Type something to search...
What is domain registrar lock and why should you enable it?

What is domain registrar lock and why should you enable it?

A domain registrar lock, often called a transfer lock or domain lock, is a setting at your domain registrar that prevents your domain name from being transferred to another registrar without your explicit approval. When it's switched on, a transfer request is rejected automatically, even if someone has your authorization code. You should enable it because losing control of your domain means losing your website, your email, and your online identity in one move, and the lock is free, takes seconds to turn on, and blocks one of the most damaging attacks a website owner can face.

Most people think about securing their website, their hosting, and their WordPress login, but forget about the domain that sits in front of all of it. This article explains what a registrar lock actually does, how it differs from the stronger registry lock, how to check whether your domain is locked, and how to enable it at your registrar.

What Is a Domain Registrar Lock?

Every domain name is managed by two organisations. The registry runs the top-level domain (for example, Verisign runs .com and .net), and the registrar is the company you bought the domain from and pay renewals to, such as Namecheap, Cloudflare Registrar, GoDaddy, Porkbun, or Google's former domain business that moved to Squarespace.

A registrar lock is a status flag your registrar sets on the domain at the registry level. The flag uses the standard EPP (Extensible Provisioning Protocol) status codes that every registry understands. The main one is:

  • clientTransferProhibited: The domain cannot be transferred to another registrar.

Many registrars also set, or let you set, related flags:

  • clientUpdateProhibited: The domain's details, including its nameservers, cannot be changed.
  • clientDeleteProhibited: The domain cannot be deleted.

The word "client" in these names means the lock was applied by the registrar. The registrar can remove it when you ask, usually with a single toggle in your account.

Why Domain Hijacking Is So Damaging

Domain hijacking happens when someone takes control of your domain without permission, usually by transferring it to a registrar account they control or by changing its nameservers. Once they control the domain, they can:

  • Point your website to a copy or a scam page that looks like yours.
  • Redirect your email and receive password reset messages for your other accounts, including hosting, social media, and payment services.
  • Issue valid SSL certificates for your domain, because certificate authorities verify control through DNS or HTTP.
  • Demand a ransom to give the domain back, or sell it.
  • Damage your search rankings and customer trust.

Getting a stolen domain back is possible, but it can take a long time and involve disputes between registrars, ICANN procedures, or even legal action. Prevention is far easier.

How a Registrar Lock Protects You

A normal domain transfer between registrars works roughly like this:

  1. Unlock: The owner removes the transfer lock at the current registrar.
  2. Get the auth code: The owner requests the authorization code (also called an EPP code or transfer key).
  3. Start the transfer: The owner enters the domain and auth code at the new registrar and pays for the transfer.
  4. Approval period: The transfer completes, usually within a few days, unless it's rejected.

The registrar lock stops this process at step one. With clientTransferProhibited in place, the registry refuses the transfer request outright. An attacker would first need to get into your registrar account and turn the lock off, which is exactly why the lock works best when combined with strong account security.

What a Registrar Lock Doesn't Do

It's important to understand the limits:

  • It doesn't stop someone who logs in to your registrar account from unlocking the domain, changing DNS records, or changing nameservers.
  • A standard transfer lock alone doesn't prevent DNS changes. Only clientUpdateProhibited does that, and not every registrar exposes it.
  • It doesn't protect against expired domains. If you forget to renew, the lock won't save you.

Think of the registrar lock as one layer. The others are account security and renewal management, which are covered below.

Registrar Lock vs Registry Lock

You may also come across registry lock, which is a much stronger, usually paid service.

FeatureRegistrar lockRegistry lock
Who applies itYour registrarThe registry, at your registrar's request
EPP status codesclientTransferProhibited and similarserverTransferProhibited, serverUpdateProhibited, etc
How to removeToggle in your registrar accountManual, out-of-band verification with the registry
Protects againstUnauthorised transfersTransfers, DNS changes, and deletions
Typical costFreeVaries widely, often a yearly fee
AvailabilityAlmost every registrarSelected registrars and top-level domains only

Registry lock requires a manual process, often a phone call or signed request with pre-agreed contacts, before any change goes through. That means even an attacker who fully compromises your registrar account can't change your nameservers. It's common for banks, large e-commerce sites, and high-profile brands. For most small business sites and blogs, a registrar lock plus a well-secured account is a reasonable level of protection.

How to Check If Your Domain Is Locked

You can check the lock status of any domain in a few ways.

Using a WHOIS or RDAP Lookup

Search for your domain on the ICANN Lookup tool (lookup.icann.org) or your registrar's WHOIS page. Look at the Domain Status field. A locked domain shows clientTransferProhibited.

If you're comfortable with a terminal, you can run a WHOIS query on macOS or Linux:

whois example.com | grep -i "status"

A locked domain returns lines similar to these:

Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited

If you see only ok or active, the domain has no locks applied.

In Your Registrar Dashboard

Log in to your registrar and open the domain's settings page. The option is usually labelled Domain Lock, Registrar Lock, Transfer Lock, or Theft Protection, often with a simple on or off toggle.

Note that some country-code domains, such as certain .uk, .de, or .eu domains, handle transfers differently and may not use the same lock flags. Check your registrar's documentation if the option isn't visible.

How to Enable a Registrar Lock

The exact steps vary by registrar, but the process is similar everywhere:

  1. Log in to your registrar account: Use the account where you pay for the domain's renewal.

  2. Open the domain list: Look for a section called Domains, Domain List, or My Domains.

  3. Select the domain: Click Manage or the domain name to open its settings.

  4. Find the lock setting: It's often in an overview, security, or transfer section.

  5. Turn the lock on: Toggle it on and save. Some registrars ask you to confirm by email or with a two-factor code.

  6. Verify the change: Run a WHOIS or ICANN Lookup check after a few minutes to confirm the clientTransferProhibited status appears.

Many registrars lock domains by default when you register them. It's still worth checking, especially for domains you transferred in, bought years ago, or inherited from a previous developer or agency.

When You Need to Unlock Your Domain

There are legitimate reasons to remove the lock temporarily:

  • You're moving the domain to a different registrar.
  • You're selling the domain and transferring it to the buyer.
  • Your registrar's lock setting blocks a nameserver change you need to make (if they apply the update lock too).

Unlock the domain only for as long as you need, complete the change, and turn the lock back on straight away. After a transfer to a new registrar, check that the new registrar has applied its own lock, because it doesn't always carry over.

It's also worth knowing that ICANN's transfer rules can restrict transfers for a period after a new registration, a recent transfer, or certain contact changes. The exact rules have been updated over time and vary by domain type, so check with your registrar if a transfer is refused unexpectedly.

Securing Your Registrar Account

Because anyone who can log in to your registrar account can remove the lock, the account itself is the real front door. Protect it properly:

  • Enable two-factor authentication: Use an authenticator app or a hardware security key rather than SMS where possible. SIM-swap attacks have been used to take over accounts protected only by text messages.
  • Use a unique, strong password: Store it in a password manager and don't reuse it anywhere else.
  • Use a secure, dedicated email address: Your registrar sends transfer notices and password resets to your account email. If that email address uses the same domain you're protecting, a hijacker who changes your DNS could intercept those messages. Consider using an address on a different domain that you also secure with two-factor authentication.
  • Keep contact details current: Registrars send important notices to the registrant email. An outdated address means you may miss a warning.
  • Limit account access: If you share access with a developer or agency, use the registrar's team or delegate features rather than sharing your main login, and remove access when the work ends.
  • Watch for phishing: Fake "your domain is expiring" emails are a common way attackers steal registrar credentials. Always log in by typing your registrar's address directly.

Don't Forget Renewals

A surprising number of lost domains aren't stolen at all. They simply expire. A lock doesn't help if the domain lapses and someone else registers it after the grace and redemption periods end.

To avoid this:

  • Turn on auto-renew for every domain you care about.
  • Keep a valid payment method on file and update it when cards expire.
  • Consider renewing important domains for several years at a time.
  • Add renewal dates to your calendar as a backup reminder.

Other Domain Protections Worth Considering

Once your lock is on and your account is secure, a couple of related protections are worth a look:

  • DNSSEC: Adds cryptographic signatures to your DNS records so resolvers can detect tampered responses. It protects the DNS answers themselves rather than who controls the domain.
  • CAA records: A DNS record that tells certificate authorities which companies are allowed to issue SSL certificates for your domain, reducing the risk of mis-issued certificates.
  • WHOIS privacy: Hides your personal contact details from public WHOIS records, which reduces targeted phishing and social engineering.
  • Domain monitoring: Some registrars and security services alert you when your domain's status, nameservers, or records change.

FAQ: Domain Registrar Lock

Yes, at almost every registrar the standard transfer lock is free and included with the domain. Registry lock, the stronger version applied at the registry level, is usually a paid service offered only by some registrars.

No. A transfer lock doesn't change your DNS, website, or email in any way. Visitors and email delivery work exactly the same with the lock on or off.

In most cases, yes. A standard transfer lock only blocks transfers. If your registrar also applies an update lock, you may need to remove it briefly to change nameservers, although individual DNS records hosted with a DNS provider can usually still be edited.

It's the EPP status code that shows your registrar has locked the domain against transfers. You can see it in WHOIS or ICANN Lookup results under Domain Status.

Not while the transfer lock is active. The registry rejects the transfer request. However, if the hacker can log in to your registrar account, they could unlock the domain first, which is why two-factor authentication on that account is essential.

Usually not. A registrar lock combined with a strongly protected registrar account, auto-renew, and a secure contact email is enough for most small sites. Registry lock makes more sense for high-value brands, financial services, and sites that would be serious targets.

Transfers can be blocked by other rules, such as a recent registration or transfer, certain recent contact changes, an expired domain, or a registrar-specific hold. Your current registrar can tell you the exact reason.


Conclusion

A domain registrar lock is one of the simplest security settings you can turn on, and one of the most valuable. It stops unauthorised transfers at the registry level, so even someone holding your authorization code can't move your domain away from you. Check your domain's status today with a WHOIS or ICANN Lookup, and if you don't see clientTransferProhibited, switch the lock on in your registrar dashboard.

Remember that the lock is only as strong as the account that controls it. Protect your registrar login with two-factor authentication and a unique password, keep your contact email secure and up to date, and turn on auto-renew. With those pieces in place, your domain, and everything that depends on it, is far harder to take away.

Tags :
Share :

Related Posts

What are the best WordPress security plugins?

What are the best WordPress security plugins?

The best WordPress security plugins for most sites are Wordfence, Sucuri Security, Solid Security, MalCare, All-In-One Security (AIOS), Patchstack, a

Dive Deeper
What are the most common website security threats?

What are the most common website security threats?

The most common website security threats are vulnerable or outdated software, weak and stolen passwords, malware infections, injection attacks like S

Dive Deeper
How does GDPR affect website security?

How does GDPR affect website security?

GDPR affects website security by turning it from a good habit into a legal obligation. If your website collects personal data from people in the EU (

Dive Deeper