Skip to content
Inspect My DNS

Registration

Transfer lock

registration.transfer-lock

The lock is what stops someone who has compromised your registrar account, or forged an authorisation, from moving the domain away before you notice.

What this check measures

The transfer lock is the clientTransferProhibited status, or serverTransferProhibited where the registry sets it. While either is present the registry refuses a transfer request outright. This check reports whether one is set, and warns when neither is.

It is the cheapest meaningful control a domain has. Hijacking overwhelmingly goes through the registrar rather than through DNS: somebody gets into the account or forges an authorisation, retrieves the auth code, and pushes a transfer. Transfers complete on a timer, and once the name is at another registrar — very often in another jurisdiction — recovery stops being a support ticket and becomes a formal dispute measured in months.

What it does not do is worth being clear about. The lock stops the name moving to another registrar. It does not stop somebody with access to the account changing the nameservers, which is faster and quite bad enough: a hijacker who redirects DNS has your mail and your website within a TTL, without transferring anything.

The check is skipped entirely while a transfer is already in progress, because at that point the finding is the transfer, and telling somebody to lock a domain mid-move is wrong.

How to fix it

Turn it on in the registrar control panel. It is free, it takes a moment, and it only has to come off on the rare occasion you genuinely change registrar.

Then close the door it is guarding: two-factor authentication on the registrar account, and an account contact that is a role address rather than one person's. A password reset to a mailbox nobody watches is how most of these start.

For names the business genuinely cannot lose, ask the registrar about registry lock — serverTransferProhibited and serverUpdateProhibited set at the registry, with an out-of-band process to lift them. It costs money and makes routine changes slow and manual, which is exactly the point: it also stops a nameserver change made with a stolen session.

References

Run this check on a domain

Transfer lock is one of 52 checks in every report, alongside delegation, mail authentication, TLS and registration.