Practical guide
Domain and DNS Expiration Checklist for IT and Ops Teams
A domain looks like a once-a-year admin chore until it isn’t. Use this checklist to inventory names, assign owners, and keep registrar and DNS renewals boring — without treating every notice as a fire drill.
September 25, 2026 · 10 minute read
Why domains still catch teams off guard
A domain looks like a once-a-year admin chore until it isn't. Miss the renewal and you lose email, SSO redirects, marketing sites, API endpoints, and customer trust in one afternoon. The failure mode is rarely “we forgot domains exist.” It is usually fragmented ownership: marketing bought one registrar account, IT owns another, a contractor still has the login, and the auto-renew toggle is on a card that expired last month.
This domain and DNS expiration checklist is for IT and ops teams (with marketing and finance in the loop) who need a repeatable pass across the company's domain portfolio. Use it quarterly for active brands, and at least annually for the long tail of parked, redirect, and legacy names.
Who should own the domain portfolio
If nobody can name the portfolio owner in one sentence, treat that as the first finding — not a footnote.
- Primary owner
- IT ops, IT admin, or a platform/ops generalist who can reach registrar accounts.
- Required partners
- Marketing (brand and campaign domains), security (DNS hijack and takeover risk), finance/AP (renewal spend and card on file), legal (trademark and entity names when relevant).
- Cadence
- Quarterly for production and customer-facing domains; annually for redirects, parked names, and low-risk holdings.
- Timebox
- 45–75 minutes for the working session, plus async inventory homework beforehand.
Pre-work: build the domain packet
Before the meeting, assemble facts so the room is not guessing. If you still need a first inventory for other date-bound obligations, start with how to track expiration and renewal dates without missing one.
- Export every domain from each registrar and DNS provider the company uses, including personal or “temporary” accounts that still hold production names.
- List who can log in, who gets renewal emails, and which payment method is on file.
- Flag renewals in the next 90–180 days, plus anything with auto-renew off.
- Note which names are production, redirect-only, parking, staging, or candidate for drop.
- Capture nameserver / DNS host separately from the registrar when they differ.
- Pull recent SSL/certificate owners for the same hostnames so domain and cert ownership stay aligned.
Unowned domains and domains tied to departed contractors go to the top of the agenda. Pair this packet with the SSL and certificate expiration checklist so hostname owners are not split across two silent clocks.
The domain / DNS expiration checklist
Mark an item done only when evidence exists — a screenshot, export, or ticket — not when someone “thinks so.”
1) Inventory and classification
- Every company domain appears once in a master list, with no shadow registrar accounts.
- Each row has domain, registrar, renewal or expiration date, annual cost, owner, and business use.
- Date meaning is labeled: registrar renewal date vs DNS host billing date vs SSL expiry — they are different.
- Criticality is tagged: production, redirect, parking, legacy, or drop candidate.
- Related hostnames and subdomains that matter operationally are noted.
- DNS host is recorded when it is not the registrar.
Domain expiration tracking fails when the spreadsheet lists names but not the person who can renew them. If those columns keep drifting, clean the columns before you treat the sheet as source of truth.
2) Access and recovery
- Registrar login is a company-controlled identity, not a personal inbox.
- MFA is enabled, and recovery codes live somewhere the backup owner can reach.
- At least two current employees can access the account.
- Billing email and renewal contact emails are monitored inboxes.
- Transfer lock / registrar lock status is intentional, not accidental.
- An offboarding path exists for anyone who previously held the credentials.
3) DNS and operational dependency
- Nameservers point where you expect; no orphaned or forgotten DNS hosts.
- Critical records are documented at a useful level (MX, SPF/DKIM/DMARC owners, primary A/CNAME targets, SSO/IdP hosts).
- Who can change DNS is known and limited.
- A change process exists for production DNS (ticket plus a second set of eyes).
- Domains used only for redirects still have a named owner and a reason to keep paying.
4) Commercial and renewal readiness
- Auto-renew is on for every domain you intend to keep — and verified, not assumed.
- The payment method on file is a current company card or AP process.
- Multi-year renewals are considered for critical brand domains where that reduces miss risk.
- Domains you plan to drop have a cancel or let-expire decision and a date.
- Privacy/WHOIS settings match company policy.
- Spend is visible to finance, with no surprise personal reimbursements for production names.
5) Decision and documentation
- The decision is recorded per domain: renew, transfer, consolidate registrar, or drop.
- Owner and backup owner are named.
- Reminder dates are set for renewals, and for SSL when the hostname matters.
- The master inventory is updated the same day.
- Security is notified if access, DNS host, or ownership changed.
Quarterly vs annual: how deep to go
Quarterly focus
Production and customer-facing domains, anything renewing in 90 days, auto-renew failures, new marketing or campaign domains added since last review, and domains still sitting in personal accounts.
Annual deep dive
Full long-tail cleanup (redirects, parked names, old product brands), registrar consolidation, WHOIS/privacy audit, and a written map of which teams depend on which names.
Do not renegotiate every registrar every quarter. Use the checklist to triage: most names get a fast renew-or-drop call; a few get a transfer or consolidation project.
Meeting agenda (60 minutes)
0–10 min
Confirm packet completeness and registrar account list.
10–30 min
Walk production domains renewing in 90 days and any auto-renew or payment risks.
30–45 min
Access recovery gaps, personal accounts, and DNS host mismatches.
45–55 min
Drop/consolidate candidates and transfer plans.
55–60 min
Update inventory, reminder dates, and finance/security handoffs.
End with a written decision log. “We'll clean that up later” is how domains become emergencies.
Red flags that mean your process is broken
- Renewal notices go to an ex-employee or a contractor inbox.
- Production DNS is editable by one person with no backup.
- Auto-renew is “probably on” but nobody verified this quarter.
- Marketing launched a campaign domain that never entered the master list.
- Registrar and DNS host disagree about who controls the zone.
- Domain expiry and SSL expiry are tracked in different places with different owners and never compared.
If two or more of these are normal, fix ownership and reminder hygiene before you add more domains.
After the review: keep momentum
- File the decision log where IT, marketing, and finance can find it.
- Schedule the next quarterly pass before you leave the room.
- Convert every “transfer” or “consolidate” into a dated task with a named owner.
- For domains you will drop, set a decommission date and confirm no email or SSO still depends on them.
- Align domain owners with SSL/certificate owners for the same hostnames so one missed renewal does not strand the other.
Teams that treat domain review as a standing operating rhythm stop treating registrar emails as fire drills.
Frequently asked questions
Is domain tracking the same as SSL certificate tracking?
No. The registrar renewal date, the DNS host billing date, and the certificate expiry date are often three different clocks. Track them as related items with clear date meanings — not as one vague “website date.” Use the SSL and certificate expiration checklist for the TLS side of the same hostnames.
Who should get the renewal email?
A monitored team inbox plus a named human owner. Distribution lists that nobody watches are how silent failures start.
Should we move every domain to one registrar?
Usually yes over time, for access control and visibility — but do not block the checklist on a big-bang migration. Get inventory, owners, and auto-renew truth first; consolidate second.
What about domains we only use for email or redirects?
They still expire. If the name still matters operationally, it belongs on the list with an owner and a renew-or-drop decision.
Can this checklist cover vendor portals and SaaS custom domains?
Yes for the hostname and DNS pieces. Keep the SaaS product renewal itself on your software renewal review checklist so commercial terms and seat usage stay in the right review.