A registrar lock (also called a domain lock, transfer lock, or clientTransferProhibited status) is a protective flag your registrar sets on a domain to block it from being transferred to another registrar without your consent. If a transfer is refused, the lock is the most common cause, but an expired authorization code, a recent registration or transfer, missing WHOIS contact access, or an unpaid balance can also stop it. This guide explains each status and how to clear it.

What registrar lock actually does

Domain status codes are set at the registry level and reported through WHOIS/RDAP. The relevant one here is clientTransferProhibited, which tells the registry to reject any incoming transfer request for that domain. It is a security feature: it prevents an attacker who briefly gains access to your account or email from moving the domain out from under you. The lock is fully reversible. You toggle it off when you are ready to transfer, and you should turn it back on afterward.

Do not confuse this with serverTransferProhibited, which is set by the registry (often for disputes, legal holds, or fraud) and cannot be removed by you or your registrar directly.

New registrar transfer request Registry checks status Locked: transfer refused Unlocked: transfer proceeds clientTransferProhibited must be cleared before the registry will accept the request A valid authorization (EPP) code and unlocked status together allow the move

Why a transfer gets refused

  • The domain is locked. clientTransferProhibited is present in the WHOIS/RDAP status.
  • The 60 day change rule. Under ICANN policy a domain cannot be transferred within 60 days of registration or of a previous transfer. This also applies after certain registrant (owner) contact changes.
  • Wrong or expired authorization code. The EPP/auth code (transfer secret) must be current and typed exactly.
  • Contact email is unreachable. Transfer approval messages go to the administrative contact, so outdated WHOIS contacts stall the process.
  • Privacy protection is on. Some registrars require WHOIS privacy to be temporarily disabled so the transfer email can reach you.
  • Unpaid or disputed status. Outstanding balances or a UDRP dispute can hold the domain.

How to unlock a domain before transferring

  1. Sign in to your current (losing) registrar's control panel and open the domain management page for the specific domain.
  2. Find the registrar lock or transfer lock toggle and set it to off. Save the change.
  3. Disable WHOIS privacy temporarily if your registrar requires it for transfers.
  4. Request the authorization code (labeled auth code, EPP code, or transfer key) and copy it exactly.
  5. Confirm the administrative contact email is one you can access, and update it if not.
  6. Start the transfer at the new (gaining) registrar, paste the auth code, and approve the confirmation email.

You can verify the lock is gone by checking the domain's status in a WHOIS/RDAP lookup: it should no longer list clientTransferProhibited. Transfers typically complete within about five days once approved.

Good practice

Keep the lock on at all times except during a planned transfer, and re-enable it as soon as the move finishes. This is one of the simplest defenses against domain hijacking. The authoritative rules for who may transfer and when are set out in ICANN's transfer policy.

If you are moving a domain to us or registering a new one, see domain transfer and domain registration, or review common questions in the domains FAQ. For account specific help, contact us. The full policy is published by ICANN.

Was this answer helpful? 0 Users Found This Useful (0 Votes)