Domain Locked? Every Lock Status Code & How to Unlock Each
"Your domain is locked" can mean six different things. EPP defines three prohibition types — transfer, update, delete — and each exists in a registrar-set (client) and registry-set (server) version. Which code you're looking at determines who can remove it and how long that takes.
Run a WHOIS or RDAP lookup first. The exact status codes tell you everything the error message didn't.
The six lock codes at a glance
Server codes take precedence over client codes: if both are set for the same operation, clearing the registrar-side lock alone changes nothing.
| Status code | Blocks | Set by | Removed by |
|---|---|---|---|
| clientTransferProhibited | Registrar transfers | Registrar | Registrar (often a self-service toggle) |
| clientUpdateProhibited | Nameserver/contact changes | Registrar | Registrar (often a self-service toggle) |
| clientDeleteProhibited | Deletion | Registrar | Registrar (often a self-service toggle) |
| serverTransferProhibited | Registrar transfers | Registry | Registry, via your registrar |
| serverUpdateProhibited | Nameserver/contact changes | Registry | Registry, via your registrar |
| serverDeleteProhibited | Deletion | Registry | Registry, via your registrar |
Unlocking client codes (registrar locks)
- •Log in to your registrar and open the domain's settings. Look for "Domain Lock," "Transfer Lock," or "Registrar Lock" — one toggle usually controls the transfer/update/delete set together.
- •Turn it off, make your change or start your transfer, then turn it back on.
- •No toggle? Open a support ticket. Only the sponsoring registrar can remove a client code — no other party can do it for you.
- •If the registrar refuses to unlock for a transfer without a listed reason, note that ICANN's Transfer Policy governs when registrars may deny transfers; escalate within the registrar first.
Monitor every domain status automatically
Sourdough pulls live RDAP status for every domain you track and flags anything unusual — holds, locks, redemption — before it becomes a problem. 7 days free, then $10/mo. $0 due today.
Unlocking server codes (registry locks)
You cannot contact a registry directly as a registrant — everything routes through your registrar. If the server code is part of a registry lock service you purchased, use its verified unlock procedure. If you never requested it, ask your registrar to find out why it's set: legal disputes and redemption-related holds are the usual explanations, and those don't clear until the underlying issue does.
Expect registry-side removal to take longer than a registrar toggle — per ICANN, the registrar must forward your request to the registry and wait for them to lift the restriction.
Locks you cannot remove: the 60-day rules
Two transfer restrictions come from ICANN policy rather than a removable lock: no inter-registrar transfer within 60 days of initial registration, and none within 60 days of a previous transfer. Many registrars also apply a 60-day transfer hold after registrant contact information changes. No unlock toggle bypasses these — you wait them out.
Frequently Asked Questions
How do I know if my domain is locked?
Run a WHOIS or RDAP lookup and read the status codes. Any of the six *TransferProhibited, *UpdateProhibited, or *DeleteProhibited codes is a lock; client* codes are registrar-set, server* codes are registry-set.
Should I keep my domains locked?
Yes — ICANN recommends the client prohibition codes as protection against unauthorized transfers, updates, and deletions. Unlock only for a specific operation, then re-lock. For high-value names, consider a registry lock service on top.
How can I monitor lock status across my whole portfolio?
Check each domain's RDAP status codes periodically — or use a portfolio tool that does it for you. Sourdough enriches every tracked domain with live RDAP data, including status codes, with a 7-day free trial.