8 ms·
I recall a time when a company I had association with lost their main domains due to a failed renewal. In this case it was a long-term employee who left the com
by davidgh 8y ago
I recall a time when a company I had association with lost their main domains due to a failed renewal. In this case it was a long-term employee who left the company that had loads of company bills going to his card. He cancelled the card sometime after he left and the domains were not renewed. I’m not sure where the renewal failure emails were going but probably some unmonitored admin email box.
These were very important domains. Without them, this $1 billion+ company immediately lost all of its ability to generate revenue. It was quite shocking.
The problem was discovered when users started getting the registrar’s landing pages rather than the company website pages. It was fixed relatively quickly once identified but do to DNS propagation took about 48 hours for complete resolution. During the window unrecoverable revenue well into the hundreds of thousands was lost.
It seems to me that a domain renewal is always a risk, even with a highly reliable registrar. A good defense is to limit the renewals for important domains by registering them for as long as possible (10 years). Even then you have a weak spot because your credit card will be expired by then so you should back that up with a calendar reminder a few months prior to renewal to make sure everything is set.
- crooked-v 8y agoPersonally, I'd rather have a corporate domain be renewed once per year and have a defined process for it (e.g. literally have a binder somewhere listing all the details, and put reviewing it on a checklist of other yearly legal and financial tasks) than have it be forgotten about for 10 years at a time.
- jethro_tell 8y agoI've set it up before to have 10y which is the max, and renew for 1 year every year. So the domain always has a lead time of 9-10 years but it is still renewed once a year for practice. for most domains thats like 100 bucks to lock it down for 10 years. You can also monitor the domain expiry in your monitoring system i.e. nagios or whatever you are using.
- imhoguy 8y agoGreat idea!
- jethro_tell 8y agoThanks, I learned the hard way. =)
- scrollaway 8y agoHow does one set that up? Im using gandi and didn't know this was possible.
- davewasthere 8y agoBuy 10 years of registration initially, then each year set yourself a reminder to extend this by one year. It's not automagical. That said, with Gandi, you can just set it to auto-renew, which works pretty well.
- kijin 8y agoThe problem with relying on auto-renew is that, sooner or later, your credit card will expire (or the employee who was in charge of the domain will be gone) and the renewal will fail. The account needs maintenance one way or another.
- kuschku 8y agoIf you’re in SEPA, use SEPA direct debit instead. As long as the bank account exists it’ll run on forever.
- jethro_tell 8y agoNo, the problem isn't auto renew, the problem is using unmonitored automation.
- galaxyLogic 8y agoMakes sense it is a bit like having a fire-drill
- cialowicz 8y ago> A good defense is to limit the renewals for important domains by registering them for as long as possible (10 years) This is an interesting take. I prefer the opposite approach: choose the shortest possible registration window (1 year), and have a very clearly defined, properly-documented renewal process that multiple people at the company understand. It's unlikely that all of those people leave the company in a 1-year window, so the knowledge gets passed on reliably. If a renewal happens only once every 10 years, then it seems very likely that the person responsible for it has moved on, knowledge around the process is lost, and at best the documentation is very out-of-date (but more likely it's missing). My process is to have a shared calendar for these high-risk renewals. Top company officers should be on this calendar (CEO, CTO, and some engineering VPs). The calendar contains recurring events for domain and SSL cert renewals. These calendar events are set up for about 1-month before the actual renewal, and fire reminder emails at several intervals beforehand (in case people are away or on PTO).
- hinkley 8y agoWe had this same argument about certificate expiration on a code signing project I worked on. I maintained that having to remember to renew a cert every September was more likely to stick with someone than 18 months or two years. It also keeps your blacklist smaller because dead ones age off faster. I don’t recall how it ended up but we added automated reminders every 30 days starting three months before expiry.
- deleted 8y ago[deleted]
- abraham 8y agoYou could do both. Register it out ten years and each your register an additional one.
- kijin 8y ago10 years sounds a bit inflexible for me. Things can get a little weird if you switch registrars but you have more than 9 years left on your domain so you can't get a full additional year. I do try to maintain a margin of at least 3 years on important personal and business domains, though. Less than 37 months left = immediate attention required.
- matte_black 8y agoThey got lucky, because if it were me and I left on mild terms I would be invoicing them $50k a year to renew their domain.
- jacquesm 8y agoYou are lucky, because if I ran that company I'd haul your ass in court so quick you wouldn't know what hit you. The fact that you can doesn't give you a right to do so and in this case it is pretty clear that you would be acting maliciously. I've seen such 'tricks' up close a couple of times and judges tend to take a very dim view of this kind of behavior.
- matte_black 8y agoGood luck proving I have any connection to the company in the foreign country sending you the invoice. Also, if payment isn’t received within 30 days you can expect to see the domain forwarded to a “for sale” page. And given how fast the legal system moves especially across international borders, you will lose hundreds of millions in revenue before getting any kind of verdict, possibly even go bankrupt.
- scrollaway 8y agoCould you do an AMA once you get out of jail? I'd love to see how this all turns out for you. You seem to be the kind of person who just makes fantastic life decisions.
- yrro 8y agoWow, breach of contract, theft and extortion all in one convenient package!
- cuckcuckspruce 8y agoWho says technology doesn't have a sociopath problem
- 8y ago
- flurdy 8y agoJohn Lewis (the big retailer, not the politician, and not http://twitter.com/johnlewis http://twitter.com/johnlewis) forgot to renew the domain of one of their services just this week: http://www.bbc.co.uk/news/technology-44108830 http://www.bbc.co.uk/news/technology-44108830
- bhartzer 8y ago>> registering them for as long as possible To clarify, you can register them for 100 years, not 10 years. Network Solutions offers the 100 year renewal. While 100 years or even 10 isn't for everyone, I do still agree: register them for as long as feasible.
- paulsutter 8y agoMore mature companies usually keep a contract calendar where they aggregate important dates for all signed contracts. Funny thing about domain renewal is that it’s so inexpensive that it can fall through the cracks and not get on the calendar. Could be useful to think of all the little deadlines that cause risk and use a single process.
- partiallypro 8y agoThis is why -generally- there is a period after the domain expires in which it is locked and cannot be purchased by anyone other than the previous owner. Just in case someone tries to squat. There are a few registrars that do this. I've seen it (squatting) happen more to small businesses, because even if their site it showing the landing page they might not notice it until a month later and by then it has been released and squatted. Bigger companies with lots of traffic would usually get a notice from a customer or internal employee that the site is down. This is my experience at least.
- jamespo 8y agoPersonally I recommend adding domain expiry checks to your monitoring system. Same with SSL certificate expiry.
- snowwrestler 8y agoProbably late to this party but at my employer we have a contract with MarkMonitor under which domains are auto-renewed and then we are invoiced for the cost. The advantage of this is that domain renewals are not broken by payment problems. Payment problems produce a failure state of "domain got renewed, the vendor is harassing us about an invoice"--which is much preferred to "domain did NOT get renewed, our site is down until we update our credit card." It also helps mitigate the "crucial employee departed" problem, since MarkMonitor won't just give up on an unpaid invoice... they will escalate if they don't get paid. Of course as a matter of practice we always have multiple people with access to the dashboard, but if all those people got kidnapped at once, the domains would still renew. I recognize that MarkMonitor is more expensive than Namecheap or GoDaddy or whoever, but I also bet that a lot of successful companies that are super reliant on their domains have never called for pricing. I don't work for a mega-corp; we're a nonprofit. And who knows, maybe other registrars may be willing to offer a similar payment structure. (I'm not affiliated with MM in any way--just a happy customer.)
- dumbfounder 8y agoSeems like an opportunity to me: makedamnsureirenewmydomainname.com