Trackords - Tracking Records

Domain and SSL Certificate Expiry: Why It Happens and How to Prevent It

Why domains and TLS certificates lapse and how to prevent it: inventory, auto-renew pitfalls, 90-day certificates, registrar locks and a monitoring checklist.

Domains & IT 6 min read

A lapsed domain or an expired TLS certificate is the most visible failure a small IT estate can have: the website shows a browser warning or an advertising parking page, email stops arriving, and customers assume the business has closed or been hacked. It is also one of the most avoidable, because every domain and certificate has a known expiry date months in advance. This guide covers why they lapse anyway, what actually happens when they do, how to build an inventory, the pitfalls of relying on auto-renew, how to deal with 90-day certificates, registrar locks, and a monitoring checklist.

Why domains and certificates lapse

Almost never because nobody knew the date. The usual causes are:

  • The card on file expired. Auto-renew was on; the payment failed; the warning emails went to an address nobody reads.
  • The registrant email is dead. The domain was registered years ago by a founder, a former employee or a web agency, using an address that no longer exists. Renewal notices, verification requests and transfer approvals all go into the void.
  • The agency relationship ended. The developer who set up the site was paying for the domain or certificate on their own account. When the engagement ended, so did the renewals.
  • Certificates were installed manually once. A one-year certificate was bought and installed by hand; a year later the person who did it has moved on, and nothing is scheduled.
  • Too many providers. Domains at two registrars, certificates from a third, DNS at a fourth, each with its own login and renewal cycle.
  • Nobody owns it. Marketing thinks IT handles the domain; IT thinks the agency does; the agency thinks the client does.

What actually happens when they expire

Domain expiry is a sequence, not a cliff. On the expiry date most registrars suspend DNS resolution, so the website and email stop working immediately even though the domain is not yet lost. A grace period follows during which you can renew at the normal price, then usually a redemption period during which renewal is still possible but with a substantially higher fee, and finally the domain is released for anyone to register. The exact lengths and fees vary by registrar and by top-level domain; check your registrar’s current terms. Expired domains with traffic history are routinely bought by speculators and squatters within minutes of release.

Beyond the website, email is the real casualty. Every message sent to your domain bounces; password-reset emails for every other service you use go nowhere; and if the domain is captured, whoever holds it can receive your email and reset those passwords.

Certificate expiry is a cliff. The moment it passes, browsers show a full-page warning for the site, API clients refuse to connect, and anything that depends on the connection — payment pages, mobile apps, integrations with partners — fails. Internal certificates on mail servers, VPNs and management interfaces expire just as hard and are noticed later.

Build the inventory

You cannot renew what you do not know about. For domains:

  • List every domain the business owns, including defensive registrations, country variants, old brand names and campaign domains. Search your card statements and accounts-payable ledger for registrar charges, and ask long-serving staff.
  • For each, record: registrar, account login owner, registrant and admin contact emails, expiry date, auto-renew status, payment method, where DNS is hosted, and what depends on it (website, email, SaaS custom domains).
  • Run a WHOIS or RDAP lookup on each to confirm the expiry date and registrant contacts are what you think they are.

For certificates:

  • List every hostname that serves TLS: public websites, subdomains, APIs, mail servers, VPN endpoints, internal admin consoles, load balancers and CDN edges.
  • For each, record: certificate authority, expiry date, how it was issued (manual, ACME automation, managed by a CDN or hosting provider), where the private key lives, and who can reissue it.
  • Use certificate transparency logs (searchable public databases of issued certificates) to find certificates for your domains that you did not know existed.

Auto-renew pitfalls

Auto-renew is necessary but not sufficient. The failure modes are predictable:

  • It depends on a payment method that will itself expire. Record the card expiry alongside the domain expiry, and review both.
  • Registrars often attempt renewal a set number of days before expiry and retry a few times; if the retries fail, they stop and send email. If that email is unread, the domain lapses with auto-renew “on”.
  • Some registrars disable auto-renew after a failed payment, a changed account email or a transfer.
  • Multi-year renewals reduce the frequency of the problem but not its severity, and the longer interval makes the renewal easier to forget institutionally.

Treat auto-renew as the second line of defence. The first is a human who receives a reminder in good time and checks that the renewal has actually happened.

90-day certificates and automation

Publicly trusted certificates have been getting shorter-lived for years, and the industry is moving towards validity periods measured in weeks rather than a year. At those intervals manual renewal is not a realistic option; the only sustainable approach is automation using the ACME protocol, where a client on the server (or your CDN or hosting provider) requests, validates and installs certificates on a schedule without human involvement.

Automation does not remove the need for monitoring; it changes what you monitor. Automated renewals fail silently when DNS changes break validation, when a firewall rule blocks the validation request, or when the client software is out of date. Keep an external check on every public hostname that alerts when the certificate presented has less than, say, 14 days left — if automation is working, that alert should never fire, and when it does you still have two weeks.

Certificates that cannot be automated — some internal systems, code-signing certificates, certificates for appliances — go into the inventory with explicit reminders, exactly like a domain.

Registrar lock and account hygiene

While you have the inventory open, close the other common gaps:

  • Enable the registrar lock (transfer lock) on every domain so it cannot be transferred away without an explicit unlock.
  • Turn on two-factor authentication on registrar, DNS and certificate-authority accounts, and make sure more than one person can get in.
  • Set the registrant and admin contact emails to a role mailbox the business controls (such as domains@ or it@), not a person’s address, and make sure it is monitored.
  • Consolidate domains with one or two registrars where practical.
  • Where the registrar offers it, use the renewal-notice settings to send alerts to a second address.

Monitoring checklist

  1. Every domain and certificate is in one inventory with an owner and an expiry date.
  2. Reminders for each domain at 90, 30 and 7 days before expiry, sent to more than one person.
  3. Payment card expiry dates recorded for every auto-renewing account, with their own reminders.
  4. External certificate monitoring on every public hostname, alerting at 14 days remaining.
  5. Quarterly: confirm registrant contacts, locks and two-factor status on each registrar account.
  6. Annually: rebuild the inventory from statements, WHOIS lookups and certificate transparency logs to catch anything new.
  7. At offboarding: check whether the leaver was the account holder or contact for any domain, certificate or DNS provider.

How Trackords helps

Trackords is a free tracker with no credit card required, and domains and certificates are a natural fit. Create “Domain” and “Certificate” record types with custom fields for registrar or certificate authority, account owner, DNS host, auto-renew status and payment card expiry. Each record takes up to three email reminders at a chosen number of days before expiry, or on a fixed date, plus an optional alert on the expiry day — the 90/30/7 schedule above is set once per record.

Reminders are emailed to every active user of the workspace plus an optional extra address per record, so the alert reaches more than the one person who happens to hold the login. CSV import loads the inventory from a spreadsheet in minutes, and the audit log shows who updated a renewal date. Trackords is a reminder and record system, not a live certificate monitor, so pair it with an external uptime or TLS check for the hostnames that matter most. See the operations tracker page or the live demo, and for a fuller inventory of recurring IT costs read the SaaS subscription audit checklist.

Frequently asked questions

What happens when a domain name expires?

Most registrars suspend DNS on the expiry date, so the website and email stop working. A grace period usually follows, then a redemption period with a higher fee, and then the domain is released for anyone to register. Exact periods vary by registrar and top-level domain.

If auto-renew is on, can my domain still expire?

Yes. Auto-renew fails when the card on file has expired, when the account email is no longer monitored, or when the registrar disabled it after a failed payment or a transfer. Treat it as a backup to human reminders, not a replacement.

How do I find all the SSL certificates my company has?

List every hostname that serves TLS, including internal systems, and search certificate transparency logs for your domains to find certificates issued without central knowledge. Record the authority, expiry, issuance method and who can reissue each one.

Why are SSL certificates moving to 90-day validity?

Shorter validity limits the damage from compromised keys and forces automation. With certificates that short-lived, manual renewal is impractical, so ACME-based automated issuance with external expiry monitoring is the standard approach.

Track these dates in Trackords — free

Your own record types, up to three email reminders per record, and everyone on the team notified before the deadline.

Related guides

← All guides