6 min read

Domain status codes explained: clientTransferProhibited and the rest

EPP status codes look alarming and usually are not. What each one means, which are protective, which are trouble, and which mean the clock is running.

Look up any domain and you get a list of status codes that read like error messages: clientTransferProhibited, serverUpdateProhibited, clientHold. Most are routine protections. A few mean something is genuinely wrong. The distinction is worth knowing before you call your registrar.

The client and server prefixes

This is the key to reading all of them. A code starting with client was set by your registrar, and you can usually change it yourself in their control panel. A code starting with server was set by the registry that runs the top-level domain, and only the registry can lift it. Same restriction, very different conversation.

Normal and protective

  • ok: no restrictions at all. Slightly misleading, because a domain with protective locks is arguably in better shape than one with a bare ok.
  • clientTransferProhibited: your registrar blocks transfers to another registrar. This is the standard anti-hijacking lock and you want it on. Lift it yourself when you genuinely intend to transfer.
  • clientDeleteProhibited and clientUpdateProhibited: your registrar blocks deletion or changes to the record. Also protective, common on domains that matter.
  • serverTransferProhibited: the registry blocks transfers, normally for 60 days after registration or after a previous transfer. Temporary and expected.

Worth investigating

  • clientHold: your registrar has removed the domain from the zone, so it does not resolve at all. Usually an unpaid invoice or a failed contact verification. The site and email are down until it is cleared.
  • serverHold: the registry has done the same, typically for a legal or compliance reason. Harder to resolve and rarely a surprise.
  • inactive: no name servers are assigned, so nothing resolves. Common on a freshly registered domain, a problem on an established one.

The clock is running

  • autoRenewPeriod: the domain passed its expiry date and was auto-renewed. You can normally still pay or cancel during this window.
  • redemptionPeriod: the domain expired and was deleted. Only the original registrant can restore it, for an extra fee, and only for a limited time.
  • pendingDelete: the final stage. The name cannot be restored by anyone and will be released to the public shortly.

Why check them at all

Status codes are the earliest public signal that something is happening to a domain. A clientHold appears the moment a registrar suspends it, well before anyone in the business connects the dots between an unpaid invoice and the website being unreachable. Reading them is free, and they are published by the registry precisely so that anyone can.

Stop finding out from your customers

WWT watches uptime, certificates, domain expiry and email records around the clock, and tells you before any of them break.