Skip to main content

Transfers & Locks

EPP code — The Credential That Moves a Name, and the Locks Around It

Getting the code is the easy half. The locks, the confirmation email and the order you do things in are what decide whether anything goes dark.

The short answer

An EPP code — auth code, transfer key, authorisation string, depending on whose panel you are in — is the credential that proves a transfer request comes from the party entitled to move the name. The gaining registrar submits it to the registry along with the request, and the registry checks it against what it holds.

It is a live credential rather than a reference number. Paired with an unlocked domain it authorises a move, which is why you take a fresh one for each transfer and treat it as a password until the move completes.

Getting hold of it is usually straightforward. What decides whether a transfer is uneventful is the locks in front of it, the confirmation email behind it, and whether the destination zone existed before you started.

By the Hosting & Domains team · Reviewed 24 August 2026

100+

Entries in this domains reference

2 min

Read time, roughly

Plain

English, no registry jargon

24/7

Desk cover, every day

The sequence is fixed: unlock the name at the registrar holding it, obtain the code, hand it to the registrar taking it on, and approve the confirmation the registry or losing registrar sends to the registrant address. Most generic endings then complete within a few days, and the registration usually gains a year in the process.

Around that sit the rules that catch people out. A 60-day lock after registration or after a previous transfer. A further lock after a change of registrant details on many endings. And the requirement that the registrant contact address actually receives mail, which is where transfers most often stall.

What the code is, and what it is not

It is a per-domain secret held at the registry and disclosed to the registrant on request. It is not a reference number, not a customer ID, and not something to keep on file. One code authorises one move; another can always be generated afterwards.

It carries no information about where the name should go. Direction is decided entirely by which registrar submits the request, which is why possession of the code plus an unlocked name is the whole of the authorisation.

The locks standing in front of it

The registrar lock — clientTransferProhibited in the status field — is set by default on well-run accounts and is the one you switch off deliberately when you want to leave. Then there are registry-imposed locks you cannot switch off: 60 days after a new registration, 60 days after a previous transfer, and on many endings a further 60 days after the registrant details are changed.

Read the status codes before promising anyone a date. A name that shows pendingTransfer already has a request in flight; a name inside a registry lock will simply be refused, and no support desk on either side can shorten the period.

Not every registry uses a code

Auth codes are the generic-domain convention. Country registries do their own thing: the .uk namespace moves a name by changing the tag recorded against it, which the losing registrar sets and the gaining registrar accepts, with no string passed between them at all. Others issue codes with their own short expiry, or require a form signed by the registrant.

So the first question on any transfer is which registry the name belongs to, and the second is what that registry's process actually is. Assuming .com mechanics on a country ending is how a two-day job becomes a fortnight.

The confirmation email is the weak link

Transfers are confirmed to the registrant contact address, and that address is frequently the problem. It may be behind a privacy proxy forwarding to a mailbox nobody monitors, it may be an old employee's account, or it may be at the very domain being transferred — which is fine until the zone breaks mid-move.

Before you start, send a test message to whatever address is on the record and confirm it arrives somewhere a human reads. An unanswered confirmation is the single most common reason a transfer quietly expires.

Timing it so nothing goes dark. A registrar transfer moves the registration, not the zone. If the gaining registrar puts you on its default nameservers, the site and the mail stop the moment the delegation changes. So build the destination zone first — A record, MX set, SPF, DKIM, DMARC — verify it answers, and only then move the registration.

One more piece of timing: if the name is close to expiry, renew before you transfer rather than during. Transfers near an expiry date behave unpredictably across registries, and a renewal you can see is worth more than one you are hoping will be applied.

Treat the string like a password. Do not email it in plain text, do not paste it into a chat channel that keeps history, and do not leave it in a ticket after the transfer completes. Generate a new one when you need one, and if a code has been shared more widely than you intended, request a fresh one and re-lock the name.

Once the transfer has finished, put the registrar lock back on at the new registrar. A locked name with a current card and a monitored registrant address is about as safe as a domain gets.

Checking whether the name is still free before somebody else asks

The transfer, in the order that keeps everything running

A transfer is a five-minute job surrounded by rules that will cost you a week if you meet them in the wrong order. So this reference puts the locks, the confirmation address and the destination zone before the code itself.

The rate you register at is the rate you renew at, so year two costs precisely what year one did — nothing lying in wait on the invoice.

  • Registry locks listed, with their durations
  • Non-generic transfer mechanisms covered
  • The zone built before the registration moves
  • 100+ entries, cross-linked to their neighbours

Why Hosting & Domains

Standard on every plan

Codes on request, not on negotiation

Unlock and auth code from the client area when you ask, with no retention script to sit through first.

The remaining term carried over

Whatever registration time is left travels with the name when it moves in, as the registry rules provide.

The zone built before the switch

Our engineers recreate the records — MX, SPF, DKIM and DMARC included — so a transfer does not take the mail with it.

Registrar lock on by default

Names held here carry the lock, so an unauthorised transfer request has something to fail against.

Privacy that does not eat approvals

Redaction as standard with forwarding you can test, because an unread confirmation is how transfers die.

Answers at any hour

People on the support desk every hour of every day, transfers very much included.

Quick Start

Order placed to site online

  1. 1

    Read the status codes first

    Look the name up and check for registry locks and any transfer already in flight. This is what decides whether a date is realistic.

  2. 2

    Prove the registrant address receives mail

    Send a test message to whatever address is on the record. An unanswered confirmation is the commonest reason a transfer expires.

  3. 3

    Build the destination zone

    Records recreated and verified here before the registration moves, so the site and the mail carry on regardless.

  4. 4

    Unlock, take the code, submit, then re-lock

    One code, one move. Once the transfer completes, put the registrar lock back on at the new registrar.

Built In

Fitted to every plan

  • Unlock and auth code from the client area on request
  • The registrar lock set on names held with us
  • The remaining registration term carried over on a transfer in
  • MX, SPF, DKIM and DMARC rebuilt by our engineers during a migration
  • Public registration details redacted as standard
  • A renewal figure identical to the one you registered at
  • cPanel, which is what most of the industry already runs
  • Free SSL on every plan, reissued before the old one lapses
  • Your existing site brought across by our engineers, at no charge
  • People on the support desk every hour of every day

Frequently Asked

Questions we field again and again

Why is my brand-new domain refusing to transfer?

A registry lock. Generic endings block transfers for 60 days after a new registration and for 60 days after a previous transfer, and many also lock for 60 days after a change of registrant details. It is not the registrar being obstructive and the period cannot be shortened by either side.

Do I lose the time left on the registration when I transfer?

No. Whatever term remains carries over, and on most generic endings the transfer itself adds a further year. What you should not do is transfer within days of expiry — renew first, then move, because behaviour close to an expiry date varies between registries.

Will my website and email keep working during a transfer?

They will, provided the zone is not disturbed. A registrar transfer moves the registration only. The risk is the gaining registrar putting you on default nameservers, which changes the delegation and empties the zone from the world's point of view. Build the destination zone first and the transfer is invisible.

Should I renew before transferring or after?

Before, if expiry is within a month or so. A renewal applied at the losing registrar is one you can see on an invoice; a renewal you are hoping the transfer will add is one you find out about later. Away from the expiry date it makes no difference.

Does changing the registrant details restart the lock?

On many endings, yes — a change of registrant triggers a further 60-day transfer lock. If you are planning both a details correction and a move, do the move first, or accept that the correction pushes the transfer back by two months.

Keep reading

Changing provider? Work through this checklist beforehand.

A straightforward running order for a migration your visitors never spot: which files travel first, how to bring the mail across without dropping a single message, the right moment to repoint DNS, and the two errors that sit behind almost every outage we get called in to fix.

You get the checklist, followed now and then by a note on keeping a site responsive. Unsubscribe whenever you want; the privacy policy covers the rest.

Move the name without moving the outage.

Codes on request, the remaining term carried over, the zone rebuilt before the switch, and support at any hour.

View Domain Names plans