serverHold vs clientHold: What's the Difference?
serverHold and clientHold have identical symptoms: your domain is removed from the TLD's DNS zone and stops resolving — no website, no email, nothing. The difference is who imposed it, and that single fact determines how bad it is and how you get out.
clientHold is set by your registrar. serverHold is set by the registry operator itself, and registries don't act casually.
Side-by-side comparison
| clientHold | serverHold | |
|---|---|---|
| Set by | Your registrar | The registry operator |
| Typical causes | Failed email verification, non-payment, abuse complaints, pending deletion | Registry-level abuse action, TLD policy violations, court orders, missing delegation |
| Severity | Moderate — often administrative | High — usually policy, abuse, or legal |
| Who can lift it | The registrar, directly | Only the registry, at the registrar's request |
| Typical fix time | Hours to days | Days to indefinite, depending on cause |
| Your first move | Check email for verification/billing notices, then registrar support | Registrar support — ask them to query the registry |
When each one appears
clientHold is the registrar's enforcement lever. Per ICANN it's usually enacted during legal disputes, non-payment, or pending deletion — and in day-to-day practice, the single most common trigger is a registrant who never clicked the ICANN-required contact verification email. It's serious but usually administrative, and the fix is often self-service.
serverHold means the registry acted. Per ICANN, if you provided delegation information, it may indicate an issue needing resolution — in practice registry-level abuse enforcement, TLD policy noncompliance (common with restricted ccTLDs), or legal orders. One benign exception: some registries use serverHold on domains that simply have no nameservers yet, where it functions like inactive.
Monitor every domain status automatically
Sourdough pulls live RDAP status for every domain you track and flags anything unusual — holds, locks, redemption — before it becomes a problem. 7 days free, then $10/mo. $0 due today.
Which is worse?
serverHold, almost always. A registrar hold has a short list of mundane causes and a support queue that can fix it today. A registry hold implies the problem was severe enough to escalate past the registrar — and adds a layer to every step of the fix, since you can't talk to a registry directly and your registrar must relay everything.
Both deserve the same response speed, though: every hour on hold is downtime for whatever runs on the domain.
Diagnosing and monitoring
RDAP output tells you which hold you have — and whether both are present, which happens when registrar and registry each flagged the domain. Fix order then matters: the registrar can clear its own hold, but the registry hold requires the underlying registry-level issue resolved first.
Because holds land without warning to anyone who isn't reading the registrant inbox, portfolio owners should watch status codes continuously. Sourdough monitors every tracked domain's RDAP status, with a 7-day free trial — a hold shows up in your dashboard, not just in your bounce logs.
Frequently Asked Questions
Do serverHold and clientHold both take my site offline?
Yes — both remove the domain from the TLD zone, so DNS resolution fails globally for web, email, and everything else. The difference is who imposed the hold and how it gets lifted, not the symptom.
Can a domain have both serverHold and clientHold?
Yes. Registrar and registry can each set their hold independently, and both appear in RDAP. Both must be lifted before the domain resolves again — clearing only the registrar's hold isn't enough.
Which hold is faster to fix?
clientHold, usually — common causes like email verification or a missed payment can clear the same day via your registrar. serverHold requires the registry to act, which adds a relay through your registrar and typically days or more.