New Customers: 50% OFF Your First Month on All VPS Servers & Web Hosting Plans!

Locking a domain against transfer

A transfer lock blocks inter-registrar transfers by setting clientTransferProhibited status at the registry. Enable it in your registrar's control panel and confirm it in ICANN Lookup. Protect your account with strong two-factor authentication and keep your email address secure.

HostworldDomains & DNS 8 min read Updated 24 Sep 2026

To stop someone moving your domain away, enable the transfer lock at your registrar. That sets the clientTransferProhibited status at the registry so inter-registrar transfers are rejected. You can confirm the lock yourself in ICANN Lookup under Domain Status.

Before you start

This picks up from having full access to your current registrar account and a working email address you can read. Your domain is active and not in Redemption Grace Period.

  • Know your extension. Most of this guide concerns gTLDs such as .com and .net. .uk domains have their own process today, with a change to TAC-style transfers announced for 2027.
  • Have a stable email that is not at the domain you are protecting. Many transfer and recovery steps rely on that mailbox.
  • Understand what the lock does. clientTransferProhibited blocks inter-registrar transfers. It does not fix weak account security: turn on strong two-factor authentication at your registrar.
  • Plan your DNS. Nameservers usually stay the same during a registrar transfer, yet DNS hosted by the losing registrar may be withdrawn soon after the domain leaves. You generally cannot change nameservers during a transfer, and some registrars require their own nameservers post-transfer. Sequence DNS changes before or after, not during.
  • Avoid the 60-day trap. ICANN policy imposes no-transfer periods after initial registration, after a successful transfer, and after a Change of Registrant unless you opted out in advance. Transfer first, then update contacts when possible.
  • Policy timing varies. ICANN’s 2024–2025 Transfer Policy updates roll out per registrar between 21 August 2024 and 21 August 2025. Expect small differences in wording or screens.
  • If you host with us and need to point your domain to Hostworld, set our nameservers at your registrar: ns1.serverworld.uk, ns2.serverworld.uk, ns3.serverworld.uk and ns4.serverworld.uk. Do this before or after any registrar transfer, not while one is in progress.

Step 1: Check the lock in ICANN Lookup

You are confirming your current registry status. This is the authoritative view that transfer systems respect.

  1. Open ICANN Lookup.
  2. Enter your domain and view the result.
  3. Find the “Domain Status” lines. If you see clientTransferProhibited the registrar lock is on. If you see serverTransferProhibited a registry-side lock is in place. Either one prevents an inter-registrar transfer until removed. ICANN’s status code guide explains these values: EPP status codes.
  4. If you do not see either status, the domain is transferable. Note this and continue to Step 2.

Step 2: Enable the transfer lock at your registrar

The lock is set from your registrar’s control panel. Many registrars keep it enabled by default and require you to unlock before a legitimate transfer, which ICANN policy allows when disclosed in your agreement.

  • Sign in to your registrar account and open the domain’s settings.
  • Find the transfer or domain lock control. It may be labelled “Transfer Lock” or “Domain Lock”. Turn it on.
  • Save, then repeat Step 1 to confirm you now see clientTransferProhibited in ICANN Lookup.

Tip: whenever you unlock for any reason, plan exactly when you will re-lock. Leaving the lock off serves an attacker.

Step 3: Protect the weak point: your email and registrar login

The biggest practical weak point is email. Many transfer and recovery workflows still hinge on messages sent to the addresses on the domain’s contact record or the registrar account mailbox.

  • Use a stable email that you will not lose. ICANN recommends using a non-domain email and keeping it current. Guidance: Securely managing your domain name.
  • Turn on strong two-factor authentication for your registrar account.
  • Review and update recovery details on the account. If you cannot get into the mailbox later, recovery is painful.

ICANN has deferred enforcement of the gaining-registrar email confirmation in many cases. In practice, an attacker who has your account and a valid code could move the name. Treat mailbox and account security as part of your lock.

Step 4: Plan around the 60-day no-transfer windows and expiry

ICANN’s Transfer Policy adds mandatory waiting periods that can catch you out if you change data in the wrong order.

  • A 60-day no-transfer period applies after initial registration.
  • Another 60-day period applies after a successful inter-registrar transfer.
  • A 60-day lock can apply after a Change of Registrant. You can avoid that one by opting out in advance where your registrar offers it. ICANN recommends requesting the transfer first, then changing registrant details afterwards.
  • If a gTLD enters Redemption Grace Period you cannot transfer it. You must restore it with the current registrar first.

These rules are defined in ICANN’s policy and FAQ: Transfer Policy and Name holder FAQs.

Step 5: Handle authorisation codes carefully and re-lock promptly

For gTLDs, a transfer also needs a code from the current registrar. It is the second factor for the move.

  • Request the code when you are ready to transfer. Terms vary by registrar: many make codes single-use or time-limited. There is no universal time-to-live mandated in policy.
  • If the code is not self-service, the registrar must provide it within five calendar days of your request. They must also remove any clientTransferProhibited lock that would block the transfer when you are proceeding.
  • Keep the code private. Share it only with the person who will submit the transfer to the gaining registrar.
  • If you unlocked to fetch the code but are not transferring now, turn the lock back on. Then repeat Step 1 to confirm you see clientTransferProhibited again.

Policy references: ICANN on Auth-Info Codes and the Transfer Policy. Registrar behaviour notes: Cloudflare Registrar troubleshooting.

Step 6: Know how .uk transfers work today and what changes in 2027

.uk domains use Nominet’s registrar TAG system today. The registrant can move the domain by setting the new registrar’s TAG. This is different from the gTLD Auth-Code model, although Nominet has announced a move to TAC/EPP-style transfers.

  • To transfer a .uk now, use Nominet Online Services to set the new registrar’s TAG: Nominet Online Services. Nominet charges a fee if they perform the registrar change themselves rather than you doing it through the gaining registrar and your account.
  • Nominet is transitioning .uk to a standardised TAC/EPP process on its RSP/Dragon platform. Policies take effect at transition on 9 February 2027. Expect TAC-style transfers to replace the legacy TAG push. References: .uk registry FAQ and How to transfer a domain.
  • Take care when setting a TAG. A wrong TAG hands control to the wrong registrar until corrected.

Step 7: Consider Registry Lock for high-value names

Registry Lock is a stronger, registry-side control offered on some extensions. For .com and .net, Verisign’s service sets serverTransferProhibited and related statuses. Changes then require out-of-band verification between the registrar and registry.

It is separate from the normal registrar lock. Ask your registrar about availability and process. Background: Verisign Registry Lock.

Step 8: Keep DNS and nameservers stable while you change registrar

Your website and email depend on DNS. Transferring the registration does not move your DNS by itself.

  • Nameservers typically remain unchanged during an inter-registrar transfer, so live DNS continues. If your current registrar also hosts your DNS, some providers discontinue DNS shortly after the domain leaves. Plan a deliberate DNS migration before or after the registrar transfer, not during it.
  • You generally cannot change nameservers while a transfer is in progress. Some registrars require their own nameservers once the domain arrives. Plan sequencing so that you update DNS at a calm moment rather than at the same time as a transfer.
  • If you are pointing your domain to Hostworld hosting, set our nameservers at your registrar: ns1.serverworld.uk, ns2.serverworld.uk, ns3.serverworld.uk and ns4.serverworld.uk. Do this either before you start a registrar transfer or after it completes.

Registrar behaviour examples: Namecheap on transfers and Cloudflare Registrar FAQ.

Step 9: Watch for and respond to hijacking signs

Domain hijacking often looks like one of these events:

  • Nameservers change unexpectedly to new hosts you do not recognise. DNS records change without your action.
  • Registration data suddenly shows a different registrant or admin email.
  • The domain transfers to another registrar without your approval.

If you suspect a hijack, act quickly and be methodical.

  • Document what you see. Take screenshots of ICANN Lookup and registrar screens, and note times.
  • Contact your current registrar’s support urgently and provide your evidence. Ask them to use the Transfer Emergency Action Contact route if the name appears to have moved across registrars. TEAC is the channel registrars use to coordinate urgent transfer issues and it requires a response within hours.
  • Keep a clear history of actions and responses. ICANN’s SSAC guidance stresses that documentation speeds recovery.
  • If your website or email with us are affected because DNS changed, open a support ticket. We can help you stabilise DNS on our side while you and your registrar resolve the registration.

Background reading: ICANN SSAC on domain hijacking and Documentation is key. TEAC context: TPR webinar transcript.

Step 10: Recheck and keep a record

After any change that could affect transferability, verify and note the result.

  • Run your domain through ICANN Lookup again. Confirm you see clientTransferProhibited or serverTransferProhibited as appropriate.
  • Record what you changed, when you re-locked, and where your DNS is hosted. A short log helps you and your colleagues avoid surprises later.

What next

If you are moving workloads to us, plan hosting and DNS together. Our VPS guides cover migration patterns and practical DNS work. If you are choosing a server first, see our Linux VPS range in London.

If you need help making nameserver changes or suspect something is wrong with your domain’s DNS while you secure the registration, open a support ticket and we will take a look.

Common questions

How do I tell if my domain is actually locked?

Use ICANN Lookup and read the Domain Status lines. If you see clientTransferProhibited the registrar lock is on. If you see serverTransferProhibited a registry-side lock is in place. Either one blocks an inter-registrar transfer until removed. ICANN explains these codes here: EPP status codes.

Do I need a code to transfer a .com or .net?

Yes. For gTLDs you need an authorisation code, sometimes called an Auth-Code, AuthInfo or TAC, from the current registrar. If it is not available self-service, the registrar must provide it within five calendar days of your request and remove any clientTransferProhibited lock that would prevent the move when you proceed. Many registrars issue codes that expire or can be used only once. There is no universal expiry time in policy.

Can I change nameservers during a transfer?

In general, no. You usually cannot change nameservers while a transfer is in progress, and some registrars require their own nameservers once a transfer completes. Keep your DNS steady during the move, then switch nameservers before or after the transfer, not during. If your current registrar also hosts your DNS, plan for that service to end shortly after the transfer and migrate DNS deliberately to avoid outages.

How do .uk transfers differ?

Today, .uk uses Nominet’s registrar TAG system. You can change the registrar by setting the new TAG in Nominet Online Services. Nominet charges a fee when it performs the registrar change itself. Nominet is moving .uk to a standard TAC/EPP-based process, with policies taking effect on 9 February 2027. Expect the TAG push to be replaced by a code-based flow around that time.

What should I do first if I think my domain was hijacked?

Contact your current registrar immediately with evidence and ask them to take emergency action. If the domain appears to have moved across registrars, ask them to use the Transfer Emergency Action Contact route to coordinate a response. Then stabilise services. If your site or email with us are affected because DNS changed, open a support ticket so we can help you keep services reachable while the registrar-side issue is resolved.