The domain you let lapse now works for someone else
Most businesses collect domains the way they collect old paperwork. The main one you use every day, then a scatter of others: the name from a campaign that ended, a product you renamed, a spelling you bought to stop anyone else having it, the site for an event three years ago. At some point the renewal notice arrives, nobody can quite remember why you have it, and you let it go.
Here is the part nobody mentions when you let it go. The domain does not vanish. It goes back on the market, and there is a whole industry waiting to buy it, precisely because your old domain can be worth more than a brand-new one.
What happened, and how much to make of it
Buying expired domains is a normal business, and mostly a legitimate one. It is called dropcatching: registering a domain the instant its previous owner lets it drop. Investors do it to resell names, businesses do it to recover a domain they lost track of, and plenty of it is ordinary trading in a finite resource. That is the honest baseline, and it is worth stating before the alarming part, because the alarming part gets reported without it.
Researchers at Infoblox published analysis putting some large numbers on the practice. They counted around 65,000 domains registered this way each day in the first half of the year, close to one in five of all newly seen domains, and tracked one operator, nicknamed Sable Squirrel, said to have spent more than $7 million on over 10,000 domains used for illegal streaming, gambling, and malware. They also reported finding more than 31,000 malware samples using such domains as control channels.
Treat those figures with some care. They come from a single security company, which sells products in this space, and the eye-catching leap is from "65,000 domains dropcatched a day" to "criminals are spending millions", when the first number plainly includes all the legitimate trading too. The write-up is thin on how it separates the two, and "one in five new domains is a dropcatch" is a claim about volume, not about crime. The specific criminal cases it names may well be real. The implied scale of the threat is the part to hold loosely.
What survives the scepticism is the mechanism, and it is genuine. A domain that has existed for years carries history: links pointing to it from other sites, a track record, and a standing with the automated reputation systems that email providers and security tools use to decide what to trust. A brand-new domain registered this morning looks suspicious to those systems. A domain that has been around since 2015 does not. So whoever catches an expired domain inherits its reputation, and if that person's intentions are bad, the reputation you built is now working for them. As Infoblox's Renée Burton put it, "expired domains can be a shortcut to both trust and traffic." That much is true regardless of the headline numbers.
Why this is your problem, not just theirs
There are two ways this reaches an ordinary business, and neither requires you to be a target.
The first is the domain you gave up. If you let a domain lapse, whoever catches it inherits its reputation, and for a while its old links and traffic. If your former domain once sent legitimate email, that history can help a scammer's messages land in inboxes. If customers or partners still have old links or saved addresses, those can now point at somebody else's page. The trust you spent years building does not retire when you do. It transfers.
The second is the domain you trust. Every business relies on links it did not create: a supplier's portal, a payment page, a login someone bookmarked, an address in an old email. Any of those can quietly change hands. The web address that was safe last year is not guaranteed to be the same organisation this year, and nothing on the surface tells you it changed. This is a cousin of the problem we wrote about in the address your kit still phones home to may belong to someone else now, moved from the machinery behind the scenes to the plain web addresses your people click every day.
What to do
None of this needs a big budget. It needs someone to treat domains as assets worth minding rather than bills worth cancelling.
- List the domains you own, and why. Most businesses cannot produce this list, which is the root of the problem. Include the ones nobody uses. You cannot make a sensible decision about a domain you have forgotten you hold.
- Think twice before dropping a domain that ever mattered. For a domain that carried your brand, sent email, or had real traffic, the safe option is usually to keep renewing it, or to park it deliberately, rather than release it into the market. Renewal is cheap. Handing your reputation to a stranger is not.
- Set renewals to automatic, and check who gets the reminders. A domain lost by accident, because the reminder went to someone who left, is the same outcome as one dropped on purpose. Make sure the important ones cannot lapse through inattention.
- Be a little wary of links you have not checked recently. For anything that matters, a supplier's payment page, a login, reach it the way you know is current rather than through an old bookmark or an address in an ageing email. If a familiar site starts behaving oddly, the owner may have changed.
- If a caught domain trades on your name, you may have recourse. For a
.ukdomain, Nominet's Dispute Resolution Service can order a name transferred back where the registration abuses your brand, and it decides these cases at high rates when the domain is a plain version of your name or a typo of it. It is not a remedy for a domain you deliberately gave up, but it is a real route when someone catches a lapsed name and uses it against you. We wrote about how those decisions actually get made.
The useful shift in thinking is small. A domain is not a subscription you switch off when you are done with it. It is a piece of your reputation, and reputation is exactly what the other side is buying.
How Steelwise can help
Working out which domains your business holds, which ones carry risk if you drop them, and which of the addresses you rely on are worth a second look, is the kind of practical security review we do with smaller firms. Get in touch.