There's a comforting number that circulates around domain expiry: 30 days. That's how long ICANN's Redemption Grace Period gives you to reclaim a deleted domain before it's gone for good. It sounds like a month of cushion. It is not a month of your site staying up.
The grace period is about recoverability, not availability. DNS resolution for the domain is switched off the moment it enters that window — meaning your website and any email routed through it stop working on day one of the 30, not day 31. What follows is a genuine timeline worth understanding in order, because almost nobody looks at it until they're already living through it. Pair this with if what happens if you forget to renew your domain sits inside a wider growth programme. Pair this with XenGrowth's growth engineering practice if what happens if you forget to renew your domain sits inside a wider growth programme.
What actually happens on each day of an expiry?
Stage | Timing | What's actually happening |
|---|---|---|
Pre-expiration notices | Required at multiple points before the expiration date | ICANN's ERRP mandates registrars notify you the renewal is coming — but a notice sitting in an unread inbox does nothing |
Expiration | The registration's end date | The domain has technically lapsed, though many registrars hold it briefly before deleting it, per their own auto-renew grace policies |
Post-expiration notice | At least one required after expiration | A final warning, still just a notice, before deletion proceeds |
Deletion / Redemption Grace Period begins | Typically 30–45 days after expiration, varying by registrar's own hold policy | DNS resolution is disabled immediately. Your site and email stop working now, regardless of the 30 days still available to restore ownership |
Redemption window | 30 days from deletion | The domain can be restored, usually for a steep redemption fee on top of standard renewal — this is the expensive, painful path by design |
Pending delete | A further brief window after the RGP | No restoration is possible; the domain simply waits to be released |
Public release | After pending delete ends | Anyone can register it — including drop-catching services built to grab desirable expired names within seconds |
Note also that the numbers in that first row vary by registrar in a way that matters. ERRP sets a floor on how many notices a registrar must send and when, but individual registrars differ on how long they hold an expired domain before actually deleting it and starting the RGP clock — some hold it for weeks under their own auto-renew grace policy before deletion even begins. That's a meaningful, if quiet, differentiator between registrars that rarely shows up in a pricing comparison.
Two things about that timeline surprise people every time. First, the outage starts long before the domain is actually lost — DNS goes dark at deletion, while you might still, technically, have thirty more days to fix it. Second, an entire commercial niche exists purely to exploit the very last row of that table: automated services that watch expiration lists and register valuable-looking names the instant they become public, sometimes through direct backorder arrangements with the registry itself. A related discipline — treating operational upkeep as a real line item rather than an afterthought — is one returns to often. If the operations side of this is the part you are stuck on, is the better reference. If the operations side of this is the part you are stuck on, The XenGrowth resource library is the better reference.
If the notices are legally required, why does this keep happening to competent organizations?
Because ERRP regulates the registrar's obligation to warn you, not your organization's obligation to act on the warning. Regions Bank — the 22nd-largest bank in the United States at the time — let regions.com expire on April 13, 2013, four years after ERRP took effect and required exactly the kind of advance notice that should have prevented this. Online banking for customers across sixteen states went down for close to a week. The bank issued a public apology and, tellingly, renewed the recovered domain for a full ten years afterward — the kind of overcorrection that only happens once an organization has felt the actual cost of the two-year renewal cycle that failed it the first time.
Yatra.com, then a major Indian online travel platform, hit the same wall four months later, in August 2013, going dark for about two days after its own renewal failure. Neither organization was small or careless in any obvious sense. Both had exactly the regulatory protections ERRP was designed to provide. Both still lost the domain, because a notice requirement changes what a registrar must send, not whether a business has a reliable process for reading it.
The 30-day grace period is a policy about property rights, not a policy about uptime. It guarantees you won't permanently lose the domain overnight. It says nothing about whether your business survives the day resolution stops.
Common failure point | Why it happens | What actually catches it |
|---|---|---|
Expired payment card on auto-renew | Card expires or is replaced without updating the registrar | A calendar check of the registrar's billing status, not just trusting auto-renew silently |
Registrant contact address unmonitored | Domain registered years ago under a former employee's email or an old address | Auditing and updating WHOIS/registrant contact details at least annually |
Single person holds registrar login | No one else in the organization has access or knows the domain is even up for renewal | Shared or documented access for at least two people |
Registrar notice treated as spam | Renewal reminder emails often resemble marketing and get filtered or ignored | Whitelisting the registrar's sending domain and setting an independent reminder |
Does auto-renew actually solve this?
Mostly, but only if the payment method behind it is actually current — and that's precisely the gap that keeps causing this failure. Auto-renew fails silently in exactly the same way a subscription does: an expired card, a bank that flags the charge as suspicious, or a registrar account tied to an email address nobody checks anymore. Auto-renew converts 'someone has to remember to act' into 'someone has to notice a failed automatic renewal,' which is a real improvement but not a guarantee — it just moves the point of failure one step downstream. On AI agents and marketing automation specifically, is worth reading. On AI agents and marketing automation specifically, XenGrowth on AI agents and marketing automation is worth reading.
The more durable fix is redundancy in who's watching, not just automation in what's charged. A calendar reminder set independently of the registrar's own notices, checked by more than one person, catches the case auto-renew itself is blind to: the failed charge that nobody at the registrar or the business happens to notice until DNS has already gone dark.
There's also a version of this problem that has nothing to do with payment failure at all: the domain outliving the person who set it up. A common pattern in small organizations is a single founder or early employee registering the domain personally, on a personal card, under a personal email address, years before the business has any formal process around it. That person leaves, changes jobs, or simply stops checking that inbox, and the renewal notices go to an address nobody in the current organization can access — a failure mode ERRP's notice requirements cannot fix, because the notices are being delivered exactly as required. They're just being delivered to the wrong person.
This is worth treating as a distinct risk from a simple missed payment, because the fix is different. A payment failure is solved by better monitoring of a card. An orphaned registrant contact is solved only by actively auditing who's listed as the registrant and updating it deliberately — something almost no organization does on any regular schedule, precisely because it doesn't feel like the kind of task that has a deadline attached to it, right up until it does. There is a longer treatment of AI search, GEO and discovery in . There is a longer treatment of AI search, GEO and discovery in XenGrowth on AI search, GEO and discovery.
What should you actually do about this?
Confirm auto-renew is on and the payment method behind it is current, checked at least twice a year rather than assumed to be fine indefinitely
Set an independent calendar reminder 60 days before expiration, owned by a specific named person, separate from whatever notices the registrar sends — treat the registrar's ERRP notices as a backup, not the primary system
Register domains for multiple years at once where the registrar allows it, which reduces how often the renewal decision has to be made correctly at all
Know your specific registrar's redemption fee before you ever need it — it varies significantly between registrars and is rarely on the standard pricing page
If a domain is genuinely business-critical, put a second person on the registrar account with visibility into billing status, so the single-point-of-failure isn't one employee's inbox
It's worth being honest that no amount of process eliminates this risk entirely — a registrar can still fail to send a notice it was required to send, a payment processor can flag a legitimate charge as fraud at exactly the wrong moment, and a person responsible for checking can still be on vacation the one week it matters. The goal isn't a system that makes domain loss impossible. It's a system where the failure requires two or three independent things to go wrong at once, rather than the single missed email that took down Regions Bank's online banking for a week in 2013.
None of this requires distrusting ICANN's policy — the Redemption Grace Period and ERRP notices are real protections that make domain loss recoverable rather than instantaneous and total. But recoverable still means an outage, a redemption fee, and days of downtime while the fix goes through. The businesses in this post didn't need better ICANN policy. They needed one more person checking a calendar, and a second person who'd notice if the first one didn't. For the wider set of ways a domain can be lost beyond simple non-renewal, see What Actually Happens to Your Business If You Lose Your Domain?.
Further reading from XenGrowth
Where this work meets go-to-market
Building the operational discipline that keeps a business from losing revenue to a missed renewal? publishes operator guides on exactly this kind of unglamorous, high-stakes process work.
Further reading from XenGrowth
Where this work meets go-to-market
writes for the teams who have to run what happens if you forget to renew your domain day to day.
Further reading from XenGrowth
The XenGrowth resource library — what you'll learn: how the commercial side of this work is run, across search, automation and revenue operations.
XenGrowth on AI agents and marketing automation — what you'll learn: how the teams who own AI agents and marketing automation plan and measure it.
XenGrowth on AI search, GEO and discovery — what you'll learn: how the teams who own AI search, GEO and discovery plan and measure it.
Where this work meets go-to-market
XenGrowth's marketing operations practice writes for the teams who have to run what happens if you forget to renew your domain day to day.
Five questions on what actually happens, and when, after a domain lapses. Most people badly overestimate how much cushion the ICANN grace period actually provides.






