Canceling an Old Domain Name: The Hidden Risk of a Data Breach

Photo of a weathered, overflowing mailbox with envelopes spilling out, accompanied by the text “Ten euros or a data breach,” a subtitle explaining that canceling an old domain may seem like a savings but opens the door to data leaks, and the “Protect Old Domains” button, featuring the New Yard logo.

Imagine this: it’s the beginning of the year, and as an IT manager or entrepreneur, you’re reviewing your fixed costs. Among the subscriptions, a list of domain names catches your eye. One belongs to a company you acquired years ago. One is for an old product name. One is from before the last rebranding. No one uses them anymore; the websites have been offline for ages. So you think: why are we still paying for these? A few clicks later, they’re canceled, and you’ve saved a few tens a year.

It feels like a logical cleanup. And that’s exactly where the problem lies.

In early June 2026, RTL Nieuws published an investigation that made this painfully clear. An ethical hacker re-registered expired domain names belonging to debt administrators. Within a few weeks, he gained access to 258 financial records of people in debt, including names, addresses, bank account numbers, and even medical information. The debt management agencies had canceled their old domain names to cut costs. One of them had canceled twelve domains, saving 120 euros per year. As a result, the personal data of hundreds of vulnerable people was exposed.

This isn’t a problem that affects only administrators. It can happen to any organization that has ever used a domain name and later canceled it. In this article, I’ll explain exactly what goes wrong, what risks you face, and what you should do instead.

What does it actually mean to cancel a domain name?

A domain name is more than just your website’s address. Your email is also linked to that same domain. Think of [email protected] or an employee’s email address. As long as you own the domain, that email will be delivered to you.

When you cancel a domain, something happens that many people don’t realize. The registration expires and the domain becomes available. Anyone in the world can then re-register it, often for just a few euros. Whoever registers the domain will, from that moment on, receive all new email still sent to it. Not your old, already-delivered messages—those were delivered and are long gone. But everything that customers, suppliers, banks, and government agencies continue to send because they still have the address in their systems.

There is a big difference between the two options:

  • Cancel and forget about it: you’ll save a few euros, but you’ll lose all control over who will be reading your mail at your old address.
  • Keep it and manage it properly: you pay a small annual fee, but you retain control over the domain and any email that comes in.

What risks do you face if you let an old domain name expire?

The risks are greater than most organizations realize. Here are the most important ones:

  • Intercepted email. A new owner of the domain can read all incoming mail. This could include invoices, contracts, or sensitive personal data.
  • A reportable data breach. If personal data falls into the wrong hands, it constitutes a data breach that you must report to the Dutch Data Protection Authority. That costs time, money, and trust.
  • Account takeovers. Many services send password reset links to an email address. In some cases, anyone who controls the email account for an old domain can take over old accounts.
  • Misuse of your name. Malicious actors can send phishing emails from your old domain that look legitimate and include your company name.

The figures show that this is not just a theoretical risk. In 2024, the Dutch Data Protection Authority received a record number of 37,839 data breach reports, an increase of nearly fifty percent compared to the previous year. Email errors and phishing have been among the leading causes for years. Source: Dutch Data Protection Authority, Data Breach Report 2024 (https://www.autoriteitpersoonsgegevens.nl/documenten/rapportage-datalekken-2024).

And an incident is costly. The average cost of a cyberattack to an affected organization is around 103,976 euros, with a median loss of 30,000 euros. Source: Lumen Group, based on the AP Report 2024 (https://www.lumengroup.nl/ap-datalekken-rapportage-2024/). Compared to ten euros per year for a domain, the math is easy to do.

How can you keep old domain names secure without any unnecessary hassle?

The good news is that the solution is simple and inexpensive. It mainly requires attention, not a large budget. The key is not to cancel an old domain, but to phase it out deliberately and gradually.

Start by simply keeping the domain registered and monitoring incoming email for a while. That way, you’ll see exactly who is still sending emails to the old addresses. You can then actively contact those senders to let them know that the address is no longer in use, providing the correct alternative. As a result, the volume of email will naturally decrease.

Only when almost no mail is coming in anymore should you clean up the mail records (MX). Senders will then receive a polite bounce message and know that the address no longer exists. You should keep the domain itself registered and monitor it as a protected, inactive domain, so that it never becomes available to anyone else. This approach is also known as domain name protection.

Isn’t ten euros a year a waste for a domain you don’t use?

That’s a valid question, and I get asked it often. Below are the most common objections, along with my honest answers.

“We don’t use that domain anymore, do we?” That’s true, but the outside world doesn’t know that. Customers, suppliers, and government agencies continue to send emails to old addresses, sometimes for years. The ethical hacker featured in the RTL investigation was surprised himself by how much email was still coming in to inboxes that were officially no longer in use.

“That’s something for large organizations, not for small and medium-sized businesses.” I want to be honest here. Smaller companies report fewer data breaches, but that doesn’t mean they’re more secure. In fact, there’s often less visibility into who’s managing them. A canceled domain isn’t a matter of company size, but of whether someone is keeping an eye on it.

“Our IT partner will take care of that.” Maybe. But domain management often falls through the cracks, especially after an acquisition or when a service has been phased out. Ask specifically who is responsible for the domains you’ve ever owned—not just the ones you’re currently using.

“We’ve merged; that old name is gone.” Just because the name is gone doesn’t mean the email is gone. As IT lawyer Arnoud Engelfriet notes in the RTL investigation: you can’t just say that a name has been discontinued and leave it at that. The responsibility for the data remains.

What should you do with domain names you no longer use?

A practical checklist to eliminate this risk in your organization:

  1. Make a list of all the domain names you currently own or have ever owned, including domains from acquired companies and former brand names.
  2. During the initial period, monitor the incoming email at the old addresses so you know who is still sending messages there.
  3. Contact the senders and let them know that the address is no longer in use, providing the correct alternative.
  4. Only after that, once the flow of email has dried up, should you delete the mail records (MX). Senders will then receive a bounce message, and the domain will remain registered.
  5. After that, keep the domain registered and monitored as a protected, inactive domain so that it never becomes available to anyone else.
  6. Specify who has management and ownership responsibilities so that they are not left to no one.
  7. Make domain management a standard part of every merger, acquisition, migration, and rebranding.
  8. Respond to warnings from SIDN, the organization that manages Dutch domain names, if a sensitive domain is about to expire.

Who monitors your old domains?

Domain management is not some exotic specialty. It’s simply part of good IT management. Yet we regularly see at SMBs that old domains fall through the cracks. Not because of a lack of will, but because they’ve simply slipped under the radar amid all the migrations and acquisitions. It’s precisely these forgotten corners that pose the greatest risk, because no one is paying attention to them anymore.

As an MSP, we handle these kinds of matters as a matter of course for our clients. In our view, keeping old domains registered and monitored as protected, inactive domains is simply part of responsible IT management.

Want to bounce some ideas off me about your domains?

Are you unsure whether your organization still has any old domains that pose a risk? If so, now is a good time to take a close look at them. The warning from industry associations following the RTL investigation shows that this is an issue right now, not something that will happen in the future. A forgotten domain that expires today could be registered by someone else as early as tomorrow.

We’d be happy to have a no-obligation conversation with you. During a brief introductory meeting, we’ll work together to identify the risks and determine what a logical first step would be. Visit newyard.nl or schedule an introductory meeting right away.