
Q4 is when most small businesses do the bulk of their year’s revenue, and it’s exactly when nobody has time to deal with a lapsed domain or an expired SSL certificate. A ten-minute check now avoids a very bad afternoon in November.
What to check before Q4 hits
- Renewal dates. Confirm your domain isn’t expiring between now and January. A missed renewal during your busiest season is the worst possible timing. Domains get a grace period after expiring, but your site and email can already be down during it, and a squatter can grab the name the moment it actually releases. If you’ve ever gotten a renewal notice that looked almost real but wasn’t, you’re not imagining it — scammers specifically target public renewal data to send fake invoices.
- WHOIS/contact info. If your renewal notice would go to a departed employee’s inbox or an address nobody checks, you won’t see it until it’s too late. This got more complicated in 2025: ICANN’s shift from WHOIS to RDAP changed how registrant and organization fields are treated, so it’s worth confirming your organization and admin contact fields are still accurate under the new system, not just that an email address exists.
- SSL certificate expiration. An expired certificate throws a browser warning at exactly the moment a customer is trying to buy something, and that warning alone can tank a checkout. Certificate lifespans are also shrinking industry-wide, down to 200 days as of last year and headed lower, so a renewal cadence that worked fine a year ago may already be too infrequent.
- DNS redundancy. If your DNS runs through a single provider, an outage during peak traffic takes your whole site down with it, with no failover to catch it. It’s one of the five domain security controls most companies still skip entirely, often because it’s assumed to be an enterprise-only concern rather than a single point of failure any business can hit.
- Domain lock status. Make sure transfer lock is on. Attackers often target high-traffic periods, when a distracted team is less likely to notice something’s wrong. Transfer lock and registry lock aren’t the same protection — transfer lock stops casual unauthorized moves, while registry lock adds a manual verification step for anything more determined. For a founder juggling Q4, having both matters more than usual.
Why this is worth doing now, not in November
Every one of these takes minutes to check and hours (or a lost sales day) to fix if it goes wrong at the wrong moment. September to early October is the window when founders have the bandwidth to do this calmly, before the holiday rush eats every spare hour.
What to do next
Pick a day this week, run through the five checks above, and fix anything that’s off. If you don’t know where to look for any of them, that’s usually a sign it’s worth having someone else check.
Get your domains Q4-ready. 101domain can review your renewal dates, DNS setup, and lock status in one pass.