dotvitals

The domain is suspended by the registrar or registry

CriticalConfirmeddomain.rdap.on-hold

What this check looks for

A clientHold or serverHold status means the domain has been pulled from the zone deliberately. It resolves nowhere: no website, no email, regardless of how the DNS is configured.

Why it matters

Nothing else in this report can help while a hold is in place — the name does not resolve, so every other check is measuring a site nobody can reach. Holds are also usually a symptom of something with a deadline attached: unpaid renewal, unverified contact data, or a dispute.

When the check passes, your report says: “The domain is active at the registry, with no hold in place”.

What it costs your score

When this check fails it removes 90 points from your Domain registration score, before the status, confidence and repeat multipliers are applied. Domain registration carries a weight of 5 in the overall score.

It shares the domain.lifecycle family ceiling of 90 points: however many findings that family produces, together they cannot remove more than that from Domain registration. One underlying problem showing up in several places is still one problem.

Severity
critical
Default confidence
confirmed
Status when triggered
fail
Deduction
90 points
Family cap
domain.lifecycle · 90
Category
Domain registration
Module
Domain rdap
Fix owned by
registrar
In the ruleset since
2026.09

How the whole score is calculated

How to fix it

Contact the registrar today and find out what the hold is for.

The domain resolves nowhere until it is lifted, and holds usually have a clock attached.

  1. Check for an unread registrant-verification email from the registrar. Clicking the link in it clears the most common cause of clientHold within minutes.

  2. Check for an unpaid renewal or a failed payment on the account.

  3. If the status is serverHold, ask the registrar to tell you which registry action it relates to — they can see it and you cannot.

  4. Once it is lifted, confirm the registrant contact details on the domain are accurate. Deliberately wrong contact data is grounds for suspension in its own right.

How to confirm it worked

  • Re-run this scan and confirm no hold status remains.

  • dig ‹domain› NS +short — expect the delegation to answer once the hold is lifted.

A named slot like ‹domain› — and the braces left in the configuration below — is filled in with your own values when this rule appears on a report.

Technical detail

The registry reports these status codes: ‹statuses›.

clientHold was set by your registrar. The usual causes are non-payment and an unverified registrant email address — ICANN requires registrars to verify the registrant contact and to suspend the domain when verification fails. Your registrar can lift it as soon as the cause is resolved.

serverHold was set by the registry. Your registrar cannot lift it on their own; it is used for disputes, court orders, and invalid registration data escalated past the registrar. Start with your registrar, but the release has to come from the registry.

Either way the domain has been removed from the parent zone, which is why DNS fails rather than returning empty answers.

Standards and references

Test this on your domain

Run the check that produces this finding, on its own, against any domain.

Open the domain rdap checker

Other domain rdap checks