss. The contact information required by paragraph 6(2)(b) must remain valid for a minimum of 60 days after the message has been sent [1]. Separately, the unsubscribe address or web page must also stay valid for a minimum of 60 days [1], and a request to unsubscribe must be given effect without delay and in any case within 10 business days, with no further action required from the person [1].
None of that says "use a custom domain". You can comply from a free address. But look at what you are asserting: this is the business, here is how to reach us, and this route will still work two months from now. An address that lives on a domain matching the business name, with a web address on the same domain, makes that assertion self-evidencing. An address on a consumer service is an assertion the recipient has no way to check, tied to an account that can be suspended, locked out, or lost with a phone number. The stakes are not trivial either: section 20 makes contravention of sections 6 to 9 a violation attracting an administrative monetary penalty, with a maximum of $1,000,000 for an individual and $10,000,000 for any other person [1].
Authentication is a domain-level thing, and it decides delivery
This is the argument that convinces technical people and gets skipped in most consumer-facing writing. Email as originally specified places no restriction on what a sending host can claim as the envelope sender or in the SMTP HELO command, which is why email on the internet can be forged in a number of ways [4]. Three protocols were built to patch that, and all three hang off a domain name.
- SPF lets an administrative domain explicitly authorize the hosts allowed to use its domain names, so a receiving host can check that authorization [4].
- DKIM lets a person, role or organization that owns a signing domain claim responsibility for a message by associating a domain with it; the claim is validated cryptographically by querying that domain for the public key [5].
- DMARC lets a mail-originating organization express domain-level policies for message validation, disposition and reporting, which a mail-receiving organization can use to improve mail handling, ranging from no action through altered delivery up to outright rejection [6].
Read those three descriptions again and notice the word that appears in every one: domain. The party who gets to make these statements is the party who controls the domain. On a free consumer address, that party is the provider, and the policy they publish is written for their millions of users, not for you. You cannot authorize your invoicing tool to send as your address. You cannot sign your own mail. You cannot see a DMARC report telling you someone is spoofing you. When a recipient's mail server evaluates your message, the answers it gets back describe somebody else's infrastructure.
Worth being straight about the limit here, because it gets oversold: DMARC explicitly does not produce or encourage elevated delivery privilege for authenticated email [6]. Passing authentication is not a fast lane. It removes a reason to distrust you. That is all, and it is still the difference between a quote landing in an inbox and landing nowhere.
You own the address, so leaving does not cost you your identity
A domain is an asset with your name on it. Every address at that domain is yours, and the provider behind it is a supplier you can replace. If the service gets worse, gets more expensive, or gets bought by someone you would rather not deal with, you change where the domain's mail records point and every mailbox continues working. Nobody has to be told anything.
On a free address, the situation is reversed. The address belongs to the provider's domain, so it is theirs. Moving means a new address and a migration project that runs through every customer, supplier, bank, insurer, marketplace and login recovery path you have accumulated. Ten years of business history is attached to a string of characters you do not own. That is not usually described as lock-in, but that is exactly what it is, and it deepens every year you stay.
The same logic applies to your accumulated mail. Correspondence sitting in a personal consumer account is bound to a person, not to the business. If that person is you, fine. If it is a bookkeeper or a salesperson who leaves, the business record leaves with them, and there is no administrative route to get it back.
Staff, records, and who is accountable for what
A free consumer account has no notion of an organization above it. There is no administrator, so you cannot create a mailbox for a new hire, cannot disable one for someone who has left, cannot reset a password on an account you nominally paid for, cannot enforce two-factor authentication, and cannot retain or export mail as a business record. Every account is a private relationship between one individual and the provider, and the business is not a party to it.
That matters beyond convenience. PIPEDA's Accountability principle makes an organization responsible for personal information under its control and requires it to designate someone accountable for compliance [3]. It goes further: the organization is responsible for personal information in its possession or custody, including information transferred to a third party for processing, and must use contractual or other means to provide a comparable level of protection [3]. The Safeguards principle requires protection appropriate to the sensitivity of the information, against loss, theft, unauthorized access, disclosure, copying, use and modification, regardless of the format it is held in [3]. The Openness principle expects you to make available the name or title and address of the person accountable for your privacy practices, and to whom complaints and inquiries can be forwarded [3].
Now picture your customer list, quotes, addresses and payment discussions distributed across three personal accounts belonging to three individuals, with no way for the business to reach any of them. The obligations above are still yours. The access needed to meet them is not.
When you honestly do not need this
If you are a sole proprietor just starting out, with no staff, no marketing email, and no bulk sending, you are not doing anything wrong with a free address. It is reliable, it is free, your customers already have it, and nothing above is currently biting you. Switching has a real cost that nobody selling email likes to mention: you will spend an evening changing the address on your bank, your CRA account, your accounting software, your suppliers and your platform logins, and some contacts will keep using the old address for a year. That is a genuine expense of your time, not a rounding error.
The sensible read is that this is a threshold, not a rule. Cross it when you hire your first person, when you start emailing a list rather than individuals, when you begin sending mail through a tool that is not your inbox, or when the business needs to outlive one person's personal account. Before any of those, "later" is a defensible answer.
Do this this week
Whichever side of that threshold you are on, spend twenty minutes on one thing: register the domain that matches your business name, even if you do nothing with it yet. Domains are cheap, they are first-come, and the one thing you cannot fix later is somebody else having taken yours. Point it at nothing, park it, leave it. Then, if you already send anything that looks like marketing, open your last such message and check it against section 6(2): is the business named, is there a mailing address, is there a way to reach you that will still work in 60 days, and is there an unsubscribe a person could actually use [1]? Fix whichever of those four is missing. That is the compliance work, and it is worth doing before the domain work.