
A short domain appears at auction. It is easy to remember and has been around for a decade. It has old backlinks, a trickle of visitors, and a name that would look good on a business card. It feels as if someone else has already done the hard part and all you need to do is buy it and put up a new website.
But a domain is not an empty shop whose previous tenant took everything with them. Its history stays behind. Along with a good name, you may inherit old spam campaigns, suspicious backlinks, a poor email reputation, or visitors expecting something entirely different. Sometimes the baggage is much more serious.
Research by Infoblox shows that roughly 65,000 “dropcatch” domains are registered every day — addresses acquired as soon as the previous owner’s registration expires. Most buyers are not criminals, of course. Yet old domains have become valuable raw material for fraud, illegal streaming, gambling, and malware distribution.
What are you actually buying?
At first glance, you are buying a name. In practice, you are also buying its age, links from other websites, residual traffic, and the trust it may have earned with users, search engines, and some security systems.
This is where the story gets more interesting. Infoblox described a group known as Sable Squirrel that controls more than 10,000 domains. Researchers confirmed spending of over $430,000 on approximately 160 individual purchases and estimated the group’s total investment in expired domains at more than $7 million. Some of those addresses had previously belonged to genuine businesses, media outlets, and charities.
Why would anyone pay that much for someone else’s old domain? Because a familiar or credible-looking address does not immediately raise a red flag. Automated systems may not identify it as dangerous straight away either, because it comes with a long and once perfectly respectable history. In this case, more than 31,000 malware samples were linked to domains controlled by the same group. Some addresses showed ordinary visitors a football-streaming website while serving as communication channels between infected computers and attackers.
You can be an honest buyer and still inherit a problem
Suppose you have found an excellent name for a new online store. You have no bad intentions, you are not planning a scam, and the domain’s possible SEO value is attractive. Unfortunately, that does not mean you are starting from zero.
The previous owner may have sent spam, sold questionable products, published pirated content, or distributed malicious software. The domain may therefore appear on blocklists, carry a large number of worthless backlinks, or attract an audience unrelated to your business. Old DNS records and forgotten connections to services that no longer exist create another set of risks.
The consequences often become visible only after the new website goes live: messages land in spam folders, an advertising platform rejects the address, antivirus software flags the page, or customers encounter old warnings. At that point, the bargain no longer looks quite so cheap.
Seven checks to make before bidding
1. See what used to be on the website. Open the Wayback Machine and review several snapshots from different years. One clean version is not enough; a domain may have changed owners and purpose several times.
2. Check its security reputation. Search the address with Google Safe Browsing, VirusTotal, and the Spamhaus Reputation Checker. A clean result is not an absolute guarantee, but a warning is a very good reason to stop and investigate.
3. Do not merely count backlinks. Check where they come from. If most originate from gambling, piracy, pharmaceuticals, or suspicious download pages, the supposed SEO advantage can quickly become a liability.
4. Review the registration and DNS history. ICANN Lookup shows current registration details, while specialised DNS history services can reveal previous servers, MX records, and infrastructure changes. Frequent changes are not proof of abuse, but they deserve an explanation.
5. Search for the domain name itself. Put it in quotation marks, then add words such as “scam”, “spam”, “malware”, “review”, and “complaint”. Search for the former company or brand name as well. Five minutes here can save weeks of reputation repair.
6. Do not pay for age as if it were a guarantee. An older domain is not automatically better. If its previous topic and audience have nothing to do with your new project, the old links and traffic may be worth very little.
7. Rebuild the technical setup from scratch. Create a clean DNS zone, remove unnecessary records, and configure SPF, DKIM, and DMARC correctly. Monitor email delivery and do not copy the old configuration simply because it is already there.
When is an expired domain worth buying?
An expired domain can be an excellent purchase when the name is genuinely strong, its history is clean, and its previous subject is close to your new project. Good natural backlinks, a relevant audience, and a clear business reason for acquiring it can justify the price.
However, the auction price is only one line in the calculation. Add the time required for research, possible reputation repair, email delivery problems, and the risk that old associations will follow the domain into your new brand. The simplest rule is this: never buy authority sight unseen. First find out how the domain earned its reputation, who used it before, and what still follows its name around the internet.






0 Comments