Scanning a daily domain drop list for expired domains: The workflow

Expired domains · · Last reviewed · 11 min read

Scanning a daily drop list for expired domains is a funnel problem before it is a metric problem.

A daily drop list arrives as 130,000 to 200,000 raw names across every TLD. The discipline that turns that flood into one or two names worth owning is a fixed sequence: cheap-fast filters first, expensive-slow audits second, run in the same order every day.

Operators who scan by feel burn hours and still acquire noise, because the dangerous part of the list is engineered to pass a single glance.

This workflow runs the funnel in five tiers: source the list, apply quantitative threshold filters, screen for spam and penalty residue, audit backlinks and Wayback history by hand, then route the survivors to a catch or auction.

Running it end to end by hand costs hours every day.

SEO Domains operates the curated marketplace with a 220,000+ pre-screened catalogue, ICANN-accredited, from $100 entry-level domains through $1.5 million premium acquisitions. The team has already run this exact workflow at scale. A buyer reviews the sorted slice instead of grinding the daily list one name at a time.

What scanning a drop list for expired domains involves

Scanning a drop list for expired domains is the fixed, time-boxed sequence an operator runs each day to convert the 130,000 to 200,000 raw drop pool into 1 to 10 acquisition-ready aged domain candidates.

The sequence runs five jobs in order: sourcing, quantitative filtering, spam and penalty screening, manual audit, and acquisition routing. The order carries the leverage, not any single step.

The workflow repeats on a fixed cadence rather than reacting to tips.

A drop list aggregates names finishing pendingDelete and re-entering first-come-first-served availability. That is the same pool sized and timed in The daily drop pool: size and cadence.

The workflow runs against that pool on a daily schedule. It applies progressively stricter criteria across distinct tiers. Each day’s result feeds back into the next day’s thresholds.

An operator working from ad-hoc tips evaluates one name in isolation. An operator running the workflow evaluates the whole list against a consistent bar, which is what makes the output repeatable instead of lucky.

Scanning a drop list is a separate routine from monitoring an auction.

Drop list scanning targets pending-delete and freshly released names where speed of capture decides the outcome. Auction monitoring tracks open bidding windows where deliberation and budget decide it.

Both belong in an aged domain program, and each carries its own routine and its own tooling.

The workflow described here is the scanning routine: the daily reduction of a raw list to a small set of names worth a catch attempt or a watch.

How the workflow proceeds through five tiers

The workflow proceeds through five tiers ordered cheap-fast to expensive-slow. The five tiers are:

  • Source the list.
  • Apply quantitative threshold filters.
  • Run a spam and penalty screen.
  • Audit backlinks and Wayback history by hand.
  • Route survivors to acquisition.

Each tier hands a smaller pool to the next. Manual hours land only on names that already cleared every automated test.

Pool reduction follows a defined shape. Tier 1 sourcing assembles and deduplicates 130,000 to 200,000 raw names. Tier 2 quantitative filtering cuts that to the low hundreds of candidates in minutes through tooling.

Tier 3 spam and penalty screening trims the survivors to a low-tens shortlist. Tier 4 manual audit qualifies 1 to 10 finalists. Tier 5 routes each finalist to a catch service, an auction bid, or a direct registration.

Reversing the order collapses throughput without improving precision. A manual Wayback read applied to an unfiltered list burns hours and surfaces nothing extra.

TierTypical timePrimary toolsPool after tierCommon mistake
1. Source and deduplicate5 minExpiredDomains.net, WhoisFreaks, registry feeds130,000-200,000 rawSingle-source dependency; skipping dedup
2. Quantitative filter10 minAggregator filter UI, SpamZilla, custom scriptsA few hundredThresholds too loose; ignoring TLD selection
3. Spam and penalty screen10 minSpamZilla score, Majestic TF/CF, anchor scanLow tensTrusting one headline metric in isolation
4. Manual backlink and Wayback audit2-30 min per nameAhrefs, Majestic, Wayback Machine, USPTO/WIPO1-10 finalistsSkipping the Wayback read; ignoring redeployment fit
5. Acquisition route5 minCatch service, auction platform, registrar0-3 acquiredUn-funded account; no written bid ceiling
Figure 1. The five-tier funnel ordered cheap-fast to expensive-slow. Tiers 1 to 3 run across the full list at near-zero per-name cost; tier 4 reserves the expensive manual hours for the handful that already survived.
Figure 2. The same five tiers read as a sequential pipeline, each tier carrying its own sourced tools, thresholds, and surviving pool. The vertical rail marks the order that carries the leverage: every tool and threshold is applied in sequence, cheap-fast tiers ahead of the expensive manual read.

The cadence holds across operator types. The day runs in a fixed order:

  • Sourcing happens shortly after the daily feeds publish.
  • Filtering follows within minutes of the pull.
  • The spam screen runs immediately after.
  • The manual audit runs during working hours, before competing buyers consume the same survivors.

Mass drop events multiply the raw pool. Registry sweeps and post-holiday backlogs are the usual triggers. The response is a proactively stricter tier 2, not a longer manual read.

The mechanics of those flood days are covered in Mass drop events and what triggers them.

How operators source and deduplicate the daily list

Tier 1 ingests drop lists from ExpiredDomains.net, WhoisFreaks, SpamZilla, GoDaddy Auctions, and registry feeds, then deduplicates names that appear across multiple sources.

ExpiredDomains.net covers 676 TLDs and publishes no official API. The pull is a CSV download or a scrape. WhoisFreaks publishes a free daily list of up to 10,000 names updated at 03:00 UTC.

Source coverage shapes the entire downstream funnel. The four primary feeds each cover a different slice:

  • ExpiredDomains.net aggregates daily lists across 676 TLDs through its filter UI and CSV export, not a programmatic API.
  • WhoisFreaks publishes a free daily expired and dropped feed of up to 10,000 names with TLD data, refreshed at 03:00 UTC, as JSON or CSV.
  • SpamZilla processes 350,000 domains daily across 16 sources and layers its own scoring at ingestion.
  • GoDaddy Auctions lists 10,000 or more expiring names daily with auction context.

The export format differs by source. ExpiredDomains.net hands back a CSV export, while WhoisFreaks returns JSON or CSV that a script ingests after the 03:00 UTC refresh.

Pulling from one source alone leaves coverage gaps. Competitors fill those gaps from the sources skipped.

The ICANN ERRP sequence makes the daily cadence predictable.

ICANN’s Expired Registration Recovery Policy, effective 31 August 2013, standardizes the post-expiration sequence of renewal grace period, redemption period, and pending delete that produces a predictable daily release rhythm across gTLD registries.

Operators time their pulls against that published sequence to capture pending-delete and dropped inventory at maximum freshness, since the highest-value names resolve within hours of release.

Verification of any individual name’s current status runs through WHOIS and its RDAP successor, the lookup tooling catalogued in Domain lifecycle tracking: WHOIS, RDAP, and the workflow tools that monitor every status code.

Deduplication compresses the working set before any filtering begins.

A single dropped .com surfaces on ExpiredDomains.net, GoDaddy Auctions, and SpamZilla at the same time, and running three duplicate records through tier 2 and tier 3 triples the cost for no gain.

Hash-based deduplication against the registered domain string collapses the multi-source pull into one clean working set.

On mass drop days the duplication overhead climbs sharply, which is the point at which an automated dedup step stops being optional and starts paying for itself.

How quantitative threshold filters cut the pool fast

Tier 2 applies quantitative thresholds to cut a six-figure list to the low hundreds of candidates in minutes. The thresholds cover referring-domain count, Domain Rating or Domain Authority, Spam Score, name length, and TLD selection. These filters run across the full list at near-zero per-name cost through tooling, which is why they run first.

Figure 3. The funnel as a narrowing diagram, built from the workflow’s own numbers. A raw pool of 130,000 to 200,000 names contracts through the quantitative filter to the low hundreds, to a 5-to-10 name shortlist in about fifteen minutes, and to 1 to 10 acquisition targets per run. Each band is narrower than the last because the cheap-fast filters remove the structural majority before any manual hour is spent.

A practical starting threshold set combines five dimensions:

  • Referring domains: a floor of 20 or more unique sources eliminates lone-link names.
  • Authority floor: Domain Rating above 15 to 25 from Ahrefs, or Domain Authority above 20 from Moz.
  • Spam Score cap: flags obvious manipulation.
  • Name length: a ceiling near 18 characters favours brandable assets.
  • TLD selection: .com, .net, .org, and operator-relevant ccTLDs over novelty extensions.

The Ahrefs Domain Rating and the Moz Domain Authority set the authority floor at this stage. The mechanics of the Majestic trust metrics that tier 3 leans on are detailed in Trust Flow and Citation Flow.

Threshold strictness trades pipeline volume against shortlist quality.

Loose thresholds surface 800 to 1,200 candidates a day and demand longer audit hours downstream. Strict thresholds surface 80 to 150 candidates and constrain monthly acquisition volume.

The right calibration tracks the operator’s own historical conversion rate. That rate is the share of tier-2 survivors that became worthwhile acquisitions. A weekly review of the decision log against win and loss data refines it.

ExpiredDomains.net processes its filter set in seconds. SpamZilla and similar aggregators apply scoring at ingestion. Custom scripts in Python or Node run tier-2 logic against a CSV pull in under a minute. The cheap-fast designation is literal.

Tier-2 filters exclude, they do not endorse.

A name clearing all five thresholds earns a tier-3 screen, not acquisition status.

The quantitative pass removes the structural majority of a list. Those are the empty and machine-generated names that never accumulated equity. The low hundreds of plausible candidates pass to the screen that catches what raw numbers miss.

On mass drop days, an unchanged threshold set against a multiplied pool floods the manual stages with a multiplied survivor count. Operators tighten tier 2 proactively when a scheduled flood approaches.

How the spam and penalty screen removes contaminated names

Tier 3 screens the low-hundreds pool of quantitative survivors for spam residue and penalty exposure using a SpamZilla score, the Majestic Trust-to-Citation ratio, and an anchor-text scan. The screen reads three signals together because the dangerous tier of a drop list inflates any single headline number in isolation.

The Trust-to-Citation ratio is the fastest spam tripwire. Trust Flow weights links by proximity to a curated trusted-seed set; Citation Flow weights raw link influence.

A Trust Flow of 10 against a Citation Flow of 50 records link volume unsupported by trust, the classic spammed-profile fingerprint, and triggers rejection before any manual time goes in.

A ratio at or above 0.50 reads as a practical minimum and 0.70 or higher as stronger.

SpamZilla’s proprietary 1-to-100 score compounds this read across seven inputs:

  • Domain age
  • Archive.org active history
  • Redirect status
  • Parked-page intervals
  • Anchor text
  • Website history
  • Backlink history

That spread is why the score functions as a screening layer instead of a single metric. The Moz screen it complements is covered in Domain Spam Score.

Screen 1
Trust-to-Citation ratio
Below 0.30, such as Trust Flow 10 against Citation Flow 50, signals link volume without trust. The cheapest spam tripwire on the list and the first to fire.
Screen 2
Anchor-text distribution
Pharma, casino, adult, forex, and replica anchors auto-disqualify regardless of surface metrics. Commercial-keyword anchors above 10 to 15 percent flag manipulation.
Screen 3
Composite spam score
SpamZilla and Moz compress age, redirect, parked, and backlink history into one flag, catching contamination that a clean Domain Rating hides.
Screen 4
Penalty residue
Mass link loss, foreign-language anchor anomalies, and topical pivots flag prior abuse cycles and proximity to a network takedown.

Anchor-text scanning audits the language attached to inbound links across the survivor set. A natural profile skews toward branded, naked-URL, and generic anchors.

Pharma, casino, adult, forex, and replica anchors are auto-disqualifiers regardless of surface metrics, because their presence records a prior abuse cycle that travels with the name.

Foreign-language anchor anomalies that mismatch a domain’s history signal link injection or hijack residue.

The signals that separate genuine value from engineered noise at this stage are catalogued in Spotting value in drop lists: signal vs noise, the companion piece on what to look for once the workflow tells where to look.

How manual backlink and Wayback review confirms value

Tier 4 reserves the expensive manual hours for the low-tens shortlist and reduces it to 1 to 10 finalists at minutes to half an hour per name. The hand audit runs four checks:

  • A hand audit of the backlink profile in Ahrefs or Majestic.
  • A Wayback Machine continuity read.
  • A trademark check.
  • A redeployment-fit verification against current abuse policy.

Backlink review moves beyond the referring-domain count that cleared tier 2. The auditor opens the strongest referring pages and confirms two things.

The links are contextual in-content placements, not sitewide footers or sidebars. Each link is still indexable, with no noindex tag or robots block.

A healthy referring-domain trend grows gradually across years. A sharp spike followed by a collapse signals a paid campaign or an injection.

Domain age on its own carries no weight here. The SEO Domains analytical desk treats that as settled: a technically old name with a manipulated link history loses to a younger name with a clean editorial profile. The audit reads continuity and source quality, not the registration year.

Wayback continuity converts a domain’s past into a pass-or-fail filter.

The Wayback Machine, operated by the Internet Archive, preserves snapshot copies of a domain’s content across its registration years.

The auditor opens one representative snapshot per year, ideally seeking ten or more years of coherent history, and flags any topical pivot, spam interval, parked-page stretch, or hacked-content episode.

A name that ran accountancy content and held that identity passes; a name that pivoted into casino content during its final two years carries inherited residue that survives the transfer.

A real organic-traffic record and a site: indexation check close the read, since a name with metric strength but zero indexed pages is a profile without a pulse.

Redeployment fit is a mandatory checkpoint, not an optimisation.

Google’s expired domain abuse policy, launched 5 March 2024, designates as spam any domain repurposed primarily to manipulate ranking off its prior reputation, and site reputation abuse enforcement followed on 5 May 2024.

Tier 4 verifies that the planned deployment continues the prior topical context: an accountancy domain rebuilt as accountancy content respects the policy, the same name redirected to fitness violates it.

A trademark check against USPTO TESS, EUIPO TMview, and the WIPO Global Brand Database closes the audit. A name matching an active mark exposes the buyer to a UDRP filing and forfeiture, one of the Risks of buying an expired domain: 7 costly mistakes and how to avoid them.

When redeployment fit fails, the name exits the funnel regardless of metrics. That is the condition under which a strong-looking name underperforms a fresh registration, set out in When an aged domain is worse than a new one.

How the shortlist routes to a catch or auction

Tier 5 routes each qualified finalist to its acquisition channel. Three channels match the name’s lifecycle position:

  • Drop-catch attempt for a pending-delete name.
  • Auction bid for a name already on a marketplace.
  • Direct registration for a name that fell clean.

The route is decided before the window opens, with a written bid ceiling. The highest-value catches resolve in seconds.

Channel selection follows the name’s lifecycle position. A name approaching pendingDelete routes to a drop-catch service. DropCatch runs Dropped, Pre-Release, and Private Seller auctions typically in the $20 to $500-plus range.

A name already listed routes to its auction. GoDaddy Auctions lists 10,000 or more expiring names daily. It opens an expired auction on day 26 that runs 10 days, then a Final Closeout on day 37 for 5 days as a reverse auction where the price falls daily.

GoDaddy phased out new backorder purchases on 8 August 2024, directing buyers to its auctions or broker services. That shift moves more pending-delete capture onto dedicated catch infrastructure. A name that drops clean without competition registers at standard cost.

The decision log turns each run into a feedback loop.

A standard log captures seven fields per name:

  • Domain name
  • Source list
  • Audit note
  • Bid ceiling
  • Acquisition channel
  • Win or loss outcome
  • A 30, 60, and 90-day post-acquisition performance read

A weekly review reads the log against the tier-2 thresholds. It tightens the cutoffs against win rate and average acquisition value. This discipline distinguishes a professional pipeline from random catches drawn from the same daily pool.

Pipeline economics frame the stakes. Operator labour at typical rates runs against a 30 to 60-minute daily routine. Catch-service fees apply per attempt with partial success rates, and auction prices climb with metrics. All of it is measured against acquired-domain resale or deployment return.

The names worth this whole sequence are documented across niches in Aged domain case studies by niche.

5 frequently asked questions about the scanning workflow

The 5 questions operators raise repeatedly about the expired domain workflow cover scan cadence, full-run time, when automation pays off, the highest-leverage tier, and the March 2024 abuse policy. The answers reflect the SEO Domains analytical position alongside documented tool capabilities and dates.

Q1How frequently does an operator scan the drop list?

Pending-delete and dropped-domain hunters scan daily, because the highest-value catches resolve within hours of registry release and a multi-day cadence misses them.

Closeout-only buyers, who target names already in a falling-price reverse auction, run a slower cadence successfully.

The decision tracks the channel: speed-of-capture targets demand a daily run, while patient marketplace and closeout targets tolerate a longer interval.

Q2How long does a full daily scan take?

A tool-assisted tier-1 and tier-2 pass reaches a 5 to 10 name shortlist in roughly fifteen minutes when thresholds are tight.

The expensive hours land in tier 4, the manual backlink and Wayback audit, at minutes to half an hour per surviving name.

A solo operator runs the full sequence in 30 to 60 minutes; a specialist team parallelises the manual audit across reviewers to process a wider shortlist in the same window.

Q3At what volume does automation pay off?

A manual workflow scales to roughly 50 candidates a day before the per-name overhead dominates. Past 100 daily candidates, scheduled feed pulls and threshold-triggered alerts earn their setup cost.

A full programmatic pipeline, with API ingestion from sources such as WhoisFreaks and scripted tier-1 and tier-2 logic, suits 500-plus candidate operations that exceed any single reviewer’s throughput.

Q4Which tier returns the largest improvement when optimised?

Tier 3, the spam and penalty screen, returns the greatest leverage, because every false positive it lets through costs a full manual audit in tier 4.

Tightening the Trust-to-Citation floor and the anchor-text rules removes the contaminated names that consume the costliest hours. Tightening tier 2 too far starves the pipeline; loosening tier 3 floods the manual stage.

The screen is the control point.

Q5How does the March 2024 abuse policy change the workflow?

It adds a mandatory redeployment-fit checkpoint to tier 4.

Google’s expired domain abuse policy of 5 March 2024 devalues a domain repurposed primarily to manipulate ranking off a mismatched prior reputation, and site reputation abuse enforcement followed on 5 May 2024.

The audit verifies that the planned deployment continues the prior topical context before any bid, since a topical mismatch converts a strong metric profile into a liability.

How the curated catalogue runs the workflow once

The expired domain workflow rewards order: cheap-fast filters first, expensive manual audit last, run the same way every day.

Done by hand on a 130,000 to 200,000 name list, it costs hours daily and still loses catches to faster infrastructure.

SEO Domains has already run this exact workflow at scale across a 220,000+ catalogue. The team scores Domain Authority, Domain Rating, Trust Flow, and Citation Flow, and runs a 7-vector inheritance screen. A buyer reviews the already-sorted slice instead of grinding the daily list one name at a time.

Workflow tierManual daily scanCurated SEO Domains catalogue
SourcingPull and dedup 130,000+ raw names dailyPre-assembled, deduplicated, metric-scored
Quantitative filterCalibrate thresholds tool by toolDA, DR, Trust Flow, Citation Flow on the listing
Spam and penalty screenOperator cross-checks every survivor alone7-vector inheritance screen before listing
Manual auditWayback and anchor reads at minutes to 30 min eachContinuity and niche-fit screened at ingestion
Acquisition routeRace the catch, risk losing to faster infraReviewed listing, ICANN-accredited transfer
Figure 4. The manual scan and the curated catalogue apply the same five-tier discipline. The difference is who absorbs the list-grinding cost: the manual operator pays it every day, the catalogue paid it once at ingestion and lists only what cleared the screen.
The long road: manual daily scan
Pull and deduplicate 130,000 to 200,000 raw names from every source, every morning
Calibrate quantitative thresholds tool by tool, then re-tune them against win and loss data weekly
Cross-check each survivor alone across SpamZilla, Majestic, and an anchor scan
Read Wayback continuity and backlink context by hand at minutes to half an hour per name
Race the catch in seconds against services holding more registrar connections
The efficient road: curated catalogue
Pre-assembled, deduplicated, metric-scored inventory already drawn from the same daily pool
Domain Authority, Domain Rating, Trust Flow, and Citation Flow reported on every listing
A 7-vector inheritance screen applied before a name reaches the catalogue
Continuity and niche-fit screened at ingestion, so the buyer reviews a confirmed profile
A reviewed listing with ICANN-accredited transfer, no millisecond catch to win
Figure 5. The same workflow, two roads. The manual operator absorbs every tier daily and still loses catches to faster infrastructure. SEO Domains ran the workflow once at scale across a 220,000+ catalogue, so the buyer reviews the already-sorted slice instead of grinding the daily list one name at a time.

The catalogue runs the funnel once so the buyer does not repeat it daily.

A raw drop list hands a buyer the full five-tier burden every morning. The contaminated tier is engineered to defeat a one-metric glance, and the catch window is measured in seconds. The curated catalogue inverts that burden.

SEO Domains sources, deduplicates, filters, spam-screens, and manually audits at ingestion. Each listing surfaces Domain Authority, Domain Rating, Trust Flow, and Citation Flow. Only the names that clear the 7-vector inheritance screen reach the catalogue.

The buyer reviews a confirmed profile, the same convergence a disciplined daily workflow would produce, without running the workflow at all.

Damyan Zagorski, Chief Commercial Officer at SEO Domains

Damyan Zagorski

Chief Commercial Officer @ SEO Domains

Damyan leads commercial strategy at SEO Domains, drawing on experience as a CEO and marketing director. He has driven the company’s branding, client growth, and revenue, helping establish it as a leading provider of aged domains for SEO.

He leads SEO at the SEO Domains marketplace, which operates a 220,000+ curated catalogue from $100 entry-level domains through $1.5 million premium acquisitions, inheritance-screened across the catalogue, with Managed Account expert support for premium-tier clients.

· Last reviewed