What is Domain Lock?
Also known as: Registrar Lock
A registrar-level status that prevents unauthorized domain transfers, modifications, or deletions until the registrant explicitly removes the lock.
Domain Lock, also known as Registrar Lock, is a security status applied by a domain registrar to a domain name. It prevents the domain from being transferred to another registrar, updated (such as changing nameservers or contact details), or deleted without the registrant first unlocking the domain. This lock is enforced by the registry via an Extensible Provisioning Protocol (EPP) status code like "clientTransferProhibited" or "clientUpdateProhibited."
The mechanism works through the interaction between the registrar and the registry. When a registrar sets a lock, it sends an EPP command to the registry to update the domain's status. The registry then returns the domain to any query with the appropriate status codes, rejecting transfer, update, or delete requests until the lock is removed. Domain locks are distinct from registry-level locks (often called Registry Lock), which provide an even higher level of security by requiring manual approval from the registry itself.
In the broader domain management stack, Domain Lock is a standard feature offered by virtually all registrars. It is considered a best practice for any domain owner who does not plan immediate changes. The lock does not affect the domain's normal operation, such as DNS resolution or email delivery. The registrant can remove or reapply the lock at any time through their registrar's control panel, subject to any authentication checks. The absence of a domain lock is a common factor in domain hijacking incidents.
Key facts
- Domain Lock prevents transfers, updates, and deletions without explicit unlock.
- Common EPP status codes: clientTransferProhibited and clientUpdateProhibited.
- Removal usually requires authentication via the registrar's control panel.
- Domain Lock does not affect DNS resolution or normal domain usage.
- Registry Lock is a stronger, separate service requiring registry approval.
How it works in practice
Related terms
References
More in Domains
Auth Code
A unique, per-domain secret code that the losing (current) registrar must provide so the gaining (new) registrar can authorize a domain transfer.
ccTLD
A ccTLD is a two-letter top-level domain assigned to a country or territory based on the ISO 3166-1 alpha-2 code, such as .us for the United States or .jp for Japan.
Domain Privacy
An optional service that replaces the domain registrant's personal contact information in WHOIS records with the registrar's proxy details to shield the owner from spam and unwanted disclosure.
EPP
EPP (Extensible Provisioning Protocol) is an XML-based application protocol used by domain name registries and registrars to provision domain names, manage contacts, and transfer registrations.
Grace Period
The grace period is a window after a domain expires during which the registrant can renew at the standard renewal fee, without incurring additional redemption costs.
IDN
An Internationalized Domain Name (IDN) is a domain name that includes characters outside the ASCII set, encoded as Punycode for compatibility with the DNS.
Punycode
Punycode is a method defined in RFC 3492 for converting Unicode strings into ASCII labels, enabling Internationalized Domain Names (IDNs) to be used in the DNS.
RDAP
RDAP (Registration Data Access Protocol) is a modern RESTful protocol for querying domain name and IP address registration data, replacing the older WHOIS protocol with structured JSON responses and role-based access controls.
Registrant
The registrant is the legal holder of a domain name, listed as the owner in the registry database and responsible for the domain's renewal and administration.
Registrar
A domain registrar is an ICANN-accredited company that sells domain name registrations to individuals and organizations, managing the reservation of domain names within the DNS.