DomainGuard · expiry monitoring

Two clocks are running, and only one of them is loud.

A certificate lapses and the browser puts a warning across your homepage the same hour. A registration lapses and the loss builds for eighty days, gets expensive in the middle, and becomes permanent at the end. DomainGuard reads both from public records and tells you at an address that is not on the domain in question.

DomainGuard is in a public TestFlight beta and is not on the App Store yet. Every check on this page runs on demand on the free plan.

They are sold as one feature

They fail nothing like each other.

Treating certificate expiry and domain expiry as the same alert is how one of them gets the attention and the other gets the outage.

Clock one

The certificate

Lifetime
90 days to about a year, depending on the issuer, usually renewed automatically
How it fails
Instant and total. Browsers stop showing the site and show a full-screen warning about it instead. Visitors do not read it, they leave.
How long to fix
Usually minutes, once somebody knows. Reissue, install, done.
What gets missed
Automation covers the main host and misses the one nobody set up: a client portal, a staging name that went public, a mail host with its own certificate.

Clock two

The registration

Lifetime
One to ten years, renewed by a card on file
How it fails
Gradual, then permanent. DNS is disrupted before deletion by policy, so the site breaks while the name is still recoverable.
How long to fix
Days and a fee, then impossible. Restoring inside the redemption window is a manual, ticketed process priced at the registrar's discretion.
What gets missed
The card on file expired and auto-renew failed silently, and the renewal notice went to an address on the domain that just stopped resolving.

After the expiry date

The window is about eighty days and it narrows in steps.

Each phase is a registry state with its own price and its own point of no return. Day counts are typical for common endings and vary by registrar and by extension.

Registry lifecycle phases after a domain expires, with the approximate day range and what recovery involves in each.
PhaseRoughlyWhat recovery means
Renewal grace periodRoughly day 0 to 30 or 45Renewable at the ordinary price. DNS is already being disrupted, and some registrars list the name at auction inside this window.
Redemption grace periodRoughly day 30 or 45 to 75No longer renewable. Restore only, by support ticket, plus a redemption fee on top of the renewal.
Pending deleteRoughly day 75 to 80Frozen. There is no restore at any price.
DroppedDay 80 and afterReleased to the open market, where drop-catchers bid before you see it available.

The redemption fee itself varies by registrar and by extension for an identical registry transaction. We put the published and reported figures side by side, with each source marked, on what a missed renewal really costs.

You already get renewal emails

Four reasons they are not the warning you need.

This is not a claim that registrars are careless. It is that the notification is structurally wired to fail in the case that matters.

  1. The alert channel dies with the domain

    Expiry notices go to an address on the domain that is expiring. Once DNS is disrupted those messages bounce. The alarm is wired to the thing it is meant to protect, which is why monitoring has to sit outside the registrar.

  2. Auto-renew fails quietly

    A replaced card, an expired card, a declined charge. Nothing errors loudly, and the account page still says auto-renew is on. What changed is whether the charge went through.

  3. Nobody owns one registrar

    The name your last developer bought, a defensive variant somewhere else, a client's name on their own account. There is no single dashboard because there is no single account.

  4. A registrar tracks one fact

    When you last paid. It has no opinion about whether the certificate on your checkout page expires next week, or whether your nameservers changed on Tuesday.

What detection looks like

Five reads, none of which need your registrar password.

Everything here comes from records the internet publishes about your domain, which is what makes it possible to watch a name you do not hold the login for.

Certificate expiry
Taken from public certificate transparency logs, which every publicly trusted certificate is written to when it is issued. The same logs are what surface subdomains you forgot were public, so a host with its own certificate becomes visible rather than staying assumed.
Registration expiry and status
Read from RDAP, the registry's own record, rather than from a registrar dashboard you may not have a login for.
Nameserver and registrar changes
Change detection runs on a five-minute tick and raises events for DNS, registrar, certificate and hosting changes, with a lifecycle rather than a color that quietly flips.
Uptime, so a break is dated
Availability is probed and outage windows are recorded, including the ones that happen at 3am. Three domains get that probe even on the free plan.
Alerts off the monitored domain
Notifications go to an address you choose, which is the one design decision that separates this from the warning you already ignore.

One deliberate behavior worth knowing: if the certificate lookup cannot be completed, the date comes back blank rather than green. Not observed and healthy are different facts, and a monitoring tool that confuses them is worse than no tool.

Straight answers

Questions about expiry monitoring.

How is this different from your DNS monitoring page?

DNS monitoring is about records changing: SPF, DKIM, DMARC, MX and nameservers, compared scan to scan, with a stored diff. This page is about two deadlines: when the certificate stops being valid and when the registration stops being yours. They run in the same product and answer different questions, so both pages exist. If your worry is “somebody edited something”, that is the DNS page.

Why does my site break before the domain is actually gone?

Because policy requires it. ICANN's Expired Registration Recovery Policy has registrars disrupt DNS for a period before deletion, and registries do the same through the redemption period, specifically so a broken site gets the registrant's attention. That is why an outage is often the first real notice, and why a warning that arrives before the deadline is worth more than an accurate post-mortem.

What does it cost to restore a lapsed domain?

The registrar's redemption fee plus a year's renewal, and the fee varies enormously between registrars for an identical registry transaction. We put the published and reported figures side by side, with sources marked, on the why DomainGuard page rather than quoting a single number here.

The certificate date is blank on one of my domains. Is that a bug?

Usually not. Certificate dates come from public transparency logs, and a lookup that could not be completed is different from a domain with no certificate. Rather than guess, the date is left blank. Blank means not observed, and the interface treats that as a question rather than as a pass — writing a healthy-looking date over an unknown is the failure mode worth avoiding.

What runs on the free plan?

Every check on this page runs on demand on the free plan, on every domain you own, with no card. Free also keeps a five-minute uptime probe on three domains. What free does not include is the nightly re-scan that re-reads certificates and registry records without being asked, and the email alert that follows it. Both start at $6.99 a month on Starter.

Find out where the clocks are

Add every domain you own and read both dates in one list.

The free plan holds all of them and runs every check on demand, with no card. The iPhone app is in a public TestFlight beta and signs in with the same account.