Creator Hubs and Community Boards

How to Check Whether an Expired Service Domain Has Been Turned Into an Advertising, Gambling, or Malware Website

Signs That an Expired Domain Has Changed Hands When a domain registration expires and the original owner does not renew it, the domain enters a grace period before becoming available for purchase. After that period, anyo

An old domain name is not permanent proof that the original service still controls the website. For a typical generic top-level domain, an expired registration may pass through recovery and deletion stages before becoming available for someone else to register. ICANN describes a 30-day Redemption Grace Period followed by a five-day Pending Delete stage for domains that reach that part of the lifecycle. Exact handling can still vary by domain type and registrar.

The safest question is therefore not simply, “Does the old address still open?” It is: Does the domain still belong to the former service, has it been repurposed by someone else, and is the current site dangerous?

User reviewing domain-registration data, ownership history, and archived pages to determine whether an expired domain has changed hands.

Computer screen displaying multiple red security warnings, illustrating phishing, malware, and fake alert risks on a suspicious domain.

Check the Domain Without Opening the Live Website

Do not begin by visiting an unfamiliar expired domain in your normal browser. A repurposed site may redirect immediately, request notification permission, display a fake warning, or attempt to make you download a file.

Start with checks that do not require interacting with the live page.

Compare the old website through a web archive

Search the domain in the Wayback Machine and open captures from the period when the original service was active. Look for the old company name, logo, legal operator, contact details, shutdown notice and any message about a replacement service.

The Wayback Machine allows searches by URL and date, but its records are not necessarily complete. A missing page may never have been captured, may have been blocked or may depend on files that were not archived. Pay attention to the capture date and avoid following links that leave the archived version for the live web.

Record the final date on which the old service clearly controlled the site. That gives you a reference point for later checks.

User cautiously examining a former service domain now displaying casino content, suggesting the website has changed ownership or been repurposed.

Review current registration information

Use a WHOIS or RDAP lookup to inspect the domain’s current registration information. KISA operates a WHOIS lookup service, while ICANN describes RDAP as the standardized replacement for WHOIS for accessing current domain-registration data.

Compare the current record with any old records or screenshots you can find. Useful fields include the creation or update date, registrar, nameservers and domain status.

A recent registration date after the original service closed may indicate that the domain expired and was registered again. A new registrar or completely different nameservers can also support the conclusion that control changed. These signs do not prove that the new operator is malicious. Registration information may also be hidden for privacy, and ordinary infrastructure changes can alter some fields.

Check its security reputation

Google Safe Browsing provides a Site Status tool that shows whether Google currently considers a site dangerous because of malware, phishing, unwanted software or related threats. Browsers using Safe Browsing may also display a warning before a user opens a known harmful page or downloads a dangerous file.

A dangerous-site warning is a strong reason not to proceed. A clean result is not proof of safety; it only means the domain has not currently been flagged by that system. A newly repurposed or recently compromised site may not yet appear in reputation databases.

Separate a Change of Ownership From Malicious Activity

A domain can change hands without becoming a malware site. Use the evidence to classify what has happened rather than treating every change as the same risk.

What You FindWhat It SuggestsAppropriate ResponseOld archive and current site identify the same legal operatorThe original organization may still control the domainVerify through another official account before signing inRegistration details changed after the service closedThe domain may have changed ownershipDo not reuse old bookmarks or login detailsPage shows a domain-sale notice or generic advertisementsThe original service has probably ended and the domain has been repurposedTreat it as unrelated to the former serviceDomain redirects to casino or betting contentThe address has been repurposed or compromisedClose it and do not interactPage requests a password, card number or verification code using the old brandPossible phishing or impersonationLeave immediately and verify through the company’s current official channelPage requests an installer, browser extension, codec or “security update”High malware riskDo not download or run anythingGoogle Safe Browsing or the browser displays a danger warningKnown or suspected unsafe contentDo not bypass the warningNo warning appears and ownership is unclearSafety remains unconfirmedDo not register, pay or download filesKISA has documented search results that routed users through unrelated domains to gambling websites. It has also warned about fake software-download pages that imitated an official service, appeared prominently in search results and delivered information-stealing malware. These examples show why a familiar name or high search position should not be treated as evidence of authenticity.

Advertising alone does not prove malicious activity. A parked domain may simply display commercial links while waiting to be sold. The important point is that the old domain should no longer be trusted as an official route to the former service.

Do Not Test Redirects or Download Buttons Yourself

If you need to know where the domain currently redirects, do not repeatedly reload it or press its buttons. Use a security service that inspects the address remotely, or ask an IT or security professional to examine it in an isolated environment.

Ordinary users should not:

  • Accept browser notifications.
  • Allow clipboard, camera, microphone or file access.
  • enter an old username or password.
  • Download an application allegedly needed to view the website.
  • Pay to “restore” an account from the former service.
  • Disable a browser warning to continue.

Even if the current page uses HTTPS, that only protects the connection to the current operator. It does not prove that the operator is the original service or that the site is safe.

Act According to What Was Exposed

If you only opened the page, close it without accepting permissions. Check the browser’s recent downloads and site permissions. Remove notification access for the domain and run an updated security scan if the page behaved unusually.

If a file was downloaded but not opened, delete it and scan the device. If you ran an installer, installed an extension or opened an unknown application, avoid sensitive logins until the device has been checked. KISA recommends using updated security software, scanning for malicious files and contacting its 118 service when infection is suspected.

If you entered a password, change it from a device you trust. Secure the associated email account first, then update every account using the same or a similar password.

If you entered card details or made a payment, contact the card issuer through its official app or the telephone number printed on the card. Ask about blocking the card, stopping recurring charges, replacing the card and disputing unauthorized transactions.

Before reporting the incident, preserve the domain, full URL, screenshots, redirect destination, downloaded filename, merchant name, payment receipt and time of access. KISA accepts cybersecurity inquiries through 118 and provides an incident-reporting route through its Boho service.

Classify the Domain Before Deciding Whether to Use It

A practical final classification is:

Still official: The former service, its parent company or another established official account clearly confirms the domain.

Repurposed but not proven malicious: The domain now contains unrelated advertising, a sale page or another legitimate project. Stop treating it as part of the former service.

Unsafe: The site triggers security warnings, requests suspicious downloads, imitates an old login page, redirects to gambling or asks for unexplained payments.

Unverified: Registration and archive information do not establish who currently controls it. Do not log in, register, pay or download anything.

The safest process is:

Check the archive → inspect current registration data → review security reputation → compare the old and current operators → interact only when the official connection is confirmed.