The .ch domain is Switzerland’s country-code top-level domain, and unlike most European ccTLDs it has no local-presence requirement — anyone anywhere can register one, which is why it shows up on plenty of sites that have never been near Zurich.
That single fact is most of what people are actually asking when they search for it. The rest of the search results are registrar landing pages that want to sell you the name and then stop talking. This post covers the part that comes after the checkout page: the records you set, the certificate you need, and the handful of Swiss-specific details that will bite you if you assume .ch behaves like .com.
Table of contents
- What .ch is, and why the letters do not spell Switzerland
- Who can register one, and what you will be asked for
- DNSSEC is the part of .ch worth knowing about
- What you actually configure once the name is registered
- When .ch is the right choice and when it is a tax
- How this fits the rest of the stack
- FAQ
What .ch is, and why the letters do not spell Switzerland
The two letters come from Confoederatio Helvetica, the Latin name for the Swiss Confederation. That sounds like trivia until you understand why the Latin was used: Switzerland has four official languages, and picking German, French, Italian or Romansh for the country’s own domain would have been a political statement. Latin was the neutral option. The ISO 3166 country code inherited the same logic, and the domain inherited it from ISO.
The registry is SWITCH, a foundation that has run the zone since the late 1980s. Registrations go through accredited registrars rather than directly with the registry, which is the standard arrangement and means your experience of .ch is mostly your registrar’s experience of .ch.
Two-letter subdomains under .ch are reserved — they map to the Swiss cantons — so you will not be registering zh.ch for your project. Beyond that reservation the namespace is open, which is a meaningful difference from ccTLDs that gate registration behind a local company registration or a physical address in-country.
One consequence of the open policy: .ch has a healthy trade in domain hacks, names that read across the dot. Any word or name ending in the letters c-h is a candidate, and a lot of them are long gone. If you are searching for a short .ch you are competing with people who bought them a decade ago on exactly that logic.
Who can register one, and what you will be asked for
There is no residency test, no company registration requirement, and no trading-name check. You supply registrant contact details, the registrar pushes them to SWITCH, and the name is yours for the term you paid for. This is genuinely simpler than .de, .fr, .it or .eu, all of which apply some form of geographic or legal-entity gate.
What you will notice is the price. .ch tends to sit well above .com at most registrars, and renewal is typically higher than registration. Budget on the renewal number, not the first-year number, because the first year is the one designed to look attractive.
Registrant data handling follows Swiss data-protection law rather than the ICANN gTLD regime, which in practice means the public WHOIS output is sparse. Do not plan any workflow around scraping .ch WHOIS for contact details; you will get a registry response and very little else.
Transfers between registrars use an authorisation code, same as most TLDs. The one thing worth checking before you start is the registrar lock status — a transfer attempt against a locked domain fails silently at some registrars and produces a confusing error at others.
DNSSEC is the part of .ch worth knowing about
SWITCH pushed DNSSEC adoption harder and earlier than most registries, including running incentive programmes for registrars to sign customer zones. The result is that a significant share of the .ch zone is signed, and a signed zone behaves differently when something goes wrong.
The practical implication: if you sign your zone and then change nameservers without updating the DS record at the registry, your domain does not degrade gracefully. Validating resolvers will refuse to answer at all, and the site is unreachable for anyone behind one — which today is most people. It is a hard failure, not a slow one.
The safe sequence for a nameserver change on a signed .ch is: remove the DS record at the registry, wait for the old DS TTL to expire, move the nameservers, then re-add the DS for the new provider’s key. Skipping the wait is the single most common way people take a signed domain offline.
If you are not ready to operate DNSSEC properly, do not half-enable it. An unsigned zone is a normal, defensible configuration. A zone with a stale DS record is an outage waiting for the next resolver cache to expire.
What you actually configure once the name is registered
A domain on its own does nothing. It is a name with no answer behind it until you create records. The minimum set for a site is smaller than most guides suggest.
- An A record on the apex pointing at your host’s address, or an ALIAS/ANAME if your DNS provider supports it and your host gives you a hostname rather than an IP.
- A CNAME on
wwwpointing at the same place, plus a redirect so one of the two is canonical and the other sends visitors to it. - A CAA record naming the certificate authority you intend to use, so nobody else can issue for your name.
- MX records only if you are actually receiving mail on the domain — and if you are not, an MX-less domain with a null SPF record is better than leaving it open.
Certificates are the step people forget until the browser warning appears. A .ch name gets a certificate the same way any other name does, through an ACME challenge that proves you control the domain. On a managed platform this is automatic once the DNS resolves; on a server you rent, it is a client you install and a renewal timer you had better verify actually fires.
Propagation is the other source of confusion. Nothing propagates — resolvers cache, and the cache expires on the TTL you set. Drop the TTL to a few minutes a day before you plan a change, make the change, then put the TTL back. That converts a mysterious multi-hour wait into a predictable one.
When .ch is the right choice and when it is a tax
The honest case for .ch is Swiss market presence. If your customers are in Switzerland, a .ch reads as local in a way .com does not, and the Swiss market is small enough and wealthy enough that the signal is worth paying for. Swiss users notice, and a meaningful share of them prefer it.
The weak case is using .ch purely for a domain hack because your brand ends in those letters. It works, and plenty of sites do it, but you are paying a premium ccTLD price every year for a naming pun, and you are inheriting Swiss registry policy for a business with no Swiss connection. That is a fine trade if you have thought about it and a bad one if you have not.
The case nobody makes but should: .ch is not a privacy jurisdiction for your website. Swiss data-protection law governs the registrant record at the registry. It says nothing about where your server is, who can subpoena your host, or what your application logs. Choosing .ch because it sounds discreet is confusing a name with an architecture.
Whatever you decide, the domain is the cheap part. The server, the database, the storage and the bandwidth are the numbers that recur and grow. A name is a fixed annual line item; infrastructure is the one that surprises people.
How this fits the rest of the stack
A domain is a pointer. What it points at is where the money and the operational risk live — the service that serves the request, the database behind it, the storage the uploads land in, and the bandwidth all of that consumes. Before committing to a stack, the RunxBuild hosting calculator puts those line items on one screen so the monthly number is something you decided rather than something you discovered. On RunxBuild, custom domains and their certificates are handled as part of the deploy: point the record, and the certificate is issued and renewed without a cron job you have to remember to check.
Useful related references:
- What Is a .link Domain, and When Does It Fit a Project?
- Domain Squatting: What It Is, What You Can Do, and What Is Not Worth Doing
- What Is a Parked Domain? And Why Yours Might Be a Liability
- Custom domains and certificates on RunxBuild
FAQ
Can anyone register a .ch domain, or do you need to be in Switzerland?
Anyone can. There is no local-presence, residency, or company-registration requirement — which puts .ch in a minority among European country-code domains. You supply registrant contact details through an accredited registrar and that is the whole gate.
Why is .ch more expensive than .com?
Country-code registries set their own wholesale pricing and .ch sits higher than the gTLD market rate. Renewal is usually higher again than the first year. Compare the renewal price across registrars rather than the promotional registration price, because the renewal is the number you pay every year after the first.
Do I need DNSSEC on a .ch domain?
You are not required to sign your zone. But .ch has unusually high DNSSEC adoption, so if you do sign it, treat the DS record at the registry as part of any nameserver change. Moving nameservers while a stale DS record is published takes the domain fully offline for anyone behind a validating resolver.
How long does it take for a new .ch domain to work?
The registration is live in the zone within minutes. What varies is how long resolvers hold old answers, which is governed by the TTL on the records — not by any propagation process. On a brand-new name with no prior records there is nothing cached, so it typically resolves almost immediately.
Does a .ch domain help with ranking in Switzerland?
A country-code domain is a geotargeting signal for that country, so it can help for Swiss-intent queries and works against you for queries aimed elsewhere. It is one signal among many. Content in the right language and a host that answers quickly from Europe matter more than the letters after the dot.