Domain transfer refers to the process of moving a domain registration from one registrar to another. Typically, the domain owner remains the same; only the service provider managing renewal, contact details, and registration settings changes. Transfer does not automatically move the website, database, email, or content, nor does it equate to changing nameservers, although some settings may be adjusted during the process. Procedures vary depending on the domain extension and registry, so official instructions should be reviewed before initiating a transfer.
Authorization Code and Requirements
Many generic top-level domains require an authorization code, known as an Auth-Code or EPP code, along with domain unlocking at the current registrar. This code allows the new registrar to verify that the request is legitimate; it must be obtained from an official source and shared only with the provider handling the transfer. Additional requirements may include email confirmation, registrant data verification, and absence of locks or disputes. Some country-code domains follow different procedures and may not use the same authorization code or have specific restrictions.
A recent registration, a change in ownership, domain lock status, imminent expiration, or a dispute can prevent or delay a transfer. The registrar may also impose a lock window after certain changes, based on TLD policies. Owners should verify the expiration date, administrative contacts, and domain status, and plan ahead. It is unwise to initiate a transfer when the domain is near expiration without confirming who will handle renewal and how a potential grace period will be managed.
DNS and Service Continuity
Before initiating a transfer, it should be confirmed whether nameservers will remain unchanged or if DNS hosting will also be moved. If only the registrar changes but delegation stays the same, the website and email can continue operating, though it's advisable to ensure that nameservers and records are not reset by the new panel. If the DNS provider is also changed, the entire zone must be copied and verified: A, AAAA, CNAME, MX, TXT, SRV, DNSSEC, and subdomains. It’s essential to align DS records published at the registry with the new DNSSEC signature, as misalignment can block resolution by authoritative resolvers.
Domain transfer does not move web content. If hosting migration is also planned, it must be coordinated separately with file and database backups, destination testing, certificates, email setup, and rollback plans. Before switching, current values should be saved and the site verified to respond. After completion, ownership, expiration, lock status, nameservers, DNSSEC, auto-renewal, and contacts should be checked. A completion notice does not confirm that all services remain properly configured.
Security Risks and Best Practices
Unexpected transfer requests may indicate an attempt at domain theft. Do not share the Auth-Code via email without verifying identity and context. Access the registrar panel using its known URL, enable strong authentication, and maintain the lock until approval is confirmed. After transfer, registrant data and user privileges should be re-reviewed, and temporary credentials revoked.
In summary, a domain transfer changes the registrar responsible for managing the registration but does not necessarily alter ownership or website infrastructure. Proper planning, secure acquisition of the Auth-Code, DNS verification, and final checks are essential to prevent disruptions and maintain control over the domain name.
← Full glossary