You do not own your domain name, and the body that governs the system says so in those exact words. ICANN’s own FAQ: “paying to register a domain name is not the same as ‘buying’ it outright or permanently. You do not ‘own’ a domain name. What you are doing is more like leasing the domain name from the registry operator.”

That is not a technicality. Everything that surprises companies about domains follows from it: why a transfer can be refused for two months, why an expired name disappears on a schedule you did not set, why the person listed as registrant matters more than the person who paid, and why recovering a lapsed domain is priced by whoever happens to hold it.

For scale, this is a market of 401.6 million registrations across all top-level domains at the end of Q2 2026, of which 166.6 million are .com, or roughly 41 percent of everything.

The registrant of record is the only name that counts

The most expensive domain problem is not losing one. It is discovering that it was never in your name.

ICANN’s definition is thin on purpose. The registrant, “also known as the ‘Registered Name Holder’ is the person or entity that holds the rights to a domain name.” The rights follow that record, not the invoice.

And the accreditation agreement anticipates exactly the situation you are in. “Any Registered Name Holder that intends to license use of a domain name to a third party is nonetheless the Registered Name Holder of record and is responsible for providing its own full contact information.” If your developer registered it, your developer holds it.

ICANN describes the recovery, and it is not automatic. If a third party “registered the domain name using their own contact details (even if you have paid them to register and manage the domain name) … they may be listed as the official Registrant of record. You may need to provide proof of your payment to the third-party/developer to prove to your registrar that you are the rightful holder.”

Verifying this got harder in 2025. Since 28 January 2025, RDAP replaced WHOIS as “the definitive source for delivering generic top-level domain name (gTLD) registration information”. Under the Registration Data Policy effective 21 August 2025, registrant name, street, postal code and phone are redacted, and the email is replaced by “an email address or a link to a web form … which MUST NOT identify the contact email address or the contact itself.”

And redaction is broader than the law requires. Registrars must redact where applicable law requires it, but may also do so where they have “a commercially reasonable purpose” or where “it is not technically feasible to limit application” of redaction. In practice many redact everyone.

So the check is no longer a lookup. Log into the registrar account yourself and read the registrant field. If you cannot log in, you have your answer.

What public domain registration data shows and hides following the 2025 policy changesWhat a public domain registration lookup reveals and conceals following two changes that took effect in 2025, and the consequence for verifying who holds a company’s domain name. From the twenty eighth of January 2025 the registration data access protocol replaced the older lookup service as the definitive source for delivering generic top level domain registration information, offering support for internationalization, secure access to data, authoritative service discovery and differentiated access. From the twenty first of August 2025 the registration data policy requires redaction of a defined list of fields, comprising the registry domain identifier, the registry registrant identifier, the registrant name, street, postal code, phone, phone extension, fax and fax extension, along with the registry technical identifier, technical contact name and technical phone, while at registry level the registrant email and technical email must also be redacted. Redaction is defined as not including the value in the output and indicating that the value is redacted. Where redaction applies, the registrar must instead publish an email address or a link to a web form facilitating communication with the relevant contact, which must not identify the contact email address or the contact itself. What remains publicly visible is the registrar of record, the creation, update and expiry dates, the domain status codes and the nameservers. Redaction is not universally compelled by law, since a registrar must apply it where necessary to comply with applicable law but may also apply it where it has a commercially reasonable purpose or where it is not technically feasible to limit its application, meaning many registrars redact all registrants regardless of jurisdiction. A registrant may consent to publication of specific fields, and the registrar must then publish the values consented to. The practical consequence is that confirming whether a company rather than its web developer or agency is the registrant of record is no longer answerable by a public lookup and must instead be verified by logging into the registrar account directly.Since August 2025, the lookup stopped answering the questionStill visibleRegistrar of recordCreation, update and expiry datesDomain status codesNameserversEnough to see where it lives. Not who holds it.RedactedRegistrant nameStreet and postal codePhone and faxEmail, replaced by a relay formThe relay “MUST NOT identify … the contact itself”.And it is not only a legal requirementRegistrars may also redact where they have “a commercially reasonable purpose” or where limiting it is not technically feasible.So the verification changedLog into the registrar account and read the registrant field yourself. If you cannot log in, that is your answer.
The registrant fields are redacted by default, so verifying who holds a domain is now a registrar account question. Source : ICANN Registration Data Policy, effective 21 August 2025, and the RDAP transition announcement (2025)

Three separate sixty-day locks, and one of them is mandatory

Transfers get refused for reasons that look arbitrary and are written down. There are three restrictions, and they behave differently.

Within sixty days of registration. A registrar may deny a transfer requested “within 60 days of the creation date as shown in the registry RDDS record for the domain name.”

Within sixty days of a previous transfer. A registrar may deny where the domain “is within 60 days … after being transferred”, excluding transfers back to the original registrar by agreement or by dispute decision.

After a change of registrant, and this one is not optional. “The Registrar must impose a 60-day inter-registrar transfer lock following a Change of Registrant, provided, however, that the Registrar may allow the Registered Name Holder to opt out … prior to any Change of Registrant request.”

And a change of registrant is easier to trigger than it sounds. It means “a Material Change” to the registrant name, organization, or email address, where a material change is defined simply as “a change which is not a typographical correction”. Updating the contact email after somebody leaves the company can lock the domain for two months.

The policy tells registrars to warn you about the order of operations. They must inform the holder that “if its final goal is to transfer the domain name to a different registrar, the Prior Registrant is advised to request the inter-registrar transfer before the Change of Registrant to avoid triggering the 60-day lock.”

One thing worth knowing about the future. A policy review group recommended in February 2025 replacing these with 720-hour restrictions and eliminating the change-of-registrant lock entirely. As of writing, no adopting board resolution was found. Treat the sixty-day locks as the operative rule and re-check before relying on the change.

The three sixty day domain transfer restrictions and their differing forceThe three separate sixty day restrictions that can prevent a domain name being transferred between registrars, and the difference in force between them. The first arises within sixty days of initial registration, where the transfer policy lists among the specific instances in which the registrar of record may deny a transfer request the case where the transfer was requested within sixty days of the creation date shown in the registry record. This restriction is permissive, meaning the registrar may deny but is not required to. The second arises within sixty days of a previous inter registrar transfer, where the registrar may again deny, with an exception for transfers back to the original registrar where both registrars agree or where a dispute resolution decision so directs. This restriction is likewise permissive. The third arises following a change of registrant and is mandatory rather than permissive, since the policy states that the registrar must impose a sixty day inter registrar transfer lock following a change of registrant, subject only to the registrar being permitted to allow the holder to opt out of that lock before making the change of registrant request. A change of registrant is defined as a material change to the registrant name, the registrant organization or the registrant email address, and a material change is defined as any change which is not a typographical correction, which means that updating a contact email address after a staff departure can lock the domain against transfer for two months. The policy requires registrars to inform the prior registrant that if the final goal is to move the domain to a different registrar, the transfer should be requested before the change of registrant in order to avoid triggering the lock. A policy review group recommended in February 2025 replacing these periods with seven hundred and twenty hour restrictions and eliminating the change of registrant lock entirely, but no adopting board resolution was located, so the sixty day rules remain operative.Why your transfer was refusedAfter registrationRequested within 60 days ofthe creation date.Registrar MAY denyAfter a transferWithin 60 days of a previousinter-registrar transfer.Registrar MAY denyAfter a contact changeFollowing a Change ofRegistrant.Registrar MUST imposeWhat counts as a Change of RegistrantA material change to the registrant name, organization or email address. Material means “a change which is not atypographical correction”. Updating the contact email after somebody leaves qualifies.The order that avoids all of thisTransfer first, then change the registrant details. The policy requires registrars to tell you this. Few do it loudly.
Two of the three are permissive. The one that follows a contact change is compulsory unless you opt out first. Source : ICANN Transfer Policy, updated 21 February 2024 (2024)

What actually happens when a domain expires

The clock is documented, most of it is not ICANN policy, and the price at the end of it is set by whoever holds your name.

Three notices are mandatory. Two before expiry, one “approximately one month prior to expiration and one … approximately one week prior”. Then at least one more “within five days after the expiration”. They must arrive in a way “that does not require affirmative action to receive the notification.”

Your site goes dark before your name is gone. For registrations deleted eight or more days after expiry, “the existing DNS resolution path specified by the RAE must be interrupted by the registrar” for at least the last eight renewable days, and any parked page “must conspicuously indicate that the domain name registration is expired and provide renewal instructions.”

Then the lifecycle, using .com as the example. A 45-day auto-renew grace period, then a 30-day redemption grace period during which “the registry must disable DNS resolution and prohibit attempted transfers”, then a pending delete period of “five calendar days”, after which the name is purged.

One distinction that matters if you hold other extensions. Only the 30-day redemption period is ICANN consensus policy across non-sponsored registries. The 45 days and the 5 days are values from the .com registry agreement. Other registries can differ.

And the price of recovery is not regulated at all. ICANN requires only that registrars make “redemption/restore fees reasonably available” and display them, adding plainly that “it is up to your registrar to set their own prices, terms and conditions.” For reference, the .com registry’s own published fee schedule charges the registrar $40 per restore command. What you are charged on top of that is a commercial decision.

Which gives one operational instruction. Put the expiry date in a shared calendar owned by the company, not in one person’s inbox, and keep auto-renew on with a payment method that outlives the employee who set it up.

The expiration lifecycle of a dot com domain name and the source of each periodThe lifecycle of an expiring generic top level domain registration, using the largest generic domain as the worked example, together with the source of authority for each stage. Before expiry, the registrar must notify the registered name holder at least twice, once approximately one month before expiration and once approximately one week before, in a manner that does not require affirmative action to receive, such as email. Within five days after expiration the registrar must transmit at least one further notice including renewal instructions. For registrations deleted eight or more days after expiry, the registrar must interrupt the existing domain name system resolution path for at least the final eight consecutive renewable days, and any web page the registrar directs traffic to during that window must conspicuously indicate that the registration has expired and provide renewal instructions, which is why an expired site shows a parking page rather than simply failing. The registration then enters an auto renew grace period whose current value in the largest generic domain is forty five calendar days, during which the registration has been automatically renewed by the system and may still be recovered at the ordinary renewal price. If deleted, the domain immediately enters a redemption grace period of thirty days, during which the registry must disable domain name system resolution and prohibit attempted transfers, and during which the only action available to a registrar is to request restoration. If not restored, the domain enters a pending delete period of five calendar days during which all registrar requests to modify or update it are rejected, after which it is purged from the registry database and becomes available for registration by anyone. Of these three periods only the thirty day redemption grace period is mandated by consensus policy across non sponsored registries, while the forty five day and five day values are set in the registry agreement for that particular domain and may differ elsewhere. No policy sets the price of restoration, which registrars need only disclose, while the registry’s own published fee schedule charges the registrar forty dollars per restore command.From expiry to goneAuto-renew grace, 45 daysRedemption grace, 30 daysPending delete, 5PurgedExpiryDeleted by registrarNot restoredAnyone can register itICANN policy, everywhereThe 30-day redemption grace period, acrossall non-sponsored registries. Plus the threemandatory expiry notices.Registry agreement, not policyThe 45-day auto-renew grace and the 5-daypending delete are .com values. Otherextensions can differ.Recovery price: no policy sets it. Registrars must only disclose it. “It is up to your registrar to set their own prices,terms and conditions.” The registry charges the registrar $40 per .com restore command.Put the expiry in a company calendar, not an inbox. Use a payment method that outlives whoever set it up.
Only the 30-day redemption period is ICANN policy. The surrounding periods come from the registry agreement. Source : ICANN Expired Registration Recovery Policy and the .com Registry Agreement, Appendix 7 (2024)

Losing a name to someone else, and the odds

Two failure modes involve a third party: the name lapses and is taken, or your name is registered by somebody else in the first place.

The dispute policy requires three things at once. A complainant must show the domain “is identical or confusingly similar to a trademark or service mark in which the complainant has rights”, that the holder has “no rights or legitimate interests in respect of the domain name”, and that it “has been registered and is being used in bad faith”. The policy closes with the operative sentence: “the complainant must prove that each of these three elements are present.”

Which means a mark comes first. Without trademark rights there is no complaint to bring, whatever the moral case.

The odds, for cases that reach a decision. Across all years, WIPO records 61,705 transfers, 5,567 complaints denied and 1,031 cancellations, out of 68,303 decided cases. That is 90.35 percent transferred and 8.15 percent denied.

And the caveat that keeps the figure honest. Those are decided cases. Roughly 14 percent of cases settle before a decision, and they are not in the table. “Over 90 percent of decided cases result in transfer” is accurate. “Over 90 percent of disputes go the complainant’s way” is not.

Volume is rising. WIPO recorded 6,282 cases in 2025, its highest on record, against 4,204 in 2020, with more than 84,700 cases handled since 1999.

And a lapsed domain is not a lost cause. In a 2023 case concerning a foundation domain that “mistakenly lapsed in 2022”, the panel found “that by snapping up the domain name after DiCaprio mistakenly allowed it to lapse, the registrant was guilty of opportunistic bad faith”. Recovery is possible. It is slower and more expensive than a renewal.

Outcomes of decided domain name dispute cases and the three elements a complainant must proveOutcomes of domain name dispute cases decided under the uniform dispute resolution policy, together with the three elements a complainant is required to establish and the caveat that keeps the outcome figures honest. Consolidated across all years, the arbitration centre records sixty one thousand seven hundred and five cases resulting in transfer of the domain name to the complainant, representing ninety point three five percent of decided cases, five thousand five hundred and sixty seven complaints denied, representing eight point one five percent, and one thousand and thirty one cases resulting in cancellation of the registration, representing one point five one percent, from a total of sixty eight thousand three hundred and three decided cases. Combining transfer and cancellation, the complainant prevails in ninety one point eight six percent of decided cases. The essential caveat is that this table covers only cases reaching a decision, whereas roughly fourteen percent of cases settle or are otherwise terminated before decision and are absent from it, so the accurate statement is that over ninety percent of decided cases result in transfer rather than that over ninety percent of disputes go the complainant’s way. Case volume is rising, with six thousand two hundred and eighty two cases filed in 2025, the highest annual caseload on record, compared with four thousand two hundred and four in 2020, and more than eighty four thousand seven hundred cases handled since 1999. The policy requires the complainant to prove three elements simultaneously, namely that the domain name is identical or confusingly similar to a trademark or service mark in which the complainant has rights, that the holder has no rights or legitimate interests in respect of the domain name, and that the domain name has been registered and is being used in bad faith, with the policy stating that the complainant must prove that each of these three elements are present. The practical implication is that trademark rights are a precondition for bringing any complaint at all.What happens when a dispute is decidedTransfer to complainant90.35%Complaint denied8.15%Cancellation1.51%68,303 decided cases, all years. 6,282 filed in 2025, the highest on record.The caveat that keeps the number honestAround 14 percent of cases settle before decision and are absent from this table. “Over 90 percent of decided cases” is right.And all three have to be proven, together1. Identical or confusingly similar to a mark the complainant has rights in2. No rights or legitimate interests | 3. Registered and used in bad faithElement one is a trademark. Without a mark there is no complaint to bring, whatever the moral case.
Over 90 percent of decided cases end in transfer. Around 14 percent of cases settle first and never appear here. Source : WIPO Arbitration and Mediation Center, consolidated case outcome statistics (2026)

Changing domain without losing what the old one earned

If the name has to change, the search guidance is specific, recently updated and mostly about patience.

Keep the redirects far longer than you think. “Keep the redirects for as long as possible, generally at least 1 year. This timeframe allows Google to transfer all signals to the new URLs, including recrawling and reassigning links on other sites that point to your old URLs.” And from the user’s side, “consider keeping redirects indefinitely.”

Use permanent redirects. “We recommend that you use HTTP permanent redirects if possible, such as 301 and 308.”

The reassurance, stated directly. “Don’t worry about link credit. 301 and other permanent redirects don’t cause a loss in PageRank.”

Two things that do cause damage. Chains, where the advice is to redirect “to the final destination directly” and otherwise keep chains to “no more than 3 and fewer than 5”. And blanket redirects: “Don’t redirect many old URLs to one irrelevant single URL destination, such as the home page of the new site.”

Expect a visible dip and a slow tail. “For medium-sized websites, it can take a few weeks or more for Google to gradually start showing the new URLs”, and “you may experience ranking fluctuations while Google recrawls and reindexes your site.”

And change one variable at a time. The guidance is explicit: if you want to move domain, change your CMS and redesign, “do them one at a time: move to a new domain, then change your site’s layout.” Most migrations that are blamed on the domain move were three changes shipped together. That is also the order to hold to when a rename and a site rebuilt for conversion fall in the same year: the move ships alone, the redesign follows once the rankings have settled.

Search engine guidance for moving a website to a new domain namePublished search engine guidance for moving a website to a new domain name, separating the recommended practices from the practices that cause avoidable damage. On duration, the guidance is to keep the redirects for as long as possible, generally at least one year, since that timeframe allows all signals to be transferred to the new addresses including recrawling and the reassignment of links on other sites pointing to the old addresses, while adding that from the users’ perspective indefinite retention should be considered, though because redirects are slow for users the site’s own links and any high volume inbound links should be updated to point directly at the new addresses. On method, server side permanent redirects should be used where technically possible, specifically the hypertext transfer protocol permanent redirect status codes three hundred and one or three hundred and eight. On ranking signals, the guidance states directly that link credit need not be a concern because permanent redirects do not cause a loss of ranking signal. Three practices cause damage. Chaining redirects is discouraged since although the crawler can follow up to ten hops, redirection should go directly to the final destination, and where that is impossible the chain should ideally be no more than three and fewer than five. Irrelevant redirects are discouraged, meaning many old addresses should not be redirected to a single unrelated destination such as the new site’s home page. Combining changes is discouraged, with the guidance stating that a domain move, a content management system change and a layout change should be done one at a time. On expectations, for medium sized websites it can take a few weeks or more before the new addresses are shown instead of the old ones, longer for larger sites, and temporary ranking fluctuation should be expected while the site is recrawled and reindexed.Moving domain, per the published guidanceDoKeep redirects “at least 1 year”, andconsider keeping them indefinitelyUse permanent redirects: 301 or 308Map old to new one for oneUpdate your own links, and high-volumeDo notChain redirects. Go direct; keep anychain under 3 to 5 hopsRedirect many old URLs to the home pageMove domain, change CMS and redesignin the same releaseThe reassurance, verbatim”301 and other permanent redirects don’t cause a loss in PageRank.”And the expectation to set”A few weeks or more” for medium sites, with fluctuation.One variable at a time”Move to a new domain, then change your site’s layout.” Most migrations blamed on the move shipped three changes at once.
Permanent redirects do not cost ranking signals. Chains, blanket redirects and shipping three changes at once do. Source : Google Search Central, Site move with URL changes, updated 20 August 2026 (2026)

What to do with this

Open your registrar account today and read the registrant field. If it names an agency, a developer or a former employee, fix that before anything else, and remember to request the transfer before changing the details rather than after.

Put the expiry date in a company calendar with two owners, and confirm the payment method on file is not a card that expires with somebody’s employment.

If you are choosing a name, the useful constraint is not the extension. It is whether you hold the trademark rights that would let you defend it, because the dispute policy starts with a mark and the domain follows.

And if the name is changing, plan the migration alone: redirects first, kept for at least a year, one to one, and nothing else changing in the same release. The related decisions are covered in naming a B2B brand and clearing it and renaming a company without losing what you built.