domain transfer

Moving a domain name A readable internet name made of labels separated by dots. Full definition of domain name from one registrar A company that registers domain names for customers with the registry. Full definition of registrar to another, often for better service or price. The owner unlocks the name, gets the auth code authorization code A secret code needed to approve moving a domain to another registrar. Full definition of auth code and asks the new registrar to start. In gTLD generic top-level domain A top-level domain not tied to a country, run under ICANN contracts. Full definition of gTLD, a transfer usually adds one year to the term. Changing the owner is a separate process.

category
Transfers and EPP

Updated on 5 min read

A domain transfer moves a domain name from one registrar, the company that manages it for the holder, to another. The holder stays the same; only the company changes. For gTLDs such as .com, ICANN Internet Corporation for Assigned Names and Numbers The nonprofit that coordinates the global DNS and gTLD policy. Full definition of ICANN’s rules set who does what and by when.

What a domain transfer is, and what it is not

The losing registrar The registrar a domain is being transferred away from. Full definition of losing registrar hands the name to the gaining registrar The registrar a domain is being transferred to. Full definition of gaining registrar. For gTLDs, ICANN’s Transfer Policy ICANN's rules for moving gTLD domains between registrars and changing registrants. Full definition of Transfer Policy, in force since 12 November 2004, gives holders the right to transfer, and only the holder can approve or deny one. As of October 2026, the version in force is the one updated on 21 February 2024, mandatory since 21 August 2025.

A transfer is not a change of owner (change of registrant A change of a domain's owner details, with confirmation steps. Full definition of change of registrant), which has its own rules, nor a change of web hosting, which needs no transfer.

ccTLD country code top-level domain A top-level domain for a country or territory, usually two letters long. Full definition of ccTLD set their own rules. In .eu, one code serves for a new registrar, a new holder or both, and a registrar lock A registrar-set lock that blocks transfers until the owner removes it. Full definition of registrar lock does not block it. For .es, Red.es The Spanish public body that manages the .es domain through its unit Dominios.es. Full definition of Red.es sets the procedure.

Before you start: locks, the auth code and the 60-day rule

The current registrar must provide two things:

  • An unlocked name. The registrar lock, clientTransferProhibited A registrar status that blocks transfers to another registrar. Full definition of clientTransferProhibited, makes the registry The central database and system of a top-level domain, or loosely the organization that runs it. Full definition of registry reject transfers. A registrar may set it only at registration Obtaining the right to use a domain name for a set period. Full definition of registration or at the holder’s request, under terms in the registration agreement.
  • The auth code. A secret code, unique to each domain, that the holder gives to the new registrar.

Without a self-service tool, the registrar must provide both within five calendar days of the request. It may not make this harder than changing contact or name server A server that holds a domain's DNS records and answers lookups. Full definition of name server details, nor hold back because of a payment dispute.

As of October 2026, two 60-day periods apply. A registrar may refuse a transfer within 60 days of the name’s creation or of a previous transfer. After a change of registrant (a material change to the holder’s name, organization or email address), it must apply a 60-day transfer lock A restriction that blocks a domain from moving to another registrar. Full definition of transfer lock unless the holder opted out beforehand. The policy advises transferring first and changing the owner afterwards.

Expired names can be transferred unless a previous period is unpaid, but a name in redemption must first be restored, which may cost a fee.

Step by step: from request to completion

  1. The holder unlocks the name and gets the auth code.
  2. The holder orders the transfer at the new registrar and gives it the code.
  3. The registry checks the code and notifies both registrars. The domain shows pendingTransfer Status code for a domain with a registrar transfer request awaiting approval or rejection. Full definition of pendingTransfer.
  4. Within 24 hours, the losing registrar asks the holder to confirm, using the FOA Form of Authorization A standard message confirming that the domain holder agrees to a registrar transfer. Full definition of FOA.
  5. The losing registrar approves or rejects. With no answer within five calendar days, the registry completes the transfer.
  6. One year is added to the registration, up to a total of ten years.

These are maximums, not typical times. As of October 2026, ICANN has not enforced the gaining registrar’s own FOA since 26 January 2020.

For example, the new registrar files a request for example.com on a Monday. If the old registrar stays silent, the move completes five calendar days later and the expiry date moves one year. Had the holder changed the registrant The person or organization that holds a domain name registration. Full definition of registrant email the week before without opting out, the transfer would be refused.

What it costs

Registrars set their own transfer prices, but a transfer cannot be refused because that fee is unpaid. Registry rules can differ: under the 2005 .net agreement, a transfer during the auto-renew grace period A period after expiry when an auto-renewed domain can still be renewed or canceled. Full definition of auto-renew grace period cancels the auto-renew A setting that renews a domain automatically so it does not expire. Full definition of auto-renew year and adds one instead.

Why a transfer can be refused

The losing registrar must give its reason. As of October 2026, it may refuse for evidence of fraud, a reasonable dispute over the holder’s identity, unpaid previous periods (or, before expiry, the current one), the holder’s express objection, or the 60-day period after creation or a previous transfer.

It must refuse during a UDRP Uniform Domain-Name Dispute-Resolution Policy ICANN's out-of-court process for trademark disputes over domain names. Full definition of UDRP or URS Uniform Rapid Suspension System A fast procedure that suspends clearly infringing domains, mainly in new gTLDs. Full definition of URS case it knows of, under a court order, during a pending dispute over an earlier transfer, or during the 60-day lock A 60-day period after certain domain events when a registrar transfer can be refused or blocked. Full definition of 60-day lock after a change of registrant.

It may not refuse because a future period is unpaid, because the holder did not respond, or because of a lock the holder could not remove.

Problems and disputes: what to do if a transfer goes wrong

  • Unexpected pendingTransfer. ICANN advises asking the registrar at once to deny the request.
  • Disputed refusal or lock. The holder can file a Transfer Complaint with ICANN.
  • Emergencies between registrars. Each registrar keeps a TEAC Transfer Emergency Action Contact A registrar's urgent contact for transfer problems, which must answer within four hours. Full definition of TEAC. As of October 2026, a person must answer within 4 hours; silence can lead to the transfer being undone.
  • TDRP Transfer Dispute Resolution Policy ICANN's process for registrars to dispute a transfer that may have broken the rules. Full definition of TDRP. Only registrars can file, within 12 months, with an approved provider (as of October 2026, the ADNDRC Asian Domain Name Dispute Resolution Centre An ICANN-approved domain dispute provider with offices in four Asian cities. Full definition of ADNDRC or Forum A United States provider of UDRP and URS domain dispute cases, also known as the National Arbitration Forum. Full definition of Forum, formerly the National Arbitration Forum). An invalid transfer is returned to the previous registrar. Courts remain open.

When a registrar is bought or loses its accreditation, ICANN can approve a bulk transfer Moving many domains between registrars in one registry operation, with ICANN approval. Full definition of bulk transfer of all its names: free up to 50,000 names, a flat US$50,000 above that (as of October 2026). Some registries offer BTAPPA Bulk Transfer After Partial Portfolio Acquisition Registry service for moving part of a registrar's domains to another registrar in bulk. Full definition of BTAPPA for part of a portfolio A collection of domains held by one owner. Full definition of portfolio.

Upcoming changes to the transfer rules

On 7 June 2026, the ICANN Board ICANN's board of directors, which adopts policies and approves key decisions. Full definition of ICANN Board adopted the 47 recommendations of the Transfer Policy Review ICANN process whose adopted but not yet implemented recommendations will change gTLD transfer rules. Full definition of Transfer Policy Review (resolution 2026.06.07.04). As of October 2026, they are not in force: ICANN lists the project as queued, with no effective date. Once implemented, the main changes will be:

  • The auth code will become the Transfer Authorization Code (TAC): at least 128 bits strong, valid for 336 hours (14 days) and usable once. The holder will be notified within 10 minutes of its issue.
  • The gaining FOA will disappear; the losing registrar’s form will become a Transfer Confirmation, with no one-click approval.
  • A mandatory 720-hour (30-day) lock will follow registration and every transfer; only the lock after a transfer may be lifted early, on a reasoned request such as a documented sale.
  • A change of registrant will bring no lock, only a notice within 24 hours, under a separate Change of Registrant Data Policy.
  • Registrars will be able to refuse for DNS abuse Harmful use of domains, defined in ICANN contracts as five specific threats. Full definition of DNS abuse and will have to refuse if the holder objects.
  • A TEAC will have 24 hours to answer.
  • BTAPPA will join the policy and extend to customers moving their own portfolio.

Sources