dotvitals

No update lock is set on the domain

MediumConfirmedQuick windomain.rdap.no-update-lock

What this check looks for

The registry shows no clientUpdateProhibited status, so the domain's nameservers and contact details can be changed from inside the registrar account with no further step. The lock is free and takes about a minute to turn on.

Why it matters

Changing the nameservers is the quiet version of stealing a domain: the registration still says your name, but the site, the email and every certificate that can be issued for the name now belong to whoever made the change. It is often noticed hours later, through a failing mailbox rather than an alert.

When the check passes, your report says: “An update lock is set, so nameservers cannot be changed quietly”.

What it costs your score

When this check fails it removes 10 points from your Domain registration score, before the status, confidence and repeat multipliers are applied. Domain registration carries a weight of 5 in the overall score.

It shares the domain.locks family ceiling of 30 points: however many findings that family produces, together they cannot remove more than that from Domain registration. One underlying problem showing up in several places is still one problem.

Severity
medium
Default confidence
confirmed
Status when triggered
warn
Deduction
10 points
Family cap
domain.locks · 30
Category
Domain registration
Module
Domain rdap
Fix owned by
registrar
In the ruleset since
2026.09

How the whole score is calculated

How to fix it

Turn on the update lock (clientUpdateProhibited) at your registrar.

It blocks the fastest route to a hijacked domain: a silent nameserver change.

  1. Open the domain in your registrar's control panel and enable the update or modification lock. Some registrars expose it only through support — ask for clientUpdateProhibited by name.

  2. Set the transfer lock at the same time if it is not already on; they are usually the same screen.

  3. Expect to unlock the domain when you next change DNS host. That one extra step is the protection working.

How to confirm it worked

  • Re-run this scan and confirm clientUpdateProhibited now appears in the domain's status codes.

A named slot like ‹domain› — and the braces left in the configuration below — is filled in with your own values when this rule appears on a report.

Technical detail

The registry reports these status codes: ‹statuses›. clientUpdateProhibited is not among them, and neither is the registry-level serverUpdateProhibited.

With the lock set (EPP clientUpdateProhibited, RFC 5731 §2.3) the registrar refuses nameserver and contact changes until it is explicitly lifted. It is a smaller protection than the transfer lock — it does not survive an attacker who can also lift it — but it removes the fastest, quietest route to a hijacked domain, and it costs nothing.

If you change DNS providers regularly, the lock adds one unlock step to that work. That is the whole trade-off.

Standards and references

Test this on your domain

Run the check that produces this finding, on its own, against any domain.

Open the domain rdap checker

Other domain rdap checks