Before you can transfer a domain to a new registrar, you have to unlock it — turn off the transfer lock that registrars apply as a security protection. It is a small, quick setting change, but it is a mandatory first step, and forgetting it is the single most common reason a transfer request bounces back rejected. This guide explains what the transfer lock is, why it exists, and exactly how to turn it off so your transfer can proceed.
You will learn what a domain (transfer) lock is and why registrars use it, how to find and turn it off, how to confirm the domain is actually unlocked, how the lock relates to the other transfer prerequisites, why you should unlock only when you are ready to transfer, and what to do if you cannot unlock it. By the end you will be able to unlock any eligible domain correctly and get your transfer moving.
Did you know?
The transfer lock is a security setting that blocks your domain from being moved without your say-so. Turning it off is a quick toggle at your current registrar — and forgetting to is the #1 reason a transfer request gets rejected.
What a domain transfer lock is
A domain transfer lock (also called a registrar lock or domain lock) is a protection setting on your domain that prevents it from being transferred to another registrar while the lock is on. When enabled — and it usually is by default — it blocks any transfer request, so an attempt to move the domain elsewhere is automatically refused until you deliberately turn the lock off.
The lock exists for security: it is a safeguard against unauthorised or malicious transfers. Domain hijacking — where someone tries to steal a domain by transferring it away from its owner — is a real threat, and the transfer lock is a simple, effective barrier against it, ensuring a domain cannot be moved unless the legitimate owner deliberately unlocks it first. That is why registrars enable it by default and why it is considered good practice to keep it on except when you are actively transferring.
So the transfer lock is a security feature, not an obstacle to resent — it protects your domain from being stolen. But it does mean that when you genuinely want to transfer your domain, you must first turn the lock off yourself, since it will otherwise block your own legitimate transfer just as it would block a malicious one. Unlocking is simply telling your registrar ‘yes, I really do want to allow this domain to move,’ which is exactly the deliberate consent the lock is designed to require.
How to turn off the transfer lock
Unlocking a domain is done at your current registrar — the one that currently manages the domain — in the domain’s management settings. You log into your registrar account, go to the specific domain you want to transfer, and look for the lock setting, which is usually labelled something like ‘Transfer Lock’, ‘Domain Lock’, ‘Registrar Lock’, or ‘Theft Protection’, often in a security or domain-settings section.
You turn the lock off by toggling or disabling that setting — a single switch, in most registrar interfaces. The change usually takes effect immediately or within a short time. Some registrars may ask you to confirm the change or send a notification about it (itself a security measure), but fundamentally it is a quick toggle from locked to unlocked.
So turning off the transfer lock is a matter of finding the lock setting in your domain’s management page at your current registrar and switching it off. It is genuinely a small action — the difficulty, when people have any, is usually just locating the setting, since registrars label and place it differently. If you cannot find it, your registrar’s help documentation or support can point you to it, but it is always somewhere in the domain’s settings, because every registrar must provide a way to unlock a domain for transfer.
Confirming the domain is unlocked
After turning off the lock, confirm the domain is actually unlocked before you proceed with the transfer, because attempting a transfer on a still-locked domain is exactly what causes the common rejection. The registrar interface should show the domain’s status as unlocked once you have disabled the setting — check that the status reflects the change rather than assuming the toggle took effect.
For a more definitive check, a domain’s transfer status is part of its public registration record, which reports a status code indicating whether the domain is locked or unlocked (a locked domain shows a ‘transfer prohibited’ status, an unlocked one does not). You do not strictly need to check this technical record — the registrar’s own display is usually sufficient — but it is the authoritative confirmation that the domain is genuinely open to transfer.
So confirm the unlock took effect by checking the domain’s status in your registrar account (and, if you want certainty, in its public registration record). This quick confirmation prevents the frustration of initiating a transfer that then bounces because the lock was still on — either because the toggle did not save, or took time to apply. Once the status clearly shows unlocked, you know the domain is ready for the next transfer steps, and you can proceed with confidence rather than discovering the lock issue only when the transfer fails.
How unlocking fits with the other prerequisites
Unlocking is one of a short set of prerequisites for a domain transfer, and it helps to see how it fits with the others so you do them together. Alongside unlocking, you need to obtain the auth/EPP code (the authorisation code that proves your right to transfer), and the domain must satisfy the standing conditions: at least 60 days old at the current registrar, in good standing, with an accessible administrative email.
Unlocking and getting the auth code are the two active preparation steps you take at your current registrar, and it is efficient to do them in the same session — unlock the domain, then grab the auth code — so the domain is fully prepared to leave. The other conditions (the 60-day rule, good standing, accessible email) are states to verify rather than actions to perform, but they matter just as much for the transfer to succeed.
So unlocking is the first of the active prerequisites, naturally paired with obtaining the auth code, and sitting alongside the conditions the domain must already meet. Handling the unlock and the auth code together, after confirming the standing conditions, gets the domain fully ready for transfer in one pass at your current registrar. Seeing unlocking as part of this small checklist — rather than an isolated step — is what ensures you do not begin a transfer with one prerequisite still missing, which is the usual cause of a bounced request.
Why unlock only when you’re ready to transfer
Because the transfer lock is a security protection, the best practice is to keep it on at all times except when you are actively transferring the domain — so you should unlock only when you are genuinely ready to begin a transfer, and consider re-locking if you decide not to proceed. Leaving a domain unlocked indefinitely removes a valuable safeguard against hijacking, for no benefit if you are not transferring.
This timing matters because an unlocked domain is, by design, more exposed: the lock’s whole purpose is to require deliberate consent for a transfer, so a domain left unlocked has that barrier down. If you unlock a domain but then delay the transfer for a long time, you are leaving it in a less protected state unnecessarily. The sensible approach is to unlock as part of starting the transfer, not far in advance.
So treat unlocking as an action tied to an active transfer: unlock when you are ready to move the domain, complete the transfer, and know that the domain will be locked again at the new registrar (where you should keep it locked as your ongoing protection). If you unlock but change your mind about transferring, turn the lock back on. This keeps the security benefit of the lock intact for all the time you are not transferring, which is almost always — the domain only needs to be unlocked for the brief window of the transfer itself.
What to do if you can’t unlock it
Occasionally you may be unable to unlock a domain, and the reason usually falls into a few categories worth knowing. The domain may be within a period where transfers (and thus unlocking for transfer) are restricted — most notably the 60-day rule after registration or a previous transfer — in which case you simply have to wait out the period before you can transfer.
There can also be a registrar-imposed hold or a status issue: a domain that is expired, in dispute, or under a specific lock (such as one applied for a pending change or a verification requirement) may not be unlockable until that underlying issue is resolved. In these cases, the block is not the ordinary transfer lock but a separate condition, and you address it by resolving the cause — renewing an expired domain, completing a required verification, or settling a dispute.
So if you cannot unlock a domain, identify why: a timing rule like the 60 days means waiting, while a hold or status issue means resolving the underlying cause first. Your registrar’s support can clarify which applies if it is not obvious from the domain’s status. In the ordinary case, though, unlocking is a simple toggle that works immediately — genuine inability to unlock is uncommon and almost always points to one of these specific, resolvable conditions rather than a real barrier to ever transferring the domain.
FAQs
How do I unlock a domain for transfer?
Log into your current registrar, go to the domain’s management settings, find the lock setting (labelled ‘Transfer Lock’, ‘Domain Lock’, ‘Registrar Lock’, or ‘Theft Protection’, usually in a security section), and toggle it off. The change usually takes effect quickly. Then confirm the domain’s status shows as unlocked before initiating the transfer, since a still-locked domain is the most common cause of a rejected transfer.
What is a domain transfer lock?
It’s a security setting (also called a registrar lock or domain lock) that prevents your domain from being transferred to another registrar while it’s on. It’s usually enabled by default to guard against unauthorised or malicious transfers (domain hijacking). Because it blocks all transfers — including your own legitimate one — you must deliberately turn it off before you can transfer the domain.
Why is my domain locked?
Registrars enable the transfer lock by default as a security protection against domain hijacking — it ensures your domain can’t be moved without your deliberate consent. So a locked domain is the normal, protected state, not a problem. When you genuinely want to transfer, you turn the lock off yourself. It’s good practice to keep it on at all times except when actively transferring.
How do I know if my domain is unlocked?
Check the domain’s status in your registrar account — it should show as unlocked after you disable the setting. For definitive confirmation, a domain’s public registration record reports a status indicating locked or unlocked (a locked domain shows a ‘transfer prohibited’ status). Confirming the unlock took effect prevents starting a transfer that bounces because the lock was still on.
Should I keep my domain locked or unlocked?
Keep it locked at all times except when you’re actively transferring it. The lock is a security safeguard against hijacking, so leaving a domain unlocked indefinitely removes that protection for no benefit. Unlock only when you’re ready to begin a transfer, and if you change your mind, re-lock it. After a transfer, keep the domain locked at the new registrar as your ongoing protection.
Why can’t I unlock my domain?
Usually a timing rule or a status issue. The 60-day rule (after registration or a previous transfer) restricts transfers, so you may have to wait. Or the domain may be expired, in dispute, or under a separate hold or verification requirement that must be resolved first. In those cases the block isn’t the ordinary transfer lock but a separate condition — resolve the underlying cause, or contact your registrar’s support to clarify.
The bottom line
Unlocking a domain is the mandatory first action of any transfer, and it is genuinely a small one — a single toggle in your domain’s management settings at your current registrar — but skipping it is the most common reason a transfer request bounces back rejected. The transfer lock (also called a registrar lock or domain lock) is a security protection, usually on by default, that prevents your domain from being moved without your deliberate consent, guarding against domain hijacking. That is why it exists and why it is good practice to keep it on at all times except when you are actively transferring: to unlock is simply to tell your registrar ‘yes, I really do want to allow this domain to move,’ which is exactly the deliberate consent the lock is designed to require.
To unlock, log into your current registrar, find the lock setting in the domain’s settings (its label varies — Transfer Lock, Domain Lock, Registrar Lock, Theft Protection), switch it off, and then confirm the domain’s status actually shows as unlocked before you proceed, since a still-locked domain is what causes the classic rejection. Pair the unlock with obtaining your auth/EPP code in the same session, so the domain leaves your current registrar fully prepared, and unlock only when you are genuinely ready to transfer rather than far in advance, keeping the security benefit intact the rest of the time. If you find you cannot unlock, the cause is almost always a specific, resolvable condition — the 60-day rule (wait it out), or an expiry, dispute, or hold (resolve the underlying issue) — rather than a real barrier. Handle the unlock as the quick, deliberate first step it is, and your transfer proceeds without the most common avoidable hitch.
When you are ready, you can start with Hostinger and use code PROTIPS for the reader discount. Unlocking a domain is the mandatory first step of a transfer: log into your current registrar, open the domain’s settings, find the lock (‘Transfer Lock’, ‘Domain Lock’, ‘Registrar Lock’, or ‘Theft Protection’), and toggle it off — then confirm the status shows unlocked. It’s a security protection against hijacking, so keep it on except when actively transferring. Forgetting to unlock is the #1 cause of a rejected transfer. If you can’t unlock, it’s usually the 60-day rule (wait) or an expiry/dispute/hold (resolve it first).