A domain doesn't expire the way an SSL certificate does. When an SSL certificate lapses, visitors see a browser warning and your site still partially loads. When a domain expires, DNS resolution fails entirely. Your website goes down, your email stops delivering, every subdomain disappears, and every service attached to that hostname becomes unreachable — simultaneously, with no warning to anyone who depends on it.
This article covers what's actually happening right now, how long each recovery window lasts, and what the path back looks like depending on how far along the expiry timeline you are.
My Domain Name Expired — How Do I Get It Back?
The short answer: it depends on one number, which is how many days ago the registration lapsed.
Expired within roughly the last 30 days — log into your registrar and renew at the normal annual price. That is the entire fix.
Between 30 and 75 days ago — the domain is in redemption. You can still get it back, but you'll pay a restore fee on top of the renewal, and at most registrars you'll have to ask support rather than clicking a button.
More than about 80 days ago — the registration is gone. No fee recovers it and no registrar can reverse it.
So check the expiry date before anything else; it sets both the price and whether recovery is possible at all. The clock also keeps running while you work out who controls the registrar account, which is the most common reason people miss the cheap window.
First: Confirm It's the Domain, Not the Certificate
The symptoms are nearly identical from the outside — site unreachable, connection errors — and the fix is completely different.
Check the domain registration status directly at WHOIS lookup or at your registrar. If the registration expiry date is in the past, you have a domain expiry problem. If the domain status shows anything other than clientTransferProhibited or active, the domain has moved into expiry processing.
A useful cross-check: if your SSL certificate still shows as valid in a TLS check but the site is unreachable, the certificate is fine — the domain isn't resolving. The SSL checker connects via the hostname; if it can't resolve the domain at all, that points directly at registration expiry rather than a certificate problem.
For more on why these two systems fail independently, the domain expiry vs SSL expiry post covers the distinction in detail.
The First Hour: What to Do Right Now
Before you know which phase the domain is in, there is a fixed set of things worth doing immediately — most of them about restoring your ability to act, not about the domain itself.
1. Run a WHOIS lookup and record the exact registration expiry date and the domain status field. That tells you which phase you're in and how much time is left.
2. Find out who actually controls the registrar account. This is the most common blocker: the domain was registered years ago by a founder, an agency, or a developer who has since left. The renewal is trivial; finding the login is not.
3. Recover account access now, not later. Password resets go to the email on the registrar account — which may itself be an address on the expired domain, in which case you need the registrar's identity-based account recovery, and that takes days.
4. Export or screenshot your DNS records while you can still see them. Registrars retain the zone through grace and redemption, but a domain that drops takes every A, MX, TXT, and CNAME record with it.
5. Tell the people who depend on it. Inbound mail is bouncing and senders are getting hard failures, so anyone who tried to reach you today thinks you ignored them.
The Expiry Timeline
Registrars handle expired domains in a sequence of phases. The fees and recovery options change at each boundary.
Grace period — 0 to ~30 days after expiry
Most registrars hold the domain in a grace period immediately after expiry. During this window:
- ✓The domain is unreachable — DNS has already stopped resolving
- ✓Renewal is still available at the standard annual registration price
- ✓No penalty fees apply
- ✓Log into your registrar dashboard and renew normally
This is the cheapest and fastest recovery path. The exact length varies by registrar and TLD — .com and .ca grace periods are typically 30 days, but verify at your registrar directly.
Redemption period — ~30 to ~75 days after expiry
If the grace period passes without renewal, the domain enters redemption. At this stage:
- ✓The domain is still held by your registrar and not yet released to the public
- ✓Recovery is possible but requires paying a redemption fee on top of the renewal cost
- ✓The redemption fee is a large multiple of a normal renewal — commonly well into the low hundreds of dollars for gTLDs — and it varies enough between registrars and TLDs that the only figure worth acting on is the one your own registrar quotes you
- ✓Not all registrars surface this option clearly — you may need to contact support directly to initiate a redemption
The domain name and all its DNS records still belong to you during redemption. Once the fee is paid and the domain renews, DNS propagation begins and services restore — though propagation can take up to 24–48 hours depending on TTL values previously set.
Pending delete — ~75 to ~80 days after expiry
After the redemption period, the domain enters a pending delete phase lasting approximately five days. During this window:
- ✓The domain cannot be recovered by the previous owner
- ✓No fee will get it back
- ✓It is queued for release to the public
Released and available for registration
Once the pending delete phase completes, the domain drops and becomes available for anyone to register. Domain drop-catching services monitor these releases and register high-value names within seconds of them becoming available. Once this happens, recovering your original domain means either re-registering it at market price if it slips through uncaught, or negotiating with whoever acquired it — often at significantly inflated cost.
How to Read Your Domain's WHOIS Status Codes
The status field in a WHOIS record is the most reliable signal of where you stand — more reliable than a registrar dashboard, which often lags. A lookup returns something like this:
Domain Name: example.com
Registry Expiry Date: 2026-06-14T07:00:00Z
Domain Status: redemptionPeriod https://icann.org/epp#redemptionPeriodThe codes that matter once a domain has lapsed:
- ✓
okoractive— registration is current. If the site is still down, the problem is DNS or hosting, not registration. - ✓
autoRenewPeriod— the registry auto-renewed the domain and your registrar has a window to bill or cancel it. This is the grace period seen from the registry side, and it renews at normal price. - ✓
redemptionPeriod— 30 days, during which the registry rejects every command except a restore. Nothing can be changed, including nameservers, which is why the site stays down until the restore completes. Recoverable, but only through your registrar and only with the redemption fee. - ✓
clientHoldorserverHold— the registrar or the registry pulled the domain out of the DNS zone. This is not expiry. It is usually an unpaid invoice, failed registrant contact verification, or an abuse complaint, and it is often resolved the same day. A held domain can still be renewed, transferred, and updated. - ✓
pendingDelete— five days, and nothing reverses it. Not your registrar, not the registry, not a fee. - ✓
pendingRestore— the redemption fee is paid and the restore command has been issued. The domain is effectively yours again.
The distinction that catches people is clientHold versus redemptionPeriod. Both take the site down. One is a support ticket; the other is a countdown.
When the Status Says Deleted and Available Again
Once pendingDelete completes, the registration is released and WHOIS reports the name as available. Seeing your own domain listed as available is disorienting — it looks like a second chance.
Occasionally it is. Names with no commercial value do slip through and can be registered again at the normal annual price, as a brand-new registration. It costs nothing to check.
Treat that as luck rather than a plan, and understand that re-registering is not recovery. You get the name; you do not get back what was attached to it. The DNS zone is gone and must be rebuilt. Email deliverability restarts from a cold reputation. Every OAuth client, SSO integration, and webhook endpoint tied to the hostname was invalidated when the registration lapsed and has to be reissued. This stage is the outcome every earlier phase exists to prevent.
When Someone Else Has Already Registered It
The honest answer is that you almost certainly cannot get it back. There is no appeal, no registrar escalation, and no ICANN procedure for having owned a name first. A registration that completed its full expiry cycle was released correctly, and whoever registered it afterwards holds it legitimately.
You can try to buy it. The new registrant's contact details are in WHOIS and an offer costs nothing. Expect to pay well above registration price, expect non-responses, and expect anyone who can tell you need this specific name to price it accordingly.
You can wait. Registrations lapse for the same reasons yours did, and a name with no commercial value may drop again. Monitor it so you find out the day it does rather than months later.
You can file a UDRP complaint, but only in narrow circumstances: you hold a trademark, the registrant has no legitimate interest in the name, and they both registered and are using it in bad faith — all three, not any one. WIPO is explicit that the UDRP is a trademark remedy and that domain holders cannot use it against one another, so having previously owned a name is not itself grounds. Cases run roughly two months, and a panel can only transfer or cancel; there are no damages.
Redemption Fees and Grace Periods Vary by Registrar
There is no single redemption price, and a specific figure quoted anywhere other than your own registrar is likely wrong for your domain.
The fee has two parts. The registry operating the TLD charges the registrar a restore fee, which is the same for everyone. Your registrar then adds a handling charge set by nothing but its own pricing. That second component is why quotes for the same .com domain can differ by a factor of three between registrars.
Grace periods vary the same way. Thirty days after expiry is the common shape for .com and .net, but it is registrar policy rather than a rule — some hold domains longer, some shorter. Country-code TLDs run on separate schedules with their own redemption fees, and a few expire several days before the date printed on your invoice.
Two things follow. The only figure worth acting on is the one your registrar quotes you today, in writing, for your specific domain. And redemption is frequently not a self-serve button — many registrars require a support ticket to start it, so open one early rather than assuming you can pay on the last day of the window.
How the Recovery Process Works at a Registrar
Prices differ, but the shape of the process is consistent.
During the grace period, recovery is self-serve. The domain still appears in your registrar account with a renew action attached, and you pay the standard annual price through ordinary checkout.
Once the domain moves into redemption, self-serve typically stops. Restoring is a registry-level command your registrar issues on your behalf, which is why it becomes a support interaction rather than a button. Namecheap, for instance, documents checking the redemption price for your TLD, adding that amount to your account balance, then contacting support to complete the restore. Cloudflare Registrar documents a 30-day redemption window in which domains are held rather than deleted, notes that restoration may carry a fee, and blocks transfers outright while a domain sits in redemption.
Those are two registrars' published processes, not rules that hold everywhere — confirm your own registrar's steps directly. The operational point does generalize: if restoring requires a human, the request needs to be in well before the window closes.
When You Cannot Get Into the Registrar Account
Knowing which phase the domain is in does not help if nobody can log in, and this is the most common reason a recoverable domain goes unrecovered. It usually takes one of a few shapes: the founder, agency, or contractor who registered it has moved on; the account email is an address on the domain that just stopped resolving; or the recovery phone number belongs to someone who left.
A password reset solves none of these, because the reset message goes to an address that either bounces or reaches someone you cannot reach. What you need is the registrar's identity-based account recovery — a manual process reviewed by a person.
Start it immediately and in parallel with everything else, because it is measured in days and the expiry clock does not pause for it. Expect to prove the organization controls the registration rather than that you personally do: incorporation or business registration documents, a billing record matching past renewals, government ID for whoever is named on the account, and any registrar correspondence still sitting in a colleague's inbox.
Two things speed it up. Use phone or live chat over email, since a ticket queue can consume the grace period by itself. And say explicitly that the domain is expired and inside a closing recovery window — registrars will often prioritize these, but only if you tell them a deadline exists.
What's Broken and Why
Unlike SSL expiry, which only affects HTTPS connections, domain expiry breaks the hostname entirely:
- ✓Your website is unreachable — HTTP and HTTPS both fail because DNS has no record to resolve
- ✓Email stops delivering — MX records resolve through the same DNS zone; no domain, no mail routing
- ✓Every subdomain disappears —
api.yourdomain.com,mail.yourdomain.com,app.yourdomain.comall resolve through the same root - ✓Third-party services pointing at your domain fail — anything relying on your hostname as an authentication callback, webhook target, or CDN origin goes down simultaneously
This is the reason domain expiry causes disproportionate damage relative to SSL expiry. A single registration lapse is a total service failure, not a degraded one.
"My Website Expired" — Everything Else That Broke With It
People describe this as the website expiring, because the website is the part they can see. The hostname is what expired, and it was load-bearing for more than the site.
The failures that surface a day or two after the outage:
- ✓Single sign-on breaks in both directions. OAuth redirect URIs and SAML endpoints on your domain stop resolving, so users get locked out of tools that have nothing to do with your website.
- ✓Email damage outlasts the outage. Senders get hard bounces rather than retries, mailing lists auto-unsubscribe your addresses, and your SPF, DKIM, and DMARC records vanish with the zone — so deliverability stays degraded after the domain returns.
- ✓Internal tooling goes down with the public site. Dashboards, staging environments, and CI webhooks on subdomains share the same root and fail at the same moment.
- ✓Certificate renewal quietly fails too. Automated issuance validates domain control over HTTP or DNS, and neither works while the domain does not resolve. A certificate that was healthy the day the registration lapsed expires on schedule with no way to renew it.
That last one compounds: you can finish redemption and find an SSL outage stacked on top, because a stopped domain also stops the automation keeping the certificate alive.
Immediate Steps
1. Log into your registrar and check which phase the domain is in
2. If in grace period: renew immediately at the standard price
3. If in redemption: contact registrar support to initiate redemption, confirm the fee, and pay it — don't wait, the window closes
4. If pending delete: the domain cannot be recovered; begin planning for a new name or set up monitoring on the old domain to catch if it drops uncaught
5. After renewal, verify DNS propagation with a WHOIS lookup before assuming services have restored
Why It Happened
The most common reasons a domain lapses despite auto-renew:
- ✓The payment method on file expired or was cancelled — renewal charges fail silently, and some registrars only send one notification before moving to grace
- ✓The account email address is outdated — registration emails go to whoever set up the account, often a former employee or a personal address nobody checks
- ✓Auto-renew was off on this specific domain — it's a per-domain toggle, not an account-wide setting, and domains added quickly don't always get it enabled
- ✓The registrar's notification went to spam
None of these surface until the domain stops resolving.
Monitoring Prevents the Entire Timeline
External domain monitoring checks your registration expiry date daily via WHOIS — the same public record that shows you where in the timeline you are — and alerts you at 30, 14, 7, and 1 day before expiry. The alert arrives when renewal is cheap and instant, not after DNS has already failed.
ExpiryPing monitors both domain registration expiry and SSL certificate expiry for every domain you add. No registrar credentials, no account access — WHOIS data is public. Setup is under five minutes. Free for up to 3 domains, paid plans from $19/month.
The grace period is where this is cheap and reversible. Redemption is expensive. Pending delete is irreversible. The only variable is whether you had 30 days of warning or zero.