Domain Locked (clientTransferProhibited): What It Means and When to Change It
VigilDog Team · October 10, 2026 · 5 min read
You went to move a domain to a new registrar, ran a WHOIS lookup, and there it was: clientTransferProhibited. It looks like an error, but it's almost always the opposite, a lock you (or your registrar) put there on purpose. Knowing what it is, and the one situation where you should remove it, saves both a support ticket and a genuinely bad afternoon.
What clientTransferProhibited means
clientTransferProhibited is an EPP status code, part of the Extensible Provisioning Protocol that registrars use to talk to domain registries. The "client" prefix means your registrar set it (as opposed to the registry). Its single job is to block any request to transfer the domain to a different registrar. While it's present, a transfer attempt is rejected before it can start.
This is not a problem state. For a domain you actively use, it's the state you want. It's the domain equivalent of a deadbolt: it doesn't affect how the domain resolves, how your website loads, or how mail flows, it only stops the domain from being moved out from under you.
The family of client status codes
clientTransferProhibited usually travels with siblings. Together they form the standard "registrar lock" most providers apply by default:
- clientTransferProhibited, blocks transfers to another registrar.
- clientUpdateProhibited, blocks changes to the domain's contact and nameserver details.
- clientDeleteProhibited, blocks deletion of the domain.
- clientRenewProhibited, blocks renewal requests (rare; occasionally used during disputes).
- clientHold, actively removes the domain from DNS so it stops resolving (this one DOES take the site offline; the others don't).
Why your registrar sets it
Unauthorized transfers are a classic hijacking route: an attacker who gets into your registrar account, or who social-engineers a transfer, can move a domain to a registrar you don't control and effectively hold your identity hostage. clientTransferProhibited raises the bar, even with account access, the lock has to be lifted first, which adds a step and a window for you to notice.
Because it's such a cheap, effective defense, most reputable registrars enable it automatically on registration and re-enable it after any transfer completes. If you see it on your domains, that's a sign your registrar is doing its job, not a misconfiguration to "fix."
The one time you should change it
There is exactly one normal reason to remove clientTransferProhibited: you genuinely intend to transfer the domain to a new registrar. In that case the lock is the thing standing between you and the move, and you'll need to lift it as part of the process.
Do not remove it "just in case," and don't leave it off after a transfer completes. An unlocked domain that sits unlocked for months is exactly the exposure the code was designed to close. Lift it, transfer, confirm the lock is back on at the new registrar.
How to safely unlock and transfer
The transfer flow is roughly the same across registrars. Log in to the current (losing) registrar and find the domain's lock or security settings, then work through the steps below. Expect the whole thing to take up to a few days, inter-registrar transfers have a mandatory waiting period.
- Unlock the domain, remove clientTransferProhibited (and clientUpdateProhibited if present).
- Disable WHOIS/privacy protection temporarily if your registrar requires it for transfer.
- Request the authorization code (also called the EPP code or auth code) from the losing registrar.
- Start the transfer at the new (gaining) registrar and enter the auth code.
- Approve the transfer email the losing registrar sends, then wait out the transfer window.
- Once it lands, confirm the new registrar has re-applied the transfer lock, and turn privacy back on.
Don't let the lock hide an expiry
A locked domain is protected from theft, but it isn't protected from lapsing. Transfer locks and renewal are completely separate, a domain can be safely locked and still quietly expire because a card on file failed. Check when yours renews with our domain expiry checker, and if you manage more than a handful, don't rely on registrar reminder emails you might miss.
VigilDog's domain and DNS monitoring tracks expiry dates, nameserver changes, and WHOIS status across every domain you manage, so if a transfer lock ever disappears unexpectedly, or an expiry creeps up, you hear about it as an alert instead of a WHOIS surprise. For agencies juggling dozens of client domains, our domain monitoring for agencies guide covers how to set that up cleanly.
