How to transfer a domain name: a step-by-step guide
Unlock your domain, get the auth code, initiate the transfer. Full walkthrough with ICANN rules, common failures, and timelines explained.
Transferring a domain takes five steps: disable the registrar lock, get the auth code from your current registrar, initiate the transfer at the new registrar, confirm via email, and wait up to 7 business days. In practice, most transfers complete in 1 to 3 days. Two conditions cause the majority of failed transfers: the domain was registered less than 60 days ago, or the registrar lock is still active.
Prerequisites before you start
Before initiating anything, verify every item on this checklist. Skipping one can block the transfer for weeks.
- The domain was registered more than 60 days ago (ICANN rule, no exceptions)
- The registrar lock (
clientTransferProhibited) is disabled, or you are ready to disable it - You have access to the email address listed as the domain owner in WHOIS
- That email address is valid and you can receive messages at it
- WHOIS data is up to date (outdated owner contact information causes confirmation emails to go missing)
- The domain is not expired, and is not within 60 days of expiration
- Privacy protection (WHOIS masking) is disabled if it hides your owner email from the confirmation process
The 60-day rule is the one people forget most. ICANN requires that a domain has been registered or last transferred at least 60 days before it can be transferred again. There is no workaround, your new registrar will simply reject the request.
The 5 steps of a domain transfer
Step 1: Disable the registrar lock
The registrar lock is a security status (clientTransferProhibited) that your current registrar sets on your domain to block unauthorized transfers. You need to remove it before any transfer can proceed. For more detail on what this status means and why it exists, see domain transfer lock explained.
Where to find it:
- Namecheap: Domain List > Manage > Transfer Lock > Off. Change is immediate.
- GoDaddy: My Products > Domains > Settings > Transfer Lock > Disable. Can take a few hours to propagate.
- Cloudflare Registrar: Cloudflare handles this differently, it uses an ICANN approval step rather than a traditional lock toggle. Contact support or initiate the transfer and follow their process.
After disabling, wait 15–30 minutes before checking WHOIS to confirm the status has changed.
Step 2: Get the auth code (EPP code)
The auth code (also called EPP code or authorization code) is a secret string generated by your current registrar that proves you authorized the transfer. Without it, the new registrar cannot accept the domain.
Where to find it:
- Namecheap: Domain List > Manage > Auth Code (displayed directly on screen or sent by email on request)
- GoDaddy: Domains > Settings > Get authorization code (sent to the owner email address)
- OVH/OVHcloud: Manager > Domaines > [domain] > Transfert sortant > Demander le code de transfert
Auth codes typically expire after 7 days. Some registrars send them only by email, check your inbox as well as spam. If you request a new one, the old one is usually invalidated immediately.
Step 3: Initiate the transfer at the new registrar
Go to the new registrar's website, find their "transfer domain" flow, enter the domain name, and provide the auth code when prompted. You will also need to pay. ICANN rules require that a transfer includes at least one year of registration, so the transfer fee typically equals one year of renewal at the new registrar.
The process at Cloudflare Registrar: go to your Cloudflare dashboard > Registrar > Transfer. Enter the domain name, then the auth code, and complete payment. Namecheap's transfer flow is under Domains > Transfer.
At this point, the transfer enters a pending state. Nothing else happens automatically on your end until the confirmation email arrives.
Step 4: Confirm the transfer by email
The domain owner will receive a confirmation email from the new registrar (and sometimes from the current registrar as well). You need to click the confirmation link. If you do not respond, the transfer will still proceed automatically after 5 days, that is the ICANN default. But clicking to confirm immediately speeds things up.
Check your spam folder. Confirmation emails from domain registrars are frequently filtered. If the owner email in your WHOIS was outdated and you cannot receive the email, you will need to update WHOIS contact data first (which itself can take 24–48 hours to propagate) before re-initiating the transfer.
Step 5: Wait and verify
ICANN allows up to 7 business days for a transfer to complete. In practice, 1 to 3 days is typical once everything is confirmed. Track progress in your new registrar's dashboard, or check WHOIS, the registrar field will update once the transfer is complete.
If a transfer is stuck: contact the losing registrar's support. They can confirm whether a lock is still active or whether the transfer was rejected for another reason.
What can cause a transfer to fail
| Problem | Solution |
|---|---|
| Domain registered less than 60 days ago | Wait until the 60-day ICANN window has passed |
| Registrar lock still active | Verify lock status via WHOIS or RDAP, then disable it |
| Auth code expired | Request a new one from the current registrar |
| Confirmation email not received | Check spam, verify owner email in WHOIS is correct |
| Domain is expired | Contact current registrar support immediately, there is usually a redemption window |
| Privacy protection hiding owner email | Disable WHOIS privacy before initiating, then re-initiate |
What happens to your DNS during a transfer
This is the question that causes the most anxiety, and the answer is straightforward: your DNS records do not change during a domain transfer unless you change them. The transfer only moves which registrar manages your domain registration. Your nameservers stay the same. Your website stays up. Your email keeps working.
The only situation where downtime can occur: if you change nameservers at the same time as you transfer the domain. If your goal is to both transfer the registrar and switch DNS providers, do them sequentially, transfer first, then change nameservers after the domain has settled. See how to change nameservers for that process.
Monitoring your domain after the transfer
The period immediately after a transfer is when monitoring matters most. The new registrar's expiration alerts can take days or weeks to activate. Your domain's RDAP history has just changed, and if anything was misconfigured during the transfer, it may not be obvious until something stops working.
Domain Sentinel lets you set up expiration monitoring and RDAP status alerts regardless of which registrar holds your domain. Add your domain to the watchlist right after a transfer completes, that way you will catch any status anomalies before they become problems.
Conclusion
Three things to get right: check the prerequisites (60-day rule, lock disabled, owner email accessible), follow the five steps in order, and plan for up to 7 business days even if it usually takes less. Before initiating the transfer, verify your domain's current RDAP status with Domain Sentinel to confirm the lock is inactive and the ownership data is correct.
Start with a domain you care about
Look it up for free. If you want alerts when status changes or expiry gets close, create an account. Takes about 30 seconds.