Skip to content

Ward opens soon: join the waitlist and we'll email you the day we open.

What Ward checks

Area: Domain

Domain registration

Expiry date, registrar and status of your domain (RDAP) and DNSSEC signing (DNS over HTTPS).

What it can report

Open each one to see what it means and how to fix it.

Renewal date has passed

What it means

You told Ward that example.com renews on a date, and that date has passed. Domains with this ending have no public record Ward can read, so we can't tell whether you already renewed it.

What could happen

If the renewal didn't happen, your website and email stop working and someone else can register the name. If it did, nothing is wrong and only the date saved in Ward is out of date.

How an attacker would use it

Someone who watches for domains about to expire registers yours the day it becomes free. They put up a site that looks like yours and start receiving emails sent to your addresses, and you only notice when customers say your messages never arrive.

How to fix it

  1. Sign in at your registrar (the company where you bought the domain) and check that the domain is active and when it expires.
  2. If it's already renewed, press “Renewed: +1 year” on the domain's page in Ward, or set the new date.
  3. If it isn't renewed, renew it today.Choose several years if you can, and turn on automatic renewal.
  4. Make sure the card on file is valid and the registrar's emails go to a mailbox someone reads.

How to check it's fixed

Update the renewal date in Ward on the domain's page. The finding clears at the next scan, once the date is in the future.

Who usually fixes it

vosotros

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Domain expires soon

What it means

example.com is registered for a limited period, and that period ends soon. The date comes from the public domain registry.

What could happen

If it expires, your website and email stop working, and after a while the name can be registered by someone else. Renewing is simple and cheap compared with recovering a lost name. The closer the date, the more urgent it is.

How an attacker would use it

Someone who watches for domains about to expire registers yours as soon as it's released. They set up a copy of your website, receive emails sent to your addresses and write to your customers from an address that looks genuine.

How to fix it

  1. Sign in at your registrar (the company where you bought the domain) and renew the domain now.Choose several years if you can, so it doesn't come up again soon.
  2. Turn on automatic renewal.
  3. Check that the payment card on file is valid and doesn't expire before the renewal date.
  4. Make sure the registrar's emails reach a mailbox someone reads, not a former employee's.

How to check it's fixed

Ward reads the new expiry date from the registry. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

vosotros

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Domain has expired

What it means

The registration of example.com has expired: the date when it had to be renewed has passed. Domains don't disappear the same day, but the registrar can switch off the website and email at any time.

What could happen

Your website and email may already be failing or are about to. Customers can't reach you, emails to you bounce, and once the grace period ends, anyone can buy the name. Registrars usually let you renew for a limited time, sometimes with a surcharge.

How an attacker would use it

Someone who watches for expired domains registers yours the moment it's released. They put a copy of your website on it, receive the emails that customers and suppliers still send to your addresses, and use them to ask for payments or reset passwords on your accounts.

How to fix it

  1. Sign in at your registrar today (the company where you bought the domain).If you don't remember which one it is, check the invoices in your accounting or ask whoever set up your website.
  2. Renew the domain. If the registrar asks for a recovery fee, pay it: it costs less than losing the name.
  3. Turn on automatic renewal and check that the card on file is valid.
  4. If you can't sign in, contact the registrar's support and explain that the domain has expired.
  5. Once it's active again, check that your website and email work, and tell your IT person.

How to check it's fixed

Ward reads the new expiry date from the registry. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

vosotros

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Domain on hold by the registry

What it means

The registry (the organization that runs the domain ending) has put example.com on “server hold” and removed it from the internet's address book. It is rarer than a hold by the registrar and often has a legal or abuse-related reason.

What could happen

Your website and email don't work for anyone while it lasts. Only the registry can lift it, and you can only ask through your registrar, so it can take time.

How an attacker would use it

Customers type your address and get an error, and your emails stop arriving. If the reason was abuse, someone may have used your domain without your knowledge, and your reputation suffers until it's lifted.

How to fix it

  1. Contact your registrar today and ask for the exact reason for the hold.
  2. If the reason is abuse or a hacked website, clean the website and change all passwords first, then tell the registrar.
  3. If the reason is legal or a dispute, ask the registrar what documents they need.
  4. Ask the registrar to request the lifting of the hold and agree on how you'll be told when it's done.
  5. Meanwhile, warn your customers by another channel (phone, social media, an alternative address).

How to check it's fixed

Ward reads the domain's status from the registry. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your provider

Example with sample data. In your dashboard, the explanation uses your own domain and details.

No transfer lock

What it means

A transfer lock is a switch at your registrar (the company where you bought example.com) that blocks moving the domain to another registrar. Yours isn't switched on.

What could happen

If someone gets into your registrar account, or fools its support, they can move the domain away without your consent. You would lose control of your website and email until it's recovered, which can take time. The lock adds a barrier; it doesn't replace a strong account password.

How an attacker would use it

Someone obtains the password of your registrar account from a data leak and signs in. With no lock in place, they start a transfer to a registrar of their own. Once done, they point your website and email to servers they control, and you can't change anything.

How to fix it

  1. Sign in at your registrar and open the domain's settings.
  2. Look for “transfer lock”, “registrar lock” or “domain lock”, and turn it on.It is usually a switch in the domain's settings page. If you can't find it, ask the registrar's support.
  3. Turn on two-step verification on the registrar account.
  4. Check that the account's email address and phone belong to your company and that more than one person knows how to reach the registrar.

How to check it's fixed

Ward reads the domain's status from the registry. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

vosotros

Example with sample data. In your dashboard, the explanation uses your own domain and details.

DNSSEC is broken

What it means

DNSSEC adds a digital signature to the answers about example.com in the internet's address book. Yours doesn't validate: the signatures and the record at your registrar don't match, so a check that works as it should would say the answers can't be trusted.

What could happen

Internet providers and networks that check DNSSEC refuse to resolve your domain. For those people your website doesn't load and your emails don't arrive, even though everything looks fine from your office. It usually happens after changing DNS provider or registrar.

How an attacker would use it

Nobody needs to attack here: the harm is the outage itself. A customer whose internet provider checks signatures types your address and gets an error, and emails they send you bounce. You hear about it from them, not from an alarm.

How to fix it

  1. Ask your DNS provider whether DNSSEC is on for the domain and whether they changed any keys recently.
  2. At your registrar, open the domain's DNSSEC section and look at the “DS record” it holds.It must match the keys published by your current DNS provider.
  3. If you moved to another DNS provider or registrar recently, the old DS record is the likely cause. Replace it with the new provider's value.
  4. If you can't fix it quickly, remove the DS record at the registrar so the domain works without DNSSEC.Then set DNSSEC up again properly when you have time. Getting your website and email back comes first.
  5. Wait for the change to spread and check the website and email from a different network.

How to check it's fixed

Ward runs the signature check again. Mark the finding as “Pending verification” and Ward will check it again. DNS changes can take a few hours to spread, so if it still shows up, try again later.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

DNSSEC not enabled

What it means

DNSSEC signs the answers about example.com in the internet's address book so they can't be forged on the way. It isn't turned on for your domain.

What could happen

Without it, a forged answer is harder to spot. It's an extra layer, not a basic need: plenty of well-run small businesses don't have it. The severity is low. Switching it on badly can take your website offline, so it should be done with care.

How an attacker would use it

Someone manages to slip a false answer into the address book used by a network your customers are on. Customers who type your address land on a copy of your website and enter their details. With DNSSEC, their provider would reject the forged answer.

How to fix it

  1. Ask your DNS provider whether it supports DNSSEC.Many do, with a single switch in the domain's settings.
  2. Turn on signing at the DNS provider. It will show a “DS record” to publish.
  3. At your registrar, open the domain's DNSSEC section and add that DS record exactly as given.If your registrar is also your DNS provider, it's often done for you.
  4. Wait a few hours and check that your website and email work from a different network.
  5. Don't turn it on if you are about to change DNS provider: do it afterwards.

How to check it's fixed

Ward looks for the DS record at the registry. Mark the finding as “Pending verification” and Ward will check it again. DNS changes can take a few hours to spread, so if it still shows up, try again later.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Only one name server

What it means

Your domain's “name server” (the computer that tells the internet where your website and email live) is a single one. Good practice is to have at least two, on different networks.

What could happen

If that server goes down because of a failure, a maintenance slip or a flood of traffic, your website and email become unreachable until it's back. It's a risk of an outage, not of a break-in, and the severity is low.

How an attacker would use it

Someone aims a flood of traffic at your only name server, or the provider has a bad day. Customers type your address and nothing loads, and email to you bounces for as long as it lasts. There is no second server to take over.

How to fix it

  1. Ask your DNS provider for its second name server.Most providers give two or more by default. If you only see one, it may have been entered incompletely.
  2. At your registrar, open the domain's name server settings and add the second one.
  3. If your provider only offers one, consider adding a secondary DNS service on a different network.
  4. Save and wait a few hours for the change to spread.

How to check it's fixed

Ward counts the name servers again. Mark the finding as “Pending verification” and Ward will check it again. DNS changes can take a few hours to spread, so if it still shows up, try again later.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

No CAA record

What it means

A CAA record says which certificate authorities (the companies that issue the HTTPS padlock certificates) may issue certificates for example.com. Your domain has none, so any authority can issue one if it is fooled.

What could happen

A certificate nobody on your team asked for can be used to build a website that shows the padlock under your name. The chance is small, and this is a low-severity improvement. Done carelessly, though, it can block your own certificate renewals.

How an attacker would use it

Someone gets a certificate for your domain from an authority with weak checks. With it, they set up a copy of your website that shows the padlock, and your customers see nothing wrong when they enter their details there.

How to fix it

  1. Find out which authority issues your certificates and who requests them.Ask your hosting provider or IT person. Hosting plans and CDNs often use more than one authority.
  2. At your DNS host, add a CAA record on the root of the domain (“@”) for each authority you use, with the tag “issue”.For example “letsencrypt.org” if you use Let's Encrypt.
  3. Before saving, confirm with your hosting provider that the list includes every authority it may use.If one is missing, certificate renewals will fail and your site will show a security warning.
  4. Save, and check in a few days that your certificate still renews.

How to check it's fixed

Ward looks for the CAA record in your DNS. Mark the finding as “Pending verification” and Ward will check it again. DNS changes can take a few hours to spread, so if it still shows up, try again later.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.