Domain Transfer Explained:Requirements, EPP Codes and Timelines
How a domain transfer between registrars works: unlocking, the auth (EPP) code, the 60-day rules, renewal on transfer, typical timelines, and keeping your website and email online throughout.

Table of Contents
A domain transfer moves the management of a domain from one registrar to another. For common extensions like .com, the process is: unlock the domain at the current registrar, get the authorization (EPP/auth) code, start the transfer at the new registrar, approve it, and wait for it to complete, which usually takes up to five days. Your website and email keep working if the DNS stays the same during the move.
This guide covers the requirements, the rules that often block transfers, and how to avoid downtime.
Transfer vs pointing a domain
A transfer changes which company you renew the domain with. It is not needed just to use the domain with a different web host: for that, you only change nameservers or DNS records. See how to point a domain to hosting.
Requirements before you start
- The domain is at least 60 days old and has not been transferred in the last 60 days. ICANN's Transfer Policy lets registrars deny transfers within 60 days of registration or a previous transfer.
- No recent registrant change, in many cases. Under the current policy, a change of registrant name, organisation or email can trigger a 60-day transfer lock unless you opted out beforehand.
- The domain is not expired or in redemption, and is in good standing.
- The registrant email works, because transfer notices are sent there.
ICANN has approved changes to the Transfer Policy that registrars are implementing over time, so the exact lock rules can change. Check your registrar's current terms.
Step-by-step
1. Check DNS before you start
Note where your DNS is hosted. If it is hosted by the current registrar and that DNS service ends when you leave, copy every DNS record first (A, CNAME, MX, TXT) and recreate them at the new provider before the transfer completes. See nameservers vs DNS records.
2. Unlock the domain
At the current registrar, turn off registrar lock (also called transfer lock or "clientTransferProhibited").
3. Get the auth code
Request the authorization code (also called EPP code or transfer code). It acts as a password for the transfer. Keep it private.
4. Start the transfer at the new registrar
Enter the domain and the auth code on the new registrar's transfer page, for example the ServerNeed domain transfer page. Most gTLD transfers include a one-year renewal, which is added to the existing expiry date.
5. Approve the transfer
You may receive emails asking you to confirm, and the current registrar may ask whether to approve or reject it. If the current registrar does not respond within five calendar days, gTLD transfers are generally approved automatically.
6. Confirm completion
Once complete, the domain appears in your new account. Check the expiry date, contact details, nameservers and DNS records, then turn registrar lock back on.
Example: a transfer timeline
An illustrative .com transfer from Registrar A to Registrar B:
| Day | Step |
|---|---|
| Day 1 morning | Owner checks the domain is over 60 days old, notes DNS records, removes registrar lock at A and requests the auth code |
| Day 1 afternoon | Auth code received by email; transfer ordered at B with the code; one year of renewal paid |
| Day 1 evening | Registrar A emails the registrant about the pending transfer, with an option to approve now |
| Day 2 | Owner approves early at A, so the transfer completes the same day (otherwise it would complete automatically after about five days) |
| Day 2 | Domain appears at B with the expiry date extended by one year; nameservers unchanged, so website and email kept working |
| Day 2 | Owner re-enables registrar lock and 2FA at B, and checks contact details |
Before you transfer: a checklist
- The domain is more than 60 days old and was not transferred in the last 60 days
- No recent change of registrant that triggers a lock
- Registrant email is current and you can receive mail there
- DNS records are copied, if DNS is hosted by the current registrar
- Domain is not expired or close to deletion
- Privacy settings will not hide transfer emails from you
- Auth code requested and kept private
Common reasons a transfer fails
| Problem | Fix |
|---|---|
| Domain still locked | Remove the transfer lock at the current registrar |
| Wrong or expired auth code | Request a new code and copy it exactly |
| Within 60 days of registration or transfer | Wait until the period ends |
| Recent registrant change | Wait for the lock to end, or check whether it applies |
| Registrant email not working | Update it at the current registrar first |
| Domain expired | Renew it at the current registrar first |
Country-code domains
Extensions such as .bd follow their own registry's rules, which can differ completely from gTLD rules: some need documents, a specific form or registry approval rather than an auth code. Check the registry or your registrar's instructions.
Keeping the website and email online
- Keep the same nameservers during the transfer if they are not tied to the old registrar's service.
- If you must change DNS provider, set up the new DNS zone fully and switch nameservers before starting the transfer, then wait for propagation. See DNS propagation explained.
- Do not cancel the old registrar's DNS hosting until the transfer completes and the new DNS answers correctly.
Frequently Asked Questions
Does transferring a domain cause downtime?
Not if DNS stays the same or is moved carefully. The transfer itself only changes the registrar of record.
Do I lose the remaining time on my domain?
For gTLDs, the remaining registration period is normally kept and the transfer adds one year. Country-code rules vary.
Can a registrar refuse to give me the auth code?
Registrars must provide it to the registrant within the timelines in the policy, though they may first verify your identity.
Next steps
Start a transfer from the ServerNeed domain transfer page. For background, read domain names explained, and protect the domain afterwards with preventing domain hijacking.
Sources
Last updated 7 October 2026



