The auth code — also called the EPP code, transfer key, or authorization code — is the single most important piece of information you need to transfer a domain. It is a unique password for your domain that proves to the new registrar you are entitled to move it, and without it, no transfer can happen. Getting it is usually quick, but registrars provide it in different ways, and a wrong or expired code is a common transfer snag. This guide shows you exactly how to obtain, handle, and use your auth code.
You will learn what the auth/EPP code is and why transfers require it, where to find it at your current registrar, how it is delivered to you, how to handle it securely, how to use it at the new registrar, and how to troubleshoot when a code does not work. By the end you will be able to get your domain’s auth code and use it to authorise a transfer with no snags.
Did you know?
The auth (EPP) code is a unique password for your domain — proof you’re allowed to move it. No transfer works without the correct, current one. It’s the one piece of information a domain transfer absolutely cannot happen without.
What the auth/EPP code is and why it’s needed
The auth code — short for authorization code, and also known as the EPP code (after the protocol domains use), transfer key, or transfer secret — is a unique string of characters assigned to your domain that acts as its transfer password. It is the credential the new registrar requires to prove that whoever is requesting the transfer is authorised to do so, because they possess this secret code tied to the domain.
Transfers require it as a fundamental security measure. Just as the transfer lock prevents a domain being moved without deliberate consent, the auth code ensures a domain cannot be transferred by anyone who does not have this specific code — which only the legitimate domain holder (with access to the current registrar account) can obtain. Requiring the auth code is how the domain system verifies the transfer is legitimate, preventing someone from moving your domain away from you without authorisation.
So the auth/EPP code is essentially a domain-specific password for transferring, and it is needed because it is the proof of authorisation that makes a transfer legitimate and secure. No transfer can proceed without the correct code, which is exactly why it is the most important thing to obtain when you decide to move a domain — and why it must be handled carefully, since anyone with your auth code (and an unlocked domain) could initiate a transfer. It is, in effect, the key to your domain’s mobility.
Where to find it at your current registrar
You obtain the auth code from your current registrar — the one that currently manages the domain — since only they can issue the code for a domain they hold. It is found in the domain’s management settings, typically alongside or near the transfer/unlock options, in a security or domain-details section. The exact label varies: look for ‘Auth Code’, ‘EPP Code’, ‘Transfer Code’, ‘Transfer Key’, ‘Authorization Code’, or ‘Get transfer key’.
In many registrar interfaces, you will find a button or link to reveal or request the code within the domain’s settings. Some registrars display the code directly on screen once you click to reveal it; others generate a fresh code on request; and some send it to your registered email rather than showing it in the interface (covered next). The domain usually needs to be unlocked first, so unlocking and getting the code are naturally done together.
So finding the auth code is a matter of going to the domain’s management page at your current registrar and locating the auth/EPP/transfer code option, which is near the transfer settings. If it is not obvious, the registrar’s help documentation or support can direct you, since every registrar must provide the code to the domain holder on request — it is a required part of allowing transfers. Once you have located and revealed or requested the code, you have the essential credential for the transfer.
How the code is delivered to you
Registrars deliver the auth code in one of a few ways, and knowing which yours uses avoids confusion:
- Displayed on screen: some registrars show the code directly in the domain settings when you click to reveal it — copy it from there.
- Emailed to you: many send the code to the domain’s registered administrative email as a security step, so it goes only to the verified contact.
- Generated on request: some create a fresh code each time you request one, so use the latest code you generated.
- Via support: occasionally you may need to request it through the registrar’s support if there is no self-service option (less common).
The email-delivery method is why an accessible administrative email matters — if the code is emailed to an address you cannot check, you cannot get the code. Whichever method your registrar uses, the code you end up with is the exact string you will paste at the new registrar. If your registrar generates a fresh code on request, be aware that requesting a new one may invalidate a previous one, so use the most recent. Knowing your registrar’s delivery method means you know where to look for the code and can retrieve it without confusion.
Handling the code securely
Because the auth code is effectively a transfer password for your domain, handle it with the same care you would any sensitive credential. Anyone who obtains your auth code, if your domain is also unlocked, could potentially initiate a transfer of your domain — so the code is genuinely sensitive and should not be shared casually or exposed where others could see it.
In practice, this means: only retrieve the code when you are ready to use it for a transfer, only enter it at the legitimate new registrar you are transferring to, and do not paste it into untrusted places or share it with anyone who does not need it. If you retrieved a code but did not end up transferring, it is good practice to consider it potentially exposed — and since codes can often be regenerated, generating a fresh one for an actual future transfer is sensible.
So treat the auth code as the sensitive credential it is: retrieve it when needed, use it only at the intended new registrar, and keep it private. The combination of an unlocked domain and a leaked auth code is exactly the scenario the transfer security system is meant to prevent, so not undermining it by mishandling the code is important. Handled carefully — retrieved when ready, used once, kept private — the auth code does its job of authorising your legitimate transfer without creating any risk to your domain.
Using the code at the new registrar
You use the auth code at the new registrar as part of initiating the transfer. When you start a transfer there and enter your domain name, the new registrar will prompt you for the auth/EPP code — you paste in the exact code you obtained from your current registrar, and this authorises the transfer request to proceed.
Accuracy is essential: the code must be entered exactly, with no missing or extra characters, no stray spaces, and the correct case if it is case-sensitive. Copy-pasting the code rather than typing it avoids transcription errors, which are a common cause of a code being rejected. Once you submit the correct code, the new registrar initiates the transfer with your current registrar, and the process moves to the approval and confirmation stage.
So using the code is simply pasting it accurately when the new registrar prompts for it during the transfer setup. This is the moment the auth code does its job — proving your authorisation and unlocking the transfer to proceed. Because a mistyped or wrong code is a frequent snag, taking care to enter it exactly (by pasting) is the small precaution that ensures the code is accepted first time and the transfer request goes through, rather than being rejected and needing to be re-entered.
Troubleshooting a code that doesn’t work
If your auth code is rejected, a handful of causes explain almost all cases. The most common is simple inaccuracy — a mistyped character, a missing or extra digit, or a stray space from copying, so re-copy the code carefully and try again. Case sensitivity can matter, so preserve the exact case. These transcription issues are the leading cause and the easiest to fix.
The next possibility is that the code is outdated: if your registrar generates a fresh code each time and you requested a new one, an older code you were using may no longer be valid — so use the most recently generated code. Relatedly, some codes are time-limited, so a code retrieved long ago might have expired, in which case you request a fresh one. And if the domain is not actually unlocked, a correct code will still not let the transfer proceed, so confirm the unlock as well.
So troubleshoot a non-working code by checking, in order: that you copied it exactly (the usual culprit), that you are using the latest generated code (not a superseded one), that the code has not expired (regenerate if so), and that the domain is unlocked. Almost every ‘the auth code doesn’t work’ situation resolves to one of these. If a freshly generated, correctly copied code on an unlocked domain still fails, your current registrar’s support can confirm the code is valid — but in practice, careful copying and a current code resolve the vast majority of auth-code problems.
FAQs
How do I get my domain’s auth/EPP code?
Get it from your current registrar (only they can issue it). Log in, go to the domain’s management settings, and find the auth code option — labelled ‘Auth Code’, ‘EPP Code’, ‘Transfer Code’, ‘Transfer Key’, or ‘Authorization Code’, usually near the transfer/unlock settings. Depending on the registrar, it’s displayed on screen, emailed to your registered address, or generated on request. The domain usually needs to be unlocked first.
What is an auth code / EPP code?
It’s a unique string of characters that acts as a transfer password for your domain — proof to the new registrar that you’re authorised to move it. Also called the EPP code, transfer key, or authorization code. It’s a security measure ensuring a domain can’t be transferred by anyone who doesn’t possess this secret code, which only the legitimate holder (with access to the current registrar account) can obtain. No transfer works without it.
Where is my EPP code delivered?
It depends on the registrar: some display it on screen in the domain settings when you click to reveal it, many email it to the domain’s registered administrative address as a security step, and some generate a fresh code on request. A few require you to request it through support. The email method is why an accessible administrative email matters — if you can’t check that inbox, you can’t receive the code.
Is the auth code sensitive — should I keep it secret?
Yes. The auth code is effectively a transfer password, so anyone who obtains it (with your domain unlocked) could potentially initiate a transfer of your domain. Retrieve it only when you’re ready to transfer, enter it only at the legitimate new registrar, and keep it private. If you retrieved a code but didn’t transfer, treat it as potentially exposed and regenerate a fresh one for any actual future transfer.
Why is my auth code not working?
Almost always a copy error — a mistyped or missing character, a stray space, or wrong case. Re-copy it exactly (paste rather than type). Otherwise: you may be using an outdated code (if your registrar generates a fresh one each time, use the latest), the code may have expired (regenerate it), or the domain may not actually be unlocked (a correct code still won’t work if it’s locked). Check those in order.
How do I use the auth code to transfer my domain?
At the new registrar, start a transfer and enter your domain name; it will prompt you for the auth/EPP code. Paste in the exact code from your current registrar — accuracy matters, so copy-paste rather than type to avoid transcription errors. Submitting the correct code authorises the transfer request, and the process moves to the approval/confirmation stage. A mistyped code is a common reason a code gets rejected.
The bottom line
The auth code — equally called the EPP code, transfer key, or authorization code — is the single indispensable credential for transferring a domain: a unique password tied to your domain that proves to the new registrar you are entitled to move it. It exists as a security measure, ensuring a domain cannot be transferred by anyone who does not possess this secret, which only the legitimate holder with access to the current registrar account can obtain — so no transfer can proceed without the correct, current code. You get it from your current registrar, in the domain’s management settings near the transfer options, where depending on the registrar it is displayed on screen, emailed to your registered administrative address (which is why an accessible email matters), or generated fresh on request.
Because the code is effectively a transfer password, handle it as the sensitive credential it is: retrieve it only when you are ready to transfer, use it only at the legitimate new registrar, keep it private, and regenerate a fresh one if a retrieved code went unused. Using it is simply pasting it exactly when the new registrar prompts during the transfer setup — and accuracy is everything, since a mistyped character, stray space, or wrong case is the leading reason a code is rejected, so copy-paste rather than type. If a code does not work, check in order that you copied it exactly, that it is the latest generated code, that it has not expired, and that the domain is actually unlocked — almost every auth-code problem resolves to one of those. Get the code, guard it, and enter it precisely, and this one small string does its job of authorising your transfer cleanly, which is exactly why it is the first thing to obtain once you decide to move a domain.
When you are ready, you can start with Hostinger and use code PROTIPS for the reader discount. The auth/EPP code (also transfer key or authorization code) is your domain’s transfer password — the credential the new registrar needs to prove you’re allowed to move it. Get it from your current registrar in the domain’s settings; it’s shown on screen, emailed to your registered address, or generated on request (unlock the domain first). Treat it as sensitive, use it only at the intended new registrar, and paste it exactly — a mistyped or outdated code is the usual reason it’s rejected. No transfer works without the correct, current code.