What Is a Domain Transfer?
A domain transfer usually means moving a registration from one registrar to another. The domain name remains the same, but the company responsible for maintaining the registration changes from the registrar of record to the gaining registrar.
Several operations are commonly confused:
Moves the registration from one registrar to another under the applicable registry and ICANN transfer rules.
Changes: Registrar of record.Changes the person or entity holding the registration rights, often during a sale or organizational transfer.
Changes: Registered Name Holder and registration agreement.Moves a domain between customer accounts at the same registrar, subject to that registrar’s process.
May also involve: A change of registrant, depending on account and data changes.Changes nameservers, DNS records, web hosting, email, CDN, or infrastructure without necessarily changing registrar or registrant.
Changes: Where services resolve and operate.Coordinates payment, registrant control, registrar movement, escrow, and acceptance under a transaction agreement.
Changes: Commercial and registration control; may use a push or transfer.A domain transfer is also different from a website migration to a new domain, which changes public URLs and requires URL mapping and redirects.
Which Transfer Policy Applies?
ICANN’s Transfer Policy applies to transfers involving registrations covered by ICANN-accredited registrars and applicable generic top-level domains. Country-code TLD managers can maintain different eligibility, authorization, identity, local-presence, trustee, fee, and transfer procedures.
Before starting, identify:
- The exact TLD and registry
- Current registrar and gaining registrar
- Registered Name Holder and account controller
- Registration, expiration, and previous transfer dates
- Domain status codes in RDAP or registry data
- Current nameservers, DNSSEC state, web, and mail dependencies
- Whether ownership is also changing
Follow the registry and both registrars’ current instructions for the specific extension. Do not assume a .com workflow applies to a country-code or restricted domain.
When Can a Registrar Transfer Be Blocked?
ICANN’s policy permits or requires denial in defined circumstances. Common examples include:
- The domain is within the first 60 days after initial registration
- The domain is within 60 days after a previous inter-registrar transfer, where the permitted restriction applies
- A 60-day inter-registrar lock follows a change of registrant and was not opted out of beforehand where that option was offered
- The Registered Name Holder expressly objects
- There is evidence of fraud or a qualifying identity dispute
- Payment disputes meet the policy conditions
- A UDRP, URS, transfer dispute, or court order prevents transfer
- The registration is expired and the holder no longer has the right to renew or transfer it under applicable expiry rules
- The domain is in a registrar-lock status and has not been unlocked through the available process
Do not update the registrant name, organization, or email casually immediately before a planned registrar transfer. A material change can trigger the change-of-registrant process and its 60-day inter-registrar lock. ICANN’s policy requires the registrar to advise that transferring registrars first can avoid this sequence, unless an applicable pre-change opt-out is available and used.
How to Prepare for a Registrar Transfer
1. Secure Both Registrar Accounts
Use unique passwords, MFA, verified recovery addresses, and device/session review. Ensure the registrant can receive required notices through an address not dependent solely on the domain being moved.
Remove unauthorized users and API keys, but preserve legitimate transaction contacts. Verify every request inside the official registrar account rather than clicking an unexpected message link.
2. Verify Registration Data
Confirm the registered holder and required contact data are accurate. Privacy or proxy service can affect what appears publicly but should not prevent the legitimate holder from controlling the transfer through the registrar.
Ask support before making a material registrant change if a transfer is imminent. The operationally “correct” update can still alter the sequence and timing.
3. Check Status, Expiration, and Renewal
Review RDAP or registry status codes and the registrar dashboard. Resolve holds, disputes, payment issues, and expiry conditions before initiating the transfer.
Renewing before transfer can be prudent when expiration is close, but understand the registrar and registry’s renewal, auto-renew, refund, and transfer-term behavior. Do not rely on a transfer to rescue a domain that may expire mid-transaction.
4. Preserve DNS and Service Evidence
Export DNS records and record nameservers, DNSSEC, certificates, web origins, MX, SPF, DKIM, DMARC, verification records, CDN, WAF, and monitoring. A registrar transfer normally does not require changing nameservers, but bad defaults, DNS-hosting coupling, or an expiring registrar DNS service can cause outages.
If the current registrar also hosts DNS, confirm whether that service continues after the domain leaves. Move DNS separately before the registrar transfer if needed, and validate it before changing another component.
What Is an Auth-Code?
An Auth-Code—also called authorization code, AuthInfo, EPP code, or transfer code—is a credential used to help authorize an inter-registrar transfer. The registrar of record creates or supplies it through its documented process.
Treat it as sensitive:
- Request it only through the official account or verified support channel
- Do not send it in public marketplace messages
- Do not share it with an unverified broker or supposed buyer
- Enter it only at the intended gaining registrar or controlled escrow workflow
- Replace or invalidate it if exposure is suspected and the registrar supports doing so
ICANN’s policy requires registrars to provide reasonable access to remove transfer lock and obtain the information needed for a transfer. If a registrar appears to violate the policy, use its escalation route and preserve dated evidence before considering an ICANN compliance complaint.
Inter-Registrar Transfer: Step by Step
- Confirm eligibility: Check TLD rules, status, dates, disputes, registrant data, and expiration.
- Prepare the gaining account: Verify identity, billing, contacts, security, and support for the TLD.
- Unlock the domain: Remove the registrar transfer lock through the registrar of record.
- Obtain the Auth-Code: Store and transmit it securely.
- Initiate with the gaining registrar: Enter the exact domain and authorization information; review fees and registration-term treatment.
- Complete authorization: Follow valid confirmation notices from the gaining and/or current registrar as applicable.
- Approve or wait: The current registrar may offer an explicit approval path; otherwise policy timing applies unless a valid denial occurs.
- Verify completion: Confirm the gaining registrar is now registrar of record and the domain appears in the correct account.
- Re-secure the domain: Enable lock, MFA, auto-renew, recovery controls, and alerts.
- Validate services: Check DNS, DNSSEC, web, email, certificates, APIs, and monitoring.
A transfer may complete sooner when it is affirmatively approved, but no universal “instant” or exact-day promise applies to every TLD and registrar. Plan around the documented deadline and leave operational margin.
How Does a Change of Registrant Work?
A change of registrant transfers registration rights to another person or entity. Under the ICANN policy, the registrar verifies eligibility, obtains secure confirmation from the new and prior registrants or their authorized designated agents, processes the confirmed change, and notifies both parties.
The new registrant must accept the registrar’s registration agreement. A 60-day inter-registrar transfer lock generally follows, although a registrar may offer the prior registrant an opportunity to opt out before the change. The option and timing must be checked in advance; it cannot safely be assumed after completion.
For a business sale, identify the legal entity precisely and align the domain registrant with the transaction agreement. Preserve consent, notices, invoices, asset schedules, and acceptance evidence.
When Is an Account Push Used?
An internal account push can deliver a sold domain to another customer at the same registrar without changing the registrar of record. It can be faster operationally, but it may still involve a change of registrant and corresponding security or transfer locks.
Before a push:
- Verify the exact recipient account identifier through a trusted channel
- Confirm whether the push changes registrant data automatically
- Understand acceptance, cancellation, lock, and reversal rules
- Coordinate payment and release through the transaction process
- Confirm which DNS, contacts, and services remain attached
Do not use an account push merely to bypass a legitimate lock, dispute, or transaction safeguard.
How Does Transfer Work in a Domain Sale?
A controlled sale usually separates payment, domain control, and inspection:
- Parties agree on the domain, price, currency, fees, registrar path, timing, representations, and included assets.
- The buyer funds the agreed transaction or escrow process.
- The seller transfers or pushes the domain as instructed.
- The buyer or transaction provider verifies control and any acceptance conditions.
- Funds are released under the agreed rules.
- Both sides retain completion records.
Verify the escrow website independently and resist messages that substitute new payment instructions. Our domain escrow guide covers transaction safeguards.
Will a Registrar Transfer Cause Downtime?
A registrar transfer does not inherently change the domain’s nameservers, website, or email. Downtime usually comes from a coupled DNS service ending, DNSSEC mismatch, expired registration, nameserver change, accidental record reset, or an unrelated hosting migration.
Reduce risk by:
- Keeping nameservers unchanged during the registrar transfer
- Confirming the DNS host operates independently of the old registrar
- Exporting and comparing every record before and after
- Reviewing DNSSEC at the registry and DNS provider
- Monitoring authoritative DNS, web, and mail from multiple networks
- Separating registrar, DNS, hosting, and email changes in time
If DNS must move, lower TTLs in advance where appropriate, prepublish and verify the new zone, then change delegation as its own controlled release.
Why Did a Transfer Fail or Stall?
The registrar status still prevents inter-registrar transfer.
Check: Unlock controls, registry status, and whether another mandatory lock exists.The credential is wrong, stale, malformed, changed, or entered for the wrong domain.
Check: Request or verify it through the registrar of record.A required confirmation was not completed, reached an inaccessible contact, or expired.
Check: Official notices, spam filtering, contact data, and deadline.The domain is newly registered, recently transferred, or under an applicable change-of-registrant lock.
Check: Event dates and exact policy basis.The registration state, payment issue, identity dispute, UDRP/URS, transfer dispute, or court order prevents completion.
Check: Registrar response and policy documentation; escalate appropriately.The registry requires a different token, trade process, local contact, identity step, or supported registrar.
Check: Registry and registrar instructions for that extension.Ask the registrar for the exact denial reason in writing. Preserve status output, notices, timestamps, receipts, and support case numbers. Do not repeatedly restart the transfer without resolving the underlying condition.
Post-Transfer Security Checklist
- Confirm the correct domain and registrar of record through authoritative data
- Confirm the domain is in the intended customer account
- Review registrant and recovery information
- Enable MFA, registrar lock, change alerts, and auto-renew
- Review renewal price, expiration date, and payment method
- Remove unknown delegates, sessions, API keys, and marketplace listings
- Compare nameservers and complete DNS records
- Validate DNSSEC, TLS certificates, website, mail, and monitoring
- Review stale verification records, subdomains, and third-party services
- Archive authorization, payment, transfer, and acceptance records securely
When acquiring a previously used domain, also repeat reputation and security checks after it reaches final infrastructure. Parking-company results do not describe the buyer’s future DNS and mail environment.
Common Domain Transfer Mistakes
- Confusing registrar transfer with website migration
- Changing registrant data immediately before checking lock consequences
- Starting close to expiration without contingency time
- Sharing the Auth-Code through an unverified message
- Assuming all TLDs use the same transfer process
- Changing registrar, DNS, hosting, and email simultaneously
- Forgetting that registrar-hosted DNS may end after transfer
- Ignoring DNSSEC and causing resolution failure
- Releasing funds before the agreed control and inspection conditions are met
- Failing to lock and secure the domain after completion
Primary Sources
- ICANN: Transfer Policy
- ICANN: FAQs for registrants transferring a domain
- ICANN: Domain Name Transfers resources
- ICANN: Information for domain registrants
