Your domain name expires tomorrow. Who gets the notice?
Your website and your email depend on a domain name renewed every year. But if it is registered under a former agency's name or tied to an ex-employee's phone, does your business actually control it?
Monday morning, 8:07. The website is down. A few minutes later a customer calls: their emails are bouncing back with an error. The hosting provider confirms the server is fine. Microsoft 365 reports no outage.
The problem is somewhere else. The company's domain name expired over the weekend.
The reminders were sent — to the address of an employee who left two years ago. Auto-renewal was attempted too, but the credit card on file had expired. And to open the registrar account, you now need a code sent to the former web developer's personal phone.
A relatively modest annual expense has just disrupted the website, the email and customer service. Nobody had forgotten the domain was important. Everyone simply assumed somebody else was handling it.
The domain is not the website, and not the hosting
The domain name is the company's digital address — company.ca , for instance. It lets people find the website and tells mail systems where to deliver email.
Several parties sit behind that address:
- the registry manages an extension, like CIRA for
.ca; - the registrar sells and administers the registration;
- the DNS provider publishes the records that direct traffic;
- the web host stores the site;
- the mail provider handles email.
One company can provide several of these services, but they remain distinct. Changing hosts does not automatically transfer the domain. Renewing hosting does not necessarily renew the registration. And a perfectly functioning website proves nothing about whether the registrant's contact details are current.
That confusion is why an executive sometimes calls their web designer about a problem that belongs to the registrar — or discovers they do not even know which registrar to contact.
Who actually controls the domain?
The word "owner" gets used loosely, but a domain is really a renewable right of use. The person or organization listed as the registrant enters the agreement with the registrar and holds the rights attached to the registration.
For a business domain, that registrant should be the organization itself, with accurate details. Not the founder's personal name, not an employee's, not a consultant's, and not the agency that built the site.
CIRA says it plainly in its guidance to businesses: always register your domain yourself, and avoid letting a third party register it in their own name. If the relationship ends, regaining control can get complicated.
A provider can perfectly well administer the technical settings without becoming the registrant. It is the same logic as Microsoft 365 or backups: the partner helps manage the environment, but the asset and the recovery access must stay under the company's control.
A .ca-specific wrinkle: registering in that extension requires selecting a category demonstrating a connection to Canada — the Canadian Presence Requirements. That has a little-known practical consequence: correcting an inaccurate registrant is not a simple name change. If CIRA issues a registrant information validation notice, action is required, and CIRA applies locks preventing any transfer and any contact update until supporting documentation is received. Better to make that correction calmly, with the paperwork in hand, than in the middle of an emergency.
The four most common ways to lose control
1. Notices land in an abandoned mailbox
Registrars send renewal reminders to the contact details on file. If the address belongs to a former employee or is never monitored, the messages can be delivered without the organization ever seeing them.
Using a functional address controlled by the company — a mailbox dedicated to administering digital services — reduces that dependency. At least two people should be able to monitor it.
2. Automatic payment fails
Auto-renewal is excellent protection, but it depends on a valid payment method. A card replaced after fraud, expired, or tied to someone who has left can cause the transaction to fail.
So you need to verify all of it: that renewal is enabled, the domain's expiry date, the card on file, and that confirmations are actually being received. "Automatic" does not mean "verified."
3. MFA belongs to one person
The registrar account is protected by multi-factor authentication — excellent news. But if the codes arrive only on a consultant's or an executive's personal phone, the company can be locked out at the moment it needs to act.
Recovery methods, emergency codes and secondary administrators have to be planned without disabling MFA or sharing a daily account. The article on the executive who becomes unavailable applies the same logic to the company's other digital keys.
4. The domain is bundled into a vendor contract
An agency may have bought the domain, the hosting and the site design as one package. As long as the relationship is good, everything looks simple. When it is time to change providers, nobody knows whether the domain can be transferred, who must approve the request, or which access will be handed over.
The contract should clearly separate company ownership, administration delegated to the provider, and the transfer procedure at the end of the engagement.
You are not powerless if a provider is holding your domain
This is the part most executives do not know, and it changes the balance of power entirely.
Transferring a .ca domain to another registrar requires an authorization code. The registrar must provide that code within five calendar days of a valid request, and must remove any registrar locks applied to the domain.
If the code does not arrive within that window, the request escalates directly to CIRA. You write to the registry, attaching all correspondence related to the request, with the subject line "Authorization Code Request." CIRA then works directly with the registrar and follows up with you.
Two useful details for planning:
- After a successful transfer, the domain cannot be transferred again for 60 days. Not a problem, but worth scheduling around — especially if you are changing provider and host at the same time.
- Checking whether a domain is locked takes 30 seconds: in WHOIS, under "Registrar Status," the entry "TransferProhibited" means the domain is locked and cannot be transferred. Your registrar is the one who can remove that lock.
What happens when a domain expires?
The .ca lifecycle is documented, and it is less reassuring than most people assume.
Past the expiry date, the domain enters an auto-renew grace period of up to 45 days. CIRA automatically renews the domain and bills the registrar. But the actual length of that period is controlled by the registrar, according to its own policies — and the domain may stop working during it. That, too, is the registrar's decision.
In other words: there is no guaranteed window during which your website and email keep working after expiry. They can go down the next day.
If the renewal is not paid, the domain is deleted and enters a 30-day redemption grace period. Here there is no ambiguity: the domain is no longer active, and any website and email addresses associated with it stop working. This is the last chance to ask the registrar to restore and renew the domain for one year. Restoration fees generally apply, and they vary enormously between registrars — from nothing to a few hundred dollars.
After that, the status changes to "pending delete" and the domain goes onto the To Be Released list before returning to circulation. Someone else can then register it. The company would lose more than an address: it would have to change its website, its email, its accounts, its documents, its campaigns, and everything else using its former digital identity.
Careful: the date shown in WHOIS can falsely reassure you
Here is the nastiest trap in this whole subject.
Because CIRA automatically renews the domain at the registry on its expiry date, the expiry date shown in WHOIS can move a year ahead while the domain is dying. It is a temporary registry-side renewal that does not reflect the real situation: if your registrar was never paid, the countdown to deletion is already running.
A WHOIS lookup therefore confirms the registrar and gives you a date. It does not confirm that your renewal has been paid. Only the registrar can do that.
A compromised domain can be worse than an expired one
Expiry is visible. Hijacking can be far quieter.
Someone who takes over the registrar account can attempt to change the name servers, redirect the site, intercept some email, or transfer the domain. Those changes can look like a hosting or Microsoft 365 incident when the real point of entry is at the domain level.
Important protections include:
- a unique password stored in a business password manager;
- multi-factor authentication that is both resistant and recoverable;
- individual accounts or delegated access where the registrar allows it;
- locking the domain against unauthorized transfers;
- alerts on sensitive changes;
- periodic review of administrators and contact details.
For particularly critical domains, some extensions offer additional protection at the registry level. CIRA offers Registry Lock for high-value .ca domains — aimed at government bodies, banks, corporations, institutions and trademark holders.
When it is applied, no attribute of the domain can be changed and no transfer or deletion transaction can be processed — with the exception of renewals, which remain possible. Only CIRA can remove that lock.
The usual objection is friction: "what if I need to change something quickly?" It does not hold. For any change, you go through your registrar, who works with the registry — and CIRA responds to lock and unlock requests in under one hour, 24/7. The service is purchased annually and follows the associated domain's expiry and renewal dates.
This does not replace securing the registrar account. It adds a second barrier for domains whose compromise would be severe.
Inventory all of your domains
The company may hold more than one. It might have:
- the
.caand the.comof its brand; - a former business name redirecting to the main site;
- variants with and without hyphens;
- a domain used only for one application;
- a domain tied to a campaign or an acquisition;
- accented domains, or common misspellings held defensively.
For each one, the inventory should record:
- the official registrant;
- the registrar and the account number;
- the expiry date;
- whether auto-renewal is on;
- the payment method and who owns it;
- administrative and technical contacts;
- who is authorized to act;
- where the recovery methods are kept;
- the DNS provider;
- the services that depend on the domain;
- the state of locks and protections.
The inventory should not contain passwords in plain text. It should record where access is stored securely and who may use it.
The 20-minute exercise to run this week
Pick the company's main domain and check the following:
- Use CIRA's WHOIS for a
.ca, or ICANN's lookup for a generic domain, to identify the registrar. Two caveats: the expiry date shown is not proof the renewal was paid, and registrant details may be hidden if the registration is privacy protected. - Confirm with the registrar directly that the renewal is paid and through what date. That is the only reliable source.
- Confirm at least two authorized people can open the registrar account.
- Verify the registrant is the company and its details are current.
- Confirm reminders arrive in a monitored mailbox.
- Check auto-renewal and the payment method.
- Test the recovery procedure without using a former collaborator's phone or personal mailbox.
- Check the lock status: in WHOIS, under "Registrar Status," look for "TransferProhibited."
- Enable domain locking and whatever alerts are available.
- Document the DNS provider and export or record the essential configuration.
- Add a periodic check to the calendar, well before expiry.
Do not change name servers just to run a test. One wrong value can take down the site and the email. The goal is to confirm control and recovery, not to cause an outage.
This check pairs well with an internet failover plan . A secondary connection protects the office against a local cut; it does nothing if the company's digital address is no longer under its control.
An employee's departure should trigger a check
When someone who administered the domain leaves, their access must be removed, their sessions revoked, and the recovery methods reviewed. You also need to confirm that notices, billing and MFA no longer depend on them.
It is a perfect example of invisible access: the laptop comes back, but a key capable of redirecting the website and the email may still exist. Our article on the access nobody remembers when an employee leaves explains how to fold this check into a systematic procedure.
The same review should happen when changing web agencies, after an acquisition, on a name change, or during a mail migration.
In closing
The domain name is easy to forget precisely because it works almost all the time. It renews once a year, costs relatively little, and makes no noise while everything is fine.
Yet it ties together the brand, the website, the email and several digital services. It is not a small web expense. It is a business continuity asset.
A well-prepared company knows who the registrant is, which registrar manages the domain, when it expires, who receives the notices, and how to recover access without depending on one person. It can delegate administration to a partner without handing over control.
So the right question is not only "is our domain renewed?" It is "if we had to recover or protect it today, do we actually hold the keys?"
An IT project or a question?
MMO Techno can help you inventory your domains, secure administrative access, document dependencies and fold renewals into your digital continuity plan.