Of all the ways a website can go down, domain expiry is the most complete. A server outage takes the site but leaves email flowing. An expired SSL certificate is alarming but fixable in minutes. An expired domain takes everything at once: the website, every mailbox, every subdomain, the API your app talks to, the links in every proposal you have ever sent. And unlike a crash, it was scheduled years in advance, visible the whole time to anyone who thought to look.
This is what actually happens when a domain expires, day by day: the grace period, the ransom-priced redemption window, the drop, and the stranger who may be waiting on the other side of it. Plus the uncomfortable truth about why "auto-renew was on" fails more often than anyone expects, and how to make sure the timeline below stays theoretical.
The first 48 hours: everything stops at once
On expiry, the registrar stops resolving the domain. Depending on the registrar, visitors see a parking page (often carrying adverts, shown to your audience on your name) or nothing at all, a browser error where a business used to be.
The website is the visible loss; email is the quiet catastrophe. The domain's MX records vanish with the rest of the zone, so every message sent to you starts bouncing: customer replies, supplier invoices, and the password-reset emails for every service your team registered with a company address. Anything else anchored to the name goes too, subdomains, webhooks, the tracking links in live ad campaigns, the email authentication records that keep your outbound mail trusted.
The timeline after that
Exact windows vary by registrar and by TLD, but for most generic TLDs the shape is standard:
- Renewal grace period (commonly up to 30 days, sometimes 45, occasionally zero). The domain is suspended but yours. Log in, pay the normal renewal fee, and it comes back, usually within hours once DNS caches clear. This is the cheap exit, and the only comfortable one.
- Redemption period (typically 30 days). The registry now holds the domain. You can still recover it, but only through a redemption process with a fee on top of the renewal, often somewhere between 50 and 150 GBP depending on the registrar, and restoration takes days rather than hours.
- Pending delete (around 5 days). Nobody can renew, restore or buy it now. The countdown to release is running and there is nothing to do but watch.
- The drop. The domain is released to the open market. Names with traffic, history or a decent keyword rarely reach an ordinary buyer: drop-catching services compete to register them in the first seconds, then hold them for auction or resale. From here, getting your name back means bidding for it or negotiating with whoever caught it.
UK domains run on different plumbing to the same destination: Nominet suspends a .uk domain roughly 30 days after expiry and cancels it around the 90-day mark, after which it becomes available again. There is no redemption fee, but there is also no way to shortcut the ending: lose the window and the name goes back to the pool.
"But auto-renew was on": why domains expire anyway
Almost every expired-domain story starts with someone certain it could not happen. The failure is rarely the setting; it is everything around the setting.
- The payment fails. The card on file expired, was cancelled, or belongs to someone who left. Auto-renew tried, failed, and sent a warning email that nobody actioned.
- The warnings go to a dead inbox. The registrar account's contact address is an old employee's mailbox, a founder's personal address, or, in the worst version, an address on the expiring domain itself, so the "your domain is about to expire" notices bounce along with everything else.
- The domain lives in an account nobody checks. It was registered years ago by whoever happened to set things up: a previous agency, a contractor, the IT person two IT people ago. The renewal is not failing in front of anyone; it is failing in a login nobody remembers.
Agencies see the compound version: dozens of client domains, each registered wherever the client happened to buy it, none of it in one place. That is precisely the inventory problem monitoring exists to solve.
The security cost nobody prices in
An expired domain is not just downtime; past the drop, it can become someone else's asset aimed at your contacts. Whoever registers it inherits your email: password resets, invoices, customer replies all delivered to a stranger who controls the MX records now. Aged domains with clean reputations are also prized for spam and phishing, because filters extend them the trust your business earned. The name you built goes on working, just not for you.
Getting a domain back, stage by stage
In the grace period: log in and renew, and if you cannot log in, contact the registrar's support with proof of ownership immediately, because this is the window where the problem is still administrative. In redemption: pay the fee and start the restore the same day you discover the problem; the process is measured in days and the clock does not pause. After the drop: place a backorder with a drop-catching service before release if you know it is coming, or prepare to bid or negotiate if someone else caught it. Throughout, treat it as an incident with communications to run, the same discipline as our website-down response plan, because clients and customers are discovering the outage in parallel with you.
Never getting here: prevention
- Renew for multiple years and keep auto-renew on, with a payment card that someone owns keeping current. Necessary, but as above, not sufficient.
- Monitor expiry from outside the registrar. An independent watch on the domain's expiry date and registrar state, with alerts at 90, 30, 14 and 7 days, catches every failure mode above, because it does not depend on the registrar's emails reaching anyone.
- Fix the account hygiene. Registrar contact address on a domain you do not own at a provider you do not rent from, two-factor authentication on, transfer lock on, and at least two people who know where the keys live.
- Keep an inventory. Every domain, who holds it, where it renews, when. For agencies this is the whole job: the client assumes you are watching, whether or not anyone agreed that.
Where this fits
Watching domain expiry is where TLDTrack started; it is in the name. Every domain you add is monitored from the outside, expiry date, registrar state, nameservers, DNS records, SSL and uptime together, with alerts long before the grace period is the only thing saving you. For everything else worth watching alongside it, start with our complete guide to monitoring client websites. The renewal is a five-minute job every year; the timeline above is what the five minutes is protecting you from.
