Drop Catch Domains: What They Are, Why They Matter, and How to Act

Executive Summary: Drop catch domains create a significant security risk when expired domains are re-registered and used as attack infrastructure. Organizations often accumulate domains through campaigns, old product names, and acquisitions, but when one lapses, a third party can inherit the trust, traffic, email history, and connections it still carries. This blog explains how drop catching works, the risks it creates, and how CheckRed DNSPM helps detect exposure at every stage—from initial expiration through third-party registration.
Organizations accumulate domains over time: campaign microsites, old product names, and domains inherited through acquisitions. When one lapses, someone else can register it and inherit all the trust it still carries. This is drop catching, one of the most overlooked risks in an external attack surface.
1. What Is Drop Catching?
Drop catching is registering a domain the moment it becomes available after its previous owner lets it expire. Specialized services monitor expiring domains and submit registration requests within milliseconds of release.
A domain doesn’t become available the instant it expires. For most generic TLDs (.com, .net, .org), it moves through a lifecycle:
Here’s what each phase means for the domain owner:
| Phase | What happens | Can you recover it? |
| Expiration | Registration term ends; DNS may be suspended or parked | Yes, usually at standard renewal cost |
| Grace period | Auto-renew grace (registrar-defined, often up to 45 days), followed by a redemption period of around 30 days | Yes, but costs rise during redemption |
| Pending delete | Around 5 days; recovery is no longer possible | No |
| Release | Domain returns to the public pool and drop catchers compete for it | Only if you win the race |
Timelines vary by registrar and TLD, and many country-code TLDs follow their own rules.
Many drop catchers are domain investors. But the same mechanism is available to attackers, and a domain with existing traffic, email history, or embedded trust is exactly what they look for.
2. Why Is It Important?
A lapsed domain is often still referenced across your environment and in your users’ habits. Whoever registers it next can exploit that trust:
- Email interception: The new owner can set up MX records and receive password resets, invoices, and partner emails still sent to the old domain.
- Account takeover: SaaS, cloud, and developer accounts registered with addresses on the domain can be hijacked through “forgot password” flows.
- Email spoofing: If your active domain’s SPF record still includes the lapsed domain, the new owner may be able to send email that passes SPF checks as you.
- Dangling references: CNAMEs, script includes, OAuth redirect URIs, webhooks, and API callbacks pointing to the domain can serve malicious content or capture tokens.
- Phishing and brand abuse: A domain your customers once trusted, with its search ranking and reputation intact, is an ideal phishing launchpad.
It Happens to Well-Known Organizations
Domain expiry incidents are not hypothetical. A few public examples, mapped to the stage each one reached:
| Organization | What happened | Stage reached |
| Foursquare (2010) | Its primary domain lapsed and the entire service went offline until the company noticed and renewed it. | EXPIRED |
| Sorenson (2017) | An expired domain caused a three-day outage of its relay services, including access to 911, followed by a $3 million FCC settlement. | EXPIRED |
| Mobi Bank, Serbia | Banking systems still relied on a legacy domain from an acquired bank. It expired, taking web, net banking, and mobile services down until renewed. | EXPIRED |
| tema.com (2020) | A domain Parker Hannifin gained through an acquisition was not renewed. Drop catchers were waiting, and it was auctioned to a new owner for $43,805. | RE-REGISTERED |
| Maryland license plates (2023) | A domain printed on around 800,000 license plates expired, was released, and was registered by a third party who pointed it to an online casino. | RE-REGISTERED |
Most of these organizations recovered their domains while they were still in the expired or grace stage. The last two show what happens when that window closes: the domain, and the trust attached to it, belongs to someone else.
These exposures usually aren’t caused by negligence but by a lack of visibility. Domain ownership is spread across marketing, IT, engineering, and acquired entities. Renewal notices go to former employees. Auto-renew fails on an expired card. Domains are retired without checking where they’re still in use.
3. How You Can Act on It
The earlier you catch a lapsing domain, the cheaper and simpler the fix. CheckRed DNSPM now detects drop catch risk at all three stages, so your team can act at the right moment.
| Stage 1: MEDIUM | Domain Expired | What CheckRed detects: Domains that have passed their expiration date.
What to do: Renew immediately if the domain is still needed. This is the lowest-cost point to resolve the risk. |
| Stage 2: HIGH | Domain in Grace Period | What CheckRed detects: Domains in the post-expiry grace or redemption period.
What to do: Treat this as urgent. Either renew the domain before the window closes, or make a deliberate decision to retire it after removing every reference to it, including DNS records, SPF includes, code, SaaS logins, and redirect URIs. |
| Stage 3: CRITICAL | Domain Registered by Someone Else | What CheckRed detects: Domains that have passed the grace period and are now registered by a third party.
What to do: Shift from recovery to containment:
|
Preventive Best Practices
- Keep a complete domain inventory, including acquired and marketing domains.
- Enable auto-renew and registrar lock, with shared, monitored inboxes as registrant contacts.
- Decommission domains deliberately, cleaning up every reference before letting them lapse.
- Keep high-risk domains (those once used for email or authentication) indefinitely; renewal costs far less than an incident.
These practices also support asset inventory and lifecycle controls in frameworks such as ISO 27001, SOC 2, the CIS Controls, and the NIST Cybersecurity Framework.
Conclusion
An expired domain isn’t a closed chapter. It’s an open door until you confirm otherwise. With drop catch detection in CheckRed DNSPM, your team gets visibility at every stage, from expiry to grace period to third-party registration, so you can renew, retire safely, or contain exposure before attackers take advantage.
Author Bios
Chaturbhuj Singh
Chaturbhuj is Director of Cloud Security Engineering at CheckRed, leading strategy, architecture, and execution for enterprise-grade security solutions across Cloud, SaaS, and DNS. With deep expertise in vulnerability management, misconfiguration remediation, and automated risk reduction, he drives the engineering vision behind CheckRed’s unified security platform – enhancing visibility, compliance, and resilience across complex hybrid environments.
Pranay Tatiparthi
Pranay is a Software Engineer and FDE-1 at CheckRed, specializing in DNS Security and DNS Posture Management. His work focuses on identifying DNS misconfigurations, dangling records, subdomain takeover risks, and other security exposures, while working directly with customers to deploy and customize security solutions. He also brings hands-on experience in cloud security across AWS and Microsoft Azure, with a focus on building secure, scalable, and resilient systems.
Jacob Lyons
Jacob is an Infrastructure Security Specialist and Product Enablement Manager at Akamai Technologies, specializing in DDI, EdgeDNS, DNS Posture Management, DDoS Posture Management, and Brand Guardian. Previously with CheckRed, Jake brings experience across infrastructure security, product enablement, and strategic partnerships, helping organizations better understand and manage risk across their external infrastructure.


