ActorStack.dev

More than half the domains that leave the zone come back

Leaving the zone runs roughly 35 days ahead of a domain being released, and most exits are never releases at all. The `minDaysAbsent` filter is what turns the signal into something usable.

By Oswaldo Carabano6 min read

Short answer

A domain disappearing from a registry zone file is a certain event and an ambiguous signal. More than half the domains that leave the zone never drop: a late renewal, a nameserver misconfiguration or a resolved registrar suspension brings them back. When an exit does lead to release, it runs roughly 35 days ahead of it, which matches ICANN's documented lifecycle — a 30-day redemption period followed by a pending-delete window. That gap is what makes the signal worth having: it is enough lead time to warn a client, prepare a backorder, or notice that an asset stopped being delegated. The `minDaysAbsent` filter trades earliness for certainty, and nothing else in the row resolves the ambiguity.

Key points

  • More than half the domains that leave a registry zone file never drop, because late renewals, misconfigurations and resolved suspensions all bring them back.
  • ICANN documents a 30-day redemption period followed by a pending-delete window, which is where the roughly 35 days of lead time before release comes from.
  • The zone exit itself is certain — the domain was in one daily snapshot and is absent from the next — and only its meaning is uncertain.
  • Setting `minDaysAbsent` to 30 leaves domains genuinely heading for release, while 0 gives the earliest and noisiest possible signal.
  • A domain already parked for sale before it left the zone is a much firmer drop candidate than one that was in active use.
  • Calling such a feed an expired domains list would misdescribe the majority of its rows, which is why the Actor is named for the event instead.
On this page6 sections

An early signal is only useful if you know how early, and how often it is wrong.

What leaving the zone actually is

The domain was in yesterday's snapshot and is not in today's. The registry stopped publishing its delegation. That comparison is certain; everything else on this page is an interpretation of it.

Most of them come back

More than half the domains that leave a zone file never drop. A renewal that landed late, a nameserver misconfiguration, a registrar suspension that got resolved — all of them produce a disappearance, and all of them reverse. A list sold as “expired domains” built on this event would be wrong on the majority of its rows.

Where the 35 days comes from

When an exit does lead to release, it runs roughly 35 days ahead of it, and that number is not arbitrary. ICANN's own status code documentation describes a domain being held in redemptionPeriod for 30 days, after which, if it has not been restored, it moves to pendingDelete. Thirty days plus that final window is the lead time this feed is buying you.

Trading earliness for certainty

minDaysAbsentWhat you get
0Includes domains that left today. Earliest, noisiest
1Everything from yesterday back, renewals included
7Most transient problems have resolved themselves
30Domains genuinely heading for release

The filter is exposed rather than applied internally, because what a false alarm costs depends on who is reading — a portfolio manager watching their own assets wants 0, and someone building a drop watchlist wants 30.

The one field that sharpens the guess

parked_for_sale, evaluated on the delegation the domain had before it left. A domain already sitting on a parking service that then leaves the zone is a much firmer drop candidate than one that was in active use, where an exit is more likely to be a misconfiguration somebody is about to notice.

Why it is not called expired domains

Because the name would put the error into every row instead of into the title — the same reasoning that keeps the other side of the feed honestly named, and which is worked through in naming a product for the event it observes.

Frequently asked questions

Does leaving the zone mean a domain expired?
No. More than half the domains that leave a zone file come back, because a late renewal, a nameserver misconfiguration or a resolved registrar suspension all produce the same disappearance. The exit is certain; expiry is an interpretation of it.
How long before a domain is actually released?
Roughly 35 days after it leaves the zone, when it is heading for release at all. ICANN documents a 30-day redemption period followed by a pending-delete window, and that lifecycle is what the lead time reflects.
What should I set minDaysAbsent to?
It depends on what a false alarm costs you. 0 includes domains that left today and is the noisiest; 7 means most transient problems have resolved themselves; and 30 leaves domains genuinely heading for release rather than ones about to be fixed.
Can I buy the domains in this feed?
Not from the feed, and often not at all. The output is a watchlist roughly 35 days ahead of any release, and more than half its rows will be renewed or restored before a release ever happens.

Sources

Every URL below was requested and returned a page on the date shown.

  1. Law or regulatorchecked 18 Sept 2026
    EPP Status Codes — What Do They Mean, and Why Should I Know?ICANN
  2. Operator claimchecked 18 Sept 2026
    Domain Expiry Watch — Actor README and input schemaActorStack / Apify Store
  3. Law or regulatorchecked 18 Sept 2026
    Expired Registration Recovery PolicyICANN
Printed notices and leaflets stapled to a wooden hoarding on a street.
DomainsExplainer

Zone entry is not registration

Zone entry is the earliest public signal that a domain went live, and roughly 20–30% of those events are re-appearances rather than new registrations. The number is an outside estimate and is labelled as one.

5 min
A row of residential mailboxes on posts in front of a wooden fence and trees.
DomainsGuide

Detecting domain hijacking

Whoever controls the nameservers controls the mail, the site and the certificates. That change happens in the registry zone, which is the one layer most monitoring never looks at.

7 min
Racks of network equipment in a dimly lit server room, lit blue by their indicators.
DomainsMeasured

What dns_provider can tell you

The nameserver identifies who runs the DNS for 69.1% of domains. It does not identify what a site is built with, and the measurement that settled that question is worth seeing.

5 min