← Back to news 04.09.2026

There is no expiry date for .de

DENIC publishes neither expiry date nor transfer lock for .de domains, while the registry returns both for .com. What that means for renewal reminders, and why an empty date field deliberately triggers no due date but is counted as a gap of its own.

A domain expires. What is lost is rarely the first thing that comes to mind. The website is the visible part, but the domain also carries inbound email and the ability to have certificates issued for it. Whoever registers it after expiry gets both.

The simplest protection is an expiry date with a name next to it. And that is exactly where things get awkward in the German-speaking market.

What the registry returns, and what it does not

Registration data can be queried programmatically via RDAP, the successor to WHOIS. For the generic top-level domains it returns what you would expect: a query for a .com domain gives registration date, expiry date and last change, plus the status, including client transfer prohibited for a transfer lock in place.

For .de the same query looks different. DENIC answers it, but the response contains last changed as its only event and active as its only status. No expiry date. No transfer lock. Nameservers and DNSSEC details are there; the commercially interesting fields are not. To see it yourself, a query against rdap.denic.de for any .de domain is enough.

This is not a glitch and not a peculiarity of individual domains, it is the registry's disclosure practice. For your own estate it means that the expiry date stays empty on precisely those domains that usually matter most to a German organisation, until someone looks it up at the registrar and enters it.

An empty field is not a due date

From this follows a decision that looks wrong at first: a domain without an expiry date does not appear in the renewal list. Not as overdue, not as due soon, not at all.

That is deliberate. Without a date there is no statement about expiry, only the absence of one. Turning that into a due date would put every .de domain into the reminder list on day one, and the list would be worthless before it was read for the first time.

Instead without expiry date is a figure of its own in the cockpit, alongside four further gaps: without owner, without contract, without transfer lock, without DNSSEC. These are backlogs to be worked through once, not alerts to be dismissed daily.

Auto-renewal takes a domain out

The renewal reminder applies when expiry falls within the lead time and the domain does not renew automatically. If renewal is automatic, it appears neither in the cockpit nor in the dashboard widget. The lead time is 90 days and can be changed.

That too is deliberate, but it has a limit worth knowing: automatic renewal only happens as long as the stored payment goes through. The checkbox in the register records what was agreed, not what actually happened. A declined card appears in no registry.

Three views, no duplicated estate

Domains appear in three places with separate jobs. Attack surface looks at the technical side: DNS, DNSSEC, SPF and DMARC, TLS, look-alike domains, plus registration data from RDAP. Certificate management handles issuance and renewal. Domain management takes the commercial half: registrar, contract, term and notice period, cost, ownership.

Nothing is maintained twice. On the detail page, import registration data pulls registrar, expiry date, transfer lock, DNSSEC status and nameservers from the attack surface, where those values are collected anyway. For .de exactly the two fields the registry withholds stay empty. That is where manual work begins, and where it ends again.

More on the domain management module page.

Matching solution isidaten for ISO/IEC 27001

Questions about this update?

Talk to us – we are happy to show you this feature in a demo.