What Happens in the First 48 Hours After a Domain Drops: The Freshly Dropped Domain Timeline
A freshly dropped domain is a name the registry has just deleted and released back into the pool of registrable names, after its previous owner let it run all the way through grace, redemption, and pending delete without renewing. At the moment it drops, anyone can register it again, and for a name that carries inherited authority the contest is measured in milliseconds.
The phrase “first 48 hours” hides two separate clocks, and the published guides blur them together. One clock is the drop event itself: the few hours around the daily delete window when automated systems race to grab the name. The other clock starts the instant the domain is caught: the diligence-and-setup window that decides whether the inherited name is an asset or a liability.
This guide runs both clocks, hour by hour, against the cited registry record. It explains what the registry does, who races for the name, and the diligence that separates a clean freshly dropped domain from a poisoned one. SEO Domains operates the curated marketplace where already-caught names are screened before listing, so the inheritance is read before the domain is priced instead of after the race is lost.
What a freshly dropped domain really is
A freshly dropped domain is a name that has just completed the full expiration lifecycle and been deleted by the registry, returning it to the open pool of registrable names. It is the precise moment the previous registration ends and a new registration becomes possible for any party. A freshly dropped domain still carries the backlinks, age, and history its prior owner built.
The word “dropped” marks an event, not a long status. A domain spends weeks in expired, redemption, and pending delete states before it drops. The drop is the single point at which the registry removes the old record and opens the name to fresh registration.
Freshly dropped versus expired, deleted, and pending delete
The four terms describe four points on one line, and the difference between them is who controls the name. While a domain is expired or in redemption, the prior owner retains the right to recover it. Once it is in pending delete, no party can touch it. Once it drops, it belongs to whoever registers it next.
The full disambiguation across the registry status codes lives in the pillar guide Expired vs deleted vs dropped: domain lifecycle disambiguation across 5 RFC 3915 states, which maps each state to its EPP status code.
Expired
The registration date has passed. The prior owner can still renew at the standard price during the registrar grace period, and the name has not yet left their control.
Redemption (deleted)
The registrar has deleted the name and the 30-day ICANN Redemption Grace Period has begun. The prior owner can restore it by paying a redemption fee, so control still rests with them.
Pending delete
The 5-day final hold. No party, including the prior owner, can register, renew, or restore the name. It is locked, counting down to release.
Freshly dropped
The registry has deleted the record and released the name. It is open to fresh registration by any party, and it still carries the inherited authority of its prior life.
Why a freshly dropped domain is worth racing for
The value of a freshly dropped domain is the history attached to it. When a business or a publisher let the name lapse, the backlinks it earned from news sites, directories, and partners did not vanish. They survive the lapse and pass to the next registrant.
That inherited backlink profile is the asset, and it is the reason a name with a real prior life draws automated competition the instant it drops while a brand-new string sits unwanted. The inheritance is also why diligence in the hours after a catch is the difference between a clean acquisition and a toxic one.
The lifecycle that ends in the drop: grace, redemption, pending delete
A domain reaches the drop only after running the full post-expiration lifecycle defined by ICANN: the registrar auto-renew grace period, the 30-day Redemption Grace Period, and the 5-day pending delete hold. ICANN states that a deleted name spends 30 days in redemption, then 5 days in a final hold, and is then deleted and released into the pool of available names.
The registrar grace period
The first stage after expiration sits with the registrar, not the registry. For a window that runs to roughly 10 to 45 days depending on the registrar, the prior owner can renew at the standard price as though nothing lapsed. Porkbun, as one published example, describes a renewal grace window in this range before the name is deleted to the registry.
During this stage the name is gone from active use but fully recoverable by its owner, so it is not yet available to anyone else.
The 30-day Redemption Grace Period
When the registrar deletes the name, ICANN’s Redemption Grace Period begins. ICANN defines the RGP as the 30 days immediately following deletion, during which the deleted registration can be restored at the request of the registrant by the registrar that deleted it. A restore request triggers a non-refundable charge to the registrar.
The mechanism exists for one reason ICANN states plainly: to give registrants a last chance to recover a name after an erroneous or forgotten deletion. The standards basis is RFC 3915, the registry grace-period extension that defines the redemption status.
The 5-day pending delete hold
If the 30 days pass with no restore, ICANN places the name in a redemption hold period of 5 days during which no change to the status of the domain can be made. The name is frozen. Not the prior owner, not a buyer, not a registrar can act on it. At the conclusion of the 5 days, the registry deletes the name and releases it into the pool of available names.
The end of pending delete is the drop. The day-by-day count from expiry to that release point is mapped in Domain expiration timeline: how long after expiry until a domain becomes available to register.
The registration expires. The registrar grace period begins, and the prior owner can still renew at the standard price. Source: registrar policy, Porkbun KB as one published example.
The registrar deletes the name to the registry. The 30-day ICANN Redemption Grace Period starts. The name is gone from active use but recoverable by its owner for a redemption fee.
If the name is not restored, it enters the 5-day pending delete hold. No party can act on it. Source: ICANN Redemption Grace Period policy.
At the end of pending delete, the registry deletes the record and releases the name into the available pool. The drop event is this single point. The name is now a freshly dropped domain.
The catch is decided in the first seconds. The first 48 hours after a successful registration are the diligence-and-setup clock that decides whether the inherited name is an asset.
The drop event, hour by hour: the daily window and the millisecond race
The drop is not random. Each registry deletes pending-delete names on a recurring daily schedule, and for .com and .net the Verisign batch runs inside a window reported at roughly 11:00 to 15:00 UTC. Inside that window the contest is decided in milliseconds: registries process competing registration requests in timestamp order and award the name to the earliest valid request, with processing reported in under 100 milliseconds.
The daily delete window
Verisign, the registry operator for .com and .net, processes its pending-delete batch on a daily cycle. Community trackers and the 2026 drop-catching field place the recurring window at roughly 11:00 to 15:00 UTC, with the exact moment shifting inside that band as the registry works through its load. The name does not become registrable a moment before the registry runs its batch, which is why drop-catchers cluster their activity around the known window.
The race is won in timestamp order
At the instant the registry opens a name for registration, the contest is a queue. As the registrar-side analysis at NameSilo documents, drop-catching systems maintain persistent protocol-level EPP connections to the registry, position servers near the registry data centres, and fire registration attempts measured in milliseconds. The registry runs short-lived internal queues, processes requests in timestamp order, and awards the name to the earliest valid request, with the response returned in under 100 milliseconds in the typical case. Microsecond differences decide the winner.
What the academic record says about the race
The contest is documented in the security literature, not just the trade press. The peer-reviewed study by Lauinger and colleagues, “Game of Registrars: An Empirical Analysis of Post-Expiration Domain Name Takeovers,” presented at USENIX Security 2017, analysed how registrars compete for expiring names and found that a concentrated set of drop-catch registrars dominates the capture of valuable expiring domains. The takeaway is structural: the open race is engineered, and a small number of well-connected operators win the names worth winning.
Hour by hour through the drop event
The 48 hours around the drop event break into a short, sharp sequence. The decisive action is compressed into the seconds at the window, and everything before and after is preparation and confirmation.
| Time relative to the drop | What happens | Who is acting |
|---|---|---|
| Drop minus 24h | The name is in its final pending-delete day. Backorders and catch attempts are already queued against it. | Drop-catchers and backorder services |
| Drop minus 1h | Catch systems confirm the registry window and prime persistent EPP connections near the registry. | Drop-catch infrastructure |
| The drop (inside 11:00-15:00 UTC) | The registry deletes the record and processes competing registration requests in timestamp order in under 100 ms. | The Verisign registry |
| Drop plus seconds | The earliest valid request wins. For a contested name the winner is a drop-catch registrar, not a manual buyer. | The winning registrar |
| Drop plus 1-24h | If multiple parties backordered the name, it moves into a private auction rather than resolving to one registrant. | Backorder platform and bidders |
| Drop plus 24-48h | The successful registrant gains control, configures DNS, and the diligence clock on the inherited profile begins. | The new owner |
Who races for a freshly dropped domain, and how
The parties racing for a freshly dropped domain are specialist drop-catch registrars running multiple ICANN accreditations, the backorder services that sell catch attempts to buyers, and the auctions that resolve contested names. A backorder is a reservation that buys participation in the catch, not a guarantee of success, and a contested name resolves through an auction among the parties that reserved it.
Drop-catch registrars and registrar accreditations
The structural advantage in the race is the number of connections a service can open to the registry. As the Wikipedia reference on domain drop catching notes, the services run through both ICANN-accredited and non-accredited registrars, and operators stack a large set of registrar accreditations so they can submit more simultaneous registration requests at the drop. DomCop describes its own catch network as spanning more than 1,000 registrars for exactly this reason: more accredited connections mean more attempts hit the registry queue at the open.
Backorders: reserving a catch attempt
A backorder is the buyer-facing product of the race. It is an instruction to a catch service to attempt registration the moment the name drops, placed before the drop. The fee, reported across the field at figures such as a 59 US dollar base at DropCatch or a 69 US dollar base at NameJet, buys participation in the catch, not the name. A backorder secures a seat at the contest, and nothing more.
Auctions resolve the contested names
When a single catch service wins a name that two or more of its own customers backordered, the name does not go to one of them by default. It moves into a private auction among those backorderers, with bidding that runs over a fixed period before the highest bid takes the name. The auction is how the race converts a single successful catch into a sale, and it is the reason a sought-after freshly dropped domain rarely clears at the base backorder fee.
The first 48 hours after the catch: the diligence clock
The second 48-hour clock starts the instant a freshly dropped domain is registered. It is not a race. It is a sequence of diligence and setup that confirms whether the inherited profile is clean, secures control of the name, and prepares it for use. The order matters: verify the history before building anything on the name, because a poisoned inheritance is a liability that no setup work can fix.
The competitor field documents the catch mechanics in detail and the lifecycle in detail, yet treats the hours after the catch as an afterthought. The sequence below is the part that decides whether the acquisition holds its value. Each stage pairs the action with the mistake that wastes the window.
-
Hour 0-6: confirm control and lock the name
The first action is to verify the registration resolved to the intended account, enable the registrar lock, and turn on auto-renew so the newly acquired name cannot lapse a second time. Confirming control comes before any content or DNS work, because a name that is not securely held is not yet an asset.
The mistake: celebrating the catch and leaving the name unlocked with auto-renew off. A freshly caught domain that expires again because nobody set renewal is the one fully avoidable loss in the lifecycle, and it is prevented in the first hour.
-
Hour 0-12: read the inherited backlink profile
The defining diligence step is to pull the backlink profile and judge the quality, not the count, of the links pointing in. A clean profile of editorially earned links from real sites is the asset. A profile dominated by spam, link networks, or hacked-site links is a liability the name carries from day one.
The mistake: reading a single authority number and skipping the link-by-link review. An inflated score can sit on top of a toxic profile, and the toxicity is what transfers to the new owner.
-
Hour 0-24: read the history with the Wayback Machine
The next step is to check what the name was before it dropped. The Internet Archive Wayback Machine shows the prior content, which confirms whether the name had a genuine, topically coherent history or was previously used for spam, adult content, or an unrelated abuse pattern that contradicts its apparent authority.
The mistake: assuming a strong backlink profile means a clean history. A name can carry real links from a real past and a hidden period of abuse that a history check would have surfaced in minutes.
-
Hour 12-36: check indexation, penalties, and trademark
With the profile and history read, the next checks are whether the name is indexed in search, whether it shows signs of a prior penalty, and whether the string collides with a live trademark. A name that earns no impressions despite inbound links, or that maps to an active brand, carries a risk the inherited authority cannot offset.
The mistake: registering a name whose authority came from a trademarked brand. The links transfer, and so does the legal exposure, which is covered in the legal overview within this hub.
-
Hour 24-48: configure DNS and a holding page, then plan the build
Only after the diligence clears does setup begin. Pointing DNS, raising a simple holding page so the name resolves, and verifying the name in a search console come last, because building on a name before confirming its inheritance is effort spent on a foundation that has not been checked.
The mistake: rushing a full site onto the name in the first hours, before the profile and history are confirmed. Effort invested ahead of diligence is effort at risk if the inheritance turns out to be poisoned.
Why the order is diligence first
The reason the sequence reads control, profile, history, then setup is that the inheritance is fixed at the drop. The links, the history, and any prior penalty arrive with the name, and no amount of post-catch work changes them. The diligence clock exists to discover what was inherited before time is spent building on it, and the cost of skipping it is documented in Risks of buying an expired domain: 7 costly mistakes and how to avoid them.
The freshly dropped diligence checklist and the walk-away rule
The diligence on a freshly dropped domain reduces to a short checklist with a clear walk-away threshold. Each check reads one part of the inheritance, and a fail on a hard-stop check means the name is a liability regardless of its authority score. The walk-away rule is the gate: a toxic backlink profile, an abuse history, or a live trademark collision overrides any inherited metric.
The table consolidates the checks scattered through the diligence clock into one reference. The left column is the check, the centre column is the signal that fails it, and the right column is the action. Read top to bottom, the fails describe a name to walk away from.
| Check | The failing signal (walk away) | The action |
|---|---|---|
| Backlink profile quality | Spam, link-network, or hacked-site links dominate the inbound profile | Walk away. A toxic profile is the hardest fail to reverse. |
| Wayback history | Prior adult, gambling, malware, or topically unrelated abuse use | Walk away. The authority is built on a poisoned past. |
| Trademark collision | The string maps to a live, active trademark or brand | Walk away. The legal exposure transfers with the name. |
| Prior penalty signals | No indexation and no impressions despite a real inbound profile | Investigate before building; treat as high risk. |
| Authority metrics | An inflated single score with no supporting link quality behind it | Discount the score; trust the link-by-link read. |
| Registrar lock and renewal | The name is unlocked and auto-renew is off after the catch | Lock and set renewal in the first hours, before anything else. |
| Topical continuity | The inherited links describe a topic unrelated to the planned use | Reconsider the use; mismatched authority transfers weakly. |
One principle runs down the action column. The inheritance is fixed at the drop, so the diligence either confirms a clean asset or surfaces a liability that no metric can buy back. How a search engine treats the inherited authority once the name is rebuilt is covered in How search engines treat re-registered expired domains, and that treatment is exactly why the link-quality read outranks the headline score.
Two paths to a freshly dropped domain: the race or the vetted asset
There are two ways to acquire a freshly dropped domain. One is to run the race directly: backorder across catch services, compete in the millisecond window, and win or lose the auction. The other is to source a name that has already been caught and screened, where the diligence clock has already been run before the name is listed. The asset is the same inherited authority; the difference is who absorbs the race and the diligence.
Path one: run the race
Running the race means engaging the catch infrastructure directly. It involves placing backorders on multiple services, accepting that the base fee buys only an attempt, competing against the well-connected operators the USENIX study identified as the structural winners, and bidding through any auction that follows. The path can deliver a name at the moment it drops, and it puts the full diligence clock on the buyer after the catch.
Path two: source the already-caught asset
The second path treats the freshly dropped domain as a finished product instead of a live contest. A curated marketplace catches and screens names, runs the backlink and history diligence, and lists the ones that pass with their profiles disclosed. The buyer acquires the inherited authority without operating EPP connections, without losing auctions, and without discovering a poisoned profile after the catch. The inheritance is identical; the race and the post-catch risk are absorbed before the name is offered.
The asset is the authority, not the race
The point both paths share is the one the catch-focused guides miss. The value of a freshly dropped domain was always the inherited authority, never the act of winning the millisecond contest. A name caught in the race and a name sourced from a screened catalogue carry the same backlinks and the same history. Sourcing the screened name on the SEO Domains marketplace delivers the authority with the diligence already done, which is the practical reason to treat the drop as a supply event instead of a sport.
Freshly dropped domain frequently asked questions
The five questions buyers raise when they search for what happens after a domain drops, answered against the cited registry record and the diligence-first sequence this guide sets out.
Q1How long after a domain expires does it drop?
For a typical generic top-level domain the path runs to roughly 75 days from expiry: a registrar grace window of around 10 to 45 days, then ICANN’s 30-day Redemption Grace Period, then a 5-day pending delete hold before the registry releases the name. The 30-day and 5-day figures are ICANN’s published values; the registrar grace window varies by registrar.
Q2What time of day do .com domains drop?
Verisign, the .com and .net registry operator, processes its pending-delete batch on a recurring daily schedule, reported across the 2026 drop-catching field at roughly 11:00 to 15:00 UTC. The exact moment shifts inside that window as the registry works through its daily load, which is why catch services cluster around the known band instead of a fixed minute.
Q3Can a person catch a freshly dropped domain manually?
For an uncontested, low-demand name, a manual registration in the hours after the drop can succeed. For a name with real inherited authority, the contest is decided in under 100 milliseconds in timestamp order by automated systems with persistent registry connections, so a manual attempt loses. The USENIX “Game of Registrars” study documents that a concentrated set of drop-catch registrars wins the valuable names.
Q4Does a freshly dropped domain keep its backlinks?
A freshly dropped domain carries the inbound links its prior owner earned, because those links live on the linking sites and survive the lapse. That inheritance is the asset and the reason the name is raced for. The links can also be toxic, which is why the first 48 hours after a catch are spent reading the profile link by link instead of trusting a single authority score.
Q5Is buying an already-caught freshly dropped domain different from running the race?
The inherited authority is identical. The difference is who runs the race and the diligence. Sourcing an already-caught name from a curated marketplace delivers the same backlinks and history with the screening done before listing, removing the millisecond contest, the auction risk, and the chance of discovering a poisoned profile after the catch. The drop becomes a supply event instead of a contest to win in person.
Sourcing freshly dropped authority without the race
The legitimate demand behind every search for what happens after a domain drops is access to inherited domain authority a buyer can own. That authority is the product, delivered as a screened name instead of a won race. SEO Domains operates the curated marketplace where freshly dropped and aged names are caught, read across their backlink profile and history, and listed only once the diligence clears.
Why the screened catalogue is the practical path
Everything in this guide converges on one fact: the value of a freshly dropped domain is the inheritance, and the inheritance is fixed at the drop. A buyer who wins the race still has to run the full diligence clock afterward, and a poisoned profile surfaces only after the name is already held. A screened catalogue inverts that order, running the backlink, history, and authority diligence before the name is offered, so the buyer acquires a confirmed asset instead of a gamble on an inheritance.
What screening before listing removes
Sourcing a screened freshly dropped domain removes the three costs the race imposes. It removes the millisecond contest against well-connected drop-catch registrars, the auction that lifts a contested name well past its base fee, and the post-catch risk of a toxic profile or an abuse history that diligence would have caught. The name still carries the same inherited authority; only the race and the risk are taken off the buyer.
