Registrar Lock vs Registry Lock: What Each One Protects
Registrar lock (clientTransferProhibited) vs registry lock (server* codes): who sets them, which attacks each stops, trade-offs, and an account checklist.
Published: · 7 min read
A registrar lock is the free "transfer lock" toggle in your registrar account: it sets clientTransferProhibited and makes the registry reject transfer requests to another registrar. A registry lock is a separate, usually paid service in which the registry sets server…Prohibited codes that nobody can remove through the registrar's panel or API: every change needs a manual, out-of-band verification first. The first protects against transfer attempts from outside your account. Only the second still protects the domain when the account itself, or the registrar's support process, has been compromised. This guide explains the codes behind both, what each does and does not cover, and the account hygiene that matters more than either.
The status codes behind the locks
Locks are not a feature bolted onto the domain system. They are EPP status codes, defined in RFC 5731, that the registry stores with the domain and enforces on every command it receives.
The prefix tells you who set the code:
| Set by the registrar | Set by the registry | Effect |
|---|---|---|
clientTransferProhibited |
serverTransferProhibited |
Transfer requests are rejected |
clientUpdateProhibited |
serverUpdateProhibited |
Changes to the domain object (nameservers, DS records, contacts) are rejected |
clientDeleteProhibited |
serverDeleteProhibited |
The domain cannot be deleted |
clientRenewProhibited |
serverRenewProhibited |
Renewal is rejected |
clientHold |
serverHold |
The domain is removed from the TLD zone and stops resolving |
The last row is not a lock. clientHold and serverHold take the delegation out of the zone: that is suspension, used for unpaid renewals, unverified contacts, abuse or legal orders. A domain "on hold" is switched off, not protected. All codes are explained one by one in domain status codes.
You can read the codes of any gTLD domain yourself:
$ whois example.com | grep -i status
Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
$ curl -sL https://rdap.org/domain/example.com | jq '.status'
[
"client delete prohibited",
"client transfer prohibited",
"client update prohibited"
]
RDAP spells the statuses with spaces (client transfer prohibited); the meaning is identical. A domain under registry lock shows server transfer prohibited, server update prohibited and server delete prohibited, usually in addition to the client codes.
Registrar lock: the transfer lock in your panel
What registrars call "registrar lock", "transfer lock" or "domain lock" is clientTransferProhibited. Some registrars add clientUpdateProhibited and clientDeleteProhibited with the same switch or a second one.
- It is free and takes effect immediately.
- While it is set, the registry refuses a transfer request even when the requester has the correct auth code.
- You switch it off yourself when you really want to move the domain, and the new registrar's request then goes through.
That last point is also its limit. The lock is controlled from your registrar account, so whoever controls the account controls the lock. An attacker who has your password, or who has persuaded the registrar's support staff to reset it, can turn the lock off, read the auth code and start a transfer, or skip the transfer altogether and simply change the nameservers. A registrar lock defends against unauthorised transfer attempts from outside. It does nothing against account takeover, a leaked API key or a socially engineered support process.
Newly registered and recently transferred domains often show a transfer lock that you cannot remove for a while. That is a policy period, not a security product; the details are in how to transfer a domain name.
Registry lock: changes need a human on the phone
Registry lock is a service that some registries offer through participating registrars. When it is active, the registry sets serverTransferProhibited, serverUpdateProhibited and serverDeleteProhibited. Because these are server codes, no command arriving through the registrar's normal connection can remove them, whatever happens in your customer account.
To change anything, the domain must be unlocked first, and unlocking is deliberately slow and manual:
- A person named in advance as authorised asks the registrar for the unlock.
- The registrar verifies that person through a separate channel, for example a call-back to a number on file and a passphrase.
- The registrar asks the registry, which performs its own verification of the registrar's authorised contact.
- The registry removes the codes, the change is made, and the lock is restored.
This defeats attacks that go through the registrar's control panel or API, including a fully compromised customer account: the attacker would also have to pass the out-of-band check.
The trade-offs:
- It usually costs money, per domain and per year. Ask the registrar; we give no figures.
- Changes take hours or days. Plan nameserver moves well ahead, and note that a DNSSEC key rollover that replaces the DS record is a change at the registry and needs an unlock too. Schedule it; an expired signature with a locked DS record is an outage you cannot fix quickly.
- Renewal normally keeps working, because the renew prohibition is not part of the usual lock set. Confirm this with the registrar.
- Availability varies by TLD and by registrar. Not every registry offers it and not every registrar sells it. If you need it, it can be a reason to choose a registrar.
What neither lock covers
A registry lock protects the delegation: which nameservers and which DS records the TLD zone publishes, and who the sponsoring registrar is. It does not protect:
- The DNS hosting account. The records inside your zone are edited at the DNS provider. An attacker in that account can repoint
wwwand the MX records without touching the registration. - Expiry. A locked domain that is not renewed still expires. See what happens when a domain expires.
- The e-mail account that receives password resets for the registrar and DNS provider.
- The web server, the CDN account and the certificate in front of the site.
| Threat | Registrar lock | Registry lock | What else helps |
|---|---|---|---|
| Transfer request from someone who obtained the auth code | Stops it | Stops it | Keep the auth code secret |
| Registrar account taken over (phishing, reused password) | No: attacker switches it off | Stops transfer, nameserver, DS and contact changes | 2FA, unique password |
| Registrar support socially engineered | No | Yes, if the unlock procedure is followed | Named contacts, passphrase |
| Leaked registrar API key | No | Yes | Review and rotate API keys |
| DNS provider account taken over | No | No | 2FA and access review at the DNS provider |
| Domain expires | No | No | Auto-renew, valid payment method, monitoring |
| Accidental deletion or nameserver change by staff | Partly (if update/delete codes are set) | Yes | Change procedure |
Account security checklist
Most domain hijacks start in an account, not in the registry. Whatever you decide about registry lock, work through this list:
- Two-factor authentication on the registrar account, with an authenticator app or hardware key rather than SMS where you can avoid SMS.
- A unique, long password from a password manager.
- The account's e-mail address is not on the domain it manages. If
example.comstops resolving, a reset mail toadmin@example.comnever arrives: a circular dependency. - That mailbox is itself protected with 2FA.
- The contact is a role mailbox that several people can read, not a person who may leave.
- Auto-renew is on and the payment method is valid.
- The transfer lock is on. The auth code is requested only when you transfer, and is treated like a password.
- Account users, sub-accounts and API keys are reviewed; unused ones are removed.
- The same care is applied to the DNS hosting account.
- The domain is monitored for changes of status codes and nameservers, so that a change you did not make is noticed in minutes, not by customers.
Who needs a registry lock
Ask what a hijack would cost. If someone pointing your nameservers elsewhere for a few hours would mean intercepted customer logins, lost mail for the whole company or a payment flow going to a stranger, the domain is business-critical and the delay a registry lock adds to planned changes is a small price.
For a personal site or a parked portfolio name, a registrar lock plus the checklist above is proportionate.
Common mistakes
- Believing the transfer lock protects against account compromise.
- Buying a registry lock and then scheduling a nameserver migration or DS rollover for the same afternoon.
- Locking the registration while the DNS provider account has no 2FA.
- Registering the registrar account to an address on the same domain.
- Reading
clientHoldorserverHoldas a kind of lock. It means the domain is down.
Check it with OrbitProbe
The OrbitProbe WHOIS lookup queries RDAP and lists every status code of a domain next to the registrar, the dates, the nameservers and the DNSSEC state, with the source server and the time of the query. You see at once whether client transfer prohibited is set, and whether the three server … prohibited codes of a registry lock are really in place after you ordered one. What a lookup cannot show is how well the account behind the domain is secured: that part is the checklist above.