Skip to content
Fixed price from 390 € – no subscription lock-in
Technology & operations

.de Domain 2026: New DENIC Duties for Domain Owners

Holder data, verification and deadlines: what small businesses, clubs and freelancers should check about their .de domain in 2026, in five clear steps.

14 min read DomainDENICNIS-2KleinunternehmenWebsite

Domains run quietly in the background for years – until an e-mail arrives that nobody reads. That is exactly the situation many small businesses find themselves in during 2026. DENIC eG, the registry for every .de address, has been legally obliged since the national implementation of the NIS-2 Directive to keep the data of all domain holders complete, correct and verifiable (DENIC eG) – and explicitly so for existing domains that have run without objection for years. For you this means: your domain can enter a verification procedure in which you have to supply evidence through your provider, and there is little time for it. Meanwhile the register is larger than ever: the 18 millionth (DENIC eG) .de domain was registered in June 2026, which means that statistically almost one in six (DENIC eG) residents of Germany holds a .de address. This article explains the new duties calmly and translates them into five manageable steps that keep your domain yours, reachable and able to move when needed. If you are still deciding which address suits you, the article on why your own domain and e-mail address build trust covers that ground – here the focus is strictly on ownership, deadlines and obligations.

Your .de domain: holder data, deadlines, fact sheetDomain fact sheetHolderyour business, not the agencyRegistrar / providerwho manages the domainHolder e-mailan inbox you read dailyAuth codevalid 30 days, single useRenewaldate plus payment methodDNS recordsA, MX, TXT documented79 %unaided awareness of .de18 millionregistered .de domains (DENIC)5 daysto verify after a DENIC e-mailVerification: process and deadlines1Automated plausibility checkDENIC screens holder data risk-basedongoing2Request goes through your providerEvidence only via the registrarprovider3E-mail from DENIC: 5 daysDeadlines cannot be postponed5 days4After 30 days out of the zonethen termination and deletion30 days

Key takeaways

  • Since Germany implemented NIS-2 on 6 December 2025 (DENIC eG), DENIC has to keep the data of every .de holder complete and verifiable – explicitly including long-standing domains that have run without objection for years.
  • Whoever is listed as the domain holder controls provider changes and the right to act; you can check the entry in your provider's customer account or through DENIC's domain lookup. Holder and website operator may legitimately differ (DENIC eG).
  • Verification runs solely through your provider; once DENIC writes directly, only 5 days (DENIC eG) remain. Without evidence the domain leaves the .de zone after 30 days (DENIC eG) – website and every mailbox on it go offline together.
  • A workable record needs the full name including legal form, a current street address rather than a P.O. box, and a shared mailbox on your own domain that is read daily. Correcting the data alone is not enough; verification requires evidence.
  • The .de provider-change password is valid for 30 days (DENIC domain terms) from issue and can be used only once; for .com or .org, lock periods of 60 days (ICANN Transfer Policy) after registration or a previous transfer apply instead.
  • A half-page fact sheet with holder, registrar, logins, renewal date, DNS records and proof documents saves the search when time is short. What binds legally are the DENIC domain terms and the terms of the managing provider.

What changed for your .de domain in 2026

The basis is European. With the NIS-2 Directive (EU) 2022/2555 the European Union adopted legislation in December 2022 to ensure a high level of cybersecurity; the range of affected sectors was widened and split into essential and important entities (DENIC eG). In Germany the directive has been transposed into national law since 6 December 2025 (DENIC eG) through the NIS-2 implementation act. One detail matters for domain holders: providers of DNS services count as essential entities, and DENIC is obliged under Section 49 (1) and (3) of the German BSI Act (DENIC domain guidelines) to ensure that domain holder data is correct. The registry states plainly that this duty applies not only to newly registered domains but also to existing ones that have been in place for many years without objection (DENIC eG).

In practice it works like this: the stored holder data is checked automatically for completeness and plausibility, supported by a comparison with external sources such as public address databases (DENIC eG). If discrepancies appear, DENIC requests an additional verification – not from you directly, but through the provider that manages your domain. If that route does not reach the holder, DENIC writes to them by e-mail; from that moment only 5 days (DENIC eG) remain for the verification, according to the registry. If it is not completed, the domain is removed from the .de zone after 30 days (DENIC eG) and is then technically unreachable. Two notes from DENIC matter here: correcting the data alone is not enough, the verification has to be backed by evidence – and the deadlines can neither be paused nor postponed (DENIC eG).

A second point concerns visibility. If the domain holder is not a natural person, DENIC makes their data publicly accessible under Section 49 (4) of the BSI Act (DENIC domain guidelines), in particular through its domain lookup. For companies, clubs and organisations, the holder's name and address, e-mail address and telephone number, the registration date and the managing DENIC member are visible there (DENIC eG). For natural persons the personal holder data remains protected; only the registration date and the managing member are public. So if a club or a limited company has a private mobile number in its record, it is worth knowing that – and choosing the entry deliberately.

  • Full name of the holder, for legal entities including the legal form (DENIC domain guidelines, section VI)
  • Current street address – a post box address is expressly not sufficient (DENIC domain guidelines, section VI)
  • Telephone number on which the holder can actually be reached
  • E-mail address that can receive requests, invoices and warnings
  • For holders based outside Germany, an authorised recipient for service, named within two weeks of a request (DENIC domain terms, Section 3 (4))

The binding rules are DENIC's terms and your registrar's

This article gives a general overview and does not replace legal advice. Which deadlines apply in your case, which evidence is accepted and how the process runs in detail is set out in the DENIC domain terms, the DENIC domain guidelines and in the terms of the provider that manages your domain. Check there if in doubt. And do not enter access data into a form whose sender you cannot reliably identify – log into your provider's customer account yourself instead.

Step 1: Who is actually the holder of your domain?

The domain holder is DENIC's contractual partner and therefore the party materially entitled to the domain (DENIC domain guidelines, section VI). This role is the single most important line in the whole record, because control, provider changes and, in a dispute, the claim to the address all hang on it. In practice you find surprisingly different names there: the nephew who set up the site seven years ago, an advertising office, a former employee or a provider that registered the domain together with the hosting. As long as everything runs smoothly, nobody notices. But as soon as a verification comes up, an invoice goes unpaid or you want to change provider, that entry decides who is allowed to act at all.

One clarification matters here, and DENIC makes it itself: the domain holder and the website operator do not have to be the same person, and there are many good and legitimate reasons why they are not (DENIC eG). A differing holder is therefore neither a flaw nor a red flag. It only becomes a problem if you are unaware of it – or if the registered person can no longer be reached. Anyone operating a website carries responsibility for its content anyway and needs a complete imprint; the article on imprint duties and mandatory details under the DDG explains what belongs in it. Domain ownership is a separate matter – and still needs to be settled.

You as the holder

The clean standard case: your business appears with its full name including legal form, a current address and a mailbox that someone reads every day. Requests arrive, and you make the decisions yourself.

A service provider as holder

It happens and it is permitted, but it shifts who can act. Verifications, transfers and terminations then run through a company whose availability and continued existence you do not control.

A private person from your circle

The classic case in clubs and small businesses: a helpful acquaintance registered it. If that person moves, changes e-mail address or loses interest, access is missing exactly when it is needed.

Step 2: Check the holder data – customer account and domain lookup

For most businesses the check takes barely half an hour and needs no technical background. Two routes lead to the answer. The first is the customer account with the provider that runs the domain: there you usually find an overview of your domains including the holder, administrative and technical contacts. The second route is DENIC's domain lookup. If the holder is a legal entity, the data is publicly visible there anyway (DENIC eG). For natural persons, holders can use the holder information option and enter their postcode or e-mail address; DENIC then sends a message to the stored address containing a link that allows the data to be viewed for a limited period (DENIC eG).

That mechanism is incidentally the best test for the most important question of all: does mail sent to the stored address arrive at all? If the information e-mail does not turn up, that is not a cosmetic issue but the heart of the problem. According to its own documentation, DENIC monitors the delivery of messages sent to domain holders in order to prove that the communication arrived (DENIC domain guidelines). A dead address is therefore not only your problem. If you notice that messages to your domain regularly land in spam or do not arrive at all, it is worth reading the companion piece on setting up SPF, DKIM and DMARC for reliable e-mail delivery.

  1. Identify the provider: who invoices you for the domain? That company usually manages it – note the customer number and contact person.
  2. Restore access: reset the password for the customer account while the address stored there still works.
  3. Read the holder line: does it show your business with the correct legal form and a current street address?
  4. Check the e-mail address: is it a mailbox someone opens daily – and not the account of a person who left the business long ago?
  5. Verify the telephone number: old landlines and cancelled mobile numbers are a common reason why queries go nowhere.
  6. Record the result: a printout or screenshot with the date in your files – so the next check takes ten minutes.

How to spot a dead mailbox

Three signals are usually enough: the address ends in a domain that means nothing to you any more. It carries the name of a person who has left the business. Or a test message to that address stays unanswered and does not bounce back as undeliverable either – the most awkward case, because messages then disappear silently. Enter a shared address on your own domain instead, for example domains@yourbusiness.de, that two people keep an eye on.

Step 3: Correct the data – and use a mailbox that is read

Corrections to holder data run through the provider that manages the domain. The DENIC domain terms explicitly oblige the holder to check their data through the domain lookup immediately after registration, to report corrections and later changes without delay, and to cooperate in the review of their data on request (DENIC domain terms, Section 3 (3)). That duty to cooperate is no longer fine print but the lever on which the entire verification hangs. Take it seriously and the unpleasant part is behind you before it even starts. A second annoyance disappears along the way: invoices and renewal notices reach the right recipient again.

The most important entry is the e-mail address, because everything runs through it when things get serious: verification requests, payment reminders, warnings before deactivation. It therefore does not belong to a private individual or to a mailbox only one person knows, but to a permanently monitored address on your own domain. That has a pleasant side effect: the same address also carries your outward appearance. How an address of your own differs from a subpage on someone else's system is shown in our comparison of website builders and a professional website; how we look after domain, hosting and mailbox day to day is described on the page about website maintenance and hosting.

Field in the recordTypical legacy entrySound entry
HolderFirst and last name of a private personFull company name including legal form
AddressOld business address or post boxCurrent street address of the business
E-mailFree mail account of a former helperShared address on your own domain, two readers
TelephoneCancelled mobile numberThe number from your imprint, actually staffed
ResponsibilityNobody feels in chargeOne named person plus a deputy
EvidenceNot availableCommercial or association register extract at hand

Half an hour now saves days later

The verification itself costs little time when the data is right and the evidence is at hand. The reverse case is expensive: a request lands in a mailbox nobody opens, the deadline expires, the domain disappears from the zone – and suddenly the website, the forms and every e-mail address are offline at once. Anyone who reviews the holder data once a year rarely ends up in that position.

Step 4: The auth code and the route to a new provider

The auth code – officially the password for a provider change in the case of .de domains – is the key that moves a domain to another provider. The holder may transfer management from one DENIC member to another or into direct management; in doing so the password has to be supplied that was previously deposited through the managing member or issued on request (DENIC domain terms, Section 1 (4)). Two details are worth remembering: the password is valid for 30 days from deposit or issue and can be used only once (DENIC domain terms, Section 1 (4)). An auth code from last year is therefore worthless, and so is one that has already been used.

Generic endings such as .com or .org follow different rules, because ICANN's Transfer Policy applies there. A transfer may be denied if it is requested within 60 days of the creation date or within 60 days of a previous transfer (ICANN Transfer Policy). Conversely, the same policy protects the holder: a registrar must remove a transfer lock within five calendar days of the holder's request, and if the losing registrar fails to respond within five calendar days to the registry's notification, the transfer defaults to approval (ICANN Transfer Policy). For your planning this means: if you have just registered a name and want to move immediately, factor those lock periods in.

  • Request the auth code from your current provider and note the day it was issued.
  • Start the transfer while it is still valid, not after the holidays.
  • Mirror the DNS records at the new provider first, then trigger the transfer – that keeps the website reachable.
  • Take the MX records with you, otherwise e-mail delivery breaks during the move.
  • Check the holder data again after the transfer, because typing errors slip in during migration.
  • Treat the auth code as used afterwards and do not pass it on in a note.

When the old provider can no longer be reached

DENIC's TRANSIT procedure exists for exactly this case: if the managing member gives up the domain, it is not deleted immediately but managed directly by DENIC for a while and cannot be registered by anyone else. DENIC informs the holder by letter about the TRANSIT status; the letter contains a personal password for the TRANSIT Service Center. For the decision – new provider, deletion or paid direct management – the holder has one month, and the individual date is stated in the letter (DENIC eG). Here the circle closes: if the contact data is out of date, the letter cannot be delivered – DENIC then terminates the domain contract by e-mail and the domain is deleted (DENIC eG).

Step 5: The domain fact sheet on half a page

The last step is the least spectacular and the one that saves the business in an emergency. Create a single document – half a page is enough – containing everything that applies to your domain. Not in an app, not in a chat history, but somewhere a stand-in can find it: in the folder next to the insurance papers and additionally as a file in your company records. If you hold several domains, use one line per domain. It sounds mundane, but it replaces the half hour of searching you cannot afford precisely when the site is down. Small businesses will find further building blocks of this basic order on our page for websites for small businesses, clubs on the page for affordable club websites.

Holder

Who appears as the domain holder in the record, with which legal form and which address? Plus the stored e-mail address and telephone number.

Registrar and contract

Which company manages the domain, under which customer number, with which contact person and which billing address?

Access

Where is the customer account, who knows the credentials, how is the second factor handled and who stands in during holidays?

Renewal

When does the registration expire, how is it paid and is the direct debit on an account that still exists? A calendar entry is enough.

DNS records

A, CNAME, MX and TXT records in short form. That is the map that makes a migration work without an outage.

Evidence

Register extract, trade registration or association register extract as a copy – exactly the documents a verification asks for.

A domain is not a technical detail but the address of the business. You keep records on it the way you do on a lease – set up once, reviewed once a year.

From Webstart project practice

What happens when nobody responds

The stages are set out soberly in the DENIC domain terms. If a verification does not establish that the data is correct and complete, and the holder neither proves this nor corrects the data within the deadline set in the request, DENIC may withdraw the connection (DENIC domain terms, Section 2 (1)). The same circumstance is also good cause to terminate the domain contract (DENIC domain terms, Section 7 (2)). Upon sending the termination, DENIC may remove the domain from the name servers for the top level domain .de (DENIC domain terms, Section 7 (3)). A terminated registration then generally enters the redemption grace period, which lasts until a randomly determined point on the 31st day after the registration ended (DENIC domain guidelines, section III).

What that means in daily operations becomes clear within a single morning: the website no longer loads, the contact form delivers nothing, every e-mail address on the domain refuses messages, and in search results and the business profile the entry leads nowhere. Orders, appointment requests and job applications vanish without anyone seeing an error message. For a trades business, a medical practice or a club this is not an IT topic but a revenue and trust topic. Law firms and other regulated professions are additionally affected on the compliance side; the article on the law firm website between professional rules and client acquisition describes what is special there.

A look at the numbers shows how large the affected stock is. At the end of 2025 around 17.7 million (DENIC eG) .de domains were registered, of which 2.15 million or 12.2 percent (DENIC eG) belonged to holders outside Germany. The strongest growth among the federal states was recorded in Lower Saxony with 1.82 percent and 27,731 (DENIC eG) additional domains. That the ending keeps this level of support has to do with trust: in a representative survey by Ipsos GmbH Hamburg among more than 1,000 people in December 2025, unaided awareness of .de stood at 79 percent compared with 67 percent for .com, and 72 percent (Ipsos GmbH Hamburg on behalf of DENIC eG) would choose .de if free to decide. Anyone holding such an address should also secure it on the administrative side.

How we look after domains

Our rule is simple: domains are registered in the client's name, not ours. The business, the club or the self-employed person appears as the holder in the record, with its full designation, a current address and a mailbox that is actually read. We keep those details current, watch renewal dates and hand over the auth code whenever you ask for it – without asking why. That is not a courtesy but the precondition for an address genuinely being yours. What this work looks like is described in detail in our services at a glance and in the packages with fixed prices.

For small businesses, clubs and the self-employed we bundle domain, hosting and mailbox into a maintenance package from 49 euros a month, without subscription lock-in and cancellable monthly. That includes checking the holder data, watching renewals, installing security updates and a contact person who calls back. Why ongoing maintenance does more for a small website than a large reinvestment every five years is shown in the article on why website maintenance pays off. If your site has aged anyway, it is also worth looking at an orderly website relaunch. And if you simply want to know who is registered for your domain: write to us via the contact page and we will check free of charge. Common questions about process and pricing are also answered in our overview of frequently asked questions.

Sources and Studies

This article is based on data from: DENIC eG, information pages on holder data verification and information for registrars and resellers (risk-based automated screening of holder data for completeness and plausibility, comparison with external sources, verification exclusively through the provider, a 5-day deadline after a verification e-mail from DENIC to the holder, removal of the domain from the .de zone after 30 days, no option to postpone deadlines, correcting the data alone is not sufficient); DENIC domain terms (Section 1 (1) on the four-week deadline for connection, Section 1 (4) on the password for a provider change valid for 30 days and usable once, Section 2 (1) on withdrawal of the connection after an unsuccessful verification, Section 3 (3) on the holder's duty to check and cooperate, Section 3 (4) on naming an authorised recipient for service within two weeks, Section 7 (2) and (3) on termination for good cause and the subsequent disconnection); DENIC domain guidelines (section III on the redemption grace period until the 31st day, section VI on the mandatory details of the domain holder, section VII on Section 49 (1), (3) and (4) of the BSI Act, on monitoring the delivery of communication and on publishing the data of legal entities); DENIC eG, TRANSIT service (letter with a personal password, one month to decide, termination by e-mail if the letter cannot be delivered); DENIC eG, whois service (publicly visible details for legal entities, holder information for natural persons); DENIC eG, press release of 30 June 2026 on reaching 18 million .de domains in June 2026 and on the statement that statistically almost one in six residents of Germany holds a .de address, including the representative survey by Ipsos GmbH Hamburg from December 2025 among more than 1,000 respondents cited there (unaided awareness of .de at 79 percent compared with 67 percent for .com, 72 percent would choose .de if free to decide); DENIC eG, domain statistics for 2025 (around 17.7 million .de domains, 2.15 million or 12.2 percent held outside Germany, strongest state growth in Lower Saxony with 1.82 percent and 27,731 additional domains); NIS-2 Directive (EU) 2022/2555 and the German NIS-2 implementation act, in force since 6 December 2025; the German Federal Office for Information Security BSI (registration duty for affected entities, original deadline 6 March 2026, extended by the BSI until the end of July 2026, self-assessment tool); ICANN Transfer Policy (grounds for denying transfer requests within 60 days of registration or of a previous transfer, removal of a transfer lock within five calendar days, default approval after five calendar days without a response from the losing registrar). This article is general information and does not replace individual legal advice.

Related Articles