Drop Catch Domains: What They Are, Why They Matter, and How to Act

Executive Summary: Drop catch domains create a significant security risk when expired domains are re-registered and used as attack infrastructure. Organizations often accumulate domains through campaigns, old product names, and acquisitions, but when one lapses, a third party can inherit the trust, traffic, email history, and connections it still carries. This blog explains how drop catching works, the risks it creates, and how CheckRed DNSPM helps detect exposure at every stage—from initial expiration through third-party registration.

Organizations accumulate domains over time: campaign microsites, old product names, and domains inherited through acquisitions. When one lapses, someone else can register it and inherit all the trust it still carries. This is drop catching, one of the most overlooked risks in an external attack surface.

 

1. What Is Drop Catching? 

Drop catching is registering a domain the moment it becomes available after its previous owner lets it expire. Specialized services monitor expiring domains and submit registration requests within milliseconds of release. 

A domain doesn’t become available the instant it expires. For most generic TLDs (.com, .net, .org), it moves through a lifecycle:

Here’s what each phase means for the domain owner:

Phase  What happens  Can you recover it? 
Expiration  Registration term ends; DNS may be suspended or parked  Yes, usually at standard renewal cost 
Grace period  Auto-renew grace (registrar-defined, often up to 45 days), followed by a redemption period of around 30 days  Yes, but costs rise during redemption 
Pending delete  Around 5 days; recovery is no longer possible  No 
Release  Domain returns to the public pool and drop catchers compete for it  Only if you win the race 

Timelines vary by registrar and TLD, and many country-code TLDs follow their own rules. 

Many drop catchers are domain investors. But the same mechanism is available to attackers, and a domain with existing traffic, email history, or embedded trust is exactly what they look for. 

 

2. Why Is It Important? 

A lapsed domain is often still referenced across your environment and in your users’ habits. Whoever registers it next can exploit that trust: 

  • Email interception: The new owner can set up MX records and receive password resets, invoices, and partner emails still sent to the old domain. 
  • Account takeover: SaaS, cloud, and developer accounts registered with addresses on the domain can be hijacked through “forgot password” flows. 
  • Email spoofing: If your active domain’s SPF record still includes the lapsed domain, the new owner may be able to send email that passes SPF checks as you. 
  • Dangling references: CNAMEs, script includes, OAuth redirect URIs, webhooks, and API callbacks pointing to the domain can serve malicious content or capture tokens. 
  • Phishing and brand abuse: A domain your customers once trusted, with its search ranking and reputation intact, is an ideal phishing launchpad. 

It Happens to Well-Known Organizations 

Domain expiry incidents are not hypothetical. A few public examples, mapped to the stage each one reached: 

Organization  What happened  Stage reached 
Foursquare (2010)  Its primary domain lapsed and the entire service went offline until the company noticed and renewed it.   EXPIRED  
Sorenson (2017)  An expired domain caused a three-day outage of its relay services, including access to 911, followed by a $3 million FCC settlement.   EXPIRED  
Mobi Bank, Serbia  Banking systems still relied on a legacy domain from an acquired bank. It expired, taking web, net banking, and mobile services down until renewed.   EXPIRED  
tema.com (2020)  A domain Parker Hannifin gained through an acquisition was not renewed. Drop catchers were waiting, and it was auctioned to a new owner for $43,805.   RE-REGISTERED  
Maryland license plates (2023)  A domain printed on around 800,000 license plates expired, was released, and was registered by a third party who pointed it to an online casino.   RE-REGISTERED  

Most of these organizations recovered their domains while they were still in the expired or grace stage. The last two show what happens when that window closes: the domain, and the trust attached to it, belongs to someone else. 

These exposures usually aren’t caused by negligence but by a lack of visibility. Domain ownership is spread across marketing, IT, engineering, and acquired entities. Renewal notices go to former employees. Auto-renew fails on an expired card. Domains are retired without checking where they’re still in use. 

 

3. How You Can Act on It 

The earlier you catch a lapsing domain, the cheaper and simpler the fix. CheckRed DNSPM now detects drop catch risk at all three stages, so your team can act at the right moment. 

Stage 1: MEDIUM Domain Expired What CheckRed detects: Domains that have passed their expiration date. 

What to do: Renew immediately if the domain is still needed. This is the lowest-cost point to resolve the risk.

Stage 2: HIGH  Domain in Grace Period What CheckRed detects: Domains in the post-expiry grace or redemption period. 

What to do: Treat this as urgent. Either renew the domain before the window closes, or make a deliberate decision to retire it after removing every reference to it, including DNS records, SPF includes, code, SaaS logins, and redirect URIs. 

Stage 3: CRITICAL  Domain Registered by Someone Else What CheckRed detects: Domains that have passed the grace period and are now registered by a third party. 

What to do: Shift from recovery to containment: 

  1. Remove all DNS records, SPF includes, and configurations that reference the domain. 
  2. Update accounts and rotate credentials tied to email addresses on the domain. 
  3. Audit code, integrations, and OAuth settings for references to it. 
  4. Monitor for phishing and warn customers or partners if impersonation is likely. 

 

Preventive Best Practices 

  • Keep a complete domain inventory, including acquired and marketing domains. 
  • Enable auto-renew and registrar lock, with shared, monitored inboxes as registrant contacts. 
  • Decommission domains deliberately, cleaning up every reference before letting them lapse. 
  • Keep high-risk domains (those once used for email or authentication) indefinitely; renewal costs far less than an incident. 

These practices also support asset inventory and lifecycle controls in frameworks such as ISO 27001, SOC 2, the CIS Controls, and the NIST Cybersecurity Framework. 

 

Conclusion 

An expired domain isn’t a closed chapter. It’s an open door until you confirm otherwise. With drop catch detection in CheckRed DNSPM, your team gets visibility at every stage, from expiry to grace period to third-party registration, so you can renew, retire safely, or contain exposure before attackers take advantage. 

 

Author Bios

Chaturbhuj Singh

Chaturbhuj is Director of Cloud Security Engineering at CheckRed, leading strategy, architecture, and execution for enterprise-grade security solutions across Cloud, SaaS, and DNS. With deep expertise in vulnerability management, misconfiguration remediation, and automated risk reduction, he drives the engineering vision behind CheckRed’s unified security platform – enhancing visibility, compliance, and resilience across complex hybrid environments.

Pranay Tatiparthi

Pranay is a Software Engineer and FDE-1 at CheckRed, specializing in DNS Security and DNS Posture Management. His work focuses on identifying DNS misconfigurations, dangling records, subdomain takeover risks, and other security exposures, while working directly with customers to deploy and customize security solutions. He also brings hands-on experience in cloud security across AWS and Microsoft Azure, with a focus on building secure, scalable, and resilient systems.

Jacob Lyons

Jacob is an Infrastructure Security Specialist and Product Enablement Manager at Akamai Technologies, specializing in DDI, EdgeDNS, DNS Posture Management, DDoS Posture Management, and Brand Guardian. Previously with CheckRed, Jake brings experience across infrastructure security, product enablement, and strategic partnerships, helping organizations better understand and manage risk across their external infrastructure.