Back to blog
domains

What happens when a domain expires (the full timeline, day by day)

An expired domain does not vanish at midnight - it walks through a grace period, a redemption period with a hefty restore fee, and a five-day pending delete before anyone else can grab it. Here is the exact timeline, what breaks at each stage, what recovery costs, and how to make sure you never see any of it.

Author

The AlertKick team

5 min read
What happens when a domain expires (the full timeline, day by day)

An expired domain does not disappear at midnight on its expiry date. It walks through a well-defined sequence - registrar grace period, registry redemption period, pending delete - that usually takes 40 to 80 days before anyone else can register it. That sounds like plenty of slack. In practice each stage breaks more things and costs more to escape, and the final stage ends with drop-catchers re-registering the domain seconds after release. Here is the full timeline and what actually breaks at each point.

Day 0: expiry - and why the site goes down before deletion

The registration lapses the moment the expiry date passes, but nothing is deleted. What most people notice first is DNS: registrars typically replace the domain’s nameservers with their own within a few days of expiry, so the website starts resolving to a “this domain has expired” parking page. This is not spite - ICANN’s Expired Registration Recovery Policy requires gTLD registrars to interrupt normal DNS resolution after expiry precisely so someone notices.

What breaks at this stage:

  • The website and every API on the domain - visitors and clients get the parking page or nothing.
  • Email, both directions. MX records stop resolving, so mail bounces. This is the quietly catastrophic one: the inbox that receives password resets, invoices, and the registrar’s own warnings is on the domain that just stopped working.
  • TLS renewals. ACME HTTP and DNS challenges fail because you no longer control resolution, so certificates start failing to renew on top of the outage.
  • Third-party logins. Anything doing SSO or magic-link auth against an address at the dead domain locks its users out.

Days 0-45ish: the registrar grace period

Most registrars offer a renewal grace period after expiry - commonly up to 30 or 45 days, but it is registrar policy, not a guarantee, and some offer far less. During grace, renewing costs the normal renewal price and everything comes back once DNS propagates again.

Two traps in this stage:

  • The warnings went to the wrong place. ICANN requires registrars to send renewal reminders roughly a month before expiry and again about a week before - but they go to the registrant email on file. If that address is a departed employee, an unmonitored ops alias, or (worst case) an address on the expiring domain itself, every reminder lands in a void.
  • Auto-renew failed silently. The card on file expired, the account balance was empty, or the registrar account itself was inaccessible. Auto-renew is a payment attempt, not a promise.

If the domain is in this window right now: log in to the registrar and renew. That is the entire fix, at normal price.

Days ~30-75: redemption period - recovery gets expensive

When the grace period ends, the registrar deletes the domain and it enters the registry’s redemption grace period - 30 days for most gTLDs. The domain shows a status of redemptionPeriod in registry data (paste it into the domain expiry checker to see live status straight from RDAP).

Recovery is still possible, but only by the original registrant, only through the original registrar, and now with a redemption/restore fee - typically somewhere between $70 and $200 on top of the renewal, set by the registrar. The website and email stay down the whole time.

Country-code TLDs play by their own rules. Some (.uk, for example) run longer suspension windows; others delete much faster and some have no redemption process at all. If the domain is a ccTLD, check the registry’s policy rather than assuming the gTLD timeline.

The last 5 days: pending delete, then the drop

After redemption ends, the domain enters pendingDelete for five days. Nothing can restore it now - not the registrant, not the registrar, not a support ticket. When the clock runs out, the registry releases the name for anyone to register.

For a domain with any traffic, backlinks, or brand value, “anyone” means drop-catching services that queue registration attempts for the exact release second. Domains with history are routinely re-registered within moments of dropping - after which the new owner controls the website, can receive email sent to the domain, and can obtain perfectly valid TLS certificates for it. Password-reset emails for accounts registered under the old domain now go to a stranger. This is the stage where an operational incident becomes a security incident, and there is no fee that undoes it.

The whole timeline at a glance

StageTypical durationSite/emailWho can recover itCost
Expiryday 0breaking within daysyou, at the registrarrenewal price
Registrar grace~0-45 days (registrar policy)down (parking page)you, at the registrarrenewal price
Redemption period30 days (most gTLDs)downyou, via registrar restorerenewal + ~$70-200 fee
Pending delete5 daysdownnobody-
Released-new owner’sanyone, instantlywhoever catches it

Making sure you never see this timeline

Every stage above is preventable with boring hygiene plus one external check:

  1. Auto-renew on, card current, and a calendar entry to re-verify the card yearly. Auto-renew fails exactly when the payment method does.
  2. Registrant email off the domain itself. Warnings about example.com must not be deliverable only to [email protected].
  3. Transfer lock on (clientTransferProhibited in the status list - it is the healthy state, not a problem).
  4. An expiry check the registrar is not involved in. Renewal reminders are emails from the party whose payment attempt just failed, sent to an address you may no longer read. An independent monitor closes that loop: a free AlertKick domain monitor watches the registry’s own expiry date via RDAP and alerts on a widening schedule as renewal day approaches - through Slack, email, Telegram, or your on-call rotation, none of which depend on the domain being up.

Domain and SSL expiry monitors are on the free plan - set one up in a couple of minutes, and the timeline above stays a piece of trivia instead of a post-mortem.

Frequently asked questions

What happens immediately when a domain expires?
The registrar typically suspends normal DNS within days - the website starts showing a parking page and email stops arriving. The registration is not deleted yet: most registrars offer a grace period (commonly up to 30-45 days, registrar-dependent) where renewal costs the normal price.
What is the domain redemption period?
For most gTLDs (.com, .net, .org and others), after the registrar deletes an expired domain it enters a 30-day registry redemption period. The original registrant can still recover it, but only through the registrar and usually for a redemption fee of roughly $70-200 on top of the renewal price.
Can someone else register my domain the moment it expires?
Not immediately - grace, redemption, and pending-delete stages usually mean weeks between expiry and public availability. But drop-catching services queue for exactly that moment, so once a domain with any traffic or history completes pending delete, it is often re-registered within seconds.
How do I stop a domain from expiring unnoticed?
Turn on auto-renew, keep the payment card and registrant email current, lock transfers - and monitor expiry independently of the registrar, because auto-renew fails silently when the card declines or the reminder emails go to a dead inbox. A free AlertKick domain monitor alerts on your schedule as the date approaches.
domains dns monitoring uptime