A small manufacturer's contact form sent enquiries to an address at a domain the owner had used years ago for a previous business. He had let that domain lapse, and it was re-registered by a stranger.
For eight months, every enquiry from the website went to the stranger's mailbox. Whether anyone ever read them is unknown. The manufacturer noticed only when a long-standing customer asked why nobody had answered.
The form recipient was changed and the owner started checking that a test submission arrives every quarter.
How a form ends up pointing at a dead domain
The business made industrial fittings and had a team of eleven. Its website had been rebuilt twice. The first version was built in the owner's earlier trading name, with an address like [email protected]. When he rebranded, the company moved to a new domain and new mailboxes, and he let the old domain go because renewing it seemed pointless.
The second rebuild copied the contact form's settings across, including the "send to" field, as part of a theme change. Nobody retyped it, because the form had always worked. It went on appearing to work, in the sense that the visitor saw a green "Thank you, we will be in touch" message. That message appears when the website hands the mail to the mail system, not when a human reads it.
So the website told every enquirer that all was well while the words went to someone else.
What happens to a domain you let go
An expired domain does not vanish at once. The exact periods vary by registry and registrar, but the usual sequence is a grace period of up to about a month and a half where the owner can still renew at the normal price, then a redemption period of about thirty days with a heavy fee, then a few days of pending delete, after which the name is released for anyone to register.
Many people register expiring names deliberately, because old domains carry leftover links and mail. A new owner can set up a catch-all mailbox, meaning every address at the domain lands in one place. That is how a message to a long-forgotten sales@ ends up in front of a stranger without them doing anything unusual.
The eight months, as far as they can be reconstructed
The old domain lapsed in the spring. A few weeks later it was registered by someone else, a fact visible in public registration records as a new creation date. Within days the old MX records pointed at a different mail provider, which a quick DNS query shows:
dig +short MX oldname.example
10 mail.parking-service.example.
From then on, every submission of the contact form was delivered to a mailbox the manufacturer had no relationship with. Enquiries contain names, phone numbers, drawings, sometimes the budget. In the worst case a stranger who is a competitor, or just curious, read them. In the likeliest case they were sorted straight into a spam folder or discarded. The manufacturer cannot know, and that uncertainty is the uncomfortable part.
It lost, by its own later estimate, somewhere between ten and twenty genuine enquiries. Only one customer complained, which is typical: most people who get no answer just buy elsewhere.
Why nobody saw an error
Email delivery is hand-over, not confirmation. The website's job is to pass the message to a mail server, which looks up where the domain's mail should go and delivers it there. If that destination accepts the message, everything upstream counts as a success. A bounce comes back only when the receiving server refuses the mail, and a stranger's catch-all mailbox does not refuse anything.
Had the old domain just stopped resolving, the form's mail would have bounced and a "delivery failed" notice would have gone to the sender address, which on many forms is the website itself and so nobody reads it either. A re-registered domain is the worst case, since it behaves perfectly.
How it was found
The customer who raised the alarm had an account and had phoned the sales line. He said he had filled in the web form twice and heard nothing. The first assumption was a spam filter, so someone searched the company's junk folders and found nothing at all, which is itself informative: spam filters leave a trace, and there was none.
The second step was to submit the form from a phone and watch the inbox. Nothing arrived. The third was to look at the form plugin's settings, where the recipient field sat in plain view with the old domain in it. Nobody had looked at that screen in four years.
The decisive check was the lookup of the old domain, which showed a creation date from the previous April and mail servers belonging to someone else.
It is tempting to blame the person who rebuilt the site. That is not quite fair. The recipient field was never part of any checklist, and the only person who could have remembered the old address had stopped thinking about it years before.
The fix and what to do about the leaked mail
Changing the recipient took thirty seconds. The follow-up took longer. The manufacturer wrote down the dates of the exposure, listed the address fields the form collected, and judged that contact details and project descriptions were involved but nothing sensitive such as payment data. Depending on where you operate and what the form collects, you may have legal duties here, so it is worth asking someone who knows rather than assuming it does not matter.
The company also searched its own site, its invoices, its email signatures and its supplier portals for any other mention of the old domain. They found it in two places: a password reset address on a trade supplier's portal, and a newsletter service account. Both were changed that day. A password reset sent to an address someone else controls is a route to taking over the account, which is the more serious version of this story.
What the manufacturer changed
The form now sends to a role address, enquiries@ on the company's current domain, which forwards to three people so that one holiday does not create a gap. Every form also writes each submission to the site database, and a short weekly job counts the week's entries and emails the total to the owner. A week with zero is a prompt to check, since even a quiet week usually has a few.
The quarterly test is a calendar entry with a named person. It takes about five minutes: submit each form with the subject "Quarterly test", confirm it arrives, delete it. Dull and effective.
The old trading name was also re-registered by the manufacturer, once the owner realised it could be bought back for an ordinary fee after the stranger let it lapse in turn. It now sits unused with auto-renew on and no mail configured at all, which is a cheap way to be sure nobody else can receive anything addressed to it.
Things people ask
Should I keep old domains forever?
Not necessarily, but renew any domain that has ever received mail you care about, at least until you have removed it from everything. A yearly fee is small next to a data leak.
Can I get the domain back?
Once someone else owns it, only by buying it from them or, in clear cases of bad faith involving a trade mark, through a dispute process. Neither is quick.
Why did the form say thank you?
Because it only reports that the mail was sent. Some form tools can also log submissions in the database, which gives you a second copy that does not depend on delivery.
Is a role address really better than a personal one?
For operational mail, yes. It survives staff changes, and you can add or remove the people behind it without touching every form and portal that uses it.
What would have caught it
- Send a test through each form after any change, and once in a while without any change.
- Avoid sending form mail to addresses on domains you do not control.
- Keep a list of every place an email address is used.
- Store form submissions in the site's database as well as emailing them, so a missing email is not the only record.