Never Lose a Domain: Renewals, Transfer Locks, WHOIS Hygiene and Portfolio Security
Nobody loses a domain in a dramatic hacking-movie moment. Domains are lost in boring ways: a renewal notice goes to an email address that no longer exists, a credit card on file expires, an employee who "handled the website stuff" leaves the company, or a registrar account protected by a reused password gets quietly taken over months before anyone notices. By the time the loss is visible, your website is down, your email has stopped, and, in the worst cases, someone else legally controls the name your entire business runs on.
The uncomfortable truth is that for most small businesses, the domain is the single most fragile piece of critical infrastructure they own. Your website can be rebuilt from a backup. Your email provider can be swapped in a day. But the domain sits underneath both, and recovering a lost or hijacked one ranges from stressful to impossible. Prevention is cheap and mostly a matter of configuration and habit; recovery is expensive and uncertain.
This article is a practical, front-to-back guide to keeping the domains you own: renewals and expiry mechanics, account security, transfer locks, WHOIS and contact hygiene, DNS-level protections, and how to run a small portfolio so that nothing depends on one person's memory.
Understand the expiry timeline before you need to
Most people believe that when a domain expires, it is gone. In reality there is a multi-stage timeline, and knowing it can save a business.
- Expiration date. The domain stops resolving or gets pointed at a registrar parking page. Your website and email typically break at this point, but you have not lost the name.
- Renewal grace period. Most registrars offer a grace window, commonly up to 30 to 45 days depending on registrar and TLD, during which you can renew at the normal price.
- Redemption period. For most gTLDs, after the grace period the domain enters a roughly 30-day redemption phase. You can still recover it, but only through your registrar and only by paying a redemption fee, often in the range of $80 to $200 on top of the renewal.
- Pending delete. A final window of about five days during which nobody can recover it. Then the domain drops and becomes available, except that valuable names rarely reach open availability, because drop-catching services snap them up seconds after release, and they go to auction.
The gotcha: country-code TLDs frequently do not follow this timeline. Many ccTLDs have shorter grace periods, no redemption phase at all, or entirely different rules set by the national registry. If your portfolio includes country extensions, look up each registry's expiry policy specifically. Assuming your .de or .com.au behaves like a .com is exactly how businesses with international domains lose them.
Auto-renew is necessary but not sufficient
Turn on auto-renew for every domain you intend to keep. Then recognize that auto-renew fails silently in three common ways: the card on file expires, the card is cancelled or replaced after fraud, or the charge is declined and the failure notification goes to a dead mailbox. Fix this structurally:
- Keep two payment methods on file where the registrar supports a backup card.
- Set important domains to multi-year registrations. Renewing your core domain for five to ten years costs little and converts an annual point of failure into a rare event.
- Put the expiry dates of your critical domains in your company calendar as recurring reminders 60 and 30 days out, independent of the registrar's emails. The registrar's reminders depend on the very contact details that fail; your calendar does not.
Your registrar account is the crown jewels: secure it accordingly
Almost every domain hijacking in the small-business world is really an account compromise. Whoever controls the registrar login controls the domain, the DNS, and by extension your email, and from your email, password resets for everything else you use. Treat the registrar account with the same seriousness as your bank account, arguably more, because banks reverse fraudulent transfers and registries frequently cannot.
The non-negotiables
- A unique, long password used nowhere else, stored in a password manager. Credential-stuffing from unrelated breaches is the most common entry point.
- Two-factor authentication, and prefer an authenticator app or a hardware security key over SMS. SIM-swap attacks specifically target SMS-based 2FA on high-value accounts, and domain accounts are high-value.
- A registrar account email on a domain you control forever, secured with its own strong password and 2FA. Here is the trap most people miss: setting the registrar account's email address to an address on the same domain the account manages. If that domain ever expires or its DNS breaks, you cannot receive the password reset needed to fix it, a circular dependency that turns a small outage into a lockout. Use an address on a separate, stable domain or a well-secured mailbox from a major provider for registrar access.
Limit and formalize access
If more than one person needs access, use the registrar's delegation or teams feature rather than sharing the master password. Shared credentials mean you cannot revoke one person's access without resetting everyone, and you have no audit trail. When an employee or agency relationship ends, revoking their delegated access should be a checklist item, the same as collecting a laptop.
The gotcha: agencies and web developers frequently register the client's domain under the agency's own registrar account, sometimes even in the agency's name. The relationship sours or the agency folds, and the business discovers it never actually controlled its own domain. If a third party manages your web presence, verify today that the domain's registrant organization is your company, and that it lives in a registrar account you own, with the agency delegated in as a user. If it is the other way around, request a transfer or account move now, while relations are good, not during a dispute.
Locks: the layers between your domain and an unauthorized transfer
Domain transfers between registrars are deliberately easy for legitimate owners, which means they are a target for attackers. Several locking mechanisms exist, in escalating strength.
Registrar lock (transfer lock)
The standard client-transfer-prohibited status, toggled in your registrar dashboard, blocks transfer requests until you unlock. Every domain you own should have this enabled; most registrars enable it by default, but verify. It stops casual and automated transfer attempts, though not an attacker who has already compromised your account, since they can simply unlock it.
The authorization code
Transfers to a new registrar require an auth code (EPP code) obtained from the current registrar. Treat this code like a password: generate it only when you are actively transferring, and never send it to anyone who asks for it in an unsolicited email. "We need your transfer code to fix your listing" is a standing phishing pattern.
Registry lock
For genuinely critical domains, ask your registrar about registry lock, a service where changes to the domain are frozen at the registry level and require an out-of-band manual verification process, often a phone call with passphrases, to alter. It typically costs a meaningful annual fee and is overkill for most names, but if your entire company runs on one domain, it is the strongest protection money can buy, and it is what large enterprises use on their primary brands.
The 60-day rules
Two related rules surprise people at the worst moments. First, a domain generally cannot be transferred between registrars within 60 days of initial registration or a previous transfer. Second, under ICANN's transfer policy, many registrars apply a 60-day transfer lock after a change to the registrant's name, organization, or email. The gotcha: if you update your registrant details, say, changing the contact email or your company name, right before a planned sale or registrar move, you can trigger that 60-day freeze and stall the entire transaction. Some registrars let you opt out of the post-update lock at the moment you make the change; if you know a transfer is coming, either complete the transfer first or explicitly opt out during the update if offered.
WHOIS and contact hygiene: unglamorous, decisive
Every domain carries registrant, admin, and technical contact records. Since GDPR, public WHOIS output is largely redacted for gTLDs, and most registrars include privacy services that hide your details from the public. Use the privacy service; it cuts spam and blocks casual harvesting of your information for phishing.
But privacy is about what the public sees. What the registrar and registry have on file still matters enormously:
- The registrant email must be alive and monitored. ICANN requires registrars to verify contact details, and an unverified or bouncing registrant email can lead to domain suspension, a self-inflicted outage that surprises people every year. Renewal notices, transfer approvals, and dispute correspondence all go there.
- The registrant organization should be your legal entity, not a person. If the domain is registered to a founder personally or to a former employee, ownership follows that person in a dispute, a divorce, an estate, or a bitter exit. Registering to the company also simplifies proving ownership to a registrar's recovery team.
- Use a role address, not a personal one, something like domains@yourcompany on a stable domain, forwarded to at least two people. Single-person contact chains are how renewal failures happen during vacations, illnesses, and departures.
Here is the trap most people miss with privacy services: some sellers and services historically placed the privacy provider itself as the registrant of record. If the registrar or privacy service ever shuts down, changes hands, or disputes your account standing, proving that you are the beneficial owner becomes harder than it should be. Confirm in your registrar dashboard that the underlying registrant data, the data behind the privacy curtain, names you or your company accurately.
DNS-level protection: hijacking without touching the domain
Attackers do not need to steal your domain to abuse it; controlling your DNS is enough to intercept email, harvest credentials on a cloned site, or issue TLS certificates in your name. A few configurations close most of this off:
- Secure the DNS provider account with the same rigor as the registrar account, unique password and app-based 2FA, if your DNS is hosted separately from your registrar.
- Enable DNSSEC if your registrar and DNS host both support it. It cryptographically signs your DNS records so resolvers can detect tampering. Note the operational caveat: if you later change DNS providers, you must handle the DS records correctly during the move or you will cause an outage, so document that it is on.
- Add a CAA record specifying which certificate authorities may issue certificates for your domain. It is one DNS record and it narrows an attacker's options considerably.
- Set SPF, DKIM, and DMARC on domains that send email, and publish restrictive SPF plus a reject-policy DMARC on domains that do not send email at all. Parked and defensive domains without these records are freely spoofable, and attackers specifically use a company's own unused domains to phish its customers and staff.
Running a portfolio: process beats memory
Once you own more than two or three domains, defensive registrations, product names, old brands, campaign microsites, informal management stops working. You do not need enterprise software; you need a simple system.
Keep a single inventory
Maintain one spreadsheet or document listing every domain, its registrar, expiry date, auto-renew status, what it is used for, where its DNS is hosted, and who is responsible. Review it quarterly. The most common portfolio failure is a domain nobody remembered existed until it expired, along with the email forwarding or redirects that quietly depended on it.
Consolidate registrars deliberately
Domains scattered across five registrars, accumulated from old hosting bundles and one-time promotions, multiply your attack surface and your chances of a missed renewal. Consolidating to one or two reputable registrars simplifies security, billing, and monitoring. Choose registrars on the strength of their account security options, support quality, and transparent renewal pricing rather than first-year teaser rates. The gotcha: bargain first-year pricing often conceals renewal rates several times higher, and certain TLDs carry premium renewal tiers on specific names, meaning that a domain you registered for a few dollars can renew at hundreds per year, every year. Check the renewal price, not the promotional price, before you register or transfer anything, and before you build a brand on a name whose carrying cost you have not read.
Decide what to keep, and let the rest go on purpose
Renewal review is also portfolio pruning. For each name ask: does it protect the brand (common misspellings, key alternate TLDs), does it serve a live function (redirects, email), or does it have plausible resale value? If none of the three, letting it lapse is a decision, not a failure, just make it consciously, after confirming nothing still points at it: old marketing materials, printed QR codes, email addresses, OAuth callback URLs, or link equity you would rather redirect.
Plan for succession
Someone other than the founder should be able to access the registrar account in an emergency, through documented break-glass credentials in a company password manager or the registrar's account-recovery designation. Businesses have gone dark because the one person with registrar access was unreachable, and untangling access without them takes weeks of identity verification.
If the worst happens: recovery basics
Move fast; every stage of loss is easier to reverse early.
- Expired domain: renew immediately if within grace, pay the redemption fee if within redemption. Do not wait for a better price; waiting only moves you toward the drop and the drop-catchers.
- Compromised account: contact the registrar's security team through their documented emergency channel, change credentials, and ask them to lock the domain and freeze pending transfers.
- Domain already transferred away: ask your registrar to file a transfer dispute under ICANN's Transfer Dispute Resolution Policy, gather evidence of the unauthorized change, and act quickly, disputes are far more effective in the days after a hijack than months later, and stolen domains get flipped fast.
- Someone registered your trademarked name: that is a UDRP or legal question rather than a recovery one, and worth a conversation with counsel before you email the squatter and reveal your interest.
Conclusion: a checklist worth an hour of your time
Domain protection is unusual among security topics in that nearly everything meaningful can be done in a single afternoon: auto-renew with a backup card, multi-year registration on the core domain, 2FA on the registrar and DNS accounts, a registrar contact email that does not depend on the domain itself, transfer locks verified, registrant details in the company's name at a role address, SPF, DKIM, DMARC, and CAA records published, and one inventory document with a quarterly calendar reminder. None of it is difficult and none of it is expensive.
What it buys you is the removal of a category of catastrophic, unrecoverable failure from your business. Websites and campaigns are replaceable. The name, once lost to expiry mechanics or an account takeover, often is not. Spend the hour.