Dropcatch (or “drop-catching”) is the practice of automatically registering a domain the instant it becomes available following prior expiry. Dropcatch services (SnapNames, DropCatch.com, NameJet) queue registration requests against the exact microsecond the registry releases the name.
How It Works
- Domain expires → 45-day auto-renew → 30-day redemption grace → 5-day pending-delete → drops
- Registry announces the drop time in advance
- Multiple registrars submit registration requests via EPP at that instant
- Whoever’s request lands first wins; usually decided at the millisecond level
Why Attackers Care
Old domains carry residual traffic — inbound links, hardcoded configs, SaaS integrations, expired-but-cached SSL certs. An attacker who dropcatches a domain formerly used by a known brand can:
- Intercept legacy email addresses (password resets to
[email protected]) - Serve phishing pages to users hitting bookmarks
- Pass reputation checks based on the domain’s historical trust score
Defence
- Set your registrar’s auto-renew to on plus a backup billing method
- Watch domain expiry as a monitored asset, not a calendar reminder
- If a strategic domain does drop, buy it back via dropcatch first (or use one of the dropcatch services to try)
Related
Check the redemption period glossary entry, the transfer lock glossary entry, and read what typosquatting is.