The Watchbillby LatticeDDI

What happens when a domain expires

Published . Updated .

This guide walks through what happens to a domain name that nobody renews, and the short checklist that keeps a client's name in the account that should hold it.

When a domain expires, the registrar usually stops its DNS within days, so the website and email go down. After the registrar deletes it, most gTLDs give a 30-day redemption period at extra cost, and then the name can be registered by anyone. Monitor expiry dates and keep registrar contacts current.

A domain name is a registration, not a file on the web server. The website and the mail exchangers are records under that name. When the registration lapses, those records stop being yours to publish. Renewing the hosting bill does not renew the name. They are different vendors more often than people think.

What does the expiration timeline look like?

ICANN's Expired Registration Recovery Policy sets a floor for generic top-level domains. Country-code domains are outside that policy, and sponsored gTLDs are exempt from the 30-day redemption period. The dates below are the policy, not a promise from every registrar. Read the registrar's own terms for fees and for how long they wait before they delete.

The registrant explainer says registrars must send at least two renewal reminders before expiry, about one month before and about one week before. If the registrar deletes the name, it must also send a notice within five days after expiration with instructions for restoring it. Notices go to the registrant email on the name. A stale contact is a missed notice.

Registrars may delete a registration at any time after it expires. If they do not delete it immediately, they may offer an auto-renew grace period of 1 to 45 days. During that stretch the name can still be renewed, sometimes for an extra fee. The explainer also says that, depending on the registrar's terms, the name may be offered to someone else or auctioned during that period. Do not treat the grace period as spare time you can spend.

DNS interruption is required, within the limits of what the registry allows. If the name is deleted within eight days of expiration, the registrar must interrupt the existing DNS path from expiration until deletion. If deletion is eight or more days after expiration, DNS must be interrupted for at least the last eight consecutive days that the registered name holder can still renew. On renewal, the registrar must restore that DNS path immediately or as soon as is commercially reasonable. The explainer summarizes this as disruption for up to eight days before deletion. During the redemption period the registry disables DNS.

After deletion, unsponsored gTLD registries must offer a redemption grace period of 30 days. The deleted registration can be restored at the request of the registered name holder, through the registrar that deleted it, usually for a fee that is higher than a normal renewal. During those 30 days the registry disables DNS and prohibits transfers, with narrow exceptions for approved bulk transfers. Names deleted during an add-grace period are not in this redemption window.

What happens after redemption is registry-specific. The name can be registered by anyone once it is released. ICANN's policy doesn't set a length for the pending-delete step that follows, so check the registry's own rules.

StepWhat the ERRP requires for most gTLDs
About 1 month beforeA renewal reminder to the registrant email
About 1 week beforeA second renewal reminder
ExpirationThe registrar may delete at any time, or offer a 1 to 45 day auto-renew grace period
Before deletionDNS for the existing resolution path is interrupted, for up to the last 8 days
Within 5 days after expiration, if deletedAnother notice, with restore instructions
30 days after deletionRedemption grace period, DNS disabled, restore through the same registrar for a fee
After redemptionThe name can be registered by someone else. The length of the pending-delete step is set by each registry.

Why does email feel the outage first?

The policy treats the website and email the same way: both depend on DNS, and both stop when resolution is interrupted. In a real week, mail is what people notice. Servers keep trying to deliver, then they bounce, and the client forwards you a failure. A website is only noticed when someone opens it. Some registrars also replace the site with a parking page and drop the mail records, so the homepage still answers while invoices stop arriving.

Tell the client that both will fail, and that mail will be the complaint that arrives first. Do not promise that the website "stays up a few days." The interruption starts on the registrar's clock, not yours.

Who should own the registrar account?

The client should be able to prove they hold the name. That means the registrant email, the account login, and the listed organization should be ones the client can still open if you part ways. An MSP can be the technical contact and can hold the login as a delegate. An MSP should not be the only human who can renew, transfer, or recover the name.

Write down which account is the registrar of record, who pays the renewal, and who receives the reminders. If reminders go to a former employee, the timeline above still runs. The policy does not pause because the mailbox is closed.

Auto-renew fails in ordinary ways. The card expired. The bank declined a charge from a vendor the client did not recognize. A staff member who owned the two-factor device left. The reseller account and the registrar account are different, and the reseller stopped paying. Turn auto-renew on, and still read the expiry date. Auto-renew is a convenience, not a receipt.

What should you check on a schedule?

Once a month is enough for names you already track, if the warning threshold is a month out. A name inside 30 days needs a person, not another calendar ping.

Country-code names (.uk, .au, .ca, and the rest) follow the registry that operates them. Some are stricter than the gTLD timeline and some are looser. Do not paste the table above into a proposal for a .uk name and call it ICANN's rule. Look up that registry.

What should you do this week?

Pick the ten names whose loss would stop a client from taking orders, read the expiry dates, and fix any registrant email that would bounce. The certificate on that name is a separate expiry, covered in the certificate checklist. If you also want a baseline of the records themselves, use the DNS change note. Short definitions are in the glossary.

How The Watchbill helps

The Watchbill reads the expiry date of each site's domain over RDAP, the registration lookup service that has replaced WHOIS for generic top-level domains, and keeps the result with that site's check. A name inside 30 days is marked soon, and a name past its date is marked expired. When a date can be read, it's refreshed about once a day. When it can't, the lookup is tried again later and the status shows as unknown rather than a guess.

That covers the "read the expiry date from outside the registrar panel" step on the checklist without a spreadsheet. It doesn't renew the name, log into the registrar, or replace the registrar's own reminders, so the person you assigned at 30 days still has to act. If a name does lapse and DNS stops, the HTTPS check on the site fails and you get a Down email once two consecutive minutes agree. To start tracking your clients' most important names, create a free account and add their websites.

Sources

  1. ICANN Expired Registration Recovery Policy (21 February 2024). Accessed October 10, 2026.
  2. ICANN, 5 things every registrant should know about the ERRP. Accessed October 10, 2026.

Related guides