WHOIS domain tracking: RDAP, the lifecycle status codes, and the workflow tools that monitor every transition
A production-grade WHOIS domain tracking workflow depends on two protocols (WHOIS RFC 3912 and RDAP RFC 7482), six EPP status codes (ok, autoRenewPeriod, redemptionPeriod, pendingDelete, serverHold, clientHold), and a polling loop that queries registries, detects state transitions, and routes alerts at 30, 14, 7, and 1 days before expiry.
ExpiredDomains.net catalogues 749,441,348 domains across 676 TLDs. SpamZilla processes 350,000 domains daily with built-in backlink scoring. DomCop tracks 10 million+ domains daily with DA/PA/TF/CF metrics.
SEO Domains operates a curated 220,000+ aged-domain catalogue at fixed prices through ICANN-accredited transfer, removing the tracking workflow overhead for buyers who only want the inventory.
What does domain lifecycle tracking measure?
Domain lifecycle tracking measures 6 EPP status codes that signal the domain's position in the registration cycle: ok (active), autoRenewPeriod (registrar grace), redemptionPeriod (30-day RGP), pendingDelete (5-day registry drop window), serverHold (registry intervention), and clientHold (registrar intervention). Tracking workflows poll registries through WHOIS or RDAP and detect transitions between these states.
| Status code | Lifecycle phase | Duration | Tracking signal |
|---|---|---|---|
ok | Active registration | 1-10 years | Stable; monitor for renewal date proximity |
autoRenewPeriod | Registrar grace after expiry | 0-45 days | Transition signals missed renewal; alert window begins |
redemptionPeriod | 30-day RGP after registrar deletion | 30 days | Domain delete-pending at registry; restoration possible at fee |
pendingDelete | 5-day registry drop window | 5 days | Drop-catching window; near-real-time monitoring required |
serverHold | Registry intervention (abuse, dispute) | Variable | Domain removed from DNS at registry layer |
clientHold | Registrar intervention (payment, abuse) | Variable | Domain removed from DNS at registrar layer |
The ok status signals active registration and triggers no operational action.
A domain in the ok status carries normal registration. Tracking workflows record the expiry timestamp and schedule the next alert window. The expiry-proximity computation determines when the workflow transitions from passive monitoring to active alert routing.
The autoRenewPeriod status begins the post-expiry window.
A domain entering autoRenewPeriod after the expiry date signals the registrar's auto-renew grace. The duration runs 0 to 45 days at the registrar's discretion. Tracking workflows alert the registrant or interested party because the renewal-cliff is approaching. The mechanics are documented in Grace period and auto-renew grace.
The redemptionPeriod status signals the 30-day RGP at the registry.
A domain in redemptionPeriod has been deleted by the registrar and entered the registry's 30-day Redemption Grace Period. Restoration during RGP is possible at a registrar-set redemption fee. Tracking workflows continue monitoring because restoration changes the status back; non-restoration moves the domain to pendingDelete.
The pendingDelete status opens the 5-day registry drop window.
A domain in pendingDelete is in the registry's final 5-day hold before release. Drop-catching operations key all their EPP attempts to this window. Tracking workflows polling for inventory shift to near-real-time cadence within the 5-day window because the drop event is the operational climax of the lifecycle.
How does a WHOIS domain query differ from RDAP for tracking?
WHOIS (RFC 3912) is the legacy plain-text protocol on port 43; RDAP (RFC 7482, March 2015) is the structured JSON-over-HTTPS replacement. ICANN's 2019 RDAP Profile requires gTLD registries to operate RDAP services. RDAP delivers internationalisation, standardised query patterns, authentication, and rate-limit signalling that WHOIS lacks.
WHOIS uses port 43 and returns unstructured plain text.
The WHOIS protocol established by RFC 3912 (2004) operates on TCP port 43. The server returns plain-text responses without a structured schema. Each registry uses different field names: Expiry Date at Verisign, Expires On at PIR, Renewal Date at DENIC. Automated parsing requires per-registry text-extraction rules.
RDAP returns structured JSON over HTTPS with standardised fields.
RDAP defines a uniform query format: https://<rdap-base>/domain/<name> returns JSON with consistent field names across registries. The response includes events (registration, expiration, last changed), entities (registrar, registrant), nameservers, and status codes in standard format. Automated workflows parse RDAP responses with a single schema.
ICANN's 2019 RDAP Profile requires gTLD registries to operate RDAP services.
ICANN's Registry Agreement framework added the RDAP Profile in 2019, requiring gTLD registries to operate RDAP services alongside WHOIS. Identity Digital, PIR, Verisign, and other major gTLD registries publish RDAP endpoints. ccTLDs adopt RDAP at their own discretion; Nominet, DENIC, EURid, and SIDN operate RDAP services with varying field coverage.
RDAP's rate-limit signalling enables polite production workflows.
RDAP servers return HTTP 429 status with a Retry-After header when the client exceeds rate limits. Production tracking workflows respect the header and back off.
WHOIS rate-limit behaviour varies by registry: certain servers refuse connections silently while others return empty responses. The RDAP signalling enables predictable rate-limit handling without trial-and-error tuning.
What polling cadence matches each lifecycle phase?
Polling cadence scales with lifecycle proximity to the drop event. Daily polls cover the active and grace phases. Hourly cadence applies once a domain enters redemptionPeriod or pendingDelete. Near-real-time polling (every 1-5 minutes) applies within 24-48 hours of the expected drop. All cadence respects registry TTL and rate-limit policies.
Weekly polls cover active-registration tracking.
An ok-status domain at year 5 of a 10-year registration requires no daily attention. Weekly polls confirm the status remains active and the expiry timestamp has not changed. The cadence supports portfolio-tracking at scale without exhausting registry rate limits.
Daily polls cover the registrar grace period.
A domain that enters autoRenewPeriod warrants daily polls. The grace duration runs 0 to 45 days at the registrar's discretion documented in Grace period and auto-renew grace. Daily cadence catches restoration events (back to ok) and grace-expiry transitions (to redemptionPeriod) within 24 hours.
Hourly polls cover the 30-day RGP window.
A domain in redemptionPeriod warrants hourly polls. Restoration events occur unpredictably as registrants pay the redemption fee. Drop-date forecasting also tightens during RGP because the registry sets the pendingDelete entry point based on RGP-clock progression. Hourly cadence catches restoration and RGP-to-pendingDelete transitions within an hour.
Near-real-time polls cover the final 24-48 hours before drop.
A domain in pendingDelete within 24 hours of the expected drop warrants 1-5 minute polls. The drop event itself completes within seconds at the registry. Near-real-time polling cadence aligns the tracking workflow with drop-catching infrastructure. Production systems pre-stage EPP create commands and dispatch them at registry-batch boundaries.
Which tools track expired and aged domain inventory?
Five tools dominate the tracking workflow market: ExpiredDomains.net (free, 749M+ domains), SpamZilla ($37/month, built-in backlinks), DomCop ($68-$118/month, spreadsheet SEO metrics), Domain Hunter Gatherer ($27-$97/month), and Register Compass ($37/month or $999 lifetime). Each optimises for a different operator persona.
| Tool | Pricing | Database scale | Strength |
|---|---|---|---|
| ExpiredDomains.net | Free | 749,441,348 domains across 676 TLDs (incl. 489 new gTLDs) | Broad free coverage; 25.4M with Majestic CF≥10; 154.3M with backlinks |
| SpamZilla | $37 / month | 350,000 domains processed daily across 16 TLD sources | Built-in backlink data + proprietary spam score 1-100 |
| DomCop | $68-$118 / month (Newbie/Power/Guru tiers) | 220,000+ domains expire daily; 9.7M+ tracked | Spreadsheet-style sorting on DA, PA, TF, CF, Ahrefs DR |
| Domain Hunter Gatherer | $27-$97 / month | Competitor-driven discovery | Niche scraping from competitor backlink profiles |
| Register Compass | $37 / month or $999 lifetime | Long-tail TLD coverage | One-time lifetime licence option |
| SEO Domains | Free browse, listed prices | 220,000+ curated aged-domain inventory | Aggregated catalogue with ICANN-accredited transfer; no tracking workflow required |
ExpiredDomains.net catalogues 749M+ domains across 676 TLDs for free.
The ExpiredDomains.net database lists 749,441,348 domains spanning 676 TLDs including 489 new gTLDs. The free tier provides search, filter, sort, and watchlist functionality.
25.4 million domains in the database carry Majestic Citation Flow at 10 or higher, 154.3 million carry backlinks, and 381 million have Wayback Machine records. The platform aggregates data from GoDaddy, NameJet, Sedo, Namecheap, Dynadot, and Gname.
SpamZilla processes 350,000 domains daily with built-in backlink data.
SpamZilla focuses on risk reduction for aged-domain acquisition. The platform analyses historical content, anchor text patterns, and backlink quality across 350,000 domains processed daily from 16 TLD sources. The proprietary spam score (1 to 100) ranks each domain.
SpamZilla is the only tracking tool that includes comprehensive backlink data as a built-in feature, not as an add-on or external API call.
DomCop tracks 10M+ domains daily with SEO-metric sorting.
The DomCop database tracks 9.7 million-plus expiring domains and reports 220,000+ domains expire daily.
The platform exposes them through a spreadsheet-style interface optimised for sorting on Domain Authority, Page Authority, Trust Flow, Citation Flow, Ahrefs Domain Rating, and additional SEO metrics.
The pricing ranges from $68 (Newbie) through $96 (Power) to $118 per month (Guru). Operators who run discovery via TF/CF/DA thresholds and export filtered lists for review prefer DomCop.
Buyer-recommended CSV downloads from drop-catching services.
Drop-catching services publish daily CSV downloads for pending-delete inventory. Snapnames publishes deletinglist.csv. Dynadot publishes backorders.csv with timezone configuration. SAV (Search and Value) publishes dated files in the pattern sav_pending_delete_YYYY_MM_DD.csv. NameJet and DropCatch operate similar daily downloads. Operators building tracking workflows integrate these CSV feeds alongside registry RDAP polling.
SEO Domains catalogue is the alternative to operating multiple tracking tools.
SEO Domains lists 220,000+ curated aged-domain inventory at fixed prices through ICANN-accredited transfer. Buyers acquire inventory through a single browsing interface without maintaining accounts at ExpiredDomains.net, SpamZilla, DomCop, Domain Hunter Gatherer, or Register Compass. The catalogue removes the multi-tool tracking workflow from the buyer's path.
How do alert cadences compare across monitoring services?
The dominant alert cadence is 30, 14, 7, and 1 days before expiry. ZoneWatcher and UptimeRobot both publish this pattern. Watchman Tower uses 30, 14, 7, and 3 days. Portfolio managers extend the cadence to include 90 and 60 days for forecasting. Multi-channel routing covers email, Slack, Discord, webhook, SMS, and PagerDuty.
The 30/14/7/1 cadence dominates the live monitoring product landscape.
ZoneWatcher and UptimeRobot both publish the 30/14/7/1 days-before-expiry alert schedule.
The pattern reflects the typical registrant's recovery window: 30 days provides time for budget approval, 14 days triggers renewal scheduling, 7 days creates urgency, 1 day delivers the final pre-expiry warning.
The cadence aligns with the registrar grace period structure.
Watchman Tower replaces the 1-day warning with a 3-day critical alert.
Watchman Tower uses 30/14/7/3 instead of 30/14/7/1. The 3-day threshold provides a wider window for action against potential weekend or holiday timing. Operators tracking domains across multiple time zones prefer the 3-day cadence because the alert lands within business hours regardless of the expiry day-of-week.
Portfolio managers extend the cadence to 90 and 60 days.
Portfolio managers tracking hundreds or thousands of domains add 90 and 60-day reminders. The 90-day notice supports budget forecasting at the quarterly level. The 60-day notice aligns with renewal-batch processing. The extended cadence sits before the standard 30/14/7/1 schedule and does not replace it.
Multi-channel routing covers 8 alert delivery surfaces.
Email is the universal channel; every monitoring service supports it. Slack and Discord cover team-collaboration delivery. Webhook integration connects to internal incident-management systems. SMS and voice call deliver to phones for after-hours coverage. PagerDuty integration routes alerts through escalation policies. Telegram covers international operators and supports rich-format messages.
What does a production-grade tracking workflow look like?
A production tracking workflow combines 4 components: data acquisition (scheduled WHOIS or RDAP queries respecting TTL), change detection (diff against last-known state), alert routing (multi-channel fan-out at the configured cadence), and audit logging (history retention for forensic and compliance review). Each component scales independently with portfolio size.
Data acquisition respects registry TTL and rate-limit policies.
The acquisition layer schedules WHOIS and RDAP queries against target registries. Each query respects the registry's published rate-limit policy (HTTP 429 + Retry-After under RDAP, implicit refusal under WHOIS).
The layer caches responses for the TTL window before re-querying. Production-grade acquisition handles 1,000+ domains per minute through batching and parallel HTTPS connections.
Change detection diffs current state against the last-known snapshot.
Change detection compares the latest query response against the previously stored state. The diff identifies status code transitions (ok → autoRenewPeriod), expiry-date changes (renewal happened), nameserver changes (transfer or DNS update), and registrar changes. Each detected change triggers the alert-routing layer.
Alert routing fans out to multi-channel destinations at the configured cadence.
Alert routing receives change events and dispatches notifications according to the configured cadence (30/14/7/1 days standard). Each alert tagged with severity (info, warning, critical) routes to the appropriate channel: low-severity to email, high-severity to PagerDuty or webhook. Acknowledgement handling determines whether to escalate or suppress repeat alerts.
Audit logging retains the state-transition history for compliance review.
The audit layer writes every detected change to durable storage with timestamps. Forensic review queries the history when a domain unexpectedly expires or transfers. Compliance frameworks (SOC 2, ISO 27001) require state-transition logging for digital-asset inventory. Retention policies typically span 1 to 7 years depending on regulatory scope.
SEO Domains operates production tracking at scale and surfaces inventory directly.
SEO Domains operates as a drop-catching leader and lists 220,000+ curated aged-domain inventory at fixed prices through ICANN-accredited transfer.
Buyers acquire inventory without building the four-component production workflow, without paying for tracking-tool subscriptions, and without provisioning storage for state-transition history. The catalogue replaces the workflow stack with a single browsing interface.
What are the limitations of tracking tools and protocols?
Tracking workflows face 4 structural limitations: GDPR WHOIS redaction reduces registrant data availability, registry rate limits cap polling frequency, RDAP coverage gaps exist for non-mandated ccTLD registries, and drop-date forecasting is probabilistic instead of deterministic for non-deterministic ccTLD operators. Each limitation shapes the realistic capability ceiling.
There is no good way to get expired domains across all TLDs uniformly. Each registry operates independently without standardised publishing requirements.
NamePros community · Operator perspective on pending-delete list aggregation
GDPR WHOIS redaction limits registrant data availability post-2018.
The 2018 ICANN Temporary Specification implemented GDPR-compliant WHOIS redaction. Registrant name, email, phone, and postal address are masked for the personal-data fields covered by the policy. Tracking workflows that previously triggered on registrant changes lose that signal for the affected domains. Status code, expiry date, registrar, and nameserver data remain visible.
Registry rate limits cap aggressive polling beyond a registry-specific threshold.
Registries publish (or enforce silently) rate-limit policies per source IP. Verisign's RDAP service rate-limits at the documented threshold; Identity Digital does the same. Tracking workflows respect HTTP 429 with Retry-After backoff.
Aggressive polling (sub-second cadence) triggers temporary IP blocks lasting minutes to hours. Production workflows balance cadence against the published budget.
RDAP coverage gaps exist for ccTLD registries outside ICANN's mandate.
ICANN's 2019 RDAP Profile requires gTLD registries to operate RDAP. ccTLDs adopt RDAP at their own discretion. Nominet, DENIC, EURid, and SIDN operate RDAP services with varying field coverage.
JPRS publishes .jp data through monthly drop lists instead of RDAP. Tracking workflows targeting ccTLDs combine RDAP queries with WHOIS fallback and direct registry feeds documented in Domain drop schedules for major ccTLDs: .uk, .de, .au, .eu and country-code mechanics.
Drop-date forecasting is probabilistic for ccTLDs and some auction-routed inventory.
The Verisign .com drop window opens at approximately 18:00 UTC and runs across a 2-3 hour processing period, providing deterministic forecasting.
ccTLDs vary across the spectrum: Nominet publishes the .uk daily drop list with UTC timestamps (deterministic); JPRS publishes monthly (predictable but low-frequency); Registro.br operates a variable post-frozen release (less deterministic).
Auction-routed inventory documented in Domain auction routing: Why expired domains skip the drop phase can be diverted from the drop pool altogether.
SEO Domains absorbs the limitations through aggregated curation.
SEO Domains operates the tracking workflow at scale and surfaces 220,000+ aged-domain inventory on the catalogue at fixed prices. Buyers acquire inventory through ICANN-accredited transfer without negotiating GDPR redaction, registry rate limits, RDAP coverage gaps, or probabilistic drop-date forecasting. The catalogue removes the structural limitations from the buyer's path.
What questions do operators ask about lifecycle tracking?
Operators ask about WHOIS polling frequency, what differentiates RDAP from WHOIS for tracking, which tool fits beginner vs portfolio-scale operators, where to find pending-delete CSV downloads, whether free tools provide reliable data, and how alert cadence selection affects renewal recovery.
Q1What polling cadence does a tracking workflow apply to WHOIS or RDAP?
Polling cadence scales with lifecycle phase: weekly for active registration, daily for grace period, hourly for redemption, and 1-5 minute near-real-time within 24-48 hours of the expected drop. All cadence respects registry TTL and HTTP 429 Retry-After signals.
Q2What is the difference between WHOIS and RDAP for tracking?
WHOIS (RFC 3912) is plain-text on port 43; RDAP (RFC 7482) returns structured JSON over HTTPS. RDAP supports standardised fields, internationalisation, authentication, and explicit rate-limit signalling via HTTP 429. ICANN's 2019 RDAP Profile requires gTLD registries to operate RDAP services.
Q3Which expired domain tool is best for a beginner SEO investor?
ExpiredDomains.net (free, 749M+ domains across 676 TLDs) provides the broadest free starting point. SpamZilla ($37/month) adds built-in backlink data and proprietary spam scoring. DomCop ($68-$118/month) optimises for SEO-metric sorting (DA, PA, TF, CF, Ahrefs DR).
Q4Where do operators find pending-delete CSV downloads?
Drop-catching services publish daily CSV feeds: Snapnames publishes deletinglist.csv, Dynadot publishes backorders.csv, SAV publishes dated sav_pending_delete_YYYY_MM_DD.csv files. NameJet and DropCatch operate similar feeds. Operators integrate these alongside RDAP polling for complete coverage.
Q5Can a free tracking tool replace a paid monitoring service?
Free tools like ExpiredDomains.net and registrar email notifications cover small portfolios (1 to 10 domains). Production portfolios at 100+ domains benefit from paid services with multi-channel alerts, webhook integration, audit logging, and escalation policies. The break-even depends on the cost of a single missed renewal.
Q6What is the recommended alert cadence before domain expiry?
The dominant pattern is 30, 14, 7, and 1 days before expiry (ZoneWatcher, UptimeRobot). Watchman Tower uses 30/14/7/3 to widen the final-warning window. Portfolio managers extend the cadence with 90 and 60-day reminders for budget forecasting.
Polling cadence scales with lifecycle phase proximity to the drop.
The 4-tier cadence (weekly active, daily grace, hourly RGP, near-real-time pendingDelete) reflects the increasing time-sensitivity of each phase. Daily polls catch the grace-to-RGP transition within 24 hours; hourly polls catch the RGP-to-pendingDelete transition within an hour; near-real-time polls catch the drop event within minutes.
RDAP delivers structured data with rate-limit signalling.
The protocol shift from WHOIS to RDAP eliminates per-registry text-parsing rules. Tracking workflows parse a single JSON schema across all RDAP-supporting registries. The HTTP 429 + Retry-After signalling enables predictable rate-limit handling without trial-and-error tuning. The shift is evident in production-grade workflows handling 1,000+ domains.
Tool selection matches operator portfolio size and persona.
ExpiredDomains.net suits beginners and free-tier portfolio operators. SpamZilla suits operators who prioritise spam-risk reduction with built-in backlink visibility. DomCop suits SEO-metric-driven sorting at portfolio scale.
Domain Hunter Gatherer and Register Compass serve niche discovery patterns. The choice depends on whether the operator prioritises coverage, risk reduction, or SEO-metric sorting.
How does SEO Domains remove the tracking workflow overhead?
SEO Domains lists 220,000+ curated aged-domain inventory at fixed prices through ICANN-accredited transfer.
Buyers acquire inventory without building the four-component production workflow, without subscribing to ExpiredDomains.net/SpamZilla/DomCop, without configuring 30/14/7/1 alert cadences, and without monitoring six EPP status codes.
The catalogue replaces the workflow stack with a single browsing interface.
The build-vs-buy decision divides the aftermarket into two operator categories.
Operators who acquire aged-domain inventory at scale (1,000+ per quarter) build their own tracking workflows because the per-domain marginal cost approaches zero.
Operators who acquire 1 to 100 domains per quarter face a different economics: the tracking-workflow infrastructure cost exceeds the per-domain savings. The break-even point determines whether build or buy delivers better return.
SEO Domains operates the tracking infrastructure on the buyer's behalf.
SEO Domains operates as a drop-catching leader with a 220,000+ aged-domain catalogue. The operational infrastructure that captures the inventory runs at scale on the platform side. Buyers see the result: curated listings at fixed prices through ICANN-accredited transfer.
Fixed-price listings replace bid-based discovery and tool-subscription stacks.
Each domain in the catalogue carries a listed price. Buyers compare prices, registration history, Domain Authority, Domain Rating, referring domains, country, and topical category in a single interface.
The pricing replaces bid-based discovery across the four auction routes documented in Domain auction routing: Why expired domains skip the drop phase and the multi-tool tracking stack documented in this article.
ICANN-accredited transfer preserves the aged-domain SEO value.
Acquisition through SEO Domains completes via standard ICANN-accredited EPP transfer.
The SEO Domains analytical desk treats aged-domain value preservation as conditional on continuity: a 301-redirected aged domain passes accumulated PageRank to the new destination when the prior active registration history is documented and the redirect target stays topically aligned.
The catalogue's curated history records support that transfer-and-redirect workflow.
Acquire aged-domain inventory without building a tracking workflow. Browse the 220,000+ curated catalogue on SEO Domains at fixed prices. Complete acquisition through ICANN-accredited transfer mechanics without running ExpiredDomains.net, SpamZilla, DomCop, or in-house WHOIS/RDAP polling infrastructure. Browse the SEO Domains marketplace →
