TL;DR: If you own a domain and let that domain expire, Microsoft might disclose all sorts of information to the next owner.
It seems fitting that my first blog post here would be about the process of setting up the domain itself.
Looking for something that spoke to my holistic copy and code background, I figured codeword: creative would be a great brand for me. I went ahead and bought the domain, and a cursory search online didn't reveal anything about previous ownership.
Linking the domain to Microsoft 365
As a copywriter in Germany, having a Microsoft 365 Business plan is something of a necessity. We love Teams here. We love OneDrive. And personally, I really love the reliability of a Microsoft Exchange server for my emails. I already use it for my existing domain, so thought I’d just attach this new one as an alias.
Oh boy. That’s when the trouble started.

Given the general jankiness of the process, I assumed it'd automatically created a new Microsoft 365 account instead of linking properly with the existing one. After a frustratingly endless exchange with Microsoft support, in which I was repeatedly sent copy-paste instructions on how to verify a domain in general – not how to resolve my specific issue – I decided to investigate for myself.
First breach: Password request form
On a hunch, I figured that the email address might actually be _admin, given the underscore and n were visible. So I put that into the password reset form, and... it worked. I received an email to my catch-all email address. It contained information about the 'requesting' party: including her full name and her unassociated alternative (Gmail) email address , which was in CC.
When I spoke to Microsoft next, I told them about the privacy issue, and how I should never have been able to find her name in the first place. After all, ownership of the domain was now in dispute, and I’d made it clear I was not the original owner. Nevertheless, on the phone, staff repeatedly revealed her name to me again, asking if I was her or not (despite always saying I am not).
After a lot of back and forth, I finally got someone a bit more helpful at Microsoft’s German support team*, whom we’ll call Abdul. With his help and a bit of patience, I was given access to the associated Microsoft 365 account in order to remove the domain and close it.
* Hot tip for functionally bilingual English-speakers in Germany: The German-language support for major tech companies seems to be a lot better. I had the same experience with Hewlett Packard. Night and day.
Second breach: Full account details in the backend
That, as you might expect, is what led to the second breach. I’d sort of been hoping that I’d gain access and find everything obviously confidential had been removed. Maybe. Since that would be logical, given the fact the original registrant clearly no longer owned the domain.
But what I actually found was this:

Yes: I now had access to this woman’s full name , full address , email address , and telephone number .
So as a result of merely purchasing an expiring domain I now had access to the full set of this woman’s contact details. I even had the ability, theoretically, to put up a website claiming to be her, if I so chose, and send emails in her name. That really isn't cool.
I tried to explain how bad this was to the better support guy, Abdul, and he seemed to get it and promised it would get escalated to the right team.
Once I’d gone in to verify the severity of the breach – thankfully, there was no active subscription so no apps, so no OneDrive and no emails to worry about – I removed the domain and my own temporary access. Abdul later called me back to finish verifying the domain with my own account, and confirmed that he had also deleted the now orphaned Microsoft 365 account. He'd reached out to the original owner, who confirmed she had no access and didn't seem to know much about the domain itself.
Why this worries me
I’m a woman on the internet, need I say more?
Well, if I need to give you some idea, how about this: Many people just aren't very savvy about domains. The previous owner of my domain apparently wasn't. But she’s no idiot, either – she works in tech herself.
Now think about all the influencers, OF models, YouTubers, and Twitch streamers who might shoot into the limelight unprepared, perhaps casually register domains, and maybe let them expire when they rebrand or whatever.
Think of the dangerous parasocial relationships people have around celebrities these days, or indeed anyone they know only online through their fame or reputation (it was bad enough for me in translation circles!).
Look at the cult of social media and how it can be used to drive hate against any individual for whatever perceived transgression they may have committed (my pronouns are she/her, by the way – hashtag #ally).
Anyone could purchase your expired domain and gain access to all sorts of personal information.
This is dangerous. While we can't expect large corporations to hold our hands every step of the way, we can at least expect them to take appropriate action when there is reasonable suspicion a domain may have changed ownership. Hell, they have better, faster, more automated access to DNS histories and whois records than I do, don't they?
What I think Microsoft should have done
While it is arguably entirely the fault of the original domain owner for not removing her information or the Microsoft account in general, Microsoft still arguably has a duty of care for its customers past and present. There are also numerous guidelines on appropriate data retention periods.
It’s right that I had to go through various loopholes to verify the domain, but Microsoft doesn't seem to have any established process. Indeed, it took many back and forth emails and annoying phone calls (aside from dear Abdul, who did actually help) to even get anywhere.
Further, since they had already verified that I own the domain now, it shouldn't have been possible to gain access to the existing account with all the backend account information still intact. After all, I’d repeatedly told them that I wasn't this person, and that I didn't like her information being shared so freely with me.
In an ideal world, Microsoft would have had some means to remove all personal details from the account before giving me access. Better yet, it would have been possible to simply freeze that old account, giving the previous owner 30 days to object if needed, and allow me to add the domain once complete.
In short, I should not have been given access to personal information I never needed to see.
How we can avoid similar issues in future – Microsoft and beyond
The big lesson here is to be careful when you let domains expire, especially those linked to email addresses you actively used, or accounts you may have had in various places online and in the real world.
Why it’s worth paying that annual fee forever
My general tip is to never let any domain you actively used expire . Naturally, there are exceptions where it’s still going to be pretty safe. But that’s a good general rule.
Personal security
There are strong personal security reasons , as outlined above, to never risk someone else buying the domain. That could lead to others being able to impersonate you and/or gain access to your information – even without the obvious indicators they shouldn’t do so, as in Microsoft’s case.
SEO
But there are also strong SEO reasons . Even if you are no longer in the same line of work and no longer running your own website, there could still be some value in at least redirecting it to your LinkedIn, GitHub, or other online profile. You could also consider selling or otherwise transferring the domain to a respectable former competitor. Either way, that’s link juice that’s otherwise going to waste.
Protect your brand and network
Which leads me to the other reason you might want to register the domain: protecting your brand and network . While transferring an older translation-related blog over to my English Rose Berlin domain a while back, I did a full link audit. I found several former translators had left the profession and abandoned their domains. Some of these links were now pointing to domain registration sites or 404s, while others were pointing to everything from online casinos to big evil translation agencies. Yes, thanks to their failure to protect their previous domain, my website was now linking to the same unethical companies that made their businesses so unviable they quit the profession.
Equally, when checking out different ethical networks people are part of, I came across another example where the domain linked to an interest-sounding ethical network had expired, and it now led to an online casino. Thankfully, it wasn't malware, but links to online casinos and similar can seriously hurt a website’s SEO . Do the friends, partners, and whoever else who might link to you deserve that?
So what is a domain owner to do?
Retain your domain, forward any emails it still receives as necessary, and consider putting up a simple static page in plain HTML to inform visitors that it’s the end of this domain’s journey, or redirect it to an appropriate alternative.
Redirection is a relatively simple process and the company you bought your domain from will most likely be able to sort it out for you. If you require additional domain and DNS setting support, or help putting up an attractive static page, get professional help from someone like me. It’s a small task that could save everyone a lot of stress down the road.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.