
Head of Marketing - Earned Media
Digital Marketing | SEO
The RBI mandate requiring banks to migrate to .bank.in domains...
By Narender Singh
May 07, 2026 | 5 Minutes | |
The banking sector is staring down a deadline that most customers know nothing about. While you've been checking your balance, transferring money, or applying for loans online, there been a quiet regulatory shift happening behind the scenes. The Reserve Bank of India wants all scheduled commercial banks operating in the country to shift their primary domain to .bank.in by June 2025.
That not a suggestion. It a mandate.
For banks that have built their entire digital presence on .com or .co.in domains, this represents one of the largest technical migrations the Indian financial sector has seen. We're talking about moving millions of customer touchpoints, thousands of internal systems, countless third party integrations. The scale alone is daunting.
The reasoning is straightforward enough. Phishing attacks targeting bank customers have become sophisticated to the point where even tech savvy users get fooled. Fraudsters create websites that look identical to legitimate banking portals, often using domains that are just one letter off from the real thing. Customers enter their credentials, thinking they're logging into their actual bank account. You know the rest.
The .bank.in domain aims to solve this through restriction. Not just anyone can register one of these domains. There a verification process that confirms you're actually a legitimate banking entity regulated by the RBI. The idea is simple: if customers know that only real banks can use .bank.in, they can trust these domains more readily than generic .com addresses that anyone can purchase for a few dollars.
Does it eliminate phishing entirely? No. But it raises the bar significantly.
Moving a bank primary domain isn't like switching your personal blog from one hosting provider to another. The technical complexity involved touches nearly every aspect of digital banking operations.
Every customer who has bookmarked their banking website needs to be redirected seamlessly. Mobile apps need updates. Email templates need modification. SMS notifications that include web links must be reconfigured. Marketing materials, both digital and print, become outdated the moment the switch happens.
Then there the trust factor. Customers have been trained for years to recognize their bank domain. Suddenly changing it creates confusion, which ironically opens a window for the very phishing attacks the new domain is meant to prevent. Scammers will absolutely exploit the transition period.
The technical debt here runs deep. APIs that connect to payment gateways, credit bureaus, government databases. Every integration point that references the old domain needs updating. Session management systems need reconfiguration. SSL certificates must be reissued. Content delivery networks require new settings.
Security protocols that whitelist specific domains need modification. Third party vendors who integrate with the bank systems need advance notice. Even internal tools that employees use daily may have hardcoded domain references buried in legacy code nobody wants to touch.
This might be the most underestimated challenge. Banks have spent years building search engine authority for their existing domains. Every backlink, every piece of indexed content, every keyword ranking. All of that equity doesn't automatically transfer when you change domains.
Search engines need time to understand that the new domain is the authoritative source. During that transition, rankings can fluctuate wildly. For banks competing on search terms like "best home loan rates" or "open savings account online," even a temporary drop in visibility translates directly to lost business.
Proper redirects help, but they're not magic. A 301 redirect tells search engines the move is permanent, but there still a period where authority gradually transfers. Some SEO value inevitably gets lost in the process.
What happens if a bank misses the deadline? The RBI hasn't spelled out exact penalties, but regulatory non compliance in banking isn't something institutions take lightly. We're talking about potential restrictions on digital operations, public notices of non compliance, regulatory scrutiny on other fronts.
Beyond regulatory risk, there reputational damage. If your bank is the last one clinging to its old domain while competitors have all moved to .bank.in, customers notice. It sends a message about how seriously you take security, how capable your technology team is, how aligned you are with regulatory expectations.
Not every bank has the IT budget of an HDFC or ICIS. Regional banks, cooperative banks, smaller scheduled commercial banks face the same mandate but with fraction of the resources. They're expected to execute the same complex migration with smaller teams, tighter budgets, less technical expertise.
These institutions can't afford extended downtime. They can't risk losing their search rankings. They definitely can't afford a botched migration that leaves customers unable to access their accounts or makes the bank vulnerable to security breaches during the transition.
The playing field isn't level here, but the regulatory requirement doesn't account for that.
You can't flip a switch on migration day and hope for the best. The testing phase for a domain migration of this scale needs to be exhaustive. Staging environments that mirror production exactly. Load testing to ensure the new domain can handle peak traffic. Security audits to verify nothing got exposed during the move.
User acceptance testing with actual customers catches issues that internal teams miss. Beta programs where a subset of users transition early can surface problems before they affect the entire customer base. Rollback plans need to be ready in case something goes catastrophically wrong.
Banks that rush this will pay for it.
Imagine logging into your banking app one day only to find it directing you to a completely different domain. Without context, that looks exactly like a phishing attempt. Clear communication before, during and after the migration isn't just good practice. It essential for maintaining customer trust.
Email campaigns explaining the change need to go out weeks in advance. In app notifications should appear every time customers log in. Branch staff need talking points for customers who call with concerns. Social media teams need to be ready for questions and confusion.
The message needs to be consistent across all channels. Mixed messaging during a domain change creates exactly the kind of uncertainty that fraudsters exploit.
Domain migrations at this scale require specialized expertise, especially when SEO preservation is critical. DWAO has handled high risk migrations for major banks, including HDFC.com, achieving zero SEO disruptions during the transition.
Their approach focuses on maintaining search rankings while ensuring technical integrity throughout the migration process. For banks facing the June 2025 deadline with concerns about losing their digital visibility, having a partner who has successfully navigated similar transitions makes the difference between a smooth changeover and a costly setback.
1. Does the Central Bank of the UAE (CBUAE) mandate specific domains for banks?
The CBUAE heavily regulates digital banking infrastructure and data residency, but there is no universal mandate forcing banks onto a specific restricted TLD like .bank.ae. Most major institutions utilize the highly trusted .ae extension, which requires local presence verification through the aeDA (UAE Domain Administration).
2. How do we manage Arabic Right-to-Left (RTL) URLs during a migration? If the old domain used Arabic characters in the URL slugs (which are percent-encoded on the backend), engineering teams must map these exactly to the new domain. Failure to correctly interpret UTF-8 percent encoding in the redirect rules will result in massive 404 errors for the Arabic-language version of the site.
3. Are there data residency concerns when changing bank domains in the GCC? Yes. If the domain migration also involves migrating the underlying hosting infrastructure (e.g., moving to a new cloud provider), you must ensure the new servers are physically located within the UAE (like Azure UAE) to comply with CBUAE data sovereignty laws regarding customer financial records.
4. How do we handle expats searching via VPNs during the DNS propagation? Dubai’s large expat population frequently uses VPNs. During the 48 hours of DNS propagation, a user on a US VPN might be routed differently than a user on a local Etisalat connection. Keep the old server running with the 301 redirects active for at least 6-12 months to catch trailing global DNS caches and ensure no user is left behind.
5. How do we protect our Islamic Banking search rankings during a move? Islamic banking relies on highly specific semantic keywords (e.g., Murabaha, Wakala). Search engines weigh E-E-A-T (Expertise, Authoritativeness, Trustworthiness) heavily for these terms. Ensure that Shari'a board certifications and PDF fatwas linked on the old site are perfectly redirected to the new site; losing these verifiable trust documents will tank your rankings.