{"id":13993,"date":"2026-08-13T06:00:26","date_gmt":"2026-08-13T13:00:26","guid":{"rendered":"https:\/\/www.infoblox.com\/blog\/?p=13993"},"modified":"2026-08-13T06:01:07","modified_gmt":"2026-08-13T13:01:07","slug":"drop-something-dont-worry-someone-caught-it","status":"publish","type":"post","link":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/drop-something-dont-worry-someone-caught-it\/","title":{"rendered":"Drop Something? Don\u2019t Worry, Someone Caught it"},"content":{"rendered":"<p>An old domain is not always old trust. Dropcatch activity gives previously registered domains a second life, sometimes under very different ownership. <\/p>\n<p><strong>Infoblox Threat Intel | Dropcatch series | Part 1 of 3<\/strong><\/p>\n<h3>Executive Summary<\/h3>\n<p>Every day, tens of thousands of domain names expire and become available for registration. Some fade away and are never seen again. Others get a second chance. We refer to these as dropcatch domains: the domain was dropped, became available again, and someone caught it. This isn\u2019t just our name; it\u2019s widely used. There\u2019s even an auction service called DropCatch.com.<\/p>\n<p>During the first half of 2026, we observed over 50k dropcatch domains a day in the gTLDs alone\u2014when we add in various ccTLDs that number rises to around 65k. That\u2019s an astounding number when you put it next to the total of new registrations every day. For the gTLDs, nearly 20% of all observed registrations are dropcatch. In other words, one of every five newly registered domains had a prior life, sometimes several.<\/p>\n<p>These domains can be particularly interesting, even dangerous, because they inherit reputation and sometimes connections from their previous life. For example, a domain that was originally registered 10 years ago, later dropped, and then acquired by someone else may still carry signals associated with its long history. Researchers, security products, and reputation-based algorithms may view it more favorably than a genuinely brand-new registration. Threat actors know this and take advantage of it.<\/p>\n<p>In this first post of our three-part blog series, we focus on the fundamentals: why domains get dropped, how they get caught, and how frequently they reappear under a new registration. We also explore the challenges involved in identifying these domains at scale, particularly when creation date information is unavailable. In blogs two and three, we&#8217;ll dive into the threat actors that actively catch dropped domains and explore what happens after those domains fall into new hands.<\/p>\n<p>Disclaimer: <em>The domain name industry (as opposed to the Domain Name System) is a complex one and is not our area of expertise. Take our numbers as accurate, but the nuances of domain registration with a grain of salt.<\/em><\/p>\n<h3>Not Every Domain Lives Forever<\/h3>\n<p>Dropped domains come in all shapes and sizes. Some were once owned by failed small businesses. Others belonged to critical supply chain components. Sometimes they are intentionally abandoned, but they can also be lost through something as simple as a missed renewal notice, a forgotten email account, or an employee responsible for renewals leaving the company. Companies shut down, websites disappear, priorities change, and domains that once seemed important are no longer worth maintaining. Threat actors contribute to this cycle too. They often register domains in bulk and abandon them rather than paying renewal fees.<\/p>\n<p>Domain management is trickier than people realize. Some domains were only ever intended for &#8220;internal&#8221; use, so no one immediately notices when they disappear. Missing renewals for these domains among large collections is extremely easy and extremely common. This happened to us. There\u2019s a period where you can reclaim the domain after its expiration, but after that it may be sold at auction or eventually become available for registration again. A few missed emails and it\u2019s too late to get it back. In our case, the new owner wanted $40k to return the domain to us. We decided to pass, and the domain is still up for sale. Today the asking price is over $52k. That seems like a lot, but we\u2019ve talked to other organizations who were asked to pay over $100k to recover their lost internal domain.<\/p>\n<p>We&#8217;ve seen domains associated with temporary events, charitable initiatives, world crises, political campaigns, small businesses, and personal blogs all make their way back onto the open market. Mergers and acquisitions can contribute as well. When organizations restructure, domains are often left behind in the wake of the transition, with ownership and renewal responsibilities becoming unclear.<\/p>\n<p>We could keep going, but by now the point is probably clear: domains get dropped for all sorts of reasons.<\/p>\n<h3>By the Numbers: Sizing Up the Catch<\/h3>\n<p>Measuring dropcatch activity is not as straightforward as it might initially seem. In theory, a dropcatch occurs when a domain that was previously in use becomes available again and is subsequently re-registered. Detecting such events at scale relies heavily on access to creation date information and a rich history of domain names. One of the clearest signals of a drop is when a domain known to have existed previously appears with a new creation date. Without that information, distinguishing a dropped and re-registered domain from a brand-new registration becomes significantly more difficult.<\/p>\n<p>Throughout this report, we focus on domains that reappear with a new creation date after a prior registration. When a domain changes ownership before it is deleted, it typically retains its original creation date and therefore is not included in our dataset.<\/p>\n<p>The first challenge with creation dates is that their availability varies considerably across top-level domains (TLDs). For generic TLDs (gTLDs), registry operators are required to provide creation dates under <a href=\"https:\/\/www.icann.org\/en\/contracted-parties\/consensus-policies\/registration-data-policy\" target=\"_blank\"><strong>ICANN&#8217;s registration data policies<\/strong><\/a>, making drop activity relatively straightforward to measure. Many country code TLD (ccTLD) registries, however, do not publicly provide creation dates. In addition, there are ways a domain can transfer without having a new creation date. As a result, counting dropcatch domains is fundamentally a data-availability problem.<\/p>\n<p>Another challenge is domain history. The WHOIS record may indicate a domain name was just created today, but was it created in the past? That\u2019s also a non-trivial counting problem. We keep track of every domain we\u2019ve ever seen and have done so for years. When we detect a newly observed domain, we compare it against our historical records to see if we\u2019ve seen it in the past. If we detect a new registration, we consider it a dropcatch. There are quite a lot of nuances in identifying these domains at scale, especially when we look at ccTLDs or domains with public suffixes. Counting is hard!<\/p>\n<p>If we consider only gTLDs, on average, 50,400 dropped domains are re-registered each day, accounting for nearly 20% of all daily gTLD registrations. When we include ccTLDs, we detect around 65,000 dropcatch domains a day and the overall percentage of dropcatch is still about 20%. See Figure 1 for a graphic illustration.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-something-dont-worry-someone-caught-it-figure1.png\" alt=\"Figure 1\"><\/p>\n<p class=\"image-caption\">Figure 1: Overall average of daily dropcatch domains across gTLDs in 2026<\/p>\n<p>To understand where that activity concentrates, we looked at every gTLD with at least one dropcatch domain since the start of the year. Like many things we measure, the distribution follows a familiar long-tail pattern: a relatively small number of observations account for most of the volume. Despite observing dropcatch activity across a large number of gTLDs, approximately 92% of all dropcatch domains came from just 15 TLDs. As a result, much of the analysis that follows focuses on that relatively small number of TLDs that account for most of the observed activity.<\/p>\n<p>Ranking TLDs by dropcatch rate, defined as the share of registrations on a TLD that were previously registered rather than net new names, provides an even more focused view of where dropcatch activity is most prevalent. Figure 2 shows how uneven dropcatch activity can be across gTLDs. Particularly striking are .net and .xyz, where nearly three out of every ten newly observed domains had previously existed and were later re-registered. The com TLD, the largest contributor to overall dropcatch volume, was not far behind at 24.5%.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-something-dont-worry-someone-caught-it-figure2.png\" alt=\"Figure 2\"><\/p>\n<p class=\"image-caption\">Figure 2: gTLDs ordered by dropcatch rate; the rank shown on the Y-axis reflects each gTLD&#8217;s contribution to the total volume of re-registered domains across all gTLDs<\/p>\n<p>While looking at TLDs tells us where drop catching occurs, looking at registrars provides insight into where these domains are ultimately registered. A dropped domain doesn&#8217;t simply spring back to life on its own. Someone has to re-register it, and that registration happens through a registrar. That naturally raises the question: which registrars are seeing the most dropcatch activity? Table 1 shows the top 10 registrars with the highest median number of daily re-registered domains observed in 2026. The results reveal a mix of traditional registrars, domain-investor favorites, dedicated dropcatch services, and registrars that also operate expired-domain auction platforms. As we\u2019ll see in the next section, some of these registrars provide tools for identifying, tracking, and acquiring expired domains.<\/p>\n<table>\n<thead>\n<tr>\n<th>Normalized Registrar<\/th>\n<th>Median daily dropcatch domains<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>GoDaddy<\/td>\n<td>5246<\/td>\n<\/tr>\n<tr>\n<td>Namecheap<\/td>\n<td>4385<\/td>\n<\/tr>\n<tr>\n<td>DropCatch.com<\/td>\n<td>3568<\/td>\n<\/tr>\n<tr>\n<td>Dynadot<\/td>\n<td>2525<\/td>\n<\/tr>\n<tr>\n<td>Spaceship<\/td>\n<td>2390<\/td>\n<\/tr>\n<tr>\n<td>Hostinger Operations<\/td>\n<td>2076<\/td>\n<\/tr>\n<tr>\n<td>Gname<\/td>\n<td>1679<\/td>\n<\/tr>\n<tr>\n<td>GMO Internet<\/td>\n<td>1492<\/td>\n<\/tr>\n<tr>\n<td>Cloudflare<\/td>\n<td>1318<\/td>\n<\/tr>\n<tr>\n<td>Cosmotown<\/td>\n<td>1074<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"image-caption\">Table 1: Top 10 registrars with the highest median daily re-registered domains<\/p>\n<p>One question we attempted to answer was what ultimately happens to the roughly 50,000 dropcatch domains we identified. How many of these domains are being acquired by individuals or organizations for active use, and how many are ending up in the hands of domain investors, auction platforms, monetization services, or registrars holding inventory? It turns out that this is another tricky aspect of measuring dropcatch domains.<\/p>\n<p>To investigate this question, we examined historical WHOIS and DNS data, including registrar transitions, registrant information, nameserver changes, and associations with known parking providers, marketplaces, auction platforms, and dropcatch services. While these data can sometimes identify domains that are clearly parked, monetized, listed for sale, or controlled by known inventory holders, they are often insufficient to reliably determine how a domain is being used or the purpose for which it was acquired.<\/p>\n<p>Many of the same patterns appear across very different ownership scenarios. For example, a registrar change does not necessarily imply acquisition by an end user; domains may be transferred between registrars, domain investors, auction platforms, or organizations that manage large domain portfolios. Registrant information is also frequently protected through privacy services, making it difficult to determine whether ownership has meaningfully changed. A domain may be acquired by an individual or organization and remain parked for weeks before being put to use, while a domain investor may temporarily configure a domain in ways that resemble ordinary hosting. As a result, distinguishing between domains in active use and those that are simply being held is not always straightforward. Ultimately, answering this question was difficult. Once again, counting is hard!<\/p>\n<p>Domains can take many different paths before being registered again, whether through a backorder, a registrar-operated auction, or direct registration after release. Understanding those paths requires a closer look at what happens after a particular domain expires.<\/p>\n<h3>How Domains Get Caught<\/h3>\n<p>While the reasons a domain gets dropped can vary widely, the path a domain takes after expiration is generally more consistent. Although the exact timelines differ across registries and TLDs, most domains follow a similar lifecycle before they can be registered again. The recovery and redemption stages can vary depending on the registry. Most gTLDs follow <a href=\"https:\/\/www.icann.org\/en\/contracted-parties\/consensus-policies\/expired-registration-recovery-policy\/expired-registration-recovery-policy-28-02-2013-en\" target=\"_blank\"><strong>ICANN&#8217;s Expired Registration Recovery Policy<\/strong><\/a>, which provides registrants with opportunities to recover expired domains through an established lifecycle that typically includes a Redemption Grace Period (RGP). Some ccTLDs, however, may have shorter recovery windows or no redemption period at all because their operators are free to define their own lifecycle policies.<\/p>\n<p>We\u2019ve created a simplified version of the lifecycle followed by many gTLDs, adapted from <a href=\"https:\/\/www.icann.org\/en\/contracted-parties\/accredited-registrars\/resources\/gtld-lifecycle\" target=\"_blank\"><strong>ICANN&#8217;s gTLD lifecycle documentation<\/strong><\/a> in Figure 3.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-something-dont-worry-someone-caught-it-figure3.png\" alt=\"Figure 3\"><\/p>\n<p class=\"image-caption\">Figure 3. While the exact terminology and timing vary across registries, the general idea remains the same: expired domains often pass through one or more recovery phases before becoming available for registration again<\/p>\n<p>A domain becoming available for registration does not necessarily mean it will stay available for long. Many organizations and individuals monitor expiring domains and try to register them as soon as they are released by the registry. Some use specialized drop catching services that continuously track domains approaching deletion from the registry and automatically attempt to register them once they become available. As a result, domains can sometimes be re-registered almost immediately after they are released.<\/p>\n<p>Many users interact with these services through backorders rather than monitoring expiring domains themselves. A backorder allows someone to express interest in a domain before it becomes available. If the service successfully catches the domain, it may be awarded to the customer or, if multiple parties expressed interest, made available through an auction. Figure 4 shows examples of domain auctions and associated bids on <a href=\"https:\/\/www.dropcatch.com\/\" target=\"_blank\"><strong>DropCatch.com<\/strong><\/a>.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-something-dont-worry-someone-caught-it-figure4.png\" alt=\"Figure 4\"><\/p>\n<p class=\"image-caption\">Figure 4: Screenshot of a domain auction through drop catching service DropCatch.com<\/p>\n<p>Not all domain auctions involve domains that have completed the deletion process. Some are auctioned before they are released back to the registry. Several registrars operate their own auction platforms for expiring domains, often providing detailed information about them. Users can browse domains approaching expiration, see how much interest they have attracted, review bidding activity, and filter opportunities based on factors such as age, traffic history, or other signals of potential value. Whether the goal is to find a domain with an established history, recover a forgotten asset, or identify a promising investment, these platforms provide another path for acquiring domains throughout their lifecycle. Figure 5 shows examples of domain listings and bidding activity on <a href=\"https:\/\/auctions.godaddy.com\/beta\" target=\"_blank\"><strong>GoDaddy Domain Auctions<\/strong><\/a>.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-something-dont-worry-someone-caught-it-figure5.png\" alt=\"Figure 5\"><\/p>\n<p class=\"image-caption\">Figure 5: Screenshot of expiring domains listed for auction through major registrar GoDaddy<\/p>\n<h3>Who\u2019s Catching&#8230;and Why Does it Matter?<\/h3>\n<p>While we\u2019ll cover a few threat actors using these domains for malicious activities later in this series, not everyone acquiring dropcatch domains has bad intentions. The dropcatch market attracts a broad range of buyers.<\/p>\n<p>Security researchers, including our own team, deliberately catch expired domains as a defensive measure. For example, domains previously associated with brand impersonation risks can be registered to prevent future abuse. Similarly, when a legitimate domain is accidentally dropped, acquiring it can help ensure that it is recovered safely rather than falling into the hands of a threat actor.<\/p>\n<p>Domain investors, often referred to as domainers, may acquire domains they expect to appreciate in value for resale or monetization. Older domains may already have established traffic, search engine visibility, or memorable names that make them attractive investments. In some cases, these domains continue receiving visitors long after their original owner has stopped using them because references to them remain scattered across the web. Whatever the intent, the underlying appeal doesn&#8217;t change: a domain with a history is often more valuable than a blank slate.<\/p>\n<p>For threat actors specifically, the inherited reputation isn\u2019t the only thing valuable about acquiring a dropped domain. They also come with a variety of lingering connections: email intended for the original domain holder (see watchTowr Labs\u2019 <a href=\"https:\/\/labs.watchtowr.com\/the-perils-of-expired-domains-were-reading-your-email\/\" target=\"_blank\"><strong>The Perils of Expired Domains: We&#8217;re Reading Your Email)<\/strong><\/a>, cached search results, inherited web traffic, and in some cases, a ready-made platform for code injection on already compromised sites. Lingering DNS records can also create opportunities for threat actors. We previously discussed dangling CNAME attacks in our blog post, <a href=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/who-knew-domain-hijacking-is-so-easy\/\">Who Knew Domain Hijacking Is So Easy?<\/a>.<\/p>\n<p>For defenders, this is what turns a dropcatch domain from a registration event into a security concern. Every dropped domain represents a potential transfer of trust from one owner to another, and the security implications don\u2019t necessarily disappear when the original registration expires.<\/p>\n<p>In one fascinating case, a content distribution network (CDN) domain used by a marketing service expired after the startup was acquired by a larger, publicly traded company. Major media websites embedded URLs and apparently no one noticed when these began failing. The URLs returned no responses for years. That is, until February 2026, when Shady Squirrel, an actor we\u2019ll detail in the third part of this series, snapped it up and began sending website visitors to malware.<\/p>\n<p>This is just one story of how threat actors use dropcatch domains to further their schemes. We\u2019ll cover many more in the next two parts of this research: Part 2, <a href=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret\/\"><strong>$7 Million in Expired Domains Fuel a Streaming Empire with a Malware Secret<\/strong><\/a>, where we examine Sable Squirrel, a threat actor that has spent millions of dollars acquiring dropped domains, and Part 3, <a href=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\/\"><strong>Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows<\/strong><\/a>, where we explore actors that scavenge expired malicious domains and inherit traffic from previously compromised websites.<\/p>\n<style>\n.savy-seahorse-table {\nfont-size:14px;word-break: keep-all;}.savy-seahorse-table td:last-child, .savy-seahorse-table th:last-child {padding-right:10px;}.code-format {\/*font-family: 'Courier New';*\/}.image-caption {    font-size: 12px;margin-top:auto;}.list-spacing li{margin-bottom:20px}.img-container, .img-container-3-col {display: flex;flex-wrap: wrap;justify-content: space-between;}.img-container img {width: 49%;margin-bottom: 10px;}.img-container-3-col img {width: 30%;margin-bottom: 10px;object-fit: contain;}@media (max-width: 767px) {.img-container, .img-container-3-col {display: block;}.img-container img, .img-container-3-col img {width: 100%;}.grid-container {    grid-template-columns: 1fr!important;  }}@media (min-width: 767px) {.img-50{width:50%;}}.grid-container {  display: grid;  grid-template-columns: repeat(2, 1fr);  gap: 40px;  max-width: 800px;  margin: 0 auto;  align-items: stretch;margin-bottom: 20px;}.grid-item {   display: flex;  flex-direction: column;  justify-content: flex-start;}.grid-item img {  max-width: 100%;  height: auto;width: auto;}\n.youtube-responsive {\n  position: relative;\n  width: 100%;\n  padding-bottom: 56.25%; \/* 16:9 aspect ratio *\/\n  height: 0;\n  overflow: hidden;\n  margin-bottom: 20px;\n}\n.youtube-responsive iframe {\n  position: absolute;\n  top: 0;\n  left: 0;\n  width: 100%;\n  height: 100%;\n}\n.img-400{\nmax-width: 400px; width: 100%;\n}\n<\/style>\n<p><script>\njQuery('.single h1').html('Drop Something? <span class=\"gradient\">Don\u2019t Worry, Someone Caught it<\/span>');\n<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An old domain is not always old trust. Dropcatch activity gives previously registered domains a second life, sometimes under very different ownership. Infoblox Threat Intel | Dropcatch series | Part 1 of 3 Executive Summary Every day, tens of thousands of domain names expire and become available for registration. Some fade away and are never [&hellip;]<\/p>\n","protected":false},"author":397,"featured_media":13994,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[254],"tags":[1813,30,1814,1815,1816,1817,1818,1819,1820,1821],"class_list":{"0":"post-13993","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threat-intelligence","8":"tag-dropcatch","9":"tag-dns","10":"tag-icann","11":"tag-counts","12":"tag-whois","13":"tag-registry","14":"tag-tlds","15":"tag-creation-date","16":"tag-expired-domains","17":"tag-re-registration","18":"entry"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>The Second Life of Expired Domains<\/title>\n<meta name=\"description\" content=\"An old domain is not always old trust. Dropcatch activity gives previously registered domains a second life, sometimes under very different ownership.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/drop-something-dont-worry-someone-caught-it\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Second Life of Expired Domains\" \/>\n<meta property=\"og:description\" content=\"An old domain is not always old trust. Dropcatch activity gives previously registered domains a second life, sometimes under very different ownership.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/drop-something-dont-worry-someone-caught-it\/\" \/>\n<meta property=\"og:site_name\" content=\"Infoblox Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-13T13:00:26+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-13T13:01:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-catch-part-1-thumbnail.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"612\" \/>\n\t<meta property=\"og:image:height\" content=\"408\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Infoblox Threat Intel\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"The Second Life of Expired Domains\" \/>\n<meta name=\"twitter:description\" content=\"An old domain is not always old trust. Dropcatch activity gives previously registered domains a second life, sometimes under very different ownership.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-catch-part-1-thumbnail.jpg\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Infoblox Threat Intel\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/drop-something-dont-worry-someone-caught-it\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/drop-something-dont-worry-someone-caught-it\\\/\"},\"author\":{\"name\":\"Infoblox Threat Intel\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/b6aed8965e3298a0817c16d32c0a67ae\"},\"headline\":\"Drop Something? Don\u2019t Worry, Someone Caught it\",\"datePublished\":\"2026-08-13T13:00:26+00:00\",\"dateModified\":\"2026-08-13T13:01:07+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/drop-something-dont-worry-someone-caught-it\\\/\"},\"wordCount\":2654,\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/drop-something-dont-worry-someone-caught-it\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/drop-catch-part-1-thumbnail.jpg\",\"keywords\":[\"dropcatch\",\"DNS\",\"ICANN\",\"counts\",\"whois\",\"registry\",\"TLDs\",\"creation date\",\"expired domains\",\"re-registration\"],\"articleSection\":[\"Infoblox Threat Intel\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/drop-something-dont-worry-someone-caught-it\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/drop-something-dont-worry-someone-caught-it\\\/\",\"name\":\"The Second Life of Expired Domains\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/drop-something-dont-worry-someone-caught-it\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/drop-something-dont-worry-someone-caught-it\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/drop-catch-part-1-thumbnail.jpg\",\"datePublished\":\"2026-08-13T13:00:26+00:00\",\"dateModified\":\"2026-08-13T13:01:07+00:00\",\"description\":\"An old domain is not always old trust. Dropcatch activity gives previously registered domains a second life, sometimes under very different ownership.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/drop-something-dont-worry-someone-caught-it\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/drop-something-dont-worry-someone-caught-it\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/drop-something-dont-worry-someone-caught-it\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/drop-catch-part-1-thumbnail.jpg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/drop-catch-part-1-thumbnail.jpg\",\"width\":612,\"height\":408},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/drop-something-dont-worry-someone-caught-it\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Infoblox Threat Intel\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/category\\\/threat-intelligence\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Drop Something? Don\u2019t Worry, Someone Caught it\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"name\":\"infoblox.com\\\/blog\\\/\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\",\"name\":\"Infoblox\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"width\":137,\"height\":30,\"caption\":\"Infoblox\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/b6aed8965e3298a0817c16d32c0a67ae\",\"name\":\"Infoblox Threat Intel\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"url\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"contentUrl\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"caption\":\"Infoblox Threat Intel\"},\"description\":\"Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet's inner workings allow us to track down threat actors that others can't see. We're proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox Protective DNS solutions, so customers automatically get its benefits, along with ridiculously low false positive rates.\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/author\\\/infoblox-threat-intel\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"The Second Life of Expired Domains","description":"An old domain is not always old trust. Dropcatch activity gives previously registered domains a second life, sometimes under very different ownership.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/drop-something-dont-worry-someone-caught-it\/","og_locale":"en_US","og_type":"article","og_title":"The Second Life of Expired Domains","og_description":"An old domain is not always old trust. Dropcatch activity gives previously registered domains a second life, sometimes under very different ownership.","og_url":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/drop-something-dont-worry-someone-caught-it\/","og_site_name":"Infoblox Blog","article_published_time":"2026-08-13T13:00:26+00:00","article_modified_time":"2026-08-13T13:01:07+00:00","og_image":[{"width":612,"height":408,"url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-catch-part-1-thumbnail.jpg","type":"image\/jpeg"}],"author":"Infoblox Threat Intel","twitter_card":"summary_large_image","twitter_title":"The Second Life of Expired Domains","twitter_description":"An old domain is not always old trust. Dropcatch activity gives previously registered domains a second life, sometimes under very different ownership.","twitter_image":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-catch-part-1-thumbnail.jpg","twitter_misc":{"Written by":"Infoblox Threat Intel","Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/drop-something-dont-worry-someone-caught-it\/#article","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/drop-something-dont-worry-someone-caught-it\/"},"author":{"name":"Infoblox Threat Intel","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/b6aed8965e3298a0817c16d32c0a67ae"},"headline":"Drop Something? Don\u2019t Worry, Someone Caught it","datePublished":"2026-08-13T13:00:26+00:00","dateModified":"2026-08-13T13:01:07+00:00","mainEntityOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/drop-something-dont-worry-someone-caught-it\/"},"wordCount":2654,"publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/drop-something-dont-worry-someone-caught-it\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-catch-part-1-thumbnail.jpg","keywords":["dropcatch","DNS","ICANN","counts","whois","registry","TLDs","creation date","expired domains","re-registration"],"articleSection":["Infoblox Threat Intel"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/drop-something-dont-worry-someone-caught-it\/","url":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/drop-something-dont-worry-someone-caught-it\/","name":"The Second Life of Expired Domains","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/drop-something-dont-worry-someone-caught-it\/#primaryimage"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/drop-something-dont-worry-someone-caught-it\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-catch-part-1-thumbnail.jpg","datePublished":"2026-08-13T13:00:26+00:00","dateModified":"2026-08-13T13:01:07+00:00","description":"An old domain is not always old trust. Dropcatch activity gives previously registered domains a second life, sometimes under very different ownership.","breadcrumb":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/drop-something-dont-worry-someone-caught-it\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.infoblox.com\/blog\/threat-intelligence\/drop-something-dont-worry-someone-caught-it\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/drop-something-dont-worry-someone-caught-it\/#primaryimage","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-catch-part-1-thumbnail.jpg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-catch-part-1-thumbnail.jpg","width":612,"height":408},{"@type":"BreadcrumbList","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/drop-something-dont-worry-someone-caught-it\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.infoblox.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Infoblox Threat Intel","item":"https:\/\/www.infoblox.com\/blog\/category\/threat-intelligence\/"},{"@type":"ListItem","position":3,"name":"Drop Something? Don\u2019t Worry, Someone Caught it"}]},{"@type":"WebSite","@id":"https:\/\/www.infoblox.com\/blog\/#website","url":"https:\/\/www.infoblox.com\/blog\/","name":"infoblox.com\/blog\/","description":"","publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.infoblox.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.infoblox.com\/blog\/#organization","name":"Infoblox","url":"https:\/\/www.infoblox.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","width":137,"height":30,"caption":"Infoblox"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/b6aed8965e3298a0817c16d32c0a67ae","name":"Infoblox Threat Intel","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","url":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","contentUrl":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","caption":"Infoblox Threat Intel"},"description":"Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet's inner workings allow us to track down threat actors that others can't see. We're proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox Protective DNS solutions, so customers automatically get its benefits, along with ridiculously low false positive rates.","url":"https:\/\/www.infoblox.com\/blog\/author\/infoblox-threat-intel\/"}]}},"_links":{"self":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/13993","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/users\/397"}],"replies":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/comments?post=13993"}],"version-history":[{"count":7,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/13993\/revisions"}],"predecessor-version":[{"id":14012,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/13993\/revisions\/14012"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media\/13994"}],"wp:attachment":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media?parent=13993"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/categories?post=13993"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/tags?post=13993"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}