- Domain theft is a real, documented risk that a simple setting largely prevents.
- Here is what transfer lock actually does, and when you legitimately need to turn it off.
Domain hijacking — an attacker gaining unauthorized control of your domain and transferring it away — is a real, documented risk, particularly for valuable or established domains. Transfer lock is the primary, simplest defense against it.
What Transfer Lock Actually Does
When enabled (the default setting for most domains), transfer lock prevents the domain from being transferred to a different registrar without first being explicitly unlocked by the legitimate account holder. This blocks the most common domain hijacking method: an attacker with partial access attempting to move the domain to a registrar they control.
Why This Matters
- A stolen or transferred domain can take down your website and email simultaneously, with no warning.
- Recovering a hijacked domain, when possible at all, is a slow, often expensive dispute process.
- Business domains with real traffic, brand value or email dependency are attractive targets specifically because of that value.
Checking and Enabling Transfer Lock
- Log into your domain registrar's management panel.
- Locate the domain status or security settings section.
- Confirm "Transfer Lock" or "Registrar Lock" is enabled — most registrars enable this by default, but it is worth verifying directly.
When You Legitimately Need to Disable It
- You are intentionally initiating a transfer to a different registrar.
- The transfer requires an EPP/authorization code, which is only obtainable once the lock is disabled.
- Re-enable the lock immediately once the legitimate transfer is complete.
What a Real Domain Hijacking Attempt Looks Like
The pattern security researchers document most often does not start with breaking the registrar's own security — it starts with compromising the registrant's email account (via phishing or a reused, breached password), then using that email access to reset the registrar account password directly. Transfer lock is the layer that stops this chain from ending in a completed theft even after the account itself is compromised, which is exactly why it matters as a distinct, additional control rather than a redundant one on top of a strong password.
Additional Domain Security Layers
- Enable two-factor authentication on your domain registrar account itself, not just the domain settings.
- Ensure the registrant email address on the domain is current and actively monitored — it is the primary recovery channel.
- Consider domain privacy protection to reduce the personal information exposed publicly via WHOIS.
- Use a strong, unique password for your registrar account, distinct from other services.
Frequently Asked Questions
Does transfer lock cost extra?
No — it is a standard, free feature included with virtually all domain registrations and should already be enabled by default.
Can transfer lock prevent me from managing DNS or renewing my domain?
No — it specifically blocks registrar-to-registrar transfers only, not routine DNS management, renewal, or other administrative actions on the domain.
Should I re-lock a domain immediately after a legitimate transfer completes?
Yes — the lock is typically re-enabled by the new registrar automatically shortly after transfer, but confirming this directly rather than assuming it happened is good practice for a valuable domain.
Questions about domain security? See our domain services or ask our team.