Domains
What is domain expiry?
Domain expiry is the point at which a domain name registration period ends, the date on which the domain owner’s paid registration lapses and the domain is no longer exclusively held by that registrant. Every domain registration has an expiry date, typically one to ten years after the initial registration depending on how long the domain was registered for. When that date passes without renewal the domain enters a series of grace periods before eventually being released for anyone to register.
Domain expiry is one of the most consequential and preventable failures in domain management. A domain that expires accidentally, a missed renewal payment, an outdated credit card, a lost email notification, can disrupt a live website, break email delivery, invalidate SSL certificates, destroy accumulated SEO equity, and enable competitors or bad actors to register the domain and use it against its former owner. The consequences of accidental expiry can take months or years to fully recover from even when the domain is eventually recovered.
Understanding the domain expiry lifecycle, the recovery options available at each stage, and the practices that prevent accidental expiry is essential for anyone managing domains, whether a single personal domain or a portfolio of hundreds of brand protection registrations.
The domain expiry lifecycle
Domain expiry does not happen instantly, it unfolds through a series of stages over weeks or months, each with different implications for the domain owner and different options for recovery.
Active registration: the domain is registered and functioning normally. The expiry date is in the future. The domain resolves through DNS, SSL certificates are valid, websites serve content, email is delivered, and redirect rules function as configured. During this period the domain owner can renew at the standard renewal price, extending the registration period for one to ten additional years.
Expiry notification period: in the weeks before expiry domain registrars send renewal reminder emails to the registrant contact email address. ICANN requires registrars to send notifications before expiry, typically at 30 days, 7 days, and 1 day before the expiry date. These notifications go to the email address on file in the WHOIS record. If that email address is outdated, changed without updating the registrar, notifications are delivered to an address that nobody monitors and renewals are missed.
Expiry date: the registration period ends. Depending on the registrar and TLD the domain may immediately begin showing symptoms of expiry, DNS resolution failing, the website becoming unreachable, emails bouncing, or there may be a brief continuation period before services are disrupted. Some registrars allow a short grace period during which the domain continues to function normally while renewal can still be completed at the standard price.
Grace period: after expiry most registries provide a grace period, typically 0 to 30 days depending on the TLD, during which the previous registrant can still renew the domain at the standard renewal price. During the grace period the domain may be placed in a hold status, suspended from DNS resolution and no longer serving content, or it may continue to function. The registrar typically displays a parking page or suspension notice at the domain during the grace period. The previous registrant can renew through the registrar’s control panel at any time during the grace period.
Redemption period: after the grace period ends the domain enters a redemption period, typically 30 days for most TLDs, during which the previous registrant can still recover the domain but at significantly higher cost. Redemption fees are set by the registry and can range from $80 to $200 or more on top of the standard renewal fee. The domain is in a pending delete or redemption grace period status, DNS resolution has stopped. The previous registrant must contact their registrar to initiate redemption and pay the redemption fee.
Pending delete: after the redemption period ends the domain enters a pending delete status, typically lasting five days for .com and .net domains. During this period no action can be taken by the previous registrant, the domain cannot be renewed or redeemed. The domain is queued for deletion at the registry.
Deletion and availability: after the pending delete period the domain is deleted from the registry database and becomes available for new registration by anyone. Deleted domains typically become available at a specific time, registries release them in a predictable pattern. Domain investors and automated registration systems, drop catchers, monitor domains in pending delete and compete to register them the moment they become available.
Consequences of domain expiry
The consequences of domain expiry range from minor inconvenience to catastrophic business disruption depending on how the domain was being used and how quickly the situation is addressed.
Website becomes unreachable: when a domain expires and DNS resolution stops visitors to the domain receive DNS errors, NXDOMAIN or connection failed. The website is completely inaccessible. Any redirect rules configured for the domain stop functioning, visitors following links to the domain arrive at errors rather than being forwarded to their intended destination. Brand traffic, campaign traffic, and backlink-driven traffic all disappears.
Email delivery fails: email addressed to the expired domain bounces. MX records stop resolving when the domain expires. Incoming emails are rejected by receiving servers. Pending emails in queues fail to deliver. Outbound emails from the domain may also be affected depending on how email authentication is configured. For domains used for business email the disruption is immediate and severe.
SSL certificates become invalid: SSL certificates are issued for specific domain names. When a domain expires the certificates remain technically valid until their expiry date but they cannot be renewed or replaced because the certificate authority’s domain validation requires control of the domain’s DNS, which has lapsed. Eventually the certificates expire and HTTPS access fails entirely.
SEO equity begins to decay: the accumulated link juice and authority associated with the expired domain begins to decay when the domain goes offline. Backlinks pointing to the domain begin returning errors. Search engines crawling those links find the domain unreachable. Over time the accumulated authority of the domain fades as it spends extended time offline. The longer the domain remains expired the more authority is lost.
Redirect rules break: any redirect configuration, whether registrar forwarding, dedicated redirect management, or server-side redirects, requires the domain to be registered and DNS to be active. An expired domain’s DNS stops resolving. All redirect rules become non-functional. Visitors following links to redirect source URLs find broken connections rather than being forwarded to their intended destinations.
Domain acquisition by bad actors: the most severe consequence of complete domain expiry, the domain reaching the deletion and availability stage and being registered by someone else. A competitor or bad actor who registers the expired domain can use it to damage the brand, setting up a fake website, intercepting emails, exploiting existing backlinks and accumulated authority for their own purposes. Recovering a domain that has been registered by someone else requires legal action, UDRP proceedings, or purchasing it from the new registrant, all expensive and uncertain.
Domain expiry and redirect management
Domain expiry has specific implications for redirect management, disrupting both active redirects and long-term redirect strategies built on domain portfolios.
Expired redirect source domains: a domain configured as a redirect source, olddomain.com redirecting to newdomain.com: becomes useless when it expires. DNS resolution fails. Visitors following links to olddomain.com receive errors rather than being redirected. Backlinks pointing to olddomain.com no longer pass link juice through the redirect to newdomain.com: the redirect chain is broken. All the SEO value the redirect was transferring disappears.
This is why maintaining registration of redirect source domains is critical, particularly for domain migration redirects. The old domain must be renewed indefinitely to keep redirects functioning and link equity flowing. The standard recommendation is to maintain the redirect source domain for at least two to three years after migration, longer for domains with significant backlink profiles.
Expired brand protection domains: a domain parking registration that expires creates an immediate brand vulnerability. The expired domain, which was being registered specifically to prevent competitors and bad actors from using it, becomes available for anyone to register. The carefully maintained redirect from the brand protection domain to the primary domain disappears. Anyone who registers the expired domain can use it however they choose, including redirecting it to competitor sites or setting up phishing pages that exploit the brand association.
Cascade effects on redirect portfolios: organisations with large domain portfolios face amplified risk from the complexity of tracking renewal dates across many domains. An expired domain in a portfolio may be a redirect source for other redirect rules, creating cascading failures when the expired domain breaks its own redirects and those redirects stop working.
Preventing domain expiry
Domain expiry is entirely preventable through a combination of automated renewal, updated contact information, and portfolio monitoring.
Auto-renewal: the most reliable prevention mechanism. Enabling auto-renewal at the registrar ensures the domain is renewed automatically before expiry, charged to the registrant’s payment method on file. Most registrars offer auto-renewal as a standard feature. Enabling it for every domain eliminates the risk of missed manual renewals.
Auto-renewal has a dependency, the payment method on file must be valid. A credit card that expires, is cancelled, or hits its limit causes auto-renewal to fail. Registrars send payment failure notifications but if those notifications are missed the domain may not renew. Keeping payment information current and monitoring for payment failure notifications is essential for reliable auto-renewal.
Multi-year registrations: registering domains for multiple years, up to ten for most TLDs, reduces the frequency of renewal events and associated risk. A domain registered for five years at once has five years before expiry rather than one year. Longer registration periods also signal commitment to the domain, some registrars and hosting providers treat multi-year registrations as a trust signal.
Updated contact information: renewal notifications from registrars go to the registrant contact email on file in WHOIS. If that email address changes without the registrar being updated notifications are delivered to an address nobody monitors. Keeping registrant contact information current, particularly the email address, ensures renewal notifications reach someone who can act on them. Many organisations use a dedicated domain management email address, not tied to any individual employee, for registrar communications.
Portfolio monitoring tools: for organisations with large domain portfolios automated monitoring tools track expiry dates across all domains and send consolidated alerts well before expiry. These tools, either standalone services or features of enterprise registrars, provide centralized visibility into domain expiry status across portfolios that might span multiple registrars.
Regular portfolio audits: periodic manual review of all domain registrations, checking expiry dates, confirming auto-renewal status, verifying payment information, provides a backstop for automated systems. Quarterly audits of a domain portfolio catch potential expiry issues that automated systems might miss, a disabled auto-renewal, a failed payment that was not resolved, a domain at an overlooked registrar.
Recovering an expired domain
When a domain expires recovery options depend on which stage of the expiry lifecycle the domain has reached.
During the grace period: the simplest recovery scenario. The previous registrant logs into the registrar control panel and renews the domain at the standard renewal price. The domain is reactivated, DNS resolution resumes, the website becomes accessible again, email delivery resumes. Depending on how long the domain was suspended DNS propagation may take a few minutes to a few hours as resolvers update their caches.
During the redemption period: recovery is still possible but significantly more expensive. The previous registrant contacts the registrar to initiate redemption, paying the redemption fee set by the registry plus the standard renewal fee. Total redemption costs are typically $100 to $250 or more depending on the TLD and registrar. The domain is restored from redemption status and reactivated.
During pending delete: no recovery is possible during the pending delete period. The previous registrant must wait until the domain is deleted and becomes available for new registration, then compete to register it. Automated domain drop-catching services monitor domains in pending delete and attempt registration the moment they become available. The previous registrant can use these services to attempt to reclaim the domain but there is no guarantee of success, other parties may also be attempting to register it.
After deletion, new registration: if the domain successfully completes deletion and becomes available the previous registrant can register it as a new registration at standard prices if they are fast enough. Drop-catching services, GoDaddy Auctions, SnapNames, DropCatch, provide automated registration attempts at the moment a domain is released. Using multiple services increases the probability of successful recovery. Success is not guaranteed, particularly for valuable domains that many parties may be competing for.
After third-party registration: if a third party registers the domain after it expires recovery requires either negotiating a purchase from the new registrant, which may be expensive if they know the domain’s value, or pursuing legal action. UDRP, Uniform Domain-Name Dispute-Resolution Policy, proceedings can recover domains registered in bad faith, such as cybersquatting, but require demonstrating trademark rights and bad faith registration. Legal action is expensive and time-consuming with uncertain outcomes.
Domain expiry monitoring services
Several services provide domain expiry monitoring, alerting registrants before expiry and tracking status through the expiry lifecycle.
Registrar expiry notifications: all ICANN-accredited registrars are required to send expiry notifications at 30 days, 7 days, and 1 day before expiry. These notifications go to the registrant contact email. While mandatory the registrar notifications alone are insufficient, a single failure in email delivery can cause a missed renewal.
Third-party monitoring services: services like HexoWatch, StatusCake, UptimeRobot, and dedicated domain monitoring tools track domain expiry dates and send alerts through multiple channels, email, SMS, Slack, webhook, well before expiry. For important domains monitoring through multiple channels provides redundancy.
DNS monitoring: monitoring tools that check DNS resolution for domains regularly detect expiry-related DNS failures as soon as they occur, even if the registrar notifications were missed. An alert for DNS resolution failure on a domain that should be resolving correctly triggers immediate investigation.
WHOIS monitoring: services that periodically query WHOIS data for specific domains detect changes in domain status, from active to expired, from one registrar to another, from one registrant to another. WHOIS monitoring catches not just expiry but also unauthorised transfers and DNS hijacking events.