Two "outside the website" risks kill rankings without your dev team noticing:
- Domain expiration — the domain goes dark, recovery may include re-registration fees and traffic loss.
- DNSBL blacklisting — your IP lands on Spamhaus, SORBS, or similar; transactional emails stop landing; some search engines reduce trust score.
Both failure modes are silent. Both are cheap to monitor. Most teams discover them only after the damage compounds across days or weeks.
Step 1. Enable both checks on the project
Site → Whois and Site → DNSBL are toggleable per project. Turn both on for every production domain you own, including parked or redirect-only domains — those often have the laxest auto-renewal coverage.
Step 2. Configure thresholds
- Domain expiry: 90 / 60 / 30 / 7 days before expiration.
- DNSBL: any blacklist hit triggers an immediate Telegram or Slack alert.
Step 3. Cover every sending IP, not just your origin
DNSBL applies to outbound mail IPs and CDN IPs, not just the origin server. Add every IP your domain MX, SPF, and DKIM records resolve through. A clean origin IP plus a blacklisted Postmark or SendGrid IP still kills deliverability for transactional flows.
Step 4. Build a domain renewal runbook
When the first 90-day alert fires, your runbook should confirm:
- Registrar autopay is active and the payment method is valid.
- DNS hosting service renewal is independent and current.
- WHOIS contact email is deliverable.
- The domain is added to next quarter's manual review calendar.
Three classes of silent failure
- Expired payment method on registrar — most common cause of failed auto-renewal.
- WHOIS privacy hiding contact email — registrar cannot reach you to confirm; many privacy services drop forwarded messages.
- DNSBL only checked on A record IP — but mail goes through Postmark, SendGrid, Mailgun; check those IPs too.
Why DNSBL is an SEO concern, not just a deliverability one
Search engines factor trust signals from multiple sources. A domain listed on major blacklists shows up in brand-search rich results as a security warning. Transactional verification emails — signup confirmations, password resets — stop reaching users, which collapses your acquisition funnel even while organic traffic looks intact. Recovery from a DNSBL listing typically takes 24–72 hours after remediation; prevention is orders of magnitude cheaper.
Connect your domain to a free 2-UA project for combined domain expiration, DNSBL, and SSL monitoring under one dashboard.