Cybercriminals are increasingly acquiring expired domains to exploit their existing traffic and reputation, redirecting unsuspecting users to scams and malware. This tactic, known as ‘dropcatching,’ involves re-registering domains that have lapsed, allowing attackers to capitalize on the trust these domains previously established.
According to DNS threat intelligence firm Infoblox, during the first half of 2026, approximately 50,400 expired domains were re-registered daily within generic top-level domains (gTLDs) like ‘.com.’ When including country code top-level domains (ccTLDs), this figure rises to around 65,000 daily re-registrations. Notably, these dropcatch domains constitute nearly 20% of all daily gTLD and ccTLD registrations, indicating that one in five newly registered domains is a re-registered expired domain.
Infoblox’s analysis reveals that the ‘.net’ and ‘.xyz’ domains lead in dropcatch activity, surpassing even the popular ‘.com’ domains. Other frequently re-registered TLDs include ‘.org,’ ‘.vip,’ ‘.online,’ ‘.store,’ ‘.site,’ ‘.app,’ and ‘.shop.’ Major registrars facilitating these re-registrations include GoDaddy, Namecheap, and DropCatch.com, with median daily re-registrations of 5,246, 4,385, and 3,568 domains, respectively.
The process of domain expiration and re-registration typically follows a standard protocol. Most gTLDs adhere to a registration recovery policy that offers existing registrants a grace period to renew their domains. Once this period expires, the domains are released and become available for new registrations. Services like DropCatch.com monitor these domains approaching deletion and attempt to register them immediately upon release, often on behalf of clients who have placed backorders. In cases where multiple parties express interest in the same domain, the domain may go to a public auction, with the highest bidder securing ownership.
While some organizations proactively re-register expired domains to prevent misuse, the practice becomes concerning when malicious actors acquire these domains. By controlling a domain with an established history, attackers can exploit its inherited reputation to bypass security filters and deceive users. This strategy underscores the importance of monitoring domain expirations and implementing measures to prevent malicious re-registrations.
The exploitation of expired domains highlights a critical vulnerability in the digital landscape. Organizations must remain vigilant, ensuring they renew essential domains promptly and monitor for unauthorized re-registrations. Additionally, the cybersecurity community should advocate for enhanced policies and tools to detect and mitigate the risks associated with dropcatching, thereby safeguarding users from potential threats.