RBI .fin.in — NBFCs & Financial Institutions

Your domain changes. Your mailbox doesn't.

RBI is moving India's financial sector onto dedicated domains — .bank.in for banks, .fin.in for NBFCs and other financial institutions. Changing the domain is the easy half. Moving every mailbox without losing a single message is the hard half. That's the half we do.

100,000+ mailboxes migrated Zero mail lost Data stays in India 25+ years, national-scale
What this actually means for you

A domain mandate is really an email project

RBI's directive moves regulated entities to dedicated financial-sector domains to cut phishing and impersonation. Your website can move in an afternoon. Your email is where the risk, the cost and the disruption live.

01

Every address changes

Each mailbox gets a new identity on the new domain. Multiply that by every employee, every shared inbox, every automated alert and every system that sends mail.

02

The outside world doesn't know

Customers, lenders, auditors, vendors and regulators all hold your old address. Mail sent there has to keep arriving, or it is business lost silently.

03

History has to come with you

Years of correspondence — much of it evidence in a dispute or an inspection — must arrive intact, searchable and with its structure preserved.

04

Trust has to be rebuilt

A brand-new domain has no sending reputation. Without SPF, DKIM, DMARC and DNSSEC configured correctly from day one, your mail lands in spam — or gets spoofed.

The gap nobody closed

Your website moved. Your email didn't.

It is the most common position in the sector right now: the domain is registered, the website resolves, the compliance box looks ticked — and mail is still flowing on the old domain, because moving it was too risky to attempt without a plan.

Registered, not migrated

Holding the new domain is not the same as operating on it. Until your people send and receive from it, the anti-phishing benefit the mandate exists to deliver simply isn't there.

Deferred, not solved

Email got postponed because a bad cutover means lost customer mail. That instinct is right — the answer is a migration method where a cutover moment never happens at all.

Quietly widening

Every month on the old domain is another month of phishing exposure against a name your customers no longer have a reliable way to verify.

How we do it

Parallel Domain Delivery

One mailbox. Both addresses. No cutover moment, and therefore no window in which mail can be lost. The old domain keeps delivering into exactly the same inbox for as long as you need it to — anywhere from one month to twelve, your choice — and then retires on your schedule. Not abruptly, and not indefinitely.

What you're worried aboutA conventional cutoverParallel Domain Delivery
Losing mail in transitA switchover window where mail can bounce or vanishBoth domains live at once — no window, no loss
DowntimePlanned outage, usually a weekendZero downtime — users keep working throughout
Contacts using the old addressBounces, or a forwarder that breaks repliesDelivered to the same mailbox, replies work normally
How long you get to transitionA date fixed by the vendor's cutover plan1 to 12 months — you choose, then a managed sunset
Password resets at scaleNew credentials for every userNo password change — same credentials
Retraining staffNew interface, new habits, helpdesk spikeNo learning curve — same interface, same workflow
Reconfiguring devicesEvery desktop, laptop and phone touchedNo new configuration on the client side
Mail historyPartial or lossy export/importFolder structure and history preserved
Deliverability on a new domainAn afterthought — mail lands in spamSPF, DKIM, DMARC and DNSSEC configured up front

IDRBT is the sole authorised registrar for .bank.in and .fin.in domains. IDRBT issues your domain — XgenPlus does everything after that.

Track record

100,000+ mailboxes migrated. Zero mail lost.

Three banks already migrated onto their RBI-mandated .bank.in domains, plus five NBFCs — at national scale, on Indian infrastructure. Migration at this size under this mandate is not a capability we are describing. It is work already delivered.

Sovereign by default

Data stays in India, under Indian jurisdiction. On-premise, sovereign cloud, private cloud or hybrid — deployed the way your risk policy requires, not the way a global vendor prefers.

Security built in, not bolted on

PKI, S/MIME, DLP and protocol-level anti-spam ship as part of the platform. Data Xgen Technologies Pvt. Ltd. was recognised for “Excellent Encryption Solutions in India” at the National Cyber Security Summit & Awards 2019.

Built for Indian regulation

Audit trails, retention and access evidence designed around what RBI inspections and IS audits actually ask for. See our RBI-aligned BFSI email security detail.

Migration FAQ

The questions every institution asks first

Will mail sent to our old address still reach us?
Yes. During the transition both your old and new addresses deliver into the same mailbox, so anyone still using the old address reaches you normally and your replies work as expected. Nothing bounces and nothing is silently dropped.
Will we lose any email during the migration?
No. Because both domains run in parallel there is no cutover moment for mail to fall through. We have migrated more than 100,000 mailboxes with zero mail lost — including three banks moved onto their RBI-mandated .bank.in domains, and five NBFCs.
How much downtime should we plan for?
None. Users keep sending and receiving throughout. There is no weekend outage and no scheduled service window, because the old and new domains are live at the same time rather than being switched over.
Do our users need new passwords?
No. Users keep the credentials they already have. For an institution with thousands of staff this removes both the helpdesk load of a mass reset and the security risk that comes with one.
Will staff need training on a new system?
No. The interface and workflow stay the same, so there is no learning curve and no productivity dip. For most users the only visible change is their address on the new domain.
Does every desktop and mobile device need reconfiguring?
No. Client-side reconfiguration is not required. This is usually the single largest hidden cost in a domain migration, and it is the one most institutions discover only after committing to a cutover approach.
What happens to years of existing mail?
It comes with you, intact. Folder structure and message history are preserved and remain searchable — which matters when old correspondence is evidence in a dispute, an audit or an RBI inspection.
How long can we run both domains?
As long as your organisation needs, from one month up to twelve. You set the window based on how quickly your customers, partners and systems adopt the new address, and the old domain is then retired on a managed schedule. We do not recommend running it indefinitely: the mandate exists to give customers a domain they can trust, and an old domain left live works against that.
Can XgenPlus register our .fin.in or .bank.in domain?
No — IDRBT is the sole authorised registrar, appointed via NIXI and MeitY, and registration uses the digital signature certificates of your designated officials. We take over once IDRBT has issued the domain and handle the entire email migration onto it.
Our mail is on Google Workspace or Microsoft 365 — can you migrate that?
Yes, and it is a common starting point for NBFCs. Moving to the new domain is also the natural moment to bring mail onto Indian, sovereign infrastructure, since data residency and jurisdiction are already part of the same compliance conversation.
Will our mail land in spam on a brand-new domain?
Not if the new domain's sending reputation is established properly. SPF, DKIM, DMARC and DNSSEC are configured as part of the migration rather than left as a follow-up task, which is the usual reason a freshly migrated institution suddenly has deliverability problems.
We are an NBFC and .fin.in is not open to us yet. What should we do now?
Prepare. The work that determines whether a migration is smooth — mailbox inventory, shared and system-generated senders, retention rules, DNS and authentication readiness — is all doable before the domain exists. Institutions that start here migrate in a fraction of the time once registration opens.

Plan your migration before you need it

Tell us your institution type and roughly how many mailboxes you run. We will walk you through what the move looks like for you — what changes, what doesn't, and how long it takes.

Plan your .fin.in migration