New Customers: 50% OFF Your First Month on All VPS Servers & Web Hosting Plans!

Transferring a .com or other gTLD with an auth code

Transferring a .com, .net or .org domain requires unlocking it at your current registrar, obtaining an auth code, and submitting it to your new registrar. The process is the same everywhere because ICANN sets the rules, but most transfers fail because of a 60-day lock triggered by changing the registrant details. DNS and email hosted at your current registrar need moving separately to avoid downtime.

Gordon FairlieDomains, DNS and email deliverability 10 min read Updated 23 Sep 2026

Transferring a .com, .net or .org to a new registrar comes down to four things: unlock the domain at your current registrar, get the auth code (also called the EPP code or AuthInfo code), place a transfer order at the new registrar and submit that code, then answer the confirmation emails. The process is governed by ICANN policy, so it works the same way at every registrar, and the transfer adds a year to your registration. The part that actually breaks websites is not the transfer itself: it is the DNS, and that is worth sorting out before you start.

This guide picks up from a domain you already own, with access to the email address shown on the registrant contact. If you are not sure you have that access, stop and read the section on approval emails first, because it decides whether the transfer can complete at all.

Before you start

A few conditions have to be true before a gTLD transfer will go through. Check all of these now rather than finding out five days in.

  • The domain is at least 60 days old. ICANN allows a registrar to deny a transfer requested within 60 days of the initial registration, and in practice they do.
  • It has not been transferred in the last 60 days. Registrars have the option to deny a transfer within 60 days of the previous one.
  • You have not changed the registrant details recently. Changing the registrant name, organisation or email address triggers a mandatory 60-day Change of Registrant lock. More on this below, because it is the single most common reason a transfer fails.
  • The domain is not expired, suspended or in redemption. A domain carrying clientHold, whether for abuse, non-payment or failed ICANN contact verification, cannot be transferred until that status is cleared with the current registrar.
  • You can read email sent to the registrant or admin contact address. Approval emails go there and nowhere else.

One thing that does not matter: your hosting. A registrar transfer moves the registration only. Your website, mailboxes, SSL certificate and DNS records are not attached to the registrar, and they carry on working as long as the nameservers and the hosting behind them stay where they are. The exception is important enough to have its own step below.

Step 1: Check for a 60-day Change of Registrant lock

Since December 2016, registrars have had to apply a 60-day lock after any change to the registrant's identity. That means the registrant name, the organisation or the registrant email address, or swapping in a different contact as registrant. Correcting a phone number or a postal address on the same registrant does not normally trigger it, but behaviour varies between registrars, and at least one applies the lock when you change privacy settings. Watch the warning text on the confirmation screen when you edit anything.

The lock only stops the domain moving to another registrar. Hosting, email and everything else carries on as normal for those 60 days.

The trap catches people in a predictable order. They decide to transfer, notice the registrant email on the domain is an old address, tidy it up, and lock themselves out of transferring for two months. If the registrant email is wrong, do not fix it yet. Either transfer first and correct the details afterwards, or look for an opt-out before you make the change. Some registrars offer an opt-out as an account preference or a tick box during the owner-change flow, some offer it only at the moment of the change and not afterwards, and some do not offer it at all and will tell you to complete the transfer first. ICANN's own advice is the same: request the transfer before changing the registrant's information.

Step 2: Find out where your DNS is actually served

This is the step that decides whether the transfer is boring or expensive. Look up the domain's current nameservers.

Linux, macOS or a Hostworld VPS:

dig NS yourdomain.com +short

Windows (Command Prompt or PowerShell):

nslookup -type=ns yourdomain.com

Both ask the DNS system which nameservers are authoritative for the domain, which is to say which servers the rest of the internet asks for your A, MX and TXT records. Read the answer carefully.

  • The nameservers belong to your current registrar. This is the risk case. Those nameservers are a free service attached to the account you are about to leave, and they can stop answering for your domain once the transfer completes. The site and the email do not break on transfer day. They break a few days later, for no reason the reader can see.
  • The nameservers belong to Hostworld (ns1.serverworld.uk through ns4.serverworld.uk) or to a separate DNS provider. The transfer will not touch them. Carry on.

Also check whether your mailboxes live at the registrar. If your MX records point at the registrar's mail servers, or you collect mail through their webmail, the mailbox is part of the account you are leaving and needs moving separately.

Step 3: Move DNS to Hostworld first, as a separate change

If Step 2 put you in the risk case, do not combine the DNS move with the registrar transfer. Downtime happens when two moving parts change at once and you cannot tell which one broke. Do this instead:

  1. Export or screenshot every record in the current zone. A, AAAA, CNAME, MX, and all TXT records including SPF, DKIM and DMARC. Missing one record is normally an MX or a TXT, and the symptom is silently broken email rather than a site that is obviously down.
  2. Recreate those records on Hostworld, in the Zone Editor in cPanel for web hosting, or on whichever DNS you are using for a VPS.
  3. Change the nameservers at your current registrar to ns1.serverworld.uk, ns2.serverworld.uk, ns3.serverworld.uk and ns4.serverworld.uk.
  4. Leave it alone for a day and confirm the site and mail are still working.
  5. Then start the registrar transfer.

Getting the records right before the switch matters more than it looks. If a resolver asks for a hostname and gets back NXDOMAIN, it is allowed to cache that negative answer, so adding the missing record afterwards still leaves some visitors failing until that cache expires. Fixing it quickly does not fix it instantly.

Step 4: Unlock the domain at your current registrar

Find the domain in your current registrar's control panel and turn off the registrar lock. In WHOIS output this shows as the status clientTransferProhibited. It is a padlock you control, and it exists to stop unauthorised transfers.

Do not confuse it with the 60-day locks from Step 1. Those are ICANN policy and you cannot toggle them. The registrar lock is yours, and because you have the ability to clear it yourself, a registrar is not allowed to refuse your transfer on the grounds that the domain is locked.

While you are there, turn off WHOIS privacy if the privacy service replaces your registrant email with a forwarding address, since that can interfere with the confirmation emails arriving.

Step 5: Get the auth code

The auth code goes by several names: EPP code, authorisation code, AuthInfo code, transfer code. ICANN is renaming it the Transfer Authorization Code, or TAC, as part of a policy update that is adopted but still being implemented, so you may see either term. It is the shared secret that proves you control the domain.

Your current registrar must make it available to you on request. How they hand it over varies. Some show it in the control panel straight away, usually under the domain's settings near the lock toggle. Others email it to the registered contact address rather than displaying it. If you cannot find it anywhere on screen, check that inbox before assuming something is wrong.

Copy it exactly. Auth codes are case sensitive and often contain characters that are easy to mistype.

Step 6: Place the transfer order at Hostworld

At Hostworld, a transfer in is an order rather than a setting on an existing service. In the client area at portal.hostworld.uk, which is WHMCS, go to Store and then Transfer Domains to Us. Enter the domain, and the cart will ask for the auth code, so have it to hand before you start.

Complete the order as you would any other. Once it is submitted, the domain appears in your account under Domains and then My Domains with a status of Pending Transfer, and it stays there until the registry either completes or rejects it. WHMCS synchronises the status with the registrar on its own, so the status will update without you doing anything. If it is still showing Pending Transfer long after the timescales below, that is the point to open a support ticket.

Step 7: Answer the confirmation emails

Under the current policy you may receive one or two confirmation emails, depending on which registrars are involved. One comes from the gaining registrar confirming that you asked for the transfer, and one from the losing registrar asking whether to release the domain. ICANN has deferred enforcement of the gaining registrar's confirmation requirement while the policy review is settled, so some registrars no longer send that first one.

Answer whichever arrives. Both go to the registrant or admin contact address in WHOIS, which is why Step 1 insists you do not change it. If you do not respond to a confirmation request that was sent, the transfer request will not be processed.

Then the timing. Once the registry notifies your current registrar, that registrar has five calendar days to approve or deny. If it does nothing, the transfer completes by default at the end of those five days. The registry notification itself typically lands 12 to 24 hours after you place the order, so end to end you are looking at roughly five to seven days.

The fastest way to shorten that is to log in to the old registrar and approve the transfer out manually. Most panels have an option to accept or accelerate a pending outbound transfer. Approving it there finishes the job in minutes instead of days.

Step 8: Tidy up after the transfer completes

  • Check the nameservers survived the move. Run the command from Step 2 again and confirm you still see the four serverworld.uk nameservers.
  • Turn the registrar lock back on.
  • Re-enable WHOIS privacy if you use it.
  • Check the auto-renew setting on the domain in your Hostworld account.
  • Now is the moment to correct the registrant email or any other contact details, safely, because the 60-day lock it triggers no longer blocks anything you need.

The year you get, and the year people lose

A successful gTLD transfer adds one year to the registration term. This is automatic, it is included in the transfer fee, and you do not have to ask for it. The ceiling is ten years total, and if the extra year would push you past that, the gaining registrar is still charged for it.

Years stack on the end of the current period rather than replacing it, so a domain that expires in eight months and is transferred now expires in twenty months. This is also why you should not renew a domain and then immediately transfer it. A transfer within 45 days of a renewal falls inside the Auto-Renew Grace Period, and the losing registrar is refunded for that renewal, so the year you paid for disappears and it looks as though the transfer never added one. Transfer instead of renewing, and the year comes with it.

If the domain is close to expiry, submitting the transfer before the expiry date is normally enough. A domain sitting in pending transfer keeps resolving and does not lapse simply because the transfer finishes after the scheduled date.

Moving a domain away from Hostworld

The same policy applies in reverse, and we will not obstruct it. In the client area, go to Domains and then My Domains, click the domain, and use Registrar Lock to unlock it. From the same screen, use Get EPP Code. Depending on the registry, the code is displayed on screen or sent to the registrant email address, so check your inbox if nothing appears. If neither happens, open a support ticket and we will retrieve it.

What is changing

ICANN has adopted a full rewrite of the Transfer Policy. When it takes effect, the code becomes the TAC formally, it is generated only on request and used only once, the gaining registrar's confirmation email requirement disappears, and the registry verifies the code directly, so the transfer starts as soon as you submit it. The Change of Registrant process, and with it the 60-day lock discussed above, is removed. Registrars have asked for a long implementation window, so there is no date to work to. Until then, everything in this guide is how transfers work.

What next

With the registration at Hostworld, the next step in the sequence is Pointing your domain at Hostworld nameservers and checking the zone, which covers confirming the four serverworld.uk nameservers have propagated and verifying your A, MX and TXT records are serving correctly. You will find it with the rest of our domains guides. If you have not yet bought the hosting the domain will point at, start at domain names and hosting at Hostworld.

Common questions

Will my website and email go down during the transfer?

Not because of the transfer itself. The registration changes hands, but DNS, hosting, mailboxes and SSL do not move with it. The failure case is a domain using the old registrar's own nameservers, which can stop answering once the domain leaves. Step 2 tells you which case you are in.

My registrar refused the transfer. Can they do that?

They can refuse for a 60-day Change of Registrant lock you did not opt out of, or if the transfer was requested within 60 days of the creation date in the registry WHOIS record. They cannot refuse over non-payment for a future registration period, over no response from you, or because the domain is locked when you had a fair chance to unlock it yourself.

How long does the whole thing take?

Usually five to seven days. The old registrar has five calendar days to respond after the registry notifies it, and the transfer completes by default if it stays silent. Approving it manually at the old registrar finishes it in minutes.

I changed my registrant email last week. What are my options?

Wait out the 60 days from the change. There is no way to remove the lock after the fact at most registrars. Your site and email keep working throughout, so it is an inconvenience rather than an outage. Ask your current registrar whether they offer any bypass before you assume.

Can I transfer a domain that has expired?

No. Renew or redeem it with the current registrar first, then wait for the 45-day Auto-Renew Grace Period to pass before transferring, or you will lose credit for that renewal.