Type something to search...
What Is Registrar Lock, and Why Should You Enable It?

What Is Registrar Lock, and Why Should You Enable It?

If you have ever run a WHOIS lookup on your domain, you have probably seen lines like clientTransferProhibited followed by a link to icann.org, and wondered whether that is good or bad. It is good: it means your domain has registrar lock turned on. Those status codes are the switches that decide whether your domain can be transferred, modified, or deleted, and understanding them is one of the cheapest and most effective ways to protect a domain. This article explains what registrar lock is, what every common EPP status code means, how registry lock differs, and how to check and enable both. For the wider set of threats these locks defend against, see what domain hijacking is and how to prevent it.

What Is Registrar Lock?

Registrar lock (also called domain lock or transfer lock) is a set of status flags your registrar places on your domain at the registry. While the flags are set, the registry refuses certain operations on the domain, most importantly a transfer to another registrar.

To understand why it works, it helps to know the three parties involved:

  • The registry runs the TLD (for example, Verisign for .com) and holds the authoritative database of registrations.
  • The registrar is the company you bought the domain from. It talks to the registry on your behalf. See the difference between a domain registrar and a DNS host if those roles are blurry.
  • The registrant is you.

Registrars communicate with registries using the Extensible Provisioning Protocol (EPP), defined in RFC 5730 and, for domain objects, RFC 5731. EPP defines a fixed vocabulary of domain statuses. Registrar lock is simply your registrar setting some of those statuses on your behalf.

EPP Status Codes Explained

EPP statuses come in two families, distinguished by their prefix:

  • client* statuses are set and removed by the registrar. When you toggle "domain lock" in your registrar dashboard, these are what change.
  • server* statuses are set and removed by the registry. Registrars cannot override them. This is the basis of registry lock.

The Lock Statuses

StatusSet byWhat it blocks
clientTransferProhibitedRegistrarTransfers to another registrar
clientUpdateProhibitedRegistrarChanges to the domain at the registry, including name servers and contacts
clientDeleteProhibitedRegistrarDeletion of the domain
clientRenewProhibitedRegistrarRenewal (rare, usually during disputes)
serverTransferProhibitedRegistryTransfers, regardless of registrar settings
serverUpdateProhibitedRegistryUpdates, regardless of registrar settings
serverDeleteProhibitedRegistryDeletion, regardless of registrar settings
serverRenewProhibitedRegistryRenewal

A typical "locked" domain at a security-conscious registrar shows clientTransferProhibited, clientUpdateProhibited, and clientDeleteProhibited. Many registrars only set clientTransferProhibited by default, which stops transfers but still allows name server changes from a compromised account.

Hold Statuses (These Take You Offline)

StatusSet byEffect
clientHoldRegistrarThe domain is removed from the TLD zone, so it stops resolving
serverHoldRegistrySame effect, imposed by the registry

Hold statuses are not protections. They usually indicate an unpaid invoice, an unverified registrant contact, an abuse complaint, or a legal action. If your domain has suddenly stopped resolving and you see clientHold, contact your registrar first. The symptoms look a lot like an NXDOMAIN error, because the TLD servers no longer know about your domain.

Lifecycle and Informational Statuses

StatusMeaning
okNo restrictions are set. The domain is not locked.
inactiveNo name servers are delegated, so the domain does not resolve
addPeriodGrace period shortly after initial registration
autoRenewPeriodGrace period after the registry auto-renewed the domain
renewPeriodGrace period after an explicit renewal
transferPeriodGrace period after a completed transfer
pendingTransferA transfer request is in progress
pendingUpdate, pendingRenew, pendingCreateAn operation is being processed
redemptionPeriodThe domain expired and was deleted, but can still be restored for a fee
pendingRestoreA restore from redemption is being processed
pendingDeleteThe domain will be released for anyone to register shortly

The grace and redemption statuses come from the Registry Grace Period extension in RFC 3915. If you ever see redemptionPeriod or pendingDelete on a domain you care about, renew or restore it immediately.

What You See in RDAP

RDAP, the JSON-based replacement for WHOIS, expresses the same statuses in lowercase words, as mapped by RFC 8056. clientTransferProhibited becomes client transfer prohibited, and ok becomes active. The meaning is identical.

How Registrar Lock Fits Into a Transfer

A legitimate transfer between registrars for most gTLDs goes like this:

  1. You remove clientTransferProhibited at your current registrar.
  2. You obtain the authorization code (EPP authInfo, also called an auth code or EPP code) from your current registrar.
  3. You request the transfer at the new registrar and provide the code.
  4. The registry marks the domain pendingTransfer. The losing registrar can approve or reject it, and if it does nothing, the registry approves it automatically after five days.

Registrar lock blocks steps 3 and 4 entirely: the registry will reject a transfer request for a domain carrying a transfer-prohibited status, even if the requester has the correct authorization code. That is why it is so valuable. A leaked auth code alone is not enough.

ICANN's transfer rules also restrict transfers for a period after a domain is first registered or transferred, which is why a newly bought domain often cannot be moved for 60 days. Country-code TLDs set their own rules and may use different lock mechanisms entirely.

How to Check Your Domain's Lock Status

With WHOIS

The classic whois command shows statuses as Domain Status lines:

whois example.com | grep -i "domain status"

A properly locked domain returns output like this:

Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited

Some registrars' WHOIS servers return slightly different formatting. If the output only shows ok, the domain is unlocked.

With RDAP

RDAP is more consistent and easier to script. The bootstrap service at rdap.org redirects to the correct registry:

curl -sL https://rdap.org/domain/example.com | jq -r '.status[]'

This prints one status per line, for example client transfer prohibited.

With a Script for Your Whole Portfolio

This Python script uses only the standard library to check a list of domains and warn about any that are missing a transfer lock:

import json
import urllib.request

DOMAINS = ["example.com", "example.net", "example.org"]
REQUIRED = {"client transfer prohibited", "server transfer prohibited"}

for domain in DOMAINS:
    req = urllib.request.Request(
        f"https://rdap.org/domain/{domain}",
        headers={"Accept": "application/rdap+json"},
    )
    try:
        with urllib.request.urlopen(req, timeout=15) as resp:
            data = json.load(resp)
    except Exception as exc:
        print(f"{domain}: lookup failed ({exc})")
        continue

    statuses = {s.lower() for s in data.get("status", [])}
    locked = bool(statuses & REQUIRED)
    label = "LOCKED" if locked else "NOT LOCKED"
    print(f"{domain}: {label} -> {', '.join(sorted(statuses))}")

urllib follows the redirect from rdap.org to the registry's RDAP server automatically. The script treats a domain as locked if it has either the registrar or the registry transfer prohibition. Schedule it weekly, or after any change at your registrar, so an accidentally removed lock does not go unnoticed.

How to Enable Registrar Lock

On almost every registrar, enabling it is a single toggle:

  1. Log in to your registrar account.
  2. Open the domain's management or security settings.
  3. Look for a setting called Domain lock, Transfer lock, Registrar lock, or Theft protection, and turn it on.
  4. Wait a few minutes, then confirm with whois or RDAP that clientTransferProhibited appears.

If your registrar offers separate controls for update and delete protection, enable those as well. You will need to remove the update lock temporarily when you change name servers, which is a small price for blocking silent changes. When you do change name servers, follow how to update nameservers for a domain and re-enable the lock immediately afterwards.

Behind the toggle, your registrar sends the registry an EPP update command like this one from RFC 5731:

<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<epp xmlns="urn:ietf:params:xml:ns:epp-1.0">
  <command>
    <update>
      <domain:update xmlns:domain="urn:ietf:params:xml:ns:domain-1.0">
        <domain:name>example.com</domain:name>
        <domain:add>
          <domain:status s="clientTransferProhibited"/>
          <domain:status s="clientUpdateProhibited"/>
          <domain:status s="clientDeleteProhibited"/>
        </domain:add>
      </domain:update>
    </update>
    <clTRID>ABC-12345</clTRID>
  </command>
</epp>

You will never send this yourself unless you are a registrar, but it shows exactly what the lock is: three statuses added to the domain object in the registry database.

What Is Registry Lock?

Registrar lock has one weakness: anyone who can log into your registrar account, or convince the registrar's support team that they are you, can turn it off. Registry lock closes that gap.

With registry lock, the registry itself sets the server* statuses, typically serverTransferProhibited, serverUpdateProhibited, and serverDeleteProhibited. Removing them requires a manual, out-of-band process: an authorized contact at your organization must contact the registrar, which then verifies the request (often by phone with a pre-agreed passphrase) and asks the registry to unlock the domain. After the change is made, the lock is reapplied.

Key points about registry lock:

  • It is offered through registrars, not directly by registries, and only some registrars support it.
  • It usually costs extra, often an annual fee per domain.
  • It slows down legitimate changes, because every name server or contact change needs the unlock process. That is the point.
  • It is available for many, but not all, TLDs. Most large gTLDs and many ccTLDs support it.

Registry lock is worth it for domains whose loss would be catastrophic: your primary brand domain, domains that carry corporate email, and domains used for authentication or payments. For everything else, a registrar lock combined with strong account security is usually enough.

Registrar Lock Best Practices

  1. Lock every domain by default, including parked and defensive registrations.
  2. Enable update and delete prohibitions, not just transfer prohibition, where your registrar allows it.
  3. Re-lock immediately after any planned change.
  4. Use registry lock for your most important domains.
  5. Protect the registrar account with hardware-key MFA, because the account can remove registrar lock.
  6. Monitor status codes with a scheduled check like the one above.
  7. Treat a surprise ok status as an incident and investigate who removed the lock.

Registrar Lock FAQ

No. Transfer, update, and delete prohibitions do not affect DNS resolution. Your site and email keep working normally. Only the hold statuses, clientHold and serverHold, take a domain offline.

It means your registrar has locked the domain against transfers. That is the recommended setting. You only need to remove it when you intentionally move the domain to another registrar.

Yes. Records inside your zone, such as A, MX, and TXT records, are managed by your DNS host, not the registry, so locks do not affect them. clientUpdateProhibited does block changing the name servers at the registry until you remove it.

Registrar lock uses client statuses that your registrar can set and remove, often with a single toggle. Registry lock uses server statuses set by the registry and requires a verified, out-of-band request to remove, so a compromised registrar account cannot undo it.

No. The registry rejects transfer requests for a domain with a transfer-prohibited status even when the correct auth code is supplied. The lock must be removed first, which requires access to the registrar account.

It means the domain has no restrictions at all. It is not an error, but it does mean the domain is unlocked and can be transferred if someone has the auth code.

The registrar has removed the domain from the TLD zone, so it no longer resolves. Common causes are unpaid renewals, failed contact verification, or abuse reports. Contact your registrar to find out why and resolve it.

All gTLDs use the EPP status codes described here. Many ccTLDs do too, but some use their own mechanisms or have different transfer processes, so check with your registrar for country-code domains.

Conclusion

Registrar lock is one of the rare security controls that is free, takes seconds to enable, and has almost no downside. The EPP status codes that implement it, clientTransferProhibited, clientUpdateProhibited, and clientDeleteProhibited, tell the registry to refuse transfers, changes, and deletions until you deliberately lift them. Registry lock goes a step further with server* statuses that cannot be removed from a registrar dashboard at all.

Check every domain you own with whois or RDAP today. Anything showing ok should be locked, anything critical should be considered for registry lock, and any lock that disappears without a planned change should be treated as a warning sign. Combined with a well-protected registrar account, these statuses make your domains dramatically harder to steal.

Here are some useful references for going deeper on domain status codes and locks:

  1. ICANN: EPP Status Codes: What Do They Mean, and Why Should I Know? — ICANN's plain-English guide to every status code.
  2. RFC 5731: EPP Domain Name Mapping — defines the domain status values and update commands.
  3. RFC 3915: Domain Registry Grace Period Mapping for EPP — defines the redemption and grace period statuses.
  4. RFC 8056: EPP and RDAP Status Mapping — maps EPP status codes to the RDAP values you see in JSON output.
  5. ICANN: Transfer Policy — the rules governing transfers between registrars for gTLDs.
Tags :
Share :

Related Posts

What Is the Difference Between Authoritative and Recursive DNS Servers?

What Is the Difference Between Authoritative and Recursive DNS Servers?

When someone says "the DNS server," they could mean two completely different machines doing two completely different jobs. One kind of server holds t

Continue Reading
Can DNS settings affect website speed?

Can DNS settings affect website speed?

Yes, DNS settings can significantly affect the speed at which a website loads for its users. DNS, or Domain Name System, is often likened to the inte

Continue Reading
Can You Use a CNAME Record on the Root Domain?

Can You Use a CNAME Record on the Root Domain?

It is one of the most common DNS questions there is. Your hosting platform says "add a CNAME pointing to myapp.example-cdn.net," it works perfectly

Continue Reading