WEBINVEST.IT
Glossary

Auth-Info

Auth-Info, also known as Auth-Code, authorization code, or transfer code, is a code used in certain procedures to authorize the transfer of a domain from one registrar to another. In the context of gTLDs governed by ICANN, the code is generated by the registrar and serves to protect the transfer request from unauthorized actions. It is not the registrar account password, does not replace user authentication, and alone does not prove domain ownership. It is sensitive information because possession of it could allow someone to initiate a transfer procedure, in accordance with the rules applicable to the TLD and the domain’s status.

Transfer procedures vary by extension and registrar. Some systems allow the owner to generate or view the code from their control panel; others require a request to the registrar. For certain gTLDs, ICANN policy mandates specific obligations for registrars to provide the code upon request by the registrant. National extensions may follow different rules and not exactly mirror the same process. Therefore, users should consult the registrar’s documentation and the relevant registry rather than relying on generic instructions found online. An Auth-Info field may also refer to legacy system data, not necessarily an active code.

When It Is Needed

The code is typically required during inter-registrar transfers. The new registrar may ask for it to confirm that the request originates from the legitimate domain or account holder. Before initiating the process, it is advisable to verify that the domain is transferable, there are no holds or waiting periods, and registrant data is accessible. In some cases, a registrar lock must be disabled or an email confirmation completed; in others, transfer may be blocked by specific extension limitations. The code is part of the process but not an automatic approval.

Transmitting Auth-Info through unprotected channels or to unverified individuals can expose the domain to risk. The owner should generate it when needed, share it only with the intended new registrar, and avoid publishing it in open tickets, forwarded emails, or uncontrolled shared documents. If the code is exposed, contact the registrar immediately to revoke or regenerate it, check the domain’s status, and activate any available locks. Changing the account password may help in case of compromise but does not replace transfer procedure oversight.

Recommended Steps

An ordered transfer begins with verifying the domain and instructions from the new provider. Note the current registrar, expiration date, nameservers, DNS records, and associated email services. Then request the code using the correct account, store it securely temporarily, and enter it only in the official interface of the new registrar. Do not send it to an intermediary simply because they claim to handle the sale—the authorization must align with contractual terms and the entity performing the registration. If the domain belongs to an organization, the request should follow an internal approval process.

After submission, monitor notifications and transfer status directly through the involved registrars. Keep receipts and confirmations but avoid storing the code in plain text longer than necessary. Once the process is complete, verify who controls the domain, which registrar is associated, and whether nameservers remain correct. Registration transfer does not always include hosting, email, SSL certificates, or DNS zone transfers—these services may depend on separate providers and accounts. A continuity plan helps prevent disruptions.

In summary, Auth-Info is a limited authorization credential for transfer procedures, with rules varying by TLD. It should be treated as a temporary operational secret: request it from the official registrar, do not disclose it, and verify the entire process before and after execution. For gTLD requirements, consult ICANN’s official guide on Auth-Code.

← Full glossary