- Expires
- in 41 days · card on file declinedAt risk
- DMARC
- no record publishedFailing
- TLS cert
- expires in 9 daysAt risk
- LCP mobile
- 4.2s — threshold is 2.5sFailing
- AI crawlers
- GPTBot blocked in robots.txtFailing
Your registrar sells you the name.Nobody is watching what happens to it.
A domain is not a purchase. It is a lease with a hard deadline, an email reputation, a search footprint, and a public health record — and the only party contractually obligated to notice any of it going wrong is you.
Part one — the price of a missed date
Forgetting costs between $45 and $200. Then it costs everything.
The registry's wholesale restore fee for a lapsed .com is about $40. What you pay depends entirely on which registrar you happened to buy from.
Once a domain slips past its grace period into the Redemption Grace Period, you cannot renew it. You have to restore it — a manual, ticket-based process at most registrars, priced at whatever markup they choose to apply over the roughly $40 that Verisign charges them for a .com or .net.
The spread is not small. The same 30-day window costs $45 at one registrar and $200 at another, for an identical registry transaction.
| Registrar | Fee | Relative to the ~$40 registry cost | Source |
|---|---|---|---|
| Registry wholesale (Verisign) | ~$40 | baseline | |
| Squarespace | $45 | published | |
| Cloudflare | at cost | at cost | |
| GoDaddy | $80 | reported | |
| IONOS | $80 | reported | |
| Namecheap | ~$119 | reported | |
| Domain.com | $150 | reported | |
| 101domain | $150 | published | |
| Register.com | $175 | reported | |
| Web.com | $199 | reported | |
| Network Solutions | $200 | reported |
Read this as a range, not a quote. Squarespace and 101domain publish their fees openly; the rest are drawn from registrar help pages and third-party fee surveys and change without notice. Fees also swing hard by extension — Squarespace alone charges $45 to redeem a .com, $160 for a .ai, and $300 for a .shop. Network Solutions additionally charges a $35.99 reinstatement fee for renewals made after expiry but still inside the grace period.
Part two — the eighty-day slide
Your site goes dark long before your domain is gone.
The window is a sequence of registry states, each with its own price and its own point of no return.
Day 0 — 30/45
Renewal grace period
Renew at the ordinary price. But DNS is already being cut, and around day 26 your registrar may list the name at auction.
autoRenewPeriod · clientHold
Day 30/45 — 75
Redemption grace period
Renewal is no longer possible. Restore only — manual, support-ticketed, and priced at the registrar's discretion.
redemptionPeriod
75 — 80
Pending delete
Frozen. No restore at any price.
pendingDelete
Day 80 +
Dropped
Released to the open market. Drop-catchers bid before you ever see it available.
available — to anyone
The blackout is a feature, not a bug. ICANN's Expired Registration Recovery Policy requires your registrar to disrupt DNS for up to eight days before deletion, and requires the registry to do the same through the 30-day redemption period — specifically so that a broken website is what finally gets your attention. At GoDaddy the parking page goes up on day 5. At Namecheap the nameservers are switched at midnight on the expiry date itself, and "the respective website and email service cease to work."
Read that again: the mechanism designed to warn you is taking your business offline. Your contact forms stop submitting. Your MX records disappear, so inbound mail bounces — including the renewal reminders your registrar is sending to you@yourbusiness.com. Every lead that arrives during the window is simply never delivered, and no one tells you they tried.
Meanwhile, on day 26, the name you have spent years building equity in is quietly listed at auction — by the company you are paying to hold it.
Part three — this happens to competent people
An expired credit card is all it takes.
Sorenson Communications2016
An internal lapse let sorenson.com expire, cutting off the ASL relay service deaf users depend on to place calls — including emergency calls — for three days.
$3,000,000 FCC settlement
Marketo2017
A card on file expired, auto-renewal failed silently, and marketo.com lapsed. Forms broke across every customer site embedding their scripts. A customer noticed and re-registered the domain to save them.
Recovered for $38 + $35.99 — by an outsider
Foursquare2010
Renewal notices were missed and foursquare.com expired, taking the entire service down — weeks after closing a $10M round.
Total outage, no warning
The pattern is identical in all three: nothing was neglected on purpose. A card rotated. A notice went to an inbox nobody reads anymore. An employee left and their address kept receiving the alerts. The failure is never the renewal — it is that the only warning system lives inside the account that is failing.
Part four — the part nobody mentions
Losing the domain is not the worst outcome. Someone else getting it is.
A dropped domain is not a dead asset — it is a live credential. Whoever registers it next can receive mail at every address you ever used, which means they can run a password reset against every service where those addresses are still on file.
This is now an industrialized attack. Over 50,000 gTLD domains a day are drop-caught in 2026 — around 65,000 once ccTLDs are counted. In 2025, researchers at watchTowr registered 40 expired command-and-control domains for roughly $20 each and inherited control of more than 4,000 live backdoors. PyPI now un-verifies email addresses whose domains have lapsed and had already stripped over 1,800 of them, after an attacker used exactly this route to hijack a Python package and ship credential-stealing code to everyone who installed it.
When surveyed in 2026, CISOs ranked domain and DNS hijacking above ransomware and malware as their top threat. Your old domain, in someone else's hands, is the cheapest way into your accounts that exists.
Part five — the renewal date is the easy part
Four things silently decide whether the domain earns anything.
Every one of them can break without a single error message, on a domain that is perfectly current on its renewal.
The expiry date at least has a date attached. These do not. They degrade — quietly, on a schedule set by other people's policy changes — and the first symptom is always the same: fewer leads, for reasons nobody can name.
Signal 01 — Email authentication
42% enforced
Your mail is being rejected outright
DMARC awareness reached 78% in 2026, but only 42% of domains actually enforce it — 22% still publish no valid record at all. Gmail and Microsoft moved past spam-foldering: non-compliant mail now gets permanent 550 rejections. It never reaches any folder, and you are not told.
Signal 02 — AI visibility
15% cited
Assistants retrieve you, then drop you
ChatGPT cites roughly 15% of the pages it retrieves while composing an answer; the other 85% are evaluated and discarded. It drives 87% of all AI referral traffic. If GPTBot cannot crawl you, or your pages carry no citable structure, you are invisible in the layer where buyers now start.
Signal 03 — Search footing
93% zero-click
The click has to be earned twice
Around 93% of AI search sessions end without anyone visiting a site, and AI Overviews cut clicks to the top organic result by 58%. Ranking is no longer the finish line — being the source an answer is built from is. That depends on schema, crawlability and content that is not thin.
Signal 04 — Speed and uptime
8.4% per 0.1s
Slow is a leak you cannot see
Google and Deloitte measured an 8.4% retail conversion lift per 0.1s of load time. 53% of mobile visitors abandon a page that takes over three seconds — and the average B2B mobile LCP is 7.05s, nearly triple the threshold. Every one of those exits looks identical to traffic that never came.
Part six — the structural problem
Why the monitor cannot live inside the registrar.
This is not about bad registrars. It is about what a registrar is for. Four things follow from that, and none of them can be fixed by choosing a better one.
- 01
They profit from the failure
A registrar charging $200 to restore a domain that costs them $40 has a $160 reason not to make the warning impossible to miss. The redemption fee is a product line.
- 02
The alert channel dies with the domain
Expiry notices go to an address on the domain that is expiring. Once DNS is cut, those messages bounce. The alarm is wired to the thing it is meant to protect.
- 03
Nobody owns one registrar
Real portfolios are scattered — the domain your last developer bought, a defensive .net, a client's name on their own account. There is no single dashboard, because there is no single account.
- 04
They do not measure the things that matter
A registrar knows one fact about your domain: when you last paid for it. It has no opinion on whether your mail authenticates, whether AI crawlers can read you, or whether your homepage takes six seconds to paint.
What DomainGuard is
One independent record of every domain you own — and everything it is doing.
DomainGuard sits outside your registrars and watches all of them at once. It knows the expiry date, and it also knows the four things the expiry date cannot tell you.
Expiry and ownership
Every domain across every registrar, with escalating alerts that reach you off-domain — so the warning survives the outage it is warning about.
Mail deliverability
SPF, DKIM and DMARC checked continuously, with the actual policy you are publishing and what Gmail and Microsoft will do with it.
AI and search readiness
Crawler access, schema, thin and duplicate content, and whether your pages are structured to be cited rather than skipped.
Uptime and speed
Core Web Vitals and availability tracked over time, so a page that got slow shows up as a number instead of a quiet drop in enquiries.
Certificates and DNS
TLS expiry, record drift, and nameserver changes you did not authorize — caught before a browser warning does it for you.
Portfolio view
Personal, business and client domains separated, so a name in someone else's account is still a name you are watching.
Common questions
- How much does it cost to recover an expired domain?
- Restoring a lapsed .com during the redemption grace period costs the registrar's redemption fee plus a one-year renewal. The fee ranges from about $45 at Squarespace to $200 at Network Solutions, against a registry wholesale restore fee of roughly $40 for .com and .net. Fees also vary sharply by extension — Squarespace charges $45 for a .com, $160 for a .ai and $300 for a .shop.
- How long do you have to recover an expired domain?
- Typically about 80 days. A gTLD gets a renewal grace period of roughly 30 to 45 days at the ordinary price, then a 30-day redemption grace period where only a paid restore is possible, then about 5 days of pending delete where nothing can be done, after which the domain drops to the open market.
- Why does my website go down before the domain is actually gone?
- Because ICANN's Expired Registration Recovery Policy requires it. Registrars must disrupt DNS for up to eight days before deleting a domain, and registries must do the same through the 30-day redemption period, specifically so a broken site gets the registrant's attention. GoDaddy parks the domain on day 5; Namecheap switches nameservers at midnight on the expiry date, which stops the website and email at once.
- What happens if someone else registers my expired domain?
- They can receive mail at every address you ever used on it, which means they can run password resets against services where those addresses are still on file. Over 50,000 gTLD domains a day are drop-caught in 2026. In 2025 researchers registered 40 expired command-and-control domains for about $20 each and inherited more than 4,000 live backdoors, and PyPI now un-verifies email addresses whose domains have lapsed.
- Is registrar auto-renew enough to protect a domain?
- No. Auto-renew fails silently whenever the card on file expires, is replaced, or is declined — which is exactly how Marketo lost marketo.com in 2017. The renewal notice is also sent to an address on the domain that is expiring, so once DNS is cut the warning bounces. Monitoring has to sit outside the registrar to survive the failure it is watching for.
Sources — verified August 2026
- ICANN, Expired Registration Recovery Policy — pre-expiry notice windows and the mandated DNS interruption.
- GoDaddy, Standard domain expiration timeline — parking at day 5, auction at day 26, removal at day 72.
- Namecheap, What happens after my domain expires — nameservers switched at midnight on expiry; website and email cease to work.
- Squarespace, Domain redemption fees — published per-TLD table; $45 .com, $160 .ai, $300 .shop.
- Cloudflare Registrar, Renew domains — 30-day RGP, no transfers during redemption, at-cost fees.
- Porkbun, What happens after a domain expires — day-by-day grace, auction and deletion sequence.
- 101domain, Understanding redemption fees — $150 standard gTLD redemption fee.
- Network Solutions, Renewal timelines — grace-period reinstatement and redemption process.
- Valimail, 2026 State of DMARC Report — 78% awareness, 42% enforcement, 22% with no valid record.
- Google Workspace and Yahoo bulk sender requirements — permanent 550 rejections for non-compliant mail as of late 2025.
- watchTowr Labs, via The Hacker News — 4,000+ backdoors hijacked through expired C2 domains at ~$20 each.
- PyPI, Preventing domain resurrection attacks — 1,800+ email addresses un-verified after domain lapses.
- CSC, Domain and DNS hijacking in 2026 — 50k+ gTLD drop-catches per day; CISO threat ranking.
- Google and Deloitte, Milliseconds Make Millions — 8.4% retail conversion lift per 0.1s improvement.
- Chrome UX Report, May 2026 — 68.6% of origins with good LCP; average B2B mobile LCP 7.05s.
- AI search citation and referral data, 2026 industry aggregates — ChatGPT at 87% of AI referrals, ~15% of retrieved pages cited, ~93% zero-click sessions.
- Sophos, How forgetting to renew a domain cost $3m; ThousandEyes on the Marketo outage; contemporaneous reporting on Foursquare.
