Skip to content

Part 5 of 7 · Domain renewal watcher series ~5 min read

How a renewal gets escalated

Everything up to here has been about knowing. This post is about telling somebody who can do something, which is where domain renewal reminders overwhelmingly fail — not by not being sent, but by being sent to a mailbox that has not been opened since 2023.

Key takeaways

  • Escalation uses your staff list, never the address on the registration.
  • Ninety, thirty, seven days, then daily, and daily does not stop at expiry.
  • The message carries the registrar, the account, the card and the internal owner.
  • After expiry the message changes to the recovery clock and the redemption cost.
  • One report a quarter lists everything, so the register is checked rather than trusted.

Who is told

How a domain renewal escalation reaches people who currently work hereThree boxes across the top outside the AWS account. The Internal owner, taken from your staff list. Their manager, brought in at thirty days. And Whoever runs IT, at seven days and afterwards. Inside the account, three components. The Ladder, running at ninety, thirty and seven days and then daily. The Message builder, which includes the registrar, the account, the card and the internal owner. And After expiry, which switches to a recovery clock rather than going silent. Arrows show each party being asked to renew or to say who will. A note says the registration contact is never used, because it is the least reliable address you have.AWS ACCOUNTInternal ownerfrom your staff listTheir managerat thirty daysWhoever runs ITat seven, and afterLadder90 / 30 / 7 / dailyMessage builderregistrar, account,card, ownerAfter expiryrecovery clock,not silencerenew, or say whowillat thirty daysat seven, andafterThe registration contact is never used. It is the least reliable address you have.
Fig 1. Who hears about an approaching renewal, and in what order. The registration contact appears nowhere in this diagram, which is the point.
  • Security & identity
  • Management
  • People

Why not the registration contact

Because it is a snapshot of who bought the domain, sometimes years ago, and it is the one address in the whole business that nobody updates. Every registrar in the world already sends reminders there, and the fact that domains still lapse is the evidence that it does not work.

The internal owner comes from your own register and is a person who currently works here, checked against your staff list. A domain whose internal owner has left is itself a finding, raised immediately rather than at ninety days, because it will otherwise be discovered at ninety days when the message bounces.

What the message contains

Everything needed to fix it in five minutes

  • The domain and the date. “portal.example.com expires 14 March — 90 days.”
  • The registrar, by name, and the account identifier if the register has it. Knowing which of four registrars a domain is at saves ten minutes of looking.
  • Which card pays for it, last four digits, from the subscription register. This is what catches the expired-card case before it becomes a failed renewal.
  • What depends on it. “MX records point here; the customer portal runs on it.” A domain nobody can place gets ignored; one with consequences attached does not.
  • Two buttons. “Renewed” and “Somebody else is handling this — who?”

The card detail is the most valuable line and it only exists if something knows about recurring charges. If the subscription audit bot is running, this is a lookup; if not, it is a field somebody fills in once. Either way, an expired card is the single most common way a renewal that everybody expected to happen does not.

After the date

The recovery clock after a domain expiresA horizontal row of five boxes. Expiry day: the domain may still resolve. Grace: a registrar-dependent period. Redemption: recoverable, for a fee. Pending delete: days, then gone. Daily throughout: with the cost and the days remaining. A note says this is exactly where most watchers stop reporting, and where hours start mattering.THE CLOCK AFTER EXPIRYExpiry daymay still resolveGraceregistrar-dependentRedemptionrecoverable, for a feePending deletedays, then goneDaily throughoutwith the cost and the daysThis is exactly where most watchers stop reporting, and where hours start mattering.
Fig 2. What happens after an expiry date passes. A watcher that treats expiry as the end of its job goes quiet at the point where the situation is recoverable and getting less so.

The message changes tone entirely at that point, and it should: it carries how many days remain in the current phase, what the recovery fee will be, and what has already stopped working. “portal.example.com expired 11 days ago. It is in redemption for 19 more days; recovery is about £80. Mail to that domain has been bouncing since Tuesday.”

The quarterly review

One report a quarter listing every domain, its expiry, its registrar, its internal owner and its status. Not because anything is wrong, but because a register is only as good as the last time somebody looked at it, and a domain whose owner left or whose purpose nobody remembers is exactly what a quarterly read finds.

Next: what all of this costs to run.

All posts