A client's domain stopped working: what to do
The web server may be fine, but the site's name no longer turns into an address, so no browser can find it. To visitors the site is simply gone. Here is the order we would work in.
1. Make sure it is the name, not the server
Chrome says "This site can't be reached" and, underneath, "server IP address could not be found" with the code DNS_PROBE_FINISHED_NXDOMAIN. Firefox says "Hmm. We're having trouble finding that site." Safari says it can't find the server. Other codes that start with DNS_PROBE_ point the same way.
An expired domain does not always look like this. Many registrars point an expired domain at their own "this domain has expired" or parking page, which loads normally. If the client's site has been replaced by an ad-filled page or the registrar's logo, go straight to step 3.
A timeout or "connection refused" is a different problem: the name worked and the server did not answer. For those, see what to check when a site is down.
2. Ask the internet, not just your computer
Your computer and your network remember answers for a while, so ask a public resolver directly. On macOS or Linux:
dig @1.1.1.1 example.com A +short dig @1.1.1.1 example.com NS +shortOn Windows, nslookup example.com 1.1.1.1 does the same job. An address back means the name works and the problem is elsewhere. Nothing back, or an error, means the name is broken for everyone, not just you.
3. Look up the domain's registration
Enter the domain at lookup.icann.org and read two things: the expiry date and the domain status.
- The expiry date has passed. The renewal failed, often because the card on file expired or the reminders went to someone who left. Renew it at the registrar straight away. For .com and other generic domains, the owner can renew for at least 30 days after expiry, and then usually recover it for about 30 more at a much higher fee. Do not count on the full window: many registrars start auctioning an expired domain within weeks.
- The status says clientHold or serverHold. The domain has been suspended. Often it is simply because it expired. Another common reason, for .com and other generic domains, is an owner email address that was never confirmed: after a new registration or a change of owner details, the registrar must confirm the address within 15 days or suspend the domain. Some registrars suspend by pointing the domain at a verification page instead of setting a hold. Look for the confirmation email, or ask the registrar what the hold is for.
- The nameservers are not the ones you expect. Someone changed them, or the registrar switched them to a parking page after expiry.
4. If the registration is fine, check the records
- The records were not copied to a new DNS provider. The nameservers were moved, to Cloudflare or a new host, before every record was recreated there. Compare the old zone with the new one.
- A record was deleted or edited. Check the A record, and the www record, at whoever the nameservers point to. Most DNS panels keep an activity log.
- DNSSEC was left behind. The nameservers changed, but the registrar still has the old DNSSEC key. Resolvers that check signatures, including 1.1.1.1 and 8.8.8.8, then refuse the answer. If
dig @1.1.1.1 example.com +cdshowsstatus: NOERRORand the same command without+cdshowsstatus: SERVFAIL, this is the cause. Remove the old DS record at the registrar, or add the new one.
Most of these start with a change: a move to a new host, Cloudflare switched on, a transfer between registrars, or a new owner on the account. Start with whatever changed last.
5. Check the fix, and allow for caches
Run the commands from step 2 again against more than one resolver, for example 1.1.1.1 and 8.8.8.8. Once they return the right address, the fix is in. Other networks may keep the old answer for a while, often minutes and sometimes up to two days after a nameserver change, so a client who still sees the error may just need to wait or try another network. Then set the domain to renew automatically, with a card that will not expire soon, and make sure the renewal emails go to an address somebody reads.
6. Tell the client what happened
They may have seen the error themselves. For example:
The website itself was fine, but its web address had stopped pointing to it, so browsers could not find the site. I have fixed the address settings and set the domain to renew automatically. Some visitors may see the old error for a little while longer as the change reaches them.
7. Next time, hear about it first
Bionic Uptime looks up the website's address on every check. If the name cannot be found, the check fails. When both of our locations, on two different companies' networks, agree, it is confirmed as an outage and each person on that website's alert list gets one email. When the name does not exist, it says both checking locations could not look up the website's address. See the exact outage email.
It also reads the domain's expiry date from public registry records once a day and emails you 30 days and 7 days before it runs out, where the registry publishes the date (most do; .io, .de and .com.au do not). And an expired domain pointed at a registrar's parking page still loads, so a plain check would call it Online. Turn on Also check what the page says when you add the website, with a phrase the client's page must say, such as their business name, and a parking page fails it. Automatic renewal is still the real protection.
3 websites are free, forever, with no card. Looking after several client sites?