Domain monitoring: watch what you own, and what you don’t
Domain monitoring can be divided into two jobs: watching the domains you own, and watching the domains you don't.
Published by
Simone Catania
Date
Domain monitoring is one of those disciplines every organization should know how to do. Most resources on the subject pick a side. Brand-protection vendors say domain monitoring means hunting lookalike domains. Uptime tools say it means checking expiry dates. Both are half right, and neither helps a team running hundreds of domains. The full picture is broader and easier to remember: Domain monitoring watches the domains you own and the ones you don’t.
What is domain monitoring?
Domain monitoring is the process of keeping your domains watched and secure, while keeping an eye also on those you don’t. The job is to monitor changes that affect availability, security or your brand.
The first half of the job is to watch your own domain portfolio. This is where the operational risk lives. You track the expiry date held at the registry, the lock status, the DNSSEC state, the nameserver and other DNS records, TLS/SSL certificate expiry and any change to the registrar or registrant on record. A single change to one of these can take your website, your email and your certificates offline.
The second half watches domains outside your control. For most organizations that means new registrations imitating the brand: exact matches on other extensions, misspellings and visual lookalikes.
| – | Domains you own | Domains you don't own |
|---|---|---|
| What you watch | Expiry, EPP status codes and locks, DNSSEC, DNS records, TLS/SSL certificates, registrant data | New registrations imitating your brand |
| What a change means | Something in your infrastructure is about to break, or has been tampered with | Someone is preparing to impersonate you, or a domain you want is about to become available |
| Who acts | Portfolio manager, IT, security | Security and legal, or the investor placing a backorder |
| Typical failure | A domain expires or is hijacked without anyone noticing | A phishing site goes live before anyone reacts |
What domain monitoring is not
Three neighbouring disciplines get mistaken for domain monitoring. None of them replaces a proper domain monitoring procedure.
| – | What it does | When it acts |
|---|---|---|
| Domain monitoring | Detects changes on the domains you own and the domains you don't | First. It is the leading signal |
| Uptime monitoring | Confirms a website or service is currently reachable | After the change has taken effect |
| Brand protection | Enforces against confirmed abuse through disputes, takedowns and blocking | After a lookalike has been detected and intent established |
| Backorder and drop catching | Attempts to register a domain the moment it becomes available | After monitoring has flagged an acquisition target |
1. Uptime monitoring reports the outage, domain monitoring prevents it
Uptime monitoring fires once your visitors and customers are already affected. Domain monitoring catches the cause while everything still looks fine. Take a nameserver change on your primary domain. Domain monitoring detects it immediately, while the domain still resolves correctly, so you can confirm whether the change was authorized and revert it before propagation completes. An uptime tool sees nothing until the new nameservers take effect and traffic stops routing, perhaps a week later.
Both belong in a healthy stack, because they answer different questions. Uptime answers “Is it working right now?”. Domain monitoring answers “Is anything changing that will stop it working soon?”.
2. Brand protection enforces what domain monitoring detects
There is a real overlap between brand protection and domain monitoring. Detecting domains that imitate your brand is part of domain monitoring, and brand-protection services do exactly this job at web scale. But brand-protection vendors observe the namespace from the outside and rarely see the operational signals inside your own domain portfolio like an expiring domain, a removed Transfer Lock or a broken DNSSEC chain. On the other hand, once a lookalike is confirmed, brand protection services move into disputes, takedowns and blocking, each with its own process. Our guides on defensive domain registration and domain blocking services cover UDRP, the Trademark Clearinghouse and namespace-wide blocking.
Put simply: domain monitoring detects, brand protection enforces.
3. A backorder acts on what domain monitoring finds
Monitoring, backordering and drop catching sit in sequence. Domain monitoring is the leading signal. It watches a domain’s lifecycle and tells you it is heading toward expiry. A backorder is a standing request to register that domain once it becomes available. Drop catching is the timed, competitive attempt to register the domain the instant the registry deletes it, when it becomes available to anyone and several buyers may be waiting for the same moment. The lesson: You monitor first, then decide whether to place a backorder or attempt a catch.
Domain inventory first: you cannot monitor domains you forgot you own
Before you even talk about domain monitoring, you need to know exactly what domains your organization owns. The first step is also “discovery”. Talk to marketing, or your regional office, find out what domains they registered and create the full list.
Which domain signals to monitor in your domain portfolio
Let’s take a look on what to monitor in the domains you own. Each signal tells you something specific when it changes.
- Expiry and renewal: Check the expiry date your provider sent but also double check at the registry. Track the redemption and pending-delete windows too. An expired domain does not disappear on the expiry date. It moves through different stages, and each one is a lower chance to get it back. The domain lifecycle section of our domain management guide sets out those stages.
- Registrar and registrant changes: Registration data now lives primarily in RDAP, the Registration Data Access Protocol. ICANN made RDAP the definitive source for gTLD registration data on 28 January 2025 as WHOIS was sunset. RDAP supports tiered access, so public queries return a reduced data set. On a domain you own, a change to the registrant or registrar is a signal worth catching immediately. If you have applied WHOIS and RDAP privacy, the underlying record still needs to be accurate and monitored.
- EPP status codes and locks: EPP status codes are the machine-readable flags the registry holds on every domain. The security-relevant ones are the locks. clientTransferProhibited and serverTransferProhibited block transfers, while the update-prohibited codes block changes to nameservers and contacts. A change here is critical. For business-critical domains, Registry Lock adds the highest security level at the registry-level.
- DNS records: Monitor nameservers, A and AAAA records, MX records for mail routing, and the TXT records carrying your SPF, DKIM and DMARC policy. Our guide to DNS records covers each type.
- DNSSEC status: DNSSEC signs your DNS records so resolvers can verify they have not been altered. It depends on a DS record published at the registry. If that record is dropped or becomes invalid, resolution can fail outright for validating resolvers. It can also indicate tampering.
- TLS/SSL certificate signals: Certificate monitoring has become harder, and recently with the CA/Browser Forum’s Ballot SC-081v3, approved in April 2025, the maximum lifetime of publicly trusted TLS/SSL certificates went down from 398 days to 47 by March 2029. The first cut, to 200 days, took effect in March 2026. Alongside expiry, watch Certificate Transparency logs for certificates issued on your domains.
| Signal | Watch for | Why it matters |
|---|---|---|
| Expiry and lifecycle | Registry expiry date, grace, redemption, pending delete | An expired domain is recoverable only inside these windows |
| Registrant and registrar | Changes to either field | Can indicate an unauthorized transfer in progress |
| EPP status codes | Removal of transfer or update locks | Someone has taken a protection off |
| DNSSEC | DS record dropped or invalid | Resolution breaks for validating resolvers, or records are being tampered with |
| DNS records | NS, A/AAAA, MX, TXT, CNAME | The routing of your website, email and authentication |
| TLS/SSL certificates | Expiry across the portfolio, new issuance in CT logs | Expired certificates look like a compromise, unexpected ones may be one |
How to monitor domains you don’t own
If you want to protect your domain portfolio and brand, you should also watch the whole namespace. Bad actors registrer exact matches of your brand on other extensions. The detection of malicious domains can be done by monitoring three sources:
- Zone files, which some registries publish and which list the domains registered under an extension.
- New-registration feeds.
- Certificate Transparency logs again, because a lookalike being prepared as a phishing site usually needs a certificate, and that request becomes public immediately.
Treat a malicious domain registration is a signal. It isn’t necessarily a threat yet. Detection can happen within a day of registration or certificate issuance.
Takedown can be a slower process that depends on establishing and reporting intent. So before escalating, check three things: Is the domain parked? Have MX records been configured, so it can send mail? Is there any live content? When a case is ready to escalate, our guides on defensive domain registration and domain name protection cover the routes available: UDRP through WIPO, provider or registry takedown, or negotiated acquisition.
How often should domains be monitored?
Not every aspect of domain management deserves the same frequency. Security-relevant records need frequent checks: nameservers, lock status, DNSSEC state, certificate validity. You want to know about a change here within minutes.
Domain renewal cycles are slow and predictable. Creating a schedule with alerts 90, 30, 7, and 1 day before expiry gives you a solid overview. Auto-renewals do not make domain monitoring unnecessary. Auto-renewals can fail in different ways, such as through an payment card, a declined charge, or a processing error. This is why monitoring domain renewals belongs to a domain monitoring procedure.
High-severity signals like a removed lock, a changed nameserver or a dropped DS record should be immediate, since they are the changes an attacker makes during a hijack. Waiting a day or even some hours can be risky.
Domain monitoring answers compliance needs
If you operate in Europe, compliance is a huge topic and it involves domain monitoring as well.
The NIS2 Directive expects you to know what assets you have and to notice when something goes wrong. A monitored portfolio helps with both, and the change log it produces is much easier to keep as you go than to piece together after an incident. Our NIS2 Information Hub has the domain-specific resources. GDPR affects domain monitoring for the domains you don’t own. Registration data is no longer openly available, so a public query tells you little about who is behind a lookalike domain, and getting more may mean a formal request.
Monitor your domains today with a professional all-in-one platform
Domain monitoring comes down to one thing: turning silent changes into signals you can act on. On the domains you own, that means watching expiry, locks, DNSSEC, DNS records and TLS/SSL certificates. On the domains you don’t, it means spotting the lookalikes that imitate you and the domains you might want to acquire.
That is where a single platform earns its place. AutoDNS brings a portfolio spread across several providers into one inventory, with authoritative registrar data, API access and white-label management on EU-based infrastructure. Take a look, or talk to an InterNetX partner manager about what your domains would look like in a single view.
Monitor your domains in AutoDNS
Frequently asked questions
Domain monitoring is the continuous watching of two sets of domains, the ones you own and the ones you don’t, for changes affecting availability, security or your brand. On your own domains it tracks expiry, EPP status and locks, DNSSEC, DNS records, TLS/SSL certificates and registrant data. On domains you don’t own it detects lookalikes and typosquats, or lifecycle stages on domains you want to acquire.
No. Uptime monitoring is a lagging signal that fires once a website is already down. Domain monitoring is a leading indicator that catches the cause, such as a nameserver change or an approaching expiry date, while everything still looks fine. Both belong in a stack, but they answer different questions.
They run in sequence. Monitoring tells you a domain is heading toward expiry. A backorder is a standing request to register it once it becomes available. Drop catching is the timed, competitive attempt to register it the instant it drops.
Match the cadence to the risk. Check security-relevant records such as nameservers, locks, DNSSEC and certificates frequently, and alert on high-severity changes immediately. Check expiry daily but alert on a ladder, for example 90, 60, 30, 7 and 1 day out, plus an alert on entry into redemption.
Route by role. Portfolio managers own expiry and locks, IT owns DNS records and TLS/SSL certificates, security owns hijack and lookalike signals, legal owns brand and takedown decisions. Reserve immediate alerts for the critical tier and batch the rest into digests.
Yes. Auto-renewal fails through expired payment cards, declined charges, processing errors or domains switched to manual renewal. It reduces how often domains expire without removing the need to watch.
Yes, and they fall into three groups. In-house scripts against public RDAP are cheap but hit rate limits and serve cached data. Brand-protection vendors are strong on the domains you don’t own but rarely see your own portfolio. Registrar-sourced platforms such as AutoDNS hold authoritative data on the domains you own, consolidate portfolios spread across providers into one inventory and offer API access for automation. Many enterprises pair a registrar-sourced platform with a specialist service to cover both halves.
Each provider shows only its own domains, with its own alert logic and no shared severity model. The answer is a single monitoring layer above them, giving one inventory, one alert model and one audit trail, with API access for automation at scale.
How does domain monitoring support NIS2 compliance?
NIS2 raises expectations around asset inventory and incident detection. A monitored portfolio contributes to both, and the change log domain monitoring produces is the audit evidence regulators look for. Treat compliance as a byproduct rather than the purpose.