You need a separate domain key for every one of your domains (including if you have the .
co.uk and .com versions of your domain, or at least we had to do that).
Re the change in email address for your employees, I thought an employee update would work, but you'd need to either manually set the password or trigger the "set up your password" process as technically all of these are new user logins. I'm pretty sure roles should persist though as long as it's done through a single update and you never untick the "has login" checkbox