Yes always setting your domains to .domain is the way to go. Blank only causes a cookie to be written on one domain name say
www.domain.com what happens when the user clicks a link and goes to domain.com they are logged out. Thats because those are two different domain names