Domains & DNS
Domain transfer authorization codes: where to get one and how to use it
Understand Auth-Code, EPP, and transfer eligibility before moving a domain between registrars.
A domain transfer authorization code is a secret used in a supported transfer from one registrar to another. You may see it called an Auth-Code, AuthInfo code, EPP code, or transfer code. Obtain it from the current registrar and provide it through the destination registrar’s transfer process.
The code is not a DNS record, a website password, or a mailbox export. Having it does not mean the domain is eligible to move, and transferring registration does not move website files or email messages.
Where to get the code
Sign in to the registrar that currently manages the domain. Look for transfer-out or domain security settings. Some registrars show a code in the account; others send it to a verified contact. If you bought the domain through a reseller, start with that reseller’s support and identify the underlying registrar if necessary.
ICANN’s Auth-Code explanation applies to generic top-level domains under its contracts. It says registrars must provide a way to create the code or provide it within five calendar days of a request. ICANN itself cannot generate your code. Procedures for a country-code domain may instead follow its registry’s rules.
Use the domain’s actual registration provider, not whichever company happens to host the website. A hosting control panel may display the domain but have no authority to release its registration.
Check eligibility before using it
The ICANN transfer FAQ explains that recent registration, recent inter-registrar transfer, or a change-of-registrant lock can prevent a transfer. A normal registrar transfer lock may also need to be disabled. Ask which exact status is blocking your domain rather than repeatedly requesting fresh codes.
| What you see | Useful next step |
|---|---|
| No transfer-code option | Confirm the registrar, account permissions, and extension-specific process |
| Code rejected | Check the exact domain, copied characters, and whether a newer code replaced it |
| Transfer prohibited or locked | Identify the lock type and eligibility date with the current registrar |
| Confirmation email missing | Check the designated contact, spam folder, and support’s delivery record |
| Transfer pending | Read the destination’s status and expected next action before starting another request |
Use a controlled transfer sequence
- Confirm ownership and recovery access. Make sure the business controls the accounts and can receive the required notices.
- Check expiry and eligibility. Leave enough time to resolve a failed transfer without losing the registration.
- Preserve DNS and related services. Establish whether the old registrar will continue hosting your DNS zone.
- Unlock as required and obtain the code. Follow the current registrar’s supported process.
- Submit through the destination registrar. Review the domain spelling, transfer fee, and any term extension before paying.
- Complete the requested confirmations. Keep the order and support references until the move is finished.
- Check the new account. Confirm registration status, expiry, renewal, account protection, and working services.
Some transfers can be approved early; others follow a waiting period or require a different registry process. Use the status of your actual request. There is no single completion time that applies to every extension and registrar pair.
Treat the code like a credential
Do not put a live authorization code in a public support forum, screenshot, shared article, or repository. Give it only to the authorized person or destination service handling the transfer. If a code is exposed, ask the current registrar to invalidate or regenerate it and review the domain’s transfer status.
When an agency handles the move, define who owns the destination account. Moving a client’s domain into the agency’s personal account can make the next handover unnecessarily difficult even when the transfer itself succeeds.
What the code does not solve
The code does not back up DNS, preserve a bundled email plan, or cancel an old hosting subscription. Follow our domain transfer and email continuity guide for those dependencies. A successful registration transfer and a successful service transition should be checked separately.