Article

What Happens If You Forget to Renew Your Domain?

ICANN gives you 30 days to reclaim an expired domain before it's deleted, plus a policy requiring multiple warning notices. Regions Bank had all of that protection in 2013 and still went dark for a week, because the clock doesn't wait for the notices to be read.

Published August 23, 20269 min readUpdated Aug 23, 2026

Written by · Full-Stack Agentic AI Software Engineer — AI Agents, Automation & Revenue Systems for GTM/RevOps teams

In brief

What actually happens, day by day, when a domain registration lapses — and how much of that outcome is decided before the expiration date ever arrives?

ICANN's rules create a longer window than most people assume, and it doesn't help nearly as much as it sounds. The Expired Registration Recovery Policy, in force since August 31, 2013, requires registrars to send multiple notices before and after expiration and disclose fees in advance. If the domain still isn't renewed, it enters a 30-day Redemption Grace Period during which ICANN requires the registry to disable DNS resolution immediately and block any transfer attempt — meaning your site and email go dark on day one, however many days of 'grace' remain to reclaim it. After the RGP, a short pending-delete window follows, and then the name is released to the public, at which point anyone — including automated 'drop-catching' services built specifically to snap up desirable expired names within seconds — can register it. Regions Bank, the 22nd-largest US bank, had every one of ICANN's protections in place in April 2013 and still lost its regions.com domain for close to a week, because notices sitting unread in an inbox don't renew anything. The policy protects the domain from becoming instantly and permanently unrecoverable. It does not protect the business from the outage.

  • ICANN's Expired Registration Recovery Policy requires multiple pre- and post-expiration notices and fee disclosure — but the notices only work if someone reads them, and Regions Bank's 2013 outage shows a well-regulated process still failing on the human side
  • DNS resolution is disabled the moment a domain is deleted, immediately at the start of the 30-day Redemption Grace Period — the site and any email on that domain go dark from day one, not after some further delay
  • Redemption inside the 30-day RGP typically carries a steep restoration fee well above normal renewal, separate from and in addition to the lapsed renewal cost itself
  • After the RGP and a brief pending-delete period, the domain becomes available to the public, and automated 'domain drop-catching' services exist specifically to register desirable expired names within seconds of release
  • The single most common root cause across documented incidents — Regions Bank, Yatra.com — is not a technical failure but an administrative one: an unrenewed registration, a stale payment method, or an unmonitored contact address

Evidence notes

ICANN — Expired Registration Recovery Policy (ERRP)

In effect since August 31, 2013 for all ICANN-accredited registrars, ERRP requires registrars to provide registrants multiple renewal reminder notices before expiration and at least one notice after, disclose the standard renewal fee and any separate redemption fee in advance, and offer a defined renewal path even after a domain has technically expired but before deletion.

ICANN — Redemption Grace Period policy

ICANN requires gTLD registries, aside from sponsored gTLDs, to offer a 30-day Redemption Grace Period after a domain is deleted, during which the registry must disable DNS resolution for the name and prohibit any transfer request, while the sponsoring registrar must allow the original registrant to redeem it before the period ends.

Domain drop-catching services

A documented segment of the domain industry specializes in registering desirable domains within seconds of their public release after the pending-delete period ends, using automated systems and, in some cases, direct registry-level backorder relationships to beat ordinary registrants to the registration.

Regions Bank domain lapse, April 2013

Regions.com expired on April 13, 2013, and Regions Bank — the 22nd-largest bank in the US — had its online banking and main website unavailable to customers across a 16-state footprint for close to a week before the domain was restored and renewed for a further ten years. The bank issued a public apology. Reported contemporaneously by Domain Name Wire, TheDomains and Yahoo News.

Yatra.com domain lapse, August 2013

Yatra.com, then a major Indian online travel booking platform, was unreachable for roughly two days from August 9, 2013 after failing to renew its domain, redirecting visitors to a registrar page announcing the domain had expired. Reported contemporaneously by Gizbot and DNA India.

Continue with purpose

There's a comforting number that circulates around domain expiry: 30 days. That's how long ICANN's Redemption Grace Period gives you to reclaim a deleted domain before it's gone for good. It sounds like a month of cushion. It is not a month of your site staying up.

The grace period is about recoverability, not availability. DNS resolution for the domain is switched off the moment it enters that window — meaning your website and any email routed through it stop working on day one of the 30, not day 31. What follows is a genuine timeline worth understanding in order, because almost nobody looks at it until they're already living through it. Pair this with if what happens if you forget to renew your domain sits inside a wider growth programme. Pair this with XenGrowth's growth engineering practice if what happens if you forget to renew your domain sits inside a wider growth programme.

What actually happens on each day of an expiry?

Stage

Timing

What's actually happening

Pre-expiration notices

Required at multiple points before the expiration date

ICANN's ERRP mandates registrars notify you the renewal is coming — but a notice sitting in an unread inbox does nothing

Expiration

The registration's end date

The domain has technically lapsed, though many registrars hold it briefly before deleting it, per their own auto-renew grace policies

Post-expiration notice

At least one required after expiration

A final warning, still just a notice, before deletion proceeds

Deletion / Redemption Grace Period begins

Typically 30–45 days after expiration, varying by registrar's own hold policy

DNS resolution is disabled immediately. Your site and email stop working now, regardless of the 30 days still available to restore ownership

Redemption window

30 days from deletion

The domain can be restored, usually for a steep redemption fee on top of standard renewal — this is the expensive, painful path by design

Pending delete

A further brief window after the RGP

No restoration is possible; the domain simply waits to be released

Public release

After pending delete ends

Anyone can register it — including drop-catching services built to grab desirable expired names within seconds

Note also that the numbers in that first row vary by registrar in a way that matters. ERRP sets a floor on how many notices a registrar must send and when, but individual registrars differ on how long they hold an expired domain before actually deleting it and starting the RGP clock — some hold it for weeks under their own auto-renew grace policy before deletion even begins. That's a meaningful, if quiet, differentiator between registrars that rarely shows up in a pricing comparison.

Two things about that timeline surprise people every time. First, the outage starts long before the domain is actually lost — DNS goes dark at deletion, while you might still, technically, have thirty more days to fix it. Second, an entire commercial niche exists purely to exploit the very last row of that table: automated services that watch expiration lists and register valuable-looking names the instant they become public, sometimes through direct backorder arrangements with the registry itself. A related discipline — treating operational upkeep as a real line item rather than an afterthought — is one returns to often. If the operations side of this is the part you are stuck on, is the better reference. If the operations side of this is the part you are stuck on, The XenGrowth resource library is the better reference.

If the notices are legally required, why does this keep happening to competent organizations?

Because ERRP regulates the registrar's obligation to warn you, not your organization's obligation to act on the warning. Regions Bank — the 22nd-largest bank in the United States at the time — let regions.com expire on April 13, 2013, four years after ERRP took effect and required exactly the kind of advance notice that should have prevented this. Online banking for customers across sixteen states went down for close to a week. The bank issued a public apology and, tellingly, renewed the recovered domain for a full ten years afterward — the kind of overcorrection that only happens once an organization has felt the actual cost of the two-year renewal cycle that failed it the first time.

Yatra.com, then a major Indian online travel platform, hit the same wall four months later, in August 2013, going dark for about two days after its own renewal failure. Neither organization was small or careless in any obvious sense. Both had exactly the regulatory protections ERRP was designed to provide. Both still lost the domain, because a notice requirement changes what a registrar must send, not whether a business has a reliable process for reading it.

The 30-day grace period is a policy about property rights, not a policy about uptime. It guarantees you won't permanently lose the domain overnight. It says nothing about whether your business survives the day resolution stops.

Common failure point

Why it happens

What actually catches it

Expired payment card on auto-renew

Card expires or is replaced without updating the registrar

A calendar check of the registrar's billing status, not just trusting auto-renew silently

Registrant contact address unmonitored

Domain registered years ago under a former employee's email or an old address

Auditing and updating WHOIS/registrant contact details at least annually

Single person holds registrar login

No one else in the organization has access or knows the domain is even up for renewal

Shared or documented access for at least two people

Registrar notice treated as spam

Renewal reminder emails often resemble marketing and get filtered or ignored

Whitelisting the registrar's sending domain and setting an independent reminder

Does auto-renew actually solve this?

Mostly, but only if the payment method behind it is actually current — and that's precisely the gap that keeps causing this failure. Auto-renew fails silently in exactly the same way a subscription does: an expired card, a bank that flags the charge as suspicious, or a registrar account tied to an email address nobody checks anymore. Auto-renew converts 'someone has to remember to act' into 'someone has to notice a failed automatic renewal,' which is a real improvement but not a guarantee — it just moves the point of failure one step downstream. On AI agents and marketing automation specifically, is worth reading. On AI agents and marketing automation specifically, XenGrowth on AI agents and marketing automation is worth reading.

The more durable fix is redundancy in who's watching, not just automation in what's charged. A calendar reminder set independently of the registrar's own notices, checked by more than one person, catches the case auto-renew itself is blind to: the failed charge that nobody at the registrar or the business happens to notice until DNS has already gone dark.

There's also a version of this problem that has nothing to do with payment failure at all: the domain outliving the person who set it up. A common pattern in small organizations is a single founder or early employee registering the domain personally, on a personal card, under a personal email address, years before the business has any formal process around it. That person leaves, changes jobs, or simply stops checking that inbox, and the renewal notices go to an address nobody in the current organization can access — a failure mode ERRP's notice requirements cannot fix, because the notices are being delivered exactly as required. They're just being delivered to the wrong person.

This is worth treating as a distinct risk from a simple missed payment, because the fix is different. A payment failure is solved by better monitoring of a card. An orphaned registrant contact is solved only by actively auditing who's listed as the registrant and updating it deliberately — something almost no organization does on any regular schedule, precisely because it doesn't feel like the kind of task that has a deadline attached to it, right up until it does. There is a longer treatment of AI search, GEO and discovery in . There is a longer treatment of AI search, GEO and discovery in XenGrowth on AI search, GEO and discovery.

What should you actually do about this?

  1. Confirm auto-renew is on and the payment method behind it is current, checked at least twice a year rather than assumed to be fine indefinitely

  2. Set an independent calendar reminder 60 days before expiration, owned by a specific named person, separate from whatever notices the registrar sends — treat the registrar's ERRP notices as a backup, not the primary system

  3. Register domains for multiple years at once where the registrar allows it, which reduces how often the renewal decision has to be made correctly at all

  4. Know your specific registrar's redemption fee before you ever need it — it varies significantly between registrars and is rarely on the standard pricing page

  5. If a domain is genuinely business-critical, put a second person on the registrar account with visibility into billing status, so the single-point-of-failure isn't one employee's inbox

It's worth being honest that no amount of process eliminates this risk entirely — a registrar can still fail to send a notice it was required to send, a payment processor can flag a legitimate charge as fraud at exactly the wrong moment, and a person responsible for checking can still be on vacation the one week it matters. The goal isn't a system that makes domain loss impossible. It's a system where the failure requires two or three independent things to go wrong at once, rather than the single missed email that took down Regions Bank's online banking for a week in 2013.

None of this requires distrusting ICANN's policy — the Redemption Grace Period and ERRP notices are real protections that make domain loss recoverable rather than instantaneous and total. But recoverable still means an outage, a redemption fee, and days of downtime while the fix goes through. The businesses in this post didn't need better ICANN policy. They needed one more person checking a calendar, and a second person who'd notice if the first one didn't. For the wider set of ways a domain can be lost beyond simple non-renewal, see What Actually Happens to Your Business If You Lose Your Domain?.

Further reading from XenGrowth

Where this work meets go-to-market

Building the operational discipline that keeps a business from losing revenue to a missed renewal? publishes operator guides on exactly this kind of unglamorous, high-stakes process work.

Further reading from XenGrowth

Where this work meets go-to-market

writes for the teams who have to run what happens if you forget to renew your domain day to day.

Further reading from XenGrowth

Where this work meets go-to-market

XenGrowth's marketing operations practice writes for the teams who have to run what happens if you forget to renew your domain day to day.

The expiry timeline, tested

Five questions on what actually happens, and when, after a domain lapses. Most people badly overestimate how much cushion the ICANN grace period actually provides.

1 / 5
When exactly does DNS resolution stop working for an expired, deleted domain — at the start of the 30-day grace period, or only after it ends?

Apply this article

How to turn insights into execution

A practical sequence for teams turning concepts into production outcomes.

DomainsDNSBusiness ContinuityRisk ManagementDigital Ownershipother

Audit your current state

Map the bottlenecks and constraints connected to the article’s core problem.

Choose one bounded change

Test the most useful recommendation on one workflow before widening the scope.

Measure what changed

Keep the parts that improve the work, document what failed, and make the next decision from evidence.

Next step

Need help applying this in your stack?

I can translate these patterns into a concrete implementation plan for your team.

Discuss implementationBack to blog

Replies usually within 24 hours.

Next Steps

Continue reading

Why Is Your Domain the Only Thing Online You Actually Own?

Your Instagram following, your Gmail address, your Shopify storefront, your YouTube channel — none of it is yours in any legal sense that matters. A domain name is the closest thing to property the internet gives you, and even that is a lease with an asterisk.

Navigate

How Do You Actually Choose a Domain Registrar?

GoDaddy will sell you a .com for a penny and renew it for over twenty dollars. Cloudflare sells the same domain at what it actually costs Verisign, with no markup, forever. Almost everything registrars compete on is noise next to that one number.

Navigate

Is Email on Your Own Domain Worth It Over a Gmail Address?

When an employee with a personal Gmail address leaves, they take every contact, every thread and every attachment with them. When someone with [email protected] leaves, the address stays exactly where it was, pointing at whoever replaces them.

Navigate

How Do You Judge Exit Cost Before You Adopt a Platform?

Every platform pitch answers 'how easy is this to start?' Almost none answer 'how easy is this to leave?' — and the second question is the one that actually predicts what the relationship costs you three years in.

Navigate

Can Your Business Account Be Suspended Without Warning?

AWS gave Parler about a day's notice before cutting off its hosting. Twitter's API change killed a 12-year-old app with an update to a developer agreement. Neither company broke a law. Both simply decided, and the decision was final the moment it was made.

Navigate

How Do You Build Personal Infrastructure That Outlives Your Employer?

A LinkedIn profile, a company email address, a Slack history — none of it is yours the day you're let go. The only professional identity that survives a layoff is the one built on a domain you personally renewed, not one an employer's IT department controls.

Navigate
  • What Actually Happens to Your Business If You Lose Your Domain?

    Regions Bank, the 22nd-largest bank in the US, took its own online banking offline for close to a week in 2013 by forgetting to renew a domain. Not a hack. Not a disaster. A calendar reminder nobody set.

  • What Does Vendor Lock-In Actually Cost You?

    Wix and Squarespace don't hide that they won't let you export your site — it's a known, published limitation, not a bug. Three years of work becomes a rebuild-from-scratch the day you want to leave, and the pricing that got you in never mentioned it.

  • Who Controls Your DNS, and What Is That Control Worth?

    One DNS provider's bad Friday in October 2016 took Twitter, Netflix, Spotify and Reddit offline at once — not because any of them failed, but because they'd all quietly delegated the same single switch to the same single company.

  • What Do You Lose When Your Audience Lives on Someone Else's Platform?

    Tumblr lost nearly a third of its page views in two months after a single policy change in December 2018. Not because users left the internet — because the platform decided what they were allowed to see there, and the audience never belonged to anyone but the platform in the first place.