transferProhibited domain status
transferProhibited rejects any request to move the domain to another registrar. The client variant is routine anti-hijack hygiene; the server variant usually means a dispute or a registry lock.
Updated
- Set by
- Registrar (client) or registry (server)
- Effect
- Transfers to another registrar are rejected
- RDAP shows
- client transfer prohibited / server transfer prohibited
What clientTransferProhibited / serverTransferProhibited means
RFC 5731 defines the prohibited suffix plainly: requests to transfer the object must be rejected. clientTransferProhibited is set by the registrar and is the standard anti-hijack lock most registrars apply at registration or on request, so it is one of the most common codes a lookup will show.
serverTransferProhibited is the registry-set version. ICANN lists it as uncommon, usually enacted during legal or other disputes, at the registrant’s request, or while a redemptionPeriod is in place. Some registries also bundle it into a paid Registry Lock service together with serverUpdateProhibited and serverDeleteProhibited.
On a domain you are watching
On a domain you are watching, the client variant says little: registrars apply it by default, so it reads as ordinary hygiene rather than a defense against your report. The server variant is worth noting, since it points to a dispute in progress, a paid registry lock, or an accompanying redemptionPeriod.
Check a domain’s status codes
The lookup reads a domain’s live RDAP record and returns its current status set.
What to do about clientTransferProhibited / serverTransferProhibited
To transfer a domain held by the client code, ask the registrar to remove it. The server version must be lifted at the registry through the registrar, which takes longer and usually requires resolving whatever prompted it.
Sources
Frequently asked questions
No. It is the standard registrar lock against unauthorized transfers, and most registrars set it automatically. It only blocks moving the domain to a different registrar; everything else works normally.
The client variant is registrar-set routine protection. The server variant is registry-set and usually accompanies a legal dispute, a registry lock service, or a redemptionPeriod, per ICANN.
Related tools and resources
Domain Abuse Contacts
Query RDAP records, live status codes, and verified abuse channels for any domain.
Domain monitoring
Daily monitoring for lookalike domains across 1,570 TLDs, with every match checked and explained.
How to Report Domain Abuse to a Registrar
Find the sponsoring registrar, collect required DNS evidence, and submit an actionable report.
Ongoing brand monitoring
notolens checks daily registrations across 1,570 TLDs, trademark registers, and app stores. When a lookalike domain, conflicting mark, or copycat app appears, notolens checks it, explains the risk, and hands you the records and possible next steps.