All resources
Domain Monitoring

What to Do When a Client Domain Is About to Expire

Follow an agency workflow for an expiring client domain: verify the date, find the renewal owner, assess DNS and SSL impact, and document action.

By AlexUpdated 3 August 2026

See exactly where your domains stand.

Run a free check on the domains you manage — SSL expiry, domain expiry, and DNS health in one report. No signup needed.

Managing more than one client domain?

Managing more than one client domain? Run a free 10-domain SSL, DNS, and domain expiry audit.

Jordan's bad week starts with a renewal warning for a domain nobody can confidently own. The website still loads, the client is not worried yet, and the registrar account may belong to a founder, a previous agency, or a billing inbox that no one checks. This is the point where calm process matters more than technical confidence.

A client domain about to expire is not just a date problem. It is an ownership problem, a communication problem, and sometimes an email-continuity problem. The agency needs to verify the signal, identify the renewal owner, warn the right person, and document exactly what was confirmed. If the agency does not control the registrar, the report should make that boundary visible instead of pretending the agency can fix what it cannot access.

Use the workflow below as an escalation packet: what to check first, what to say to the client, what to document, and how to stop the same renewal panic next year.

When a client domain about to expire appears in your agency workflow, the first job is to verify the expiry date and identify who controls renewal. Do not assume the agency can renew it. Many client domains are owned in the client's registrar account, a founder's personal account, a previous vendor's account, or a reseller panel nobody has opened in years.

The right response is calm and structured: confirm the data, contact the owner, document responsibility, check related DNS and email risk, and prevent the same situation from happening again.

This guide gives agencies a practical workflow for handling domain expiry before it becomes a client-visible incident.

Client domain about to expire: first response

Start with verification. Public data can be incomplete, and registrar dashboards are the source of truth when you have access.

Use this first-response checklist:

Use this structured version:

  • Step: 1; Action: Confirm the domain and expiry date; Owner: Technical lead or operations
  • Step: 2; Action: Identify the registrar; Owner: Technical lead
  • Step: 3; Action: Identify who controls the registrar account; Owner: Account manager
  • Step: 4; Action: Check auto-renew status if access exists; Owner: Account manager or client
  • Step: 5; Action: Contact the client if they control renewal; Owner: Account manager
  • Step: 6; Action: Check DNS and email dependency; Owner: Technical lead
  • Step: 7; Action: Document the outcome; Owner: Account manager

If the expiry window is short, do these in parallel. Do not wait for perfect information before warning the client.

Verify the expiry date

Domain expiry information may come from RDAP, registrar dashboards, renewal emails, or billing records. Public RDAP is useful, but it is not equally complete across every TLD.

Use public data as an early warning, then verify through the registrar when possible.

If public data says the domain is near expiry:

  • Check the registrar account if your agency has access.
  • Ask the client for a screenshot if they own the account.
  • Confirm whether auto-renew is enabled.
  • Confirm whether the payment method is valid.
  • Confirm whether the domain is locked or in a transfer state.

If public data is unavailable, do not ignore the domain. Mark it as limited data and ask the client or registrar to confirm renewal status.

You can check a single domain with the free domain health check, or audit up to 10 client domains with the free agency audit.

Identify who controls renewal

This is usually the hardest part. Agencies often inherit domains without inheriting registrar access.

Common ownership patterns:

Use this structured version:

  • Registrar owner: Agency controls registrar; Risk: Low; Best next step: Renew or confirm auto-renew
  • Registrar owner: Client controls registrar; Risk: Medium; Best next step: Send client clear renewal instructions
  • Registrar owner: Previous vendor controls registrar; Risk: High; Best next step: Escalate ownership transfer
  • Registrar owner: Unknown account; Risk: High; Best next step: Ask client to search billing and renewal emails
  • Registrar owner: Reseller account; Risk: Medium; Best next step: Confirm reseller renewal process

The agency should not quietly take responsibility for a domain it does not control. Instead, document who owns the renewal action.

Contact the client with a clear message

The client email should be specific and action-oriented. Avoid saying "your domain might be broken" unless the domain is already expired.

A useful message includes:

  • Domain name.
  • Observed expiry date.
  • Why it matters.
  • What the client needs to confirm.
  • Deadline for confirmation.
  • What happens if renewal is not completed.

Example:

We found that example.com appears to be approaching domain renewal. Please confirm that auto-renew is enabled in your registrar account and that the payment method is current. If the domain expires, the website and email may stop resolving.

If the agency has registrar access, the message can be shorter:

We confirmed example.com is set to auto-renew. No client action is needed. We will continue monitoring it.

Check DNS and email risk

Domain expiry affects more than the website. If the domain stops resolving, email can fail, DNS records stop answering, and SSL renewal may also fail.

When a client domain is close to expiry, review:

  • MX records for email delivery.
  • NS records for DNS authority.
  • A and AAAA records for website routing.
  • TXT records for SPF, DMARC, and vendor verification.
  • CAA records for certificate issuance.

This gives you a fuller risk picture. A client may care more about email interruption than the website itself.

For DNS monitoring details, read how to monitor DNS changes across client websites.

Audit real client domains

Want to see this on real client domains? Paste up to 10 domains and CertPilot will show SSL, DNS, domain expiry, and risk status.

Decision tree: what should the agency do?

Use this simple decision tree:

Use this structured version:

  • Situation: Agency controls registrar and auto-renew is enabled; Agency action: Confirm payment method and document
  • Situation: Agency controls registrar and auto-renew is off; Agency action: Renew now or enable auto-renew with approval
  • Situation: Client controls registrar; Agency action: Send renewal instructions and request confirmation
  • Situation: Previous vendor controls registrar; Agency action: Escalate ownership transfer immediately
  • Situation: Registrar unknown; Agency action: Ask client to search renewal invoices and domain emails
  • Situation: Public data unavailable; Agency action: Mark limited data and verify manually
  • Situation: Domain already expired; Agency action: Treat as an urgent incident and use the expired client domain recovery checklist before promising an outcome

The worst action is vague ownership. Every expiring domain should have one named person responsible for the next step.

If the agency does not control the registrar

Many agencies hesitate here because they do not want to alarm the client. But a domain expiry warning is exactly the kind of operational risk clients expect an agency to surface.

If the client controls the registrar:

  1. Send the expiry warning.
  2. Ask them to confirm auto-renew.
  3. Ask them to confirm the payment method.
  4. Ask for the registrar name.
  5. Offer to document the domain in the agency's monitoring system.
  6. Recommend granting the agency appropriate access if it fits the relationship.

Do not ask for passwords over email. Use proper account access, delegated permissions, or a secure process agreed with the client.

Document ownership after renewal

Once the immediate risk is handled, document the domain so the team does not repeat the same investigation next year.

Record:

  • Registrar.
  • Account owner.
  • Renewal owner.
  • Auto-renew status.
  • Payment responsibility.
  • Domain expiry date.
  • DNS provider.
  • Notes about access limitations.

This information belongs in your agency operations system. If it only lives in a Slack thread or inbox, it will be lost. For the durable field set, move the owner, purpose, lifecycle, renewal decision, and review notes into a domain governance register.

Prevent recurrence

Prevention means monitoring and reporting, not relying on memory.

At minimum:

  • Check domain expiry regularly.
  • Check SSL expiry regularly.
  • Monitor DNS changes.
  • Group domains by client.
  • Include domain health in monthly reports.
  • Keep ownership notes current.

For a broader process, read domain expiry monitoring for agencies and how to build a monthly client domain health report.

Add the domain to the monthly review cycle

Once a close-call domain is renewed, do not treat the incident as finished. Add it to the monthly review cycle with a note about who controls renewal and what happened. This is especially useful when the client owns the registrar account.

The next report should not shame the client. It should document that the domain was checked, renewal ownership was confirmed, and the agency will keep monitoring public signals. That turns a stressful renewal warning into a better operating process for the next cycle.

What not to promise

Be careful with client communication. A domain expiry warning is not a legal compliance guarantee, uptime guarantee, or renewal guarantee.

Do not promise:

  • "We guarantee the domain cannot expire."
  • "CertPilot renews domains automatically."
  • "This replaces registrar ownership records."
  • "This proves legal ownership."

The right promise is simpler: your agency monitors public signals, flags risks early, and documents recommended actions.

The expiring-domain escalation packet

When a domain enters a warning window, do not treat the task as "send an email." Treat it as a packet with evidence, owner, risk, and deadline. The packet should be short enough to use during a client call and complete enough that another team member can pick it up tomorrow.

Capture these fields:

  • Domain: the exact hostname or apex domain being reviewed.
  • Observed expiry: the public expiry date or the registrar-confirmed date.
  • Data source: RDAP, registrar dashboard, client screenshot, renewal email, invoice, or limited public data.
  • Registrar: the company that controls registration if known.
  • Renewal owner: agency, client, previous supplier, reseller, unknown, or mixed.
  • Auto-renew state: enabled, disabled, unknown, or not visible.
  • Payment risk: current, unknown, expired card suspected, or client must confirm.
  • DNS provider: where nameservers point today.
  • Email impact: whether MX records show the domain is used for business email.
  • SSL impact: whether certificate renewal may depend on the same domain/DNS ownership.
  • Next action: renew, confirm, transfer, escalate, or verify manually.
  • Due date: the last safe date for confirmation before the escalation level changes.

This structure prevents two bad outcomes. The first is underreaction: the warning sits in a tool while everyone assumes someone else owns it. The second is overreaction: the agency panics the client without knowing whether auto-renew is already enabled. The packet creates a middle path: verify what you can, expose what you cannot, and move the next action to a named owner.

Escalation wording by ownership state

Use different wording depending on who controls the registrar.

If the agency controls the registrar:

We checked example.com and confirmed the domain renewal is inside the review window. We are verifying auto-renew and the payment method in the registrar account today. If renewal is already confirmed, no client action is needed; we will record the confirmation in the monthly domain health report.

If the client controls the registrar:

We found that example.com appears to be approaching renewal. Because the registrar account is client-owned, please confirm that auto-renew is enabled and the payment method is current. If the domain is not renewed, the website and email tied to this domain may stop resolving. We recommend confirming this by [date].

If the previous supplier controls the registrar:

We found an expiring-domain risk and the registrar ownership appears to sit outside both the current agency and the client team. This should be treated as an ownership-recovery task, not only a renewal reminder. Please identify who can access the registrar or start the transfer process before the renewal window becomes urgent.

If public data is incomplete:

Public expiry data for example.com is limited, so we cannot rely on the public check alone. Please confirm the registrar expiry date manually. We are keeping the domain in the review queue until the renewal owner and date are documented.

Run the companion DNS and SSL check

Do not close an expiring-domain task until you understand the services attached to the domain. A domain that only hosts a brochure site is still important. A domain that also handles email, authentication links, customer portals, or certificate validation deserves faster escalation.

Review the public DNS groups before writing the final client note:

  • MX records tell you whether inbound email depends on the domain.
  • TXT records may show SPF, DMARC, vendor verification, or ownership proofs.
  • NS records show who currently controls the public DNS zone.
  • A and AAAA records show website routing.
  • CAA records can affect future certificate issuance.

Then review SSL status for the primary hostname and common variants such as www. Domain expiry can break DNS, and broken DNS can break certificate renewal. The client may think the only risk is the website address, but the operational blast radius can include email and renewal automation.

After renewal, close the loop properly

The most valuable part of an expiring-domain incident is the cleanup. Once the immediate risk is handled, update the permanent record:

  1. Confirm the renewed expiry date.
  2. Record who controls the registrar account.
  3. Record who pays for renewal.
  4. Record whether auto-renew is enabled.
  5. Store the renewal notice email or ownership note.
  6. Add the domain to the monthly Domain Health review.
  7. Add a note if the agency could not independently verify the registrar state.

Do not leave the proof in the last email thread. Next year's renewal should start from the record, not from another search through inboxes and old invoices.

Where CertPilot fits without overpromising

CertPilot can help make the public signal and evidence side visible: public RDAP/domain expiry checks, SSL checks, DNS snapshots, governance notes, and on-demand Domain Health reporting. It does not renew domains, access registrar accounts, transfer ownership, guarantee recovery, or prove legal ownership. When the client controls the registrar, CertPilot can support the warning and the record; the registrar owner still has to complete the renewal.

How CertPilot helps

CertPilot checks public SSL, DNS, and domain-expiry signals across monitored domains, then helps teams turn those findings into review queues and on-demand evidence reports. It makes the public-signal work visible without claiming to control the registrar or DNS provider.

If you are responding to one urgent domain, use the single-domain health check. If you want to review a client portfolio, start with the free 10-domain audit.

Start with a free audit

CertPilot monitors SSL, DNS, domain expiry, and renewal risk across every client site your agency manages. Start with a free 10-domain audit.

Frequently Asked Questions

What should an agency do when a client domain is about to expire?

Confirm the expiry date, identify the registrar, and find out who controls renewal. If the client owns the registrar account, contact them early with a clear action request.

At the same time, check DNS, email, and SSL impact. A client domain about to expire can affect the website, email delivery, SSL renewal, and any services tied to that domain.

What if the agency does not control the registrar account?

Do not imply that the agency can renew a domain it does not control. Document the ownership gap, tell the client what needs to be checked, and ask them to confirm auto-renewal and payment status.

If the relationship allows it, recommend delegated access or a defined registrar ownership process for future website care plans.

Can domain expiry break email as well as the website?

Yes. If the domain stops resolving, MX records may stop answering and email can fail along with the website.

That is why domain expiry monitoring for agencies should include both website and email risk, especially for client domains used for business-critical communication.

Should domain renewal be part of a care plan?

It should at least be documented in the care plan. The plan should state who owns registrar access, who pays for renewal, who receives notices, and how warnings are handled.

The agency can monitor and report domain health even when the client keeps registrar ownership.

Turn daily checks into management-ready evidence.

CertPilot checks SSL, DNS, domain registration, and email authentication daily — and combines them with your renewal, people, assets, and access review registers into evidence reports. 14-day free trial, no card required.