dotvitals

The domain registration has expired

CriticalConfirmeddomain.rdap.expired

What this check looks for

The registry's expiry date for this domain is in the past. Depending on how long ago, the domain may already have stopped resolving, and after a grace period it can be deleted and registered by someone else.

Why it matters

An expired domain is the one failure that takes everything with it — website, email, logins that send to it, anything that trusts the name. Recovery gets more expensive at each stage and eventually becomes impossible: once the domain is released, whoever registers it next owns your identity.

When the check passes, your report says: “The registry's expiry date is still in the future”.

What it costs your score

When this check fails it removes 90 points from your Domain registration score, before the status, confidence and repeat multipliers are applied. Domain registration carries a weight of 5 in the overall score.

It shares the domain.expiry family ceiling of 90 points: however many findings that family produces, together they cannot remove more than that from Domain registration. One underlying problem showing up in several places is still one problem.

Severity
critical
Default confidence
confirmed
Status when triggered
fail
Deduction
90 points
Family cap
domain.expiry · 90
Category
Domain registration
Module
Domain rdap
Fix owned by
registrar
In the ruleset since
2026.09

How the whole score is calculated

How to fix it

Renew the domain at your registrar now, before it moves further through the deletion lifecycle.

Each stage costs more than the last, and the final one cannot be undone.

  1. Log in to the registrar named in this report and renew the domain immediately.

  2. If the control panel will not let you renew, the domain has probably reached redemption — open a support ticket and ask for a redemption restore. It is a manual, chargeable process at every registrar.

  3. Once it is renewed, turn on auto-renew and confirm the payment method on file has not expired. A lapsed card is the most common cause of this.

  4. Confirm the registrant email address on the domain is one you actually read: expiry notices go there and nowhere else.

How to confirm it worked

  • Re-run this scan and confirm the expiry date has moved into the future.

  • whois ‹domain› — or the RDAP record — should show the new expiration date and no redemptionPeriod or pendingDelete status.

A named slot like ‹domain› — and the braces left in the configuration below — is filled in with your own values when this rule appears on a report.

Technical detail

The registry reports an expiration date of ‹expires at›, which was ‹days ago› days ago. Registry status codes seen: ‹statuses›.

The lifecycle after expiry is fixed by registry policy and runs roughly: a 0-45 day auto-renew grace period during which the registrar can still renew at the normal price; then redemptionPeriod, about 30 days, in which only a restore at a substantially higher fee recovers it; then pendingDelete, about 5 days, after which the name is released to anyone. The domain usually stops resolving at the start of redemption, not at expiry.

A registry can also be slow to publish a renewal. If you renewed recently, re-check in a few hours before acting.

Standards and references

Test this on your domain

Run the check that produces this finding, on its own, against any domain.

Open the domain rdap checker

Other domain rdap checks