The EPP code is an authorization code used to confirm the transfer of a domain between registrars in top-level domains that adopt this mechanism. It is also referred to as Auth-Code, AuthInfo, or Transfer Code, depending on the registry and provider. The term EPP refers to the Extensible Provisioning Protocol used by registrars to communicate with registries, but the code provided to the domain owner is a specific credential for authorizing an operation. It is not the account password, does not identify the owner, and must not be published or sent to unverified recipients.
Obtaining and Using the Code
The domain owner requests the code from the current registrar's control panel or through the official support procedure. It may be necessary to unlock the domain, confirm the administrative address, or complete an identity verification. The code is then provided to the new registrar along with the transfer request. In many cases, the registry or registrar validates that it matches the registration; an incorrect or expired code can lead to rejection. Some providers generate temporary codes or allow regeneration, so instructions should be checked in the current panel.
Not all extensions follow identical procedures. Some national TLDs use a specific format or release channel for AuthInfo, while others may not require a traditional EPP code. Blocks might be imposed after registration, renewal, owner change, or contact updates. The code does not bypass such blocks nor replace the approval required by the registrar. Before scheduling a date, verify the TLD procedure and the registration status, especially if the expiration is near.
Protecting the Code
Anyone with the Auth-Code can attempt to authorize a transfer, so it must be treated as a credential. It should only be shared with the chosen registrar through an official portal or verified channel. Phishing emails often mimic urgent transfer notifications and request the code or panel credentials. Do not click suspicious links; access the provider’s known address directly and contact support via official channels. If the code is accidentally shared, ask the registrar to revoke it or generate a new one, lock the domain, and review notifications.
An organization should record in its inventory who requested the code, for which domain, and for which transfer, avoiding inclusion in logs. Ticketing systems are not always suitable for storing plain-text secrets. Registrar access must have strong authentication and individual roles; the Auth-Code does not replace account controls. After completion, verify that the domain is in the new account, the owner is correct, the lock and nameservers match expectations, and renewal is scheduled.
Common Issues
If a transfer fails, check spelling, spaces, generation date, locks, contacts, and blocking windows. The provider’s error message may indicate whether the code is invalid or if another cause exists. Repeatedly requesting codes without understanding the issue can create confusion and increase exposure. Escalation procedures should involve both registrars and the registry only through official channels.
In summary, the EPP code is a temporary or controlled key for authorizing domain transfers. It must be obtained from the current registrar, used only with the new provider, and protected as a secret. Precise rules depend on the extension and should be verified before initiating the process.
← Full glossary