Loading
GGX_LABS
KNOWLEDGE MODULE

Registrar Lock Statuses Explained

What each EPP status code means, and why they matter for domain security and transfer prevention.

Core Concept

Domain status codes, standardized under the Extensible Provisioning Protocol (EPP), describe restrictions and states applied to a domain at the registry level.

These codes control what actions can be taken on a domain — whether it can be transferred, deleted, or modified — and are a primary defense against domain hijacking.

Insight: Status codes are enforced at the registry, not just displayed as metadata — they actively block prohibited actions from being processed.

Common Transfer-Related Codes

Several status codes exist specifically to prevent unauthorized domain transfers.

  • clientTransferProhibited — set by the registrar, most common lock
  • serverTransferProhibited — set by the registry, harder to remove
  • clientUpdateProhibited — blocks modifications to registrant details

Client vs Server

Client-level locks are managed by the registrar and can be toggled by the account owner; server-level locks require registry involvement.

Codes Indicating Problems

Some status codes signal that a domain is in trouble rather than simply protected.

  • serverHold — registry-imposed restriction, often abuse-related
  • pendingDelete — domain is in its final deletion window
  • redemptionPeriod — expired domain still recoverable by the original owner
Limitation: A domain in redemptionPeriod can typically still be recovered by its original owner, but usually at a significant premium fee from the registrar.

Why Locking Matters for Security

Domain hijacking often exploits weak or absent transfer locks combined with compromised registrar account access.

Enabling client transfer and update locks as a default posture significantly raises the difficulty of an unauthorized transfer, even if account credentials are compromised.

Defense in Depth

Transfer locks work best combined with registrar account MFA and registry-level protections like domain lock services offered by major registrars.

Reading Multiple Status Codes

A domain often shows several status codes simultaneously, and reading them together tells a fuller story.

  • Multiple prohibitions together suggest an intentionally hardened domain
  • A sudden status change can indicate account compromise or dispute activity
  • Missing expected locks on a high-value domain is itself a risk signal
Insight: The absence of standard transfer locks on a valuable domain is often more informative than the presence of any single status code.

Real-World Implementation

Status code monitoring is a standard part of domain portfolio management.

  • Enterprises monitoring locks across large domain portfolios
  • Registrars offering premium domain lock services
  • Security teams alerting on unexpected status changes

Regularly auditing status codes across a domain portfolio catches unlocked or misconfigured domains before they become a hijacking target.

Common Mistakes to Avoid

A few common mistakes affect how status codes get interpreted or applied.

  • Assuming a domain has standard transfer locks without actually checking its status codes.
  • Confusing client-level locks, which the owner controls, with server-level ones set by the registry.
  • Overlooking that a domain in redemptionPeriod may still be recoverable at a premium fee.
  • Failing to enable available transfer locks as a default security posture.
  • Not investigating a sudden, unexpected status code change promptly.
  • Overlooking that some registrars offer premium, enhanced locking services beyond standard options.
  • Assuming a locked status alone fully prevents social engineering-based account compromise.
  • Failing to periodically review lock status across an entire domain portfolio.
  • Overlooking that some status codes are informational only and carry no enforcement.
  • Assuming lock status changes are always initiated deliberately by the domain owner.
  • Failing to verify lock status immediately after any registrar account access event.
  • Overlooking that some registrars apply locks automatically only after a waiting period post-registration.

Best Practices Checklist

These practices help keep domain status codes working as intended.

  • Enable client transfer and update locks as a default posture for valuable domains.
  • Monitor for unexpected status code changes as an early warning sign.
  • Pair transfer locks with registrar account MFA for stronger overall protection.
  • Understand the distinction between client-level and server-level locks before relying on either.
  • Audit status codes across a domain portfolio regularly, not just at registration time.
  • Consider premium registrar lock services for especially high-value domains.
  • Combine status code locks with strong account security practices against social engineering.
  • Review lock status across the full domain portfolio on a regular schedule.
  • Distinguish informational-only status codes from ones that actively enforce restrictions.
  • Investigate any unexpected lock status change rather than assuming it was deliberate.
  • Verify lock status promptly after any notable registrar account access event.
  • Check whether your registrar delays automatic locking, and manually enable it earlier if needed.

Frequently Asked Questions

Frequently asked questions about registrar lock statuses.

What's the difference between client and server transfer locks?

Client-level locks are managed by the registrar and can be toggled by the account owner, while server-level locks require registry involvement to change.

What does serverHold status mean?

It typically indicates a registry-imposed restriction, often abuse-related, rather than simply an expired or unpaid domain.

Can a domain in redemptionPeriod still be recovered?

Usually yes, though typically at a significant premium fee compared to a standard renewal.

Do status code locks alone fully protect against domain hijacking?

They significantly raise the difficulty, but pairing them with registrar account multi-factor authentication provides much stronger overall protection.

Why would a domain be missing standard transfer locks?

Sometimes locks are simply never enabled by the owner, which is itself worth flagging as a risk during a portfolio audit.

Do registrars offer enhanced locking beyond standard status codes?

Some do, offering premium registry-level lock services with additional verification steps for especially high-value domains.

Can status code locks alone prevent social engineering attacks?

Not entirely — they raise the difficulty of unauthorized transfer but don't replace the need for strong registrar account security practices.

How often should domain lock status be reviewed across a portfolio?

Regularly, since locks can be inadvertently disabled or never enabled in the first place for newly acquired domains.

Do all domain status codes enforce a restriction?

No — some are purely informational, describing state without actively blocking any action, which is worth distinguishing during a review.

Can a lock status change without the domain owner's action?

It shouldn't under normal circumstances, making any unexpected change worth investigating as a potential compromise indicator.

Do all registrars lock domains immediately upon registration?

Not always — some apply automatic locks only after a waiting period, so manually enabling locks earlier can be worthwhile.

Check a Domain's Status Codes

Run a WHOIS lookup to see the current EPP status codes applied to a domain.

Launch Tool →
END OF MODULE