About Expertise Work Projects
Hosted Monitoring & Dashboards Self-Hosted Observability Stack Bulk Document Data Extraction
Free Tools
Website Health Check Email Domain Health Check DNS Health Check SSL Certificate Checker Redirect Chain Checker Robots.txt Checker XML Sitemap Validator Docker Compose Checker WordPress Security Check AWS IAM / S3 Policy Checker Domain Registration Lookup Downtime Cost Calculator
Blog Certifications Hire Me

When does this domain expire, and is anyone watching?

Enter a domain. This reads the registration straight from the registry — the renewal date, the transfer lock, the status codes and the nameservers on file — and tells you what needs handling. No signup, no email required.

One request to the registry that runs the domain ending, and one DNS lookup. Nothing connects to your servers, and nothing is scanned or enumerated.

Every test, explained

Seven checks, six of them read straight from the registry that runs your domain ending and one that compares it against live DNS. Here is what each one is, and why it is worth knowing.

The renewal date

This is the one people come for. The tool reads the expiry date the registry holds and counts the days. Inside 30 days it reports high. Between 31 and 90 it reports a warning. Past the date, it reports critical.

Why the fuss? Because a lapsed domain takes the website and the email down at the same moment. There is no partial failure and no warning banner. One morning the site is simply gone, and so is every address at that domain.

Registry status codes

Registries publish status codes against every domain. Most are routine. Four are not: clientHold and serverHold pull the domain out of the zone so it stops resolving, while redemptionPeriod and pendingDelete mean it has already lapsed and is on a countdown to deletion.

A hold is worth knowing about immediately. The registration still exists, so the domain looks fine in your registrar account, but nothing resolves. That gap between "it looks fine" and "it is down" is why the check exists.

The transfer lock

A transfer lock stops the domain being moved to another registrar until somebody with account access removes it. The tool reports whether clientTransferProhibited or serverTransferProhibited is set.

It is free, it takes two clicks, and almost every registrar sets it by default. So when it is missing, that usually means somebody turned it off during a move and never turned it back on. Domain theft normally starts with a compromised registrar account and ends with a transfer nobody noticed.

A transfer already in progress

If the registry reports pendingTransfer, the tool says so. That status is completely normal when you started the move yourself.

When you did not, it is the loudest warning in this whole report. A transfer nobody authorised is what a domain being taken looks like from the outside. Stopping one before it completes is straightforward. Reversing it afterwards is not.

Registry nameservers against live DNS

The registry holds a list of nameservers for your domain. The zone itself publishes one too. The tool reads both and compares them, but only in one direction: it reports a nameserver the registry lists that DNS no longer uses.

That direction is the one that breaks things. A resolver with nothing cached goes to the registry's list first, so a stale entry there can serve old records to some visitors while everyone else gets the current ones. The reverse — a zone publishing more nameservers than the registry knows about — is normal and does no harm, so it is not flagged.

DNSSEC delegation

The tool reports whether the registry holds a signed delegation for your domain. With one, a resolver can verify that the answers it gets have not been tampered with. Without one, it cannot.

Most small business domains do not have it, so this reports as information rather than a fault. It is worth turning on where both your registrar and your DNS host support it. It is also worth doing carefully, because a botched DNSSEC change takes a domain offline more thoroughly than almost anything else.

Published registrant contact details

Most registries now redact the owner's name, email address and phone number. Some still publish them. The tool reports which kinds of contact field are public — name, email, phone, address — and never reproduces the values.

The reason it matters is narrow and real. The published email is usually the account recovery address at the registrar, which makes it the obvious target for a convincing fake renewal notice. Knowing it is out there changes how carefully you read those emails.

What usually goes wrong, and how to fix it

Domains rarely lapse because somebody decided to let them go. These are the ways it actually happens, and what to do about each one.

The domain expired and the site went down

Renew it immediately, at the registrar you already have. Do not start a transfer. Most registries give a grace period of a few weeks where a normal renewal still works, so speed matters more than anything else here.

After the grace period comes redemption, which costs considerably more than a renewal and has to be requested rather than clicked. After that the domain is deleted and anyone can register it. At that point it is gone.

Renewal notices go to an address nobody reads

This is the actual cause of almost every lapsed domain. The registrar account was set up years ago by a developer who has moved on, or it points at an address on the very domain that is expiring.

Fix the contact address on the registrar account first. Then check the card on file, because a failed renewal charge produces exactly the same outcome as no notice at all. Finally, put the date somewhere that is not an inbox.

There is no transfer lock

Turn it on. It is in the registrar control panel, usually on the domain's own settings page, and it is free. Look for "transfer lock", "registrar lock" or "theft protection" depending on who you are with.

The only reason to leave it off is that you are genuinely moving the domain right now. Turn it back on when the move completes, because that is the step people forget.

The registry says clientHold or serverHold

Contact your registrar today and ask what put it there. You cannot clear a hold yourself, and it will not clear on its own.

The usual causes are an unpaid invoice, an unverified registrant email address, or a complaint made against the domain. ICANN requires the registrant contact to be verified, and an ignored verification email will suspend a working domain without anything else going wrong.

The registry and DNS disagree about nameservers

Decide which list is right, then make the other match. Nearly always the live DNS is correct and the registry entry is left over from a move that was never finished.

Update the nameservers in the registrar control panel to match what is actually serving the zone. Then wait — the change is at the registry, so it takes as long as the parent zone's TTL rather than yours.

No renewal date came back

Some registries publish a registration date and a last-changed date but no expiry. Nominet, which runs .uk, is the one most people meet. Nothing is wrong with the domain and there is nothing to fix.

Get the date from your registrar account instead, and write it down. This is the case where an automated check genuinely cannot help you.

Domains lapse quietly.

Not because anyone stopped caring, but because the renewal notice went somewhere nobody reads. If you own more than a couple of domains and nobody is watching the dates, that is worth a conversation.

Prefer to talk? Book a free call ↗  ·  Or hire me on Upwork ↗  ·  Typical reply within one business day.

Questions

What is RDAP, and how is it different from WHOIS?
RDAP is the replacement for WHOIS. It answers over HTTPS and returns structured JSON, where WHOIS returned free text in a different layout for every registry. This tool reads RDAP only. It never connects to port 43, which is the old WHOIS protocol, because that data cannot be parsed reliably and the port sits outside the rules this site's tools follow.
Why does it say the registry does not publish a lookup service?
Because that domain ending has no RDAP service this tool can reach. Coverage comes from the registry list IANA publishes, which covers 1,203 endings here. Several common ones are missing from it entirely, including .co, .me, .eu, .it, .es and .eg. That is the registry's choice, not a fault with your domain, and it says nothing at all about whether the domain is healthy.
Why is there no expiry date for my .uk domain?
Nominet publishes a registration date and a last-changed date over RDAP, but not an expiry. So the tool reports the date as unknown rather than guessing one. Your Nominet account or your registrar will show it. This is normal for .uk and it is not a sign of a problem.
Does this change anything on my domain?
No. It reads and nothing else. The tool makes one request to the registry that runs your domain ending and one DNS lookup for your nameservers. It never connects to your servers, never tries a transfer, and never touches your registrar account.
How often are results refreshed?
Repeat lookups of the same domain are served from cache for 24 hours. That is much longer than the other tools here, and deliberately so: registration data changes a few times a year, and the registries have their own rate limits worth respecting. If you have just renewed, the date shown may be a day behind.
Is there a limit on how many domains I can look up?
Yes, and it is generous. Ten lookups an hour from one address, and three an hour for any single domain. Cached results do not count against either. The limits exist to keep the registries happy rather than to push anyone towards paying for something.
My registrar shows a transfer lock but this says there is none. Which is right?
Check the registrar again, because this tool only reports what the registry publishes. A lock set in a control panel but never pushed up to the registry does nothing at all, and that mismatch is worth resolving. If the registry does not know about the lock, the lock is not protecting the domain.
Should I turn on DNSSEC?
If your registrar and DNS host both support it properly, yes. If either half is awkward about it, the honest answer is that it matters less than a transfer lock and a renewal date that somebody is watching. A DNSSEC change made carelessly takes a domain offline completely, and the failure is not obvious from a browser.
Do you store the domains people look up?
The result is cached for 24 hours so repeat visits do not hammer the registry, and the rate limiter counts requests per address and per domain. Nothing is kept beyond that, no account is created, and no email address is asked for at any point. Result pages are also marked noindex, so a lookup you share cannot turn into a search result carrying somebody's domain.