dotvitals

No transfer lock is set on the domain

HighConfirmedQuick windomain.rdap.no-registrar-lock

What this check looks for

The registry shows no clientTransferProhibited status, so nothing at your registrar has to be unlocked before a transfer request to another registrar can proceed. The lock is free and takes about a minute to turn on.

Why it matters

This is the classic domain-takeover path. Someone who gets into the registrar account — or who convinces support they are you — starts a transfer, and with no lock in the way it completes on a timer whether you notice or not. Once the domain is at another registrar, getting it back is a formal dispute, not a support ticket.

When the check passes, your report says: “A transfer lock is set, so the domain cannot be moved quietly”.

What it costs your score

When this check fails it removes 25 points from your Domain registration score, before the status, confidence and repeat multipliers are applied. Domain registration carries a weight of 5 in the overall score.

It shares the domain.locks family ceiling of 30 points: however many findings that family produces, together they cannot remove more than that from Domain registration. One underlying problem showing up in several places is still one problem.

Severity
high
Default confidence
confirmed
Status when triggered
fail
Deduction
25 points
Family cap
domain.locks · 30
Category
Domain registration
Module
Domain rdap
Fix owned by
registrar
In the ruleset since
2026.09

How the whole score is calculated

How to fix it

Turn on the transfer lock (clientTransferProhibited) at your registrar.

Without it, a transfer request started by anyone with account access completes on a timer.

  1. Open the domain in your registrar's control panel and enable the setting called Transfer Lock, Registrar Lock or Domain Lock. It is free at every registrar.

  2. While you are there, turn on two-factor authentication for the registrar account. The lock protects against a transfer; 2FA protects against the account access that would let someone lift it.

  3. For a domain the business depends on, ask the registrar about a registry lock as well — a manual, out-of-band process that puts serverTransferProhibited and serverUpdateProhibited on the domain so no online change is possible at all.

How to confirm it worked

  • Re-run this scan and confirm clientTransferProhibited now appears in the domain's status codes.

A named slot like ‹domain› — and the braces left in the configuration below — is filled in with your own values when this rule appears on a report.

Technical detail

The registry reports these status codes: ‹statuses›. clientTransferProhibited is not among them, and neither is the registry-level serverTransferProhibited that would make it redundant.

The lock is set by your registrar at your request (EPP clientTransferProhibited, RFC 5731 §2.3). It does not stop you transferring the domain — it makes you unlock it first, deliberately, from inside the account. That extra step is the entire protection, and it is why every registrar offers it at no cost.

A newly registered or newly transferred domain often carries serverTransferProhibited for the first 60 days instead. That is a registry lock, it expires on its own, and it is not a substitute for asking your registrar to set the client lock.

Standards and references

Test this on your domain

Run the check that produces this finding, on its own, against any domain.

Open the domain rdap checker

Other domain rdap checks