Registry Lock: Maximum-Security Domain Locking
A registry lock is a high-security service that freezes a domain at the registry level: transfers, deletions, and nameserver changes are blocked by server-side statuses (serverTransferProhibited, serverUpdateProhibited, serverDeleteProhibited) that no registrar dashboard — and no compromised account — can flip. Releasing the lock requires a manual, out-of-band verification procedure between registrar and registry, often involving passphrases or a phone call.
Why it exists
The weak point in domain security is the registrar account: phish the login, and an ordinary registrar lock takes seconds to disable. A registry lock removes that path entirely, because the registry will not act without completing its human verification process. It is the standard protection for major brands' primary domains and makes sense for any name whose loss would be catastrophic.
Practicalities
- •It is typically a paid add-on (commonly tens to hundreds of dollars per domain per year) offered through registrars that support it — availability varies by registrar and TLD.
- •Changes become slower by design: expect a verification procedure and turnaround time for any nameserver update or transfer.
- •It complements, not replaces, account security — keep 2FA on the registrar account regardless.
Track your whole domain portfolio in one place
Sourdough is the system of record for domain investors: every domain, renewal date, cost, and sale across all your registrars. 7 days free, then $10/mo. $0 due today.
Frequently Asked Questions
Registry lock vs. registrar lock — what's the difference?
A registrar lock (clientTransferProhibited) is a free, self-service toggle in your registrar account. A registry lock is enforced at the registry with server-side statuses and manual verification to release — far stronger, usually paid, and deliberately slow to change.
Is registry lock worth it for a domain portfolio?
For most portfolio names, no — cost and friction outweigh the risk. For your single most valuable names or any domain running critical infrastructure, yes.