Give another person authorised access now

A business-critical domain should not depend on one person noticing an email. Use the registrar’s supported delegation or organisation controls, enable suitable multi-factor authentication and identify a second authorised administrator. Maintain independent recovery contacts so that an outage of the domain’s own email does not block account recovery.

Confirm who owns the registration and who can approve renewals or transfers. A saved password alone may not satisfy the registrar’s verification process or company authorisation requirements. Record the official support route and account identifiers in the business runbook.

Verify renewal and payment arrangements

Check auto-renewal, expiry dates and the payment method for each domain. Where supported, arrange a backup payment route and send renewal alerts to more than one responsible person. Multi-year registration can reduce near-term exposure but does not remove the need to maintain ownership, payment and contact records.

Keep a DNS export and document the services that rely on the domain, including email, identity and certificate validation. Test that the second administrator can find these records without using the absent person’s device. Use monitoring suited to urgent domain failures rather than waiting for a long inactivity period.

Do not rely on a universal expiry timeline

The ICANN expired registration guidance describes a 30-day redemption grace period after deletion for generic top-level domains. That is not a universal timetable measured from the original expiry date. Registrar terms, deletion timing, extension policies and fees matter. Country-code domains can follow different rules.

Read the actual registrar’s current expiry and recovery policy. If a domain is already at risk, contact its support team promptly. Do not wait for a fictional day-by-day schedule or assume that the website continuing to load means renewal succeeded.

Use a handoff for supporting instructions

ZeroLatch can hold a registrar inventory, DNS backup locations and escalation contacts as a secondary continuity layer. It is not domain monitoring and cannot promise delivery before a renewal deadline. Keep urgent operational access in the organisation’s normal controls.

ZeroLatch can deliver a scoped inventory and instructions after a missed check-in and safety period. It does not transfer assets, establish legal authority or confirm death. Simple permits authorised service-managed key recovery; Private requires a separate password or ZeroLatch recovery phrase. Neither option replaces an independent backup or a real recipient rehearsal. Start with harmless information and read the security model and backup checklist.