No update lock is set on the domain
What this check looks for
The registry shows no clientUpdateProhibited status, so the domain's nameservers and contact details can be changed from inside the registrar account with no further step. The lock is free and takes about a minute to turn on.
Why it matters
Changing the nameservers is the quiet version of stealing a domain: the registration still says your name, but the site, the email and every certificate that can be issued for the name now belong to whoever made the change. It is often noticed hours later, through a failing mailbox rather than an alert.
When the check passes, your report says: “An update lock is set, so nameservers cannot be changed quietly”.
What it costs your score
When this check fails it removes 10 points from your Domain registration score, before the status, confidence and repeat multipliers are applied. Domain registration carries a weight of 5 in the overall score.
It shares the domain.locks family ceiling of 30 points: however many findings that family produces, together they cannot remove more than that from Domain registration. One underlying problem showing up in several places is still one problem.
- Severity
- medium
- Default confidence
- confirmed
- Status when triggered
- warn
- Deduction
- 10 points
- Family cap
- domain.locks · 30
- Category
- Domain registration
- Module
- Domain rdap
- Fix owned by
- registrar
- In the ruleset since
- 2026.09
How to fix it
Turn on the update lock (clientUpdateProhibited) at your registrar.
It blocks the fastest route to a hijacked domain: a silent nameserver change.
Open the domain in your registrar's control panel and enable the update or modification lock. Some registrars expose it only through support — ask for
clientUpdateProhibitedby name.Set the transfer lock at the same time if it is not already on; they are usually the same screen.
Expect to unlock the domain when you next change DNS host. That one extra step is the protection working.
How to confirm it worked
Re-run this scan and confirm
clientUpdateProhibitednow appears in the domain's status codes.
A named slot like ‹domain› — and the braces left in the configuration below — is filled in with your own values when this rule appears on a report.
Technical detail
The registry reports these status codes: ‹statuses›. clientUpdateProhibited is not among them, and neither is the registry-level serverUpdateProhibited.
With the lock set (EPP clientUpdateProhibited, RFC 5731 §2.3) the registrar refuses nameserver and contact changes until it is explicitly lifted. It is a smaller protection than the transfer lock — it does not survive an attacker who can also lift it — but it removes the fastest, quietest route to a hijacked domain, and it costs nothing.
If you change DNS providers regularly, the lock adds one unlock step to that work. That is the whole trade-off.
Standards and references
Test this on your domain
Run the check that produces this finding, on its own, against any domain.
Other domain rdap checks
- The domain registration has expired
- The domain registration expires within 30 days
- The domain registration expires within 7 days
- The domain registration expires within 90 days
- No transfer lock is set on the domain
- The domain is suspended by the registrar or registry
- The domain is scheduled for deletion
- The domain is in the redemption period
- The registrant contact details are not published
- The registration data could not be read
- The registration is current and locked