clientTransferProhibited: What It Means & How to Remove It
clientTransferProhibited is the most common status code you'll see on a healthy domain. Per ICANN, it tells your domain's registry to reject any request to transfer the domain from your current registrar to another.
The "client" prefix means your registrar set it — many registrars apply it automatically at registration as a default protection, others only when you enable domain locking.
What clientTransferProhibited means
It is a registrar-set instruction to the registry: deny all transfer requests for this domain. As long as the code is present, no transfer to another registrar can start, no matter who initiates it or whether they have the authorization code. ICANN's guidance is explicit that this helps prevent unauthorized transfers resulting from hijacking or fraud.
You'll see it in WHOIS or RDAP output as clientTransferProhibited (RDAP renders it as "client transfer prohibited"). It frequently appears alongside clientUpdateProhibited and clientDeleteProhibited as a standard lock set.
Is it good or bad news?
Almost always good news. This is the lock that stops a hijacker who compromises your email or registrar account from quietly moving your domain to a registrar you can't reach. Security guidance — including ICANN's own — recommends keeping it on any domain you're not actively transferring.
The only time it's a problem is when you want to transfer and forgot the lock exists: the losing registrar will reject the transfer until it's removed.
Monitor every domain status automatically
Sourdough pulls live RDAP status for every domain you track and flags anything unusual — holds, locks, redemption — before it becomes a problem. 7 days free, then $10/mo. $0 due today.
How to remove it
- •Log in to your registrar account and find the domain's lock or security settings — usually labeled "Transfer Lock," "Domain Lock," or "Registrar Lock."
- •Toggle the lock off. The registrar removes the status at the registry, typically within minutes.
- •Request the transfer authorization code (auth/EPP code) while you're there — you'll need it at the gaining registrar.
- •If the toggle is greyed out, check for a 60-day lock: ICANN policy restricts transfers for 60 days after initial registration and after a completed transfer, and many registrars also lock for 60 days after registrant contact changes.
- •If you can't remove it yourself, open a support ticket — only the registrar that set a client code can remove it.
clientTransferProhibited vs serverTransferProhibited
If WHOIS shows serverTransferProhibited instead (or in addition), the block was set at the registry level and your registrar's unlock toggle won't clear it. Registry locks are either a premium security service you requested or a sign of a legal dispute — see the serverTransferProhibited page for the removal path.
Frequently Asked Questions
Should I remove clientTransferProhibited?
Only when you're actively transferring the domain to another registrar. The rest of the time, leave it on — it's a free protection against domain hijacking, and ICANN recommends this kind of lock.
Why can't I remove the transfer lock on my domain?
Most often a 60-day restriction: ICANN's Transfer Policy blocks transfers for 60 days after initial registration and after an inter-registrar transfer, and many registrars impose a similar 60-day lock after registrant contact changes. If none of those apply, contact your registrar's support.
Does clientTransferProhibited affect my website or email?
No. It only blocks registrar transfers. Your domain resolves, renews, and updates normally — only the transfer operation is denied.