A-R53-13

ICANN Domain Status is Pending Deletion

Risk:
High
CWE:
None

Domains marked by ICANN as pending deletion will be available for re-registration by third parties within 30 days


Details

Domains provide the backbone for all online services. ICANN (the Internet Corporation for Assigned Names and Numbers) is the ultimate authorative body for domains and the individual registrars and hold their own records tracking the status of domains. This tracking is useful for monitoring domains that are migrating between registrars and serves as a definitive source of truth regarding the status of a domain.

A domain with ICANN status of “pendingDelete” marks a domain as scheduled for deletion where the domain will become unregistered, making it available for registration by others. This allows any third party to register the domain and gain full ownership of it.

Domains are an important part of your organisation’s assets and intellectual property as they manage the authority and identity of all assets under that domain. Expired domains are a security risk as the new owner of the domain can effectively imitate your ownership and present themselves as the same entity that originally owned the domain.

If you have decided to release the domain, you should ensure that all traces of authority associated with it - such as email accounts or registration data on third-party services - are removed and any links are broken. This will be different for each third party but needs to be thorough as accounts can have their access reset allowing the new owner of a domain full access to any accounts owned by that domain. Purging these third party accounts prevents the new owner of the domains any access to old data.

If you do not wish to release the domain, you should contact your registrar as soon as possible. As ICANN has listed your domain under “pendingDelete,” it will be removed from your ownership within the next 30 days.

Remediation

If you intend to delete the domain, make sure you follow a thorough decommissioning process to eliminate any associations between the domain and your organisation’s data, whether directly owned or hosted by third parties.

For domains that are not intended to be deleted, contact your registrar immediately to retain ownership. If you have self-service capabilities through a cloud platform, quickly access your self-service dashboard to see if you can renew or otherwise secure the domain. Act promptly to protect your domain from being re-registered by someone else.

Domains are critical to your organisation and losing them is a long, protracted and costly battle. It’s best to get monitoring of your domains to ensure that your domains remain in your possession and your data and identity protected. SkySiege monitors all your domains covering their status and functionality such as email deliverability, maintenance activity and more.

Discover if you're vulnerable

SkySiege Cloud Security Assessments scan for this issue and provide same-day reports..
Available for individual projects or organisations.

Related Tests