Phase 1: Isolate the Expired DC
Before touching anything else, physically or logically isolate the broken server to ensure it does not attempt to replicate or respond to client requests during the cleanup. Disconnect the network cable or disconnect the virtual network adapter in your hypervisor. Leave it powered on and isolated if you need to run the forced demotion later, or power it down completely if you plan to wipe the machine.
Phase 2: Metadata Cleanup From a Healthy DC
Perform the entire removal process from a healthy, fully functioning Domain Controller. Log into a healthy DC as a Domain Administrator and open Active Directory Users and Computers (dsa.msc). Expand your domain and select the Domain Controllers OU. Right-click the expired Domain Controller and select Delete. Confirm the initial warning. A critical checkbox dialog will appear stating "Delete this Domain Controller anyway..." Check this box and click Delete. If the DC held any FSMO roles, AD may prompt you to seize them to the healthy DC you are currently using. Authorize the seizure if required.
Next, open Active Directory Sites and Services (dssite.msc). Expand Sites, your site name, and Servers. Expand the folder named after the expired Domain Controller. If an NTDS Settings object is still visible, right-click it and select Delete. Then right-click the Server Name object itself and select Delete.
Next, clean up the DNS records. Open DNS Manager (dnsmgmt.msc), select Forward Lookup Zones, and open your main domain zone, such as company.local. Delete any Host (A) or IPv6 (AAAA) records pointing to the expired DC's IP address. Also check the _msdcs zone and its subfolders for SRV records that reference the old DC. In the root of _msdcs, delete the CNAME record corresponding to the old DC's NTDS Settings GUID.
Phase 3: Sanitize the Expired Machine
Once Active Directory has completely removed the old server, handle the physical or virtual machine itself. The safest option is to wipe and reinstall Windows Server. Because the operating system has been out of synchronization with the domain for an extended period, power off the isolated machine, format the hard drives, and reinstall a fresh copy of Windows Server.
If you must preserve the existing operating system, you can perform a forced demotion instead. Keep the network disconnected and log into the expired DC using local or cached administrative credentials. Open PowerShell as Administrator and run:
Uninstall-ADDSDomainController -ForceRemoval -DemoteOperationMasterRole:$true
Enter a new local Administrator password when prompted and allow the server to reboot. The server will no longer function as a Domain Controller. Afterward, change the computer name to avoid conflicts, reconnect the network, and join it to the domain as a regular member server.
Phase 4: Final Health Check
On a remaining healthy DC, open an elevated Command Prompt and run repadmin /replsummary to verify that the surviving DCs are replicating without errors. Then run dcdiag /q to perform a diagnostic check. Ideally, dcdiag /q should return no significant errors.
More at https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/ad-ds-metadata-cleanup
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.
hth
Marcin