Domain Locked (clientTransferProhibited): What It Means and When to Change It

VigilDog Team · October 10, 2026 · 5 min read

You went to move a domain to a new registrar, ran a WHOIS lookup, and there it was: clientTransferProhibited. It looks like an error, but it's almost always the opposite, a lock you (or your registrar) put there on purpose. Knowing what it is, and the one situation where you should remove it, saves both a support ticket and a genuinely bad afternoon.

What clientTransferProhibited means

clientTransferProhibited is an EPP status code, part of the Extensible Provisioning Protocol that registrars use to talk to domain registries. The "client" prefix means your registrar set it (as opposed to the registry). Its single job is to block any request to transfer the domain to a different registrar. While it's present, a transfer attempt is rejected before it can start.

This is not a problem state. For a domain you actively use, it's the state you want. It's the domain equivalent of a deadbolt: it doesn't affect how the domain resolves, how your website loads, or how mail flows, it only stops the domain from being moved out from under you.

The family of client status codes

clientTransferProhibited usually travels with siblings. Together they form the standard "registrar lock" most providers apply by default:

  • clientTransferProhibited, blocks transfers to another registrar.
  • clientUpdateProhibited, blocks changes to the domain's contact and nameserver details.
  • clientDeleteProhibited, blocks deletion of the domain.
  • clientRenewProhibited, blocks renewal requests (rare; occasionally used during disputes).
  • clientHold, actively removes the domain from DNS so it stops resolving (this one DOES take the site offline; the others don't).

Why your registrar sets it

Unauthorized transfers are a classic hijacking route: an attacker who gets into your registrar account, or who social-engineers a transfer, can move a domain to a registrar you don't control and effectively hold your identity hostage. clientTransferProhibited raises the bar, even with account access, the lock has to be lifted first, which adds a step and a window for you to notice.

Because it's such a cheap, effective defense, most reputable registrars enable it automatically on registration and re-enable it after any transfer completes. If you see it on your domains, that's a sign your registrar is doing its job, not a misconfiguration to "fix."

The one time you should change it

There is exactly one normal reason to remove clientTransferProhibited: you genuinely intend to transfer the domain to a new registrar. In that case the lock is the thing standing between you and the move, and you'll need to lift it as part of the process.

Do not remove it "just in case," and don't leave it off after a transfer completes. An unlocked domain that sits unlocked for months is exactly the exposure the code was designed to close. Lift it, transfer, confirm the lock is back on at the new registrar.

How to safely unlock and transfer

The transfer flow is roughly the same across registrars. Log in to the current (losing) registrar and find the domain's lock or security settings, then work through the steps below. Expect the whole thing to take up to a few days, inter-registrar transfers have a mandatory waiting period.

  • Unlock the domain, remove clientTransferProhibited (and clientUpdateProhibited if present).
  • Disable WHOIS/privacy protection temporarily if your registrar requires it for transfer.
  • Request the authorization code (also called the EPP code or auth code) from the losing registrar.
  • Start the transfer at the new (gaining) registrar and enter the auth code.
  • Approve the transfer email the losing registrar sends, then wait out the transfer window.
  • Once it lands, confirm the new registrar has re-applied the transfer lock, and turn privacy back on.

Don't let the lock hide an expiry

A locked domain is protected from theft, but it isn't protected from lapsing. Transfer locks and renewal are completely separate, a domain can be safely locked and still quietly expire because a card on file failed. Check when yours renews with our domain expiry checker, and if you manage more than a handful, don't rely on registrar reminder emails you might miss.

VigilDog's domain and DNS monitoring tracks expiry dates, nameserver changes, and WHOIS status across every domain you manage, so if a transfer lock ever disappears unexpectedly, or an expiry creeps up, you hear about it as an alert instead of a WHOIS surprise. For agencies juggling dozens of client domains, our domain monitoring for agencies guide covers how to set that up cleanly.

Questions

Frequently asked

Is clientTransferProhibited bad?

No, it's a protective lock your registrar sets to prevent unauthorized transfers. It doesn't affect your website or email. You only need to remove it when you deliberately want to move the domain to another registrar.

What's the difference between clientTransferProhibited and serverTransferProhibited?

The "client" version is set by your registrar and you can usually toggle it yourself. The "server" version is set by the registry and typically signals a dispute, legal hold, or policy issue you can't lift on your own.

Will removing the lock take my site offline?

No. clientTransferProhibited only governs registrar transfers. The status code that removes a domain from DNS is clientHold, that one does take the site offline, but it's separate.

Locked is not the same as safe

VigilDog watches expiry, nameservers, and WHOIS status on every domain you manage, so a vanished lock or a looming renewal reaches you as an alert, not a scramble.

Your first domain is free forever