To check a domain’s registration expiry, look up its registration record; to check an SSL/TLS certificate’s expiry, inspect the certificate currently served by the website. They are separate dates, and a domain checker that shows both should label them separately. For a gTLD such as .com, start with ICANN Lookup for registration data; for a combined registration and live-certificate view, Geekflare’s checker describes checking registration through RDAP and certificate validity through a live TLS handshake.
What a domain expiry checker is actually checking
“Domain expiry” can refer to two different events. Domain registration expiry concerns the registration of the name with its registrar and registry. Certificate expiry concerns the validity period of the TLS certificate a particular website host presents when a secure connection is made. A TLS certificate may be renewed independently of the domain registration, so one date does not establish the other.
| Check | What expires | Where the date comes from |
|---|---|---|
| Domain registration | The registration of the domain name | Registration data published by the relevant registry or registrar, commonly accessed through RDAP for gTLDs |
| TLS certificate | The validity period of the certificate served by a host | A live connection to the host and inspection of the certificate it presents |
That distinction matters when a tool puts both dates on one screen: check the field label, not just the date. ICANN Lookup is a registration-data lookup, not a TLS certificate checker. Geekflare describes its combined checker as using RDAP for registration expiry and a live TLS handshake for the certificate expiry, with the current certificate issuer also reported. See the checker’s description.
How to check when a domain registration expires
- Open ICANN Lookup and search for the domain name. This is a free public RDAP lookup for gTLD registration data.
- Find the returned registration event and read its label. For example, a result may distinguish “Registrar Registration Expiration Date” from “Registry Expiry Date”; these are not interchangeable labels.
- Check the sponsoring registrar’s account for the domain’s renewal status and operational deadline. Use that account as the practical authority when a renewal decision is time-sensitive.
- If the date is absent, unclear, or different from the registrar’s account, do not assume the registration is safe to leave until the later date. Contact the registrar and ask which date governs renewal for the domain.
ICANN announced that, from 28 January 2025, RDAP is the definitive source for generic top-level domain (gTLD) registration information in place of sunsetted WHOIS services. ICANN’s 27 January 2025 announcement describes that change. It applies to gTLD registration data; country-code TLDs can have different registry practices and rules.
#1 Best Overall
Why the registrar and registry dates can differ
Some RDAP responses can expose both a registrar-level and a registry-level expiry event. ICANN’s 30 September 2025 notice distinguishes the “Registrar Registration Expiration Date,” represented by the RDAP event action registrar expiration, from the “Registry Expiry Date,” represented by expiration. The dates may differ, including when a registry auto-renews a name but the registrant or registrar has not yet renewed it. Read ICANN’s registrar notice.
For that reason, a public lookup date is useful information, but it is not a substitute for checking the registrar account’s renewal state. Preserve the field name and source when recording a date; a bare “expires on” value can conceal which event the checker actually returned.
How to check when an SSL/TLS certificate expires
Use a checker that makes a live TLS connection to the website host and reads the validity end date in the certificate presented in that connection. A combined checker may show this alongside registration data, but it should identify the certificate date separately and ideally report the issuer as well. Geekflare’s checker description says it uses a live TLS handshake for the current server certificate.
Rank #2
- 8 1/2 x 11 Teacher Record Book with Teacher's daily schedule
- Special duties
- Supplementary data sheets
- Grade recording sheets for 40 weeks with shading every other two lines
- Perforated grade recording sheets - write the class list only once
Be specific about the host you check. A certificate observed on one website host is not a domain-registration date, and it does not establish what another host or service for the same domain presents. If your concern is a particular website, check that website’s host rather than treating the certificate result as a property of the name registration.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Why expiry checkers show different dates—or no date
They may be reporting different registration events
A tool that labels a registrar expiry event can show a different date from one that reports the registry expiry event. ICANN explains this distinction and the possibility of divergence in its 30 September 2025 notice. Compare labels and sources before concluding that one checker is wrong.
They may query or cache data at different times
Lookups can reflect data at different points in renewal processing, and third-party tools may cache results differently. The Query.Domains checker notes that processing and caching can affect displayed dates. For a deadline, check the registrar’s own account and confirm the renewal status rather than relying on an unexplained date from a third-party page.
Rank #3
- Includes (one)Heavy Duty, levant-grain, imitation leather binder . Available in Black or Burgundy
- 10 Standard Wording stock Certificates. (Wording will reflect entity type)
- 7 position Index Tabs
- Stock Transfer Ledger or Membership Roll Sheets.
- If you want us to customize a kit for you, just search for our new "Corpkit Customized" kit!
Public registration data is not identical for every domain
ICANN says that returned fields can vary according to the registrar, registry operator, applicable law, and policy. The lookup may use WHOIS failover if queried information is unavailable through RDAP, and it cannot guarantee every field for every domain. TLD publication practices also vary. ICANN Lookup’s FAQ explains these limits. A blank expiry field therefore does not, on its own, prove that the checker is broken or that the domain has no expiry.
Unregistered or reserved names, some TLDs, and closed brand TLDs are examples for which a public expiry field may not be available, according to Query.Domains. Treat those examples as vendor guidance, not a universal rule for every registry.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
The certificate check and registration lookup are separate observations
A certificate checker observes what a host presents during a live connection. A registration lookup reads published registration data. Their dates can differ without either result being contradictory because they describe different things. A certificate result can also be unavailable when the checker cannot establish the relevant connection; that is not evidence about the registration record.
Rank #4
What to do when a domain is close to expiry
- Sign in to the sponsoring registrar and verify whether automatic renewal is enabled, payment details are current, and the renewal is completed or pending.
- Use the registrar’s account and support channel to resolve a mismatch between its renewal information and a public RDAP result.
- Renew before the displayed registration deadline rather than planning around a possible grace period.
- If the name appears to have expired, contact the registrar promptly. Renewal, redemption, deletion, and release rules vary by TLD and registrar.
Some gTLDs have lifecycle stages such as an auto-renew grace period, redemption period, pending delete, and eventual release. The stages and their timing are not universal: country-code TLDs have their own rules, and the example duration ranges described by Query.Domains should not be treated as a promise about any particular domain. Do not use a general lifecycle chart to delay a renewal.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.One-time checks or ongoing monitoring?
A one-time checker answers what its source reports now. Monitoring is useful when you need repeated checks or reminders, especially if you are responsible for multiple domains or hosts. Choose a monitoring service only after confirming the details that matter for your use case; the reviewed sources do not establish a vendor ranking for accuracy, alert delivery, price, or uptime.
| Decision point | What to verify |
|---|---|
| Registration source | Does the tool use RDAP, a WHOIS fallback, or another source, and does it label the expiry event? |
| TLD coverage | Which TLDs are supported, and what does the tool show when a registry does not publish a date? |
| Certificate coverage | Does the service check the host and the certificate currently presented, separately from registration data? |
| Check frequency | Is the lookup on demand, or does the service repeat checks and send reminders? |
| Operational response | Can you still verify the registration and renewal status in the registrar account? |
Or skip the browser setup
ScreenshotNeo is not a domain-expiry or certificate-expiry checker: it captures a webpage as an image or PDF. It can be useful if you want to keep a visual record of a checker result, but the screenshot does not verify the date or replace the registrar’s renewal information. ScreenshotNeo also has an MCP server with screenshot, page-info, and PDF tools for AI agents.
One GET request captures the checker page; the API does not interpret its expiry result. See the ScreenshotNeo documentation.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://geekflare.com/tools/domain-expiry-checker/ -o shot.webp
ScreenshotNeo removes known consent banners, newsletter popups, and chat widgets before capture, with each cleanup step configurable. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed; responses include X-Page-Verdict and X-Billed headers. The free plan includes 1,000 screenshots per month without a card; paid plans start at $5 for 3,000 screenshots. The MCP server lets AI agents take screenshots. Sign up for the free plan.
How much confidence should you put in a lookup?
RDAP is an established infrastructure, not a guarantee that every public response contains every field or that every checker interprets a returned event identically. ICANN’s RDAP information page estimated more than 10 billion RDAP queries per month across all types of RDAP servers in December 2024, and listed more than 40 known client implementations and more than 15 known server implementations in its December 2024 snapshot. Those figures describe ecosystem use and implementations, not the accuracy of a particular checker. ICANN’s information for RDAP users provides that context.
The reviewed sources do not establish an independently measured checker-accuracy rate or a rate of domain losses caused by expiry. Treat a public lookup as a useful signal; use the registrar account to make renewal decisions and a live TLS observation to assess the certificate currently served by a host.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

