The first 30 days after buying an expired domain decide whether you keep the value you paid for. In order: lock down the registrar account (2FA, registrar lock, auto-renew, WHOIS privacy), point DNS at a host you control, verify the domain in Google Search Console and Bing Webmaster Tools, check for manual actions and security issues, then recover the URLs that hold backlinks by restoring them with new content or 301-redirecting them to close equivalents. Return 410 for junk URLs, submit a sitemap, ping Bing through IndexNow, keep email locked down, and monitor crawl and index data weekly. The rest of this guide walks through each step and why it matters.
The 30-Day Post-Acquisition Sequence
Day 1: Secure the Registrar Account
A freshly caught expired domain is at its most vulnerable while it sits in a new account with default settings. Domain theft usually happens through the registrar account, not the website, so this comes before anything technical. If you bought the domain through an aftermarket platform or a drop-catching service, make sure it has actually been pushed into an account you own. Domains stuck in a marketplace holding account are one of the most common sources of later disputes. See How to Buy Expired Domains for how delivery works on each channel.
Account-Level Security
- Two-factor authentication: Turn on 2FA using an authenticator app or a hardware security key. SMS-based 2FA is better than nothing but is exposed to SIM-swap attacks.
- Unique password and dedicated email: The registrar login email is the master key to the domain. Use an address on a different domain that you control and that has its own 2FA.
- Review account contacts and API keys: Delete any API keys or sub-users you did not create, and confirm the registrant contact details are yours. Accurate registrant data matters if you ever need to prove ownership in a dispute.
Domain-Level Settings
- Registrar lock: Enable the transfer lock (EPP status
clientTransferProhibited). It blocks outbound transfers until you remove it yourself. Confirm the status with an RDAP or WHOIS lookup a few hours later. - Auto-renew: Turn it on and keep a valid payment method on file. Losing a domain you just paid an auction premium for because a card expired is an avoidable mistake. Many investors also renew for several years up front for important names.
- WHOIS privacy: Turn on privacy or redaction where your registrar offers it. Many gTLD registrars now redact personal data by default, but check, especially for ccTLDs, where rules differ by registry.
- Note the transfer lock date: Most gTLD registrations and inbound transfers carry a 60-day lock on moving to another registrar. Put the date in your calendar if you plan to consolidate domains at one registrar.
High-value names: For domains worth a significant amount, ask whether your registrar supports a registry lock (server-level statuses such as serverTransferProhibited). Changes then require a manual, out-of-band verification. Availability and pricing vary by registrar and TLD, so check first.
Days 1–2: DNS Setup
Most domains arrive pointing at the registrar's parking page or at nameservers left by the auction platform. Leaving a domain parked for weeks gives search engines nothing useful to crawl, and ad-filled parking pages are not a good first impression on recrawl. Move it to infrastructure you control as soon as possible.
- Choose your DNS provider (registrar DNS, Cloudflare, or your host) and set the nameservers.
- Check DNSSEC: Look for leftover DS records at the registry. A DS record that does not match your new DNS provider's keys will make the domain fail to resolve for validating resolvers. Remove stale DS records, then re-enable DNSSEC with your new provider if you want it.
- Create only the records you need: Apex and
www, pointed at your host. Do not recreate old subdomains unless you have a reason. Old subdomains with backlinks are handled in the URL recovery step below. - Pick one canonical hostname: Choose either
wwwor the bare domain, plus HTTPS, and 301 every other variant to it. - Put a real page live: Even a short, honest "new site launching" page with a clear topic and contact details is better than parking. Avoid publishing thin placeholder pages in bulk.
Days 1–3: Verify in Google Search Console and Bing Webmaster Tools
Search Console is the only first-party source that tells you whether Google has a manual action on the domain, and verification gives you crawl, index, and link data you cannot get anywhere else.
Google Search Console
- Add a Domain property using a DNS TXT record. It covers every protocol and subdomain, which matters on an expired domain where old URLs may sit on
http://or on forgotten subdomains. - Search Console data belongs to the property, not the account. Once you verify, you may see some historical data from before your purchase, depending on how recently the domain was active.
- Old owners may still have verified access via leftover tokens. Under Settings → Users and permissions, remove any owner or user you do not recognize, and delete any old verification TXT records from DNS.
Bing Webmaster Tools
- Bing lets you import a verified site directly from Google Search Console, which is the fastest route. DNS and file-based verification also work.
- Bing's data feeds other search products that license its index, so this is worth the five minutes.
Week 1: Check for Manual Actions and Security Issues
Your pre-purchase vetting (see Google Index & Penalty Check) used outside signals. Now you can see Google's own reports. Open Security & Manual Actions in Search Console:
- Manual actions: If the report says "No issues detected," there is no active manual action. If one exists (for example, unnatural links, pure spam, or a spam policy violation), the report states its scope (site-wide or partial). Fix the cause before you build anything further, and only then file a reconsideration request that explains the change of ownership and what you have done.
- Security issues: Hacked content, malware, or deceptive pages from the previous owner's era can still be flagged. Also check the domain in Google's Safe Browsing transparency report.
- Pages / Indexing report: Once crawling resumes, see which old URLs Google still knows about. This becomes your list of URLs to handle.
Under Google's spam policies, ownership change is not a reset. "Expired domain abuse" covers domains bought and repurposed mainly to host low-value content that trades on the previous reputation. A clean manual actions report today does not protect a site built that way later. Build something that fits the domain's history and serves users. See Rebuilding from the Archive for where the line sits.
Weeks 1–3: Recover and Redirect Top Backlinked URLs
Most of an expired domain's value usually sits in the backlinks pointing at specific inner URLs, not at the homepage. When those URLs return 404, the links point at nothing. Recovering them is the most valuable work of the first month.
Step 1: Export Linked Pages
- Ahrefs: Site Explorer → Best by links (filter to 404 / not crawled where available). Sort by referring domains, not by backlinks, so sitewide links don't skew the list. See our Ahrefs review.
- Majestic: The Pages report lists URLs with their own Trust Flow and Citation Flow, which helps rank which pages hold the strongest links. See our Majestic review.
- Search Console: Over the following weeks, Links → Top linked pages fills in with Google's own view, and the indexing report shows 404s that Googlebot actually requests.
- Wayback Machine: Check what each URL originally contained so you can match intent. The Wayback Machine guide covers how.
Step 2: Map Each URL 1:1
Merge the exports into one spreadsheet: old URL, referring domains, original topic, and action. For each URL, pick one action:
Restore (best)
- Publish new, original content at the same URL
- Match the original topic and search intent
- Use for URLs with the most and best referring domains
- No redirect hop needed
301 to a close equivalent
- Redirect to a new page on the same topic
- Use when the old URL structure is ugly or outdated
- Redirect one-to-one, not everything to the homepage
- Avoid chains: point straight to the final URL
410 Gone
- Spam, hacked, or off-topic URLs you never want back
- Thin tag/archive pages with no meaningful links
- Tells crawlers the removal is intentional
Leave as 404
- Low-value URLs with no links and no relevant equivalent
- Perfectly normal; 404s do not hurt the rest of the site
- Make sure your server returns a real 404 status
Don't redirect everything to the homepage. Google can treat mass redirects to an irrelevant page as soft 404s, which wastes the link equity you are trying to recover. Relevance between the old URL and the destination is what makes a 301 pass value. See 301 Redirects for implementation details.
Step 3: Implement Server-Side
Use real HTTP 301 redirects (server config, host redirect rules, or edge rules), not meta refresh or JavaScript. On Cloudflare Pages, for example, a _redirects file supports lines such as /old-guide.html /guides/new-guide 301. After deploying, test a sample of URLs with curl -I to confirm the status code and the single-hop Location header.
410 vs. 404 for Junk URLs
Expired domains often have long tails of URLs you don't want: injected pharma pages from a hack, scraped feeds, spammy query-string pages. Both 404 and 410 lead to the URL being dropped from the index. Google has said it treats them very similarly, with 410 possibly processed slightly faster because it signals the removal is deliberate. In practice:
- Use 410 for clearly spammy URL patterns that you want gone quickly, such as
/cheap-pills-*or hacked directories. A pattern-based rule on the server or CDN keeps this manageable. - Use 404 as the default for anything else that no longer exists.
- Don't block junk URLs in robots.txt while you want them removed. Googlebot has to crawl a URL to see the 404/410. Blocking it can keep the URL indexed without content.
- Search Console's Removals tool only hides URLs temporarily (about six months). It helps for embarrassing spam showing in search while the 410s take effect, but it is not a permanent fix.
Disavow: Usually Unnecessary
Almost every expired domain has spammy links: scraper sites, auto-generated directories, foreign-language link lists. Google's guidance is that its systems ignore most of these automatically and that most sites do not need the disavow tool. Overusing it can throw away links that were helping.
Disavow may make sense when:
- The domain has a manual action for unnatural links. Disavowing is part of the documented cleanup before a reconsideration request.
- You find a large, clear-cut paid or link-scheme footprint from the previous owner (bought links with commercial anchors, an obvious PBN) and you expect a manual review could trip on it.
If you disavow, use the domain: syntax for whole spam domains rather than listing individual URLs, keep a dated copy of the file, and remember that uploading a new file replaces the previous one for that property. For deeper link triage, see Backlink Analysis.
Sitemaps and IndexNow
XML Sitemap
Once your restored pages and new content are live, generate an XML sitemap that lists only canonical, indexable URLs that return 200. Don't include redirected or 410 URLs. Submit it in Search Console (Sitemaps) and Bing Webmaster Tools, and reference it in robots.txt with a Sitemap: line. Keep lastmod accurate. Search engines may ignore it if it's obviously inflated.
IndexNow for Bing
IndexNow is an open protocol that lets you notify participating search engines (including Bing and Yandex) that URLs have been added, updated, or deleted. Google does not use it. Setup:
- Generate a key and host it as a text file at your site root (for example
https://example.com/<key>.txt). - Submit changed URLs to an IndexNow endpoint such as
https://api.indexnow.org/indexnow, singly via GET or in batches via a JSON POST. - Many CMS plugins and CDNs can do this automatically. Cloudflare offers it as part of its Crawler Hints feature.
Submit your restored URLs and your 410 URLs too: telling Bing a URL is gone is as useful as telling it a URL is new.
Email: Don't Catch the Old Owner's Mail
Once you control DNS, you can receive any email sent to the domain. Expired domains keep receiving mail: newsletters, invoices, customer messages, and password-reset emails for the old owner's accounts on other services.
Do not set up a catch-all mailbox. Collecting mail meant for the previous owner or their customers exposes you to personal data you have no right to process. Using it to access third-party accounts (for example, by triggering password resets) can be unauthorized access under computer-misuse laws. Create only the specific addresses you need.
- If you won't use email on the domain: publish a null MX record (
MX 0 ., per RFC 7505), an SPF record ofv=spf1 -all, and a DMARC record withp=reject. This stops spammers spoofing your domain and tells senders not to deliver mail. - If you will use email: set up SPF, DKIM, and DMARC for your provider from day one, and check whether the domain appears on major email blocklists before relying on it for outreach.
- Mail you receive by accident should be deleted, not read or acted on. If it looks important (for example, from a former customer), a short neutral reply that the domain has changed hands is reasonable. Get legal advice for anything sensitive.
Weeks 2–4: Monitor
The first month is about catching problems early. Set a weekly review:
- Search Console Pages report: Watch for spikes in "Not found (404)", "Soft 404", or "Crawled – currently not indexed" on your restored URLs.
- Crawl stats: (Settings → Crawl stats) Rising crawl requests after DNS goes live are a healthy sign that Googlebot is rediscovering the domain.
- Server logs: Look for 404s with high request counts that you missed in your backlink export, then add them to the redirect map.
- Backlink tools: Re-crawl your top linked URLs and confirm they now resolve to 200 or a single 301.
- Brand search: Search the domain name and confirm your new site, not spam remnants, is what shows.
- Uptime and certificate expiry: Basic monitoring catches DNS or TLS mistakes before crawlers do.
Set realistic expectations: Recrawling and re-evaluating a domain that was dormant can take weeks to months. How quickly rankings recover varies widely and depends on how long the domain was down, how much the topic changed, and the quality of what you publish.
30-Day Timeline at a Glance
| When | Task | Done when |
|---|---|---|
| Day 1 | 2FA, registrar lock, auto-renew, WHOIS privacy, contact review | RDAP shows clientTransferProhibited; renewal is set |
| Day 1 | Nameservers, DNSSEC check, canonical host, live placeholder page | Domain resolves over HTTPS to your server |
| Day 1 | Email lockdown (null MX/SPF/DMARC or proper setup, no catch-all) | DNS records published and validated |
| Week 1 | Verify GSC (Domain property) and Bing; remove stale users | Both properties verified |
| Week 1 | Manual actions, security issues, Safe Browsing check | Clean reports, or a remediation plan in place |
| Week 1 | Export top linked URLs (Ahrefs, Majestic); build redirect map | Spreadsheet with an action for every linked URL |
| Weeks 2–3 | Publish restored content; deploy 301s and 410 rules | curl -I spot-checks pass |
| Weeks 2–3 | Sitemap submission; IndexNow setup and pings | Sitemap shows "Success" in GSC and Bing |
| Weeks 2–4 | Weekly monitoring: index coverage, crawl stats, logs, brand SERP | New 404s mapped; no unexpected soft 404s |
| Week 4 | Disavow decision (usually: don't) | Decision documented with reasoning |
FAQ
How soon after buying an expired domain should I enable the registrar lock?
Immediately, on day one. Enable 2FA on the registrar account first, then turn on the transfer lock (clientTransferProhibited) and auto-renew. Confirm the lock with an RDAP or WHOIS lookup.
Should I redirect all old URLs of an expired domain to the homepage?
No. Redirect each backlinked URL one-to-one to a page on the same topic, or restore it with new content at the same path. Mass redirects to the homepage are often treated as soft 404s and pass little value.
Should I return 404 or 410 for spam URLs left by the previous owner?
Both remove URLs from the index. Use 410 for clearly unwanted patterns such as hacked or spam directories, since it signals deliberate removal, and 404 for everything else. Don't block those URLs in robots.txt, because crawlers need to see the status code.
Do I need to disavow backlinks on an expired domain?
Usually not. Google says its systems ignore most spammy links automatically. Consider disavowing only if there is a manual action for unnatural links or a large, obvious paid-link or link-scheme footprint from the previous owner.
Can I set up a catch-all email on an expired domain I bought?
You shouldn't. A catch-all collects mail intended for the previous owner and their contacts, including personal data and password resets. Create only the addresses you need, or publish a null MX, a strict SPF record, and DMARC p=reject if you won't use email.
Next Steps
Continue with these related guides:
- 301 Redirects — Pass authority from old URLs correctly
- Rebuilding from the Archive — Restore an old site's structure without copyright or spam risk
- Google Index & Penalty Check — Confirm a domain is clean before and after purchase
- Backlink Analysis — Triage which links are worth recovering