Skip to content
Blogpost in
domains

Domain monitoring: watch what you own, and what you don’t

Domain monitoring with a laptop and charts.
time to read icon 15 Min

Most guides pick a side. Domain monitoring is really two jobs: watching the domains you own, and watching the domains you don't.

Published by

Author

Simone Catania

Date

25/08/2026

Domain monitoring is one of those disciplines every organization assumes it already has covered. Then a domain almost expires, or a nameserver changes and nobody notices.

Most guides on the subject pick a side. Brand-protection vendors say domain monitoring means hunting lookalike domains. Uptime tools say it means checking expiry dates. Both are half right, and neither helps a team running hundreds of domains.

The full picture is broader and easier to remember: domain monitoring watches two sets of domains, the ones you own and the ones you don’t. This guide gives you a working model. Which domain signals to watch, how often to check them, who receives each alert and what to do the moment one fires.

What is domain monitoring? The two halves explained

Domain monitoring is the continuous watching of two sets of domains, the ones you own and the ones you don’t, for changes that affect availability, security or your brand.

The first half watches your own domain portfolio. This is where the operational risk lives. You track the expiry date held at the registry, the lock status, the DNSSEC state, the nameserver and other DNS records, TLS/SSL certificate expiry and any change to the registrar or registrant on record.

A single change to one of these can take your website, your email and your certificates offline together.

The second half watches domains outside your control. For most organizations that means new registrations imitating the brand: exact matches on other extensions, misspellings and visual lookalikes. Domain investors read the same half with the opposite motive, watching domains they want to acquire once the current holder stops renewing.

Domains you own Domains you don't own
What you watch Expiry, EPP status and locks, DNSSEC, DNS records, TLS/SSL certificates, registrant data New registrations imitating your brand, or lifecycle stages on acquisition targets
What a change means Something in your infrastructure is about to break, or has been tampered with Someone is preparing to impersonate you, or a domain you want is coming free
Who acts Portfolio manager, IT, security Security and legal, or the investor placing a backorder
Typical failure A domain expires or is hijacked without anyone noticing A phishing site goes live before anyone reacts

Domain monitoring compared: uptime, brand protection and backorders

Three neighbouring disciplines get mistaken for domain monitoring. None of them replaces it, and the difference in each case is one of timing.

What it does When it acts
Domain monitoring Detects changes on the domains you own and the domains you don't First. It is the leading signal
Uptime monitoring Confirms a website or service is currently reachable After the change has taken effect
Brand protection Enforces against confirmed abuse through disputes, takedowns and blocking After a lookalike has been detected and intent established
Backorder and drop catching Attempts to register a domain the moment it becomes available After monitoring has flagged an acquisition target

1. Uptime monitoring reports the outage, domain monitoring prevents it

Uptime monitoring is a lagging signal. It fires once your visitors and customers are already affected.

Domain monitoring catches the cause while everything still looks fine. Take a nameserver change on your primary domain. Domain monitoring detects it immediately, while the domain still resolves correctly, so you can confirm whether the change was authorized and revert it before propagation completes.

An uptime tool sees nothing until the new nameservers take effect and traffic stops routing, perhaps a week later. By then the alert is a report rather than a warning.

Both belong in a healthy stack, because they answer different questions. Uptime answers “is it working right now”. Domain monitoring answers “is anything changing that will stop it working soon”.

2. Brand protection enforces what domain monitoring detects

The overlap between the two is real. Detecting domains that imitate you is part of domain monitoring, and brand-protection vendors do exactly that job at web scale.

The gap is everything else. Those vendors observe the namespace from the outside and rarely see the operational signals inside your own domain portfolio, so an expiring domain, a removed transfer lock or a broken DNSSEC chain passes them by.

Brand protection also reaches further than monitoring on its own. Once a lookalike is confirmed, the response moves into disputes, takedowns and blocking, each with its own process. Our guides on defensive domain registration and domain blocking services cover UDRP, the Trademark Clearinghouse and namespace-wide blocking, so we point there rather than repeat them here.

Put simply: domain monitoring detects, brand protection enforces.

3. A backorder acts on what domain monitoring finds

Monitoring, backordering and drop catching sit in sequence rather than in competition.

Domain monitoring is the leading signal. It watches a domain’s lifecycle and tells you it is heading toward expiry. A backorder is a standing request to register that domain once it becomes available. Drop catching is the timed, competitive attempt to register it the instant it drops.

You monitor first, then decide whether to place a backorder or attempt a catch.

Domain inventory first: you cannot monitor domains you forgot you own

Before you switch on a single alert, you need to know what you own. Most guides skip this step, and it is where domain monitoring programs fail.

The blind spot is almost always the same. Marketing buys a campaign domain on a corporate card. A regional office registers a ccTLD through a local provider. Someone who left two years ago set up a domain on a personal account nobody can access.

None of these appear in your main portfolio view. Domain monitoring only covers the domains you remembered to add.

So the first pass is discovery. Export the full list from every provider you use. Reconcile it against your DNS zones and against Certificate Transparency logs, the public, append-only records of every publicly trusted TLS/SSL certificate issued. Then flag anything that resolves to your IP ranges but is missing from your list, because that is almost certainly a domain you own and forgot.

Which domain signals to monitor in your own domain portfolio

This is the core reference for the first half, the domain you own. Each signal tells you something specific when it changes.

  • Expiry and renewal: Watch the expiry date recorded at the registry, not only the reminder email your provider sends. Track the redemption and pending-delete windows too. An expired domain does not disappear on the expiry date. It moves through defined stages, and each one is a diminishing chance to get it back. The domain lifecycle section of our domain management guide sets out those stages.
  • Registrar and registrant changes: Registration data now lives primarily in RDAP, the Registration Data Access Protocol. ICANN made RDAP the definitive source for gTLD registration data on 28 January 2025 as WHOIS was sunset. RDAP supports tiered access, so public queries return a reduced data set. That restriction matters more for the second half than the first. On a domain you own, a change to the registrant or registrar is a signal worth catching immediately. If you have applied WHOIS and RDAP privacy, the underlying record still needs to be accurate and monitored.
  • EPP status codes and locks: EPP status codes are the machine-readable flags the registry holds on every domain, and ICANN maintains the full reference. The security-relevant ones are the locks. clientTransferProhibited and serverTransferProhibited block transfers, while the update-prohibited codes block changes to nameservers and contacts. When one of these disappears, someone removed a protection, and that belongs in your highest severity tier. For business-critical domains, Registry Lock adds the registry-level equivalents. Those hold even if your provider account is compromised.
  • DNSSEC status: DNSSEC signs your DNS records so resolvers can verify they have not been altered. It depends on a DS record published at the registry. If that record is dropped or becomes invalid, resolution can fail outright for validating resolvers. It can also indicate tampering.
  • DNS records: Monitor nameservers, A and AAAA records, MX records for mail routing, and the TXT records carrying your SPF, DKIM and DMARC policy. Watch CNAME records as well, especially dangling ones. A CNAME still pointing at a cloud resource you decommissioned can be claimed by an attacker, a technique known as subdomain takeover. Our guide to DNS records covers each type.
  • TLS/SSL certificate signals: Certificate monitoring has become harder, and recently with the CA/Browser Forum’s Ballot SC-081v3, approved in April 2025, the maximum lifetime of publicly trusted TLS/SSL certificates went down from 398 days to 47 by March 2029. The first cut, to 200 days, took effect in March 2026. Annual renewal workflows no longer fit. Any certificate you have not inventoried will now expire far sooner than it used to, and without warning.
  • Alongside expiry, watch Certificate Transparency logs for certificates issued on your domains. A certificate you did not request is an early sign of misissuance, or of someone preparing a convincing lookalike.
Signal Watch for Why it matters
Expiry and lifecycle Registry expiry date, grace, redemption, pending delete An expired domain is recoverable only inside these windows
Registrant and registrar Changes to either field Can indicate an unauthorized transfer in progress
EPP status codes Removal of transfer or update locks Someone has taken a protection off
DNSSEC DS record dropped or invalid Resolution breaks for validating resolvers, or records are being tampered with
DNS records NS, A/AAAA, MX, TXT, CNAME The routing of your website, email and authentication
TLS/SSL certificates Expiry across the portfolio, new issuance in CT logs Expired certificates look like a compromise, unexpected ones may be one

How to monitor domains you don’t own

The second half applies the same discipline, pointed outward.

The imitation takes a few recognizable forms. Exact matches of your brand on other extensions. Each is a variation on one theme: a domain that reads like yours at a glance.

Detection draws on three sources:

  • Zone files, which some registries publish and which list the domains registered under an extension.
  • New-registration feeds.
  • Certificate Transparency logs again, because a lookalike being prepared as a phishing site usually needs a certificate, and that request becomes public immediately.

Here is the discipline that separates a useful setup from a noisy one: a registration is a signal, not yet a threat.

Detection can happen within a day of registration or certificate issuance. Takedown is a slower, separate process that depends on establishing intent first.

So before escalating, check three things. Is the domain parked? Have MX records been configured, so it can send mail? Is live content being served?

A dormant misspelling does not warrant the same response as a domain hosting a copy of your login page. A monitored lookalike that suddenly adds MX records has changed category, and that transition is the alert that matters.

When a case is ready to escalate, our guides on defensive domain registration and domain name protection cover the routes available: UDRP through WIPO, provider or registry takedown, or negotiated acquisition.

How often should domains be monitored?

Match the cadence to the risk each signal carries. Not everything deserves the same frequency.

Security-relevant records need frequent checks: nameservers, lock status, DNSSEC state, certificate validity. You want to know about a change here within minutes.

Expiry is different. It moves slowly and predictably, so a daily check is enough, with alerts on a fixed ladder. A practical default is 90, 60, 30, 7 and 1 day before expiry, plus one more alert if the domain enters redemption. That is not a standard, just a cadence that gives you several chances to act and a final safety net. Tune it to your renewal cycle.

High-severity signals should never wait for a daily digest. A removed lock, a changed nameserver or a dropped DS record are the changes an attacker makes during a hijack. A day of delay can be the difference between reverting a change and losing the domain. There is also a data-quality argument for registrar-sourced feeds over scraping public endpoints. Public RDAP and WHOIS services enforce rate limits and often serve cached data. Poll them across a thousand domains and your view of the portfolio will lag reality.

Domain monitoring at scale: two harder cases

1. When a domain portfolio is spread across providers

Many enterprise portfolios sit with more than one provider, often as a legacy of acquisitions or campaigns. Domain monitoring gets harder as soon as that happens.

Each provider shows you its own domains, with its own alert logic and its own idea of what a reminder is. There is no shared inventory, no shared severity model, no common audit trail. You end up reconciling dashboards by hand.

The answer is a single monitoring layer above every provider: one inventory, one alert model, one audit trail. At portfolio scale, an API turns this from manual work into automation, feeding domain status into a CMDB and critical signals into SIEM and SOC tooling.

It is worth being honest about the limits. No single tool is best at both halves, so many enterprises pair a registrar-sourced platform for the domains they own with a specialist brand-protection service for the domains they don’t.

2. Domain monitoring for resellers and MSPs

Resellers, agencies and managed service providers are accountable for domains they do not own, usually under an SLA. A client’s domain expiring, or a nameserver changing unnoticed, becomes their incident and their churn risk.

On top of the model above, this group needs multi-client visibility with clean separation, white-label alerts carrying their own brand, bulk operations across many domains, and escalation that plugs into their existing ticketing workflow.

Done properly, domain monitoring stops being an internal chore and becomes a recurring service line, offered alongside registration and DNS.

Both cases point to the same requirement, and it is what AutoDNS is built for: a registrar-sourced platform that consolidates domains into one inventory with API access and white-label management, on EU-based infrastructure.

Domain monitoring, NIS2 and GDPR

For organizations operating in Europe, the regulatory context changes how domain monitoring gets framed internally.

The NIS2 Directive raises expectations around asset inventory and incident detection, and names DNS and domain registration services among the entities in scope. A monitored portfolio contributes to both: your inventory feeds the asset register, your monitoring feeds the detection capability. It is not a compliance product, but it is demonstrable due diligence. ENISA covers the technical measures, and our NIS2 Information Hub collects the domain-specific resources.

Audit trails make this concrete. Domain monitoring produces a change log recording what changed, when and who acknowledged it, which is far easier to produce continuously than to reconstruct after an incident.

GDPR shapes the second half. Registration data access is restricted, and RDAP’s tiered model limits what a public query reveals about a lookalike’s registrant, so plan your escalation on the assumption that some data will require a formal disclosure request. Where your own monitoring data is processed and stored is worth confirming with any provider.

Start domain monitoring with what you own

Domain monitoring earns its place by turning silent changes into signals you can act on. The sequence matters more than the tooling.

Build the domain inventory, consolidate what you can, map each signal to a severity tier and a named owner, then write the runbook before the first alert fires. The second half of domain monitoring, the lookalikes and the acquisitions, sits on top of that foundation rather than replacing it.

If your domain portfolio is spread across several providers today, consolidation is the highest-leverage place to start. See how AutoDNS brings a fragmented portfolio into one inventory with API access on EU-based infrastructure, or talk to an InterNetX partner manager about what your domains would look like in a single view.

Monitor your domains in AutoDNS icon-arrow--right

Frequently asked questions

What is domain monitoring?

Domain monitoring is the continuous watching of two sets of domains, the ones you own and the ones you don’t, for changes affecting availability, security or your brand. On your own domains it tracks expiry, EPP status and locks, DNSSEC, DNS records, TLS/SSL certificates and registrant data. On domains you don’t own it detects lookalikes and typosquats, or lifecycle stages on domains you want to acquire.

Is domain monitoring the same as uptime monitoring?

No. Uptime monitoring is a lagging signal that fires once a website is already down. Domain monitoring is a leading indicator that catches the cause, such as a nameserver change or an approaching expiry date, while everything still looks fine. Both belong in a stack, but they answer different questions.

What is the difference between domain monitoring, backordering and drop catching?

They run in sequence. Monitoring tells you a domain is heading toward expiry. A backorder is a standing request to register it once it becomes available. Drop catching is the timed, competitive attempt to register it the instant it drops.

How often should domains be monitored?

Match the cadence to the risk. Check security-relevant records such as nameservers, locks, DNSSEC and certificates frequently, and alert on high-severity changes immediately. Check expiry daily but alert on a ladder, for example 90, 60, 30, 7 and 1 day out, plus an alert on entry into redemption.

Who should receive a domain alert?

Route by role. Portfolio managers own expiry and locks, IT owns DNS records and TLS/SSL certificates, security owns hijack and lookalike signals, legal owns brand and takedown decisions. Reserve immediate alerts for the critical tier and batch the rest into digests.

Do you still need domain monitoring if all domains auto-renew?

Yes. Auto-renewal fails through expired payment cards, declined charges, processing errors or domains switched to manual renewal. It reduces how often domains expire without removing the need to watch.

Are there tools for domain monitoring?

Yes, and they fall into three groups. In-house scripts against public RDAP are cheap but hit rate limits and serve cached data. Brand-protection vendors are strong on the domains you don’t own but rarely see your own portfolio. Registrar-sourced platforms such as AutoDNS hold authoritative data on the domains you own, consolidate portfolios spread across providers into one inventory and offer API access for automation. Many enterprises pair a registrar-sourced platform with a specialist service to cover both halves.

How do you monitor domains held with several providers?

Each provider shows only its own domains, with its own alert logic and no shared severity model. The answer is a single monitoring layer above them, giving one inventory, one alert model and one audit trail, with API access for automation at scale.


How does domain monitoring support NIS2 compliance?

NIS2 raises expectations around asset inventory and incident detection. A monitored portfolio contributes to both, and the change log domain monitoring produces is the audit evidence regulators look for. Treat compliance as a byproduct rather than the purpose.