Expired Domain and Link Ownership Lab

This short lab shows why an old link can become unsafe even when the page containing it never changes.

Goal

Explain how domain expiration changes the ownership and trust boundary of a link.

Safety rule

Use only the reserved domains in the supplied mock inventory, such as example.com and names ending in .invalid. Do not register, purchase, probe, or visit an expired domain.

Activity

  1. Create a small link inventory with these fields: source page, linked domain, purpose, owner, renewal status, and replacement.
  2. Add five fictional links. Include one project download, one image, one JavaScript library, one old organization, and one email domain.
  3. Mark two domains as expired and reassigned to an unknown owner.
  4. For each affected link, identify the possible impact: misleading redirect, malware delivery, lost image, compromised dependency, misdirected email, or broken historical evidence.
  5. Choose the safest response: remove the link, replace it with a verified official source, preserve a non-executable archival copy, or keep it with a warning and date.

Deliverable

Submit the completed inventory and a short paragraph answering: Why can a trusted old page become risky without being edited?

Discussion

  • Which is more serious: a broken citation, a script loaded from an abandoned domain, or mail sent to an expired domain?
  • When does an archived copy preserve history without preserving an unsafe live dependency?
  • What should an organization record before intentionally retiring a domain?

Source material

First spotted in PTIR: August 20, 2026, Morning Briefing.

Infoblox Threat Intel documented criminal acquisition of expired domains that retained traffic, backlinks, reputation, email, and other lingering connections from prior owners. The report generated this lab because link maintenance sits at the intersection of web development, cybersecurity, software supply chains, and digital preservation. The classroom version uses fictional records and reserved domains so students can reason about the risk without touching live infrastructure.

Consult the original Infoblox Threat Intel report

Written on August 20, 2026