The domain is suspended by the registrar or registry
What this check looks for
A clientHold or serverHold status means the domain has been pulled from the zone deliberately. It resolves nowhere: no website, no email, regardless of how the DNS is configured.
Why it matters
Nothing else in this report can help while a hold is in place — the name does not resolve, so every other check is measuring a site nobody can reach. Holds are also usually a symptom of something with a deadline attached: unpaid renewal, unverified contact data, or a dispute.
When the check passes, your report says: “The domain is active at the registry, with no hold in place”.
What it costs your score
When this check fails it removes 90 points from your Domain registration score, before the status, confidence and repeat multipliers are applied. Domain registration carries a weight of 5 in the overall score.
It shares the domain.lifecycle family ceiling of 90 points: however many findings that family produces, together they cannot remove more than that from Domain registration. One underlying problem showing up in several places is still one problem.
- Severity
- critical
- Default confidence
- confirmed
- Status when triggered
- fail
- Deduction
- 90 points
- Family cap
- domain.lifecycle · 90
- Category
- Domain registration
- Module
- Domain rdap
- Fix owned by
- registrar
- In the ruleset since
- 2026.09
How to fix it
Contact the registrar today and find out what the hold is for.
The domain resolves nowhere until it is lifted, and holds usually have a clock attached.
Check for an unread registrant-verification email from the registrar. Clicking the link in it clears the most common cause of clientHold within minutes.
Check for an unpaid renewal or a failed payment on the account.
If the status is
serverHold, ask the registrar to tell you which registry action it relates to — they can see it and you cannot.Once it is lifted, confirm the registrant contact details on the domain are accurate. Deliberately wrong contact data is grounds for suspension in its own right.
How to confirm it worked
Re-run this scan and confirm no hold status remains.
dig ‹domain› NS +short — expect the delegation to answer once the hold is lifted.
A named slot like ‹domain› — and the braces left in the configuration below — is filled in with your own values when this rule appears on a report.
Technical detail
The registry reports these status codes: ‹statuses›.
clientHold was set by your registrar. The usual causes are non-payment and an unverified registrant email address — ICANN requires registrars to verify the registrant contact and to suspend the domain when verification fails. Your registrar can lift it as soon as the cause is resolved.
serverHold was set by the registry. Your registrar cannot lift it on their own; it is used for disputes, court orders, and invalid registration data escalated past the registrar. Start with your registrar, but the release has to come from the registry.
Either way the domain has been removed from the parent zone, which is why DNS fails rather than returning empty answers.
Standards and references
Test this on your domain
Run the check that produces this finding, on its own, against any domain.
Other domain rdap checks
- The domain registration has expired
- The domain registration expires within 30 days
- The domain registration expires within 7 days
- The domain registration expires within 90 days
- No transfer lock is set on the domain
- No update lock is set on the domain
- The domain is scheduled for deletion
- The domain is in the redemption period
- The registrant contact details are not published
- The registration data could not be read
- The registration is current and locked