Glossary
DOMAINS

Transfer Lock

A registrar setting that prevents a domain from being transferred to another registrar without the owner's explicit action. On by default at reputable registrars.

Transfer Lock (also clientTransferProhibited in EPP status codes) is a registrar-level flag that blocks any inter-registrar transfer of the domain. It’s the first line of defence against unauthorised transfers, whether from social-engineering, credential theft, or admin error.

How It’s Set

  • The registrant enables it in the registrar’s control panel
  • It shows up in WHOIS/RDAP as clientTransferProhibited
  • Some registrars set it by default on new registrations; others require manual opt-in

Additional Lock Types

  • clientDeleteProhibited — blocks accidental deletion
  • clientUpdateProhibited — blocks unauthorised nameserver / registrant changes
  • serverTransferProhibited — set by the registry, not the registrar; used for pending disputes

Transfer Workflow

To move to a new registrar with lock on:

  1. Registrant unlocks at the losing registrar
  2. Requests an EPP auth code (a.k.a. transfer secret)
  3. Initiates transfer at the gaining registrar with that code
  4. 5-day approval window; losing registrar auto-approves after 5 days if no NACK

Recommendation

Keep transfer lock on for all business-critical domains. Only disable during an active transfer.

Check the EPP glossary entry, the WHOIS glossary entry, and the redemption period entry.