
Domain Names14 min
ICANN Transfer Policy Updates: TAC Codes, Losing/Gaining Notifications, and What Changed
NS
NameSilo Staff11/20/2025
Share
Domain transfers between registrars have evolved significantly over the past few years as ICANN refined policies to balance security with user convenience. The introduction of Transfer Authorization Codes (TAC), changes to notification requirements, and clarifications around timing windows have reshaped how domain owners move their registrations between providers. Understanding these updates helps you navigate transfers smoothly while protecting your domains from unauthorized movements.
The modern transfer process involves multiple stakeholders: the domain owner, the losing registrar (your current provider), and the gaining registrar (where you want to move the domain). ICANN's policies govern how these parties interact, what notifications must be sent, when transfers can occur, and what security measures apply. Recent updates have attempted to streamline legitimate transfers while strengthening protections against domain hijacking.
The Evolution from Auth Codes to TAC
Historically, domain transfers relied on authorization codes, sometimes called EPP codes or auth codes. The losing registrar provided these codes to domain owners, who then supplied them to gaining registrars to prove transfer authorization. This system worked but lacked standardization in code generation, storage, and handling.
ICANN introduced the concept of Transfer Authorization Code (TAC) to formalize and improve this mechanism. While functionally similar to traditional auth codes, TAC represents a more standardized approach with specific requirements for code generation, lifetime, and usage.
A TAC must be:
- Generated by the losing registrar upon domain owner request
- Unique and sufficiently complex to prevent guessing
- Valid for a reasonable time period (typically at least 30 days)
- Revocable by the domain owner if compromised
- Provided to the domain owner through secure channels
The distinction between "auth code" and "TAC" is partly semantic, but the TAC framework establishes clearer expectations. When you register a domain and later decide to transfer it, obtaining a TAC from your registrar becomes the first step in the transfer process.
Registrars implement TAC generation differently. Some display codes in control panels immediately upon request. Others send codes via email to the registered contact address. The method matters for security—immediate display in authenticated control panels reduces interception risk, while email transmission requires secure email practices.
Transfer Process Timeline and Critical Windows
ICANN's transfer policy defines specific timeframes that govern the transfer process. Understanding these windows helps you plan transfers and know when delays might indicate problems.
When a gaining registrar initiates a transfer using a valid TAC, the losing registrar receives notification. At this point, the losing registrar has five calendar days to either approve or deny the transfer. If the losing registrar takes no action within five days, the transfer automatically proceeds.
Domain owners receive notifications at multiple points:
- Initiation notification: When the gaining registrar submits the transfer request
- Losing registrar notification: Informing the domain owner that a transfer was requested, typically including instructions for canceling unwanted transfers
- Completion notification: Confirming the transfer finished successfully
The five-day window serves as a protection mechanism. If someone initiated an unauthorized transfer, domain owners have five days to notice the losing registrar's notification and cancel the transfer before it completes. This makes monitoring email associated with domain registration critical for security.
Some registrars allow immediate transfer approval, bypassing the five-day wait. The domain owner can log into the losing registrar's control panel and explicitly approve the pending transfer, completing it within hours rather than days. This option balances convenience with security—the domain owner must authenticate with the losing registrar to use it.
Losing Registrar Notifications and Response Options
When a transfer request arrives, the losing registrar must notify the domain owner. This notification typically includes:
- Confirmation that a transfer was requested
- Identity of the gaining registrar
- Instructions for denying/canceling the transfer if it was unauthorized
- Warning about the consequences of allowing the transfer to proceed
- Deadline for taking action (within the five-day window)
The notification goes to the registrant email address on file with the losing registrar. If this address is outdated or compromised, you may not receive the notification, allowing unauthorized transfers to proceed. Maintaining current contact information with your registrar is essential.
To cancel an unwanted transfer, domain owners typically:
- Log into the losing registrar's control panel
- Navigate to domain management or pending transfers section
- Select the option to deny or cancel the transfer
- Confirm the cancellation
Some registrars allow cancellation via email response to the notification, though control panel methods are more secure since they require authentication.
If you initiated a legitimate transfer but receive a cancellation notification suggesting someone is trying to block it, investigate immediately. This might indicate account compromise at the losing registrar or attempts to prevent your authorized transfer.
Gaining Registrar Responsibilities
The gaining registrar—the provider you are transferring to—has its own set of responsibilities under ICANN policy. Before initiating a transfer, the gaining registrar must:
- Verify that you provided a valid TAC
- Confirm the domain is not in certain locked states (more on this below)
- Notify you that the transfer has been initiated
- Provide contact information for transfer support
The gaining registrar cannot charge you for a transfer that ultimately fails, though policies vary on deposits or pre-authorization of funds. When you begin a transfer to a new registrar, review their specific transfer policies regarding timing, refunds, and support procedures.
After transfer initiation, the gaining registrar monitors the process and communicates status updates. If the losing registrar denies the transfer for policy reasons (like a lock status), the gaining registrar should explain why and help resolve the issue.
Upon successful transfer, the gaining registrar must add one year to the domain's registration term. This extension occurs automatically and is included in the transfer fee. Your domain effectively gets renewed as part of the transfer process, which is why transfers near renewal time make financial sense.
The 60-Day Transfer Lock
One of the most important—and sometimes frustrating—transfer restrictions is the 60-day lock following certain events. ICANN policy requires registrars to lock domains against transfer for 60 days after:
- Initial registration
- Inter-registrar transfer (a successful transfer between registrars)
- Change of registrant (updating the domain owner's information)
These locks prevent rapid-fire transfers that could be used in domain theft schemes. If someone gains unauthorized access to your account, registers a domain, and immediately transfers it elsewhere, the 60-day lock provides a window for detection and recovery.
However, the 60-day lock can complicate legitimate scenarios. If you register a domain at one registrar and immediately realize you prefer another, you cannot transfer for 60 days. If you complete a transfer and then decide the new registrar is not suitable, another 60-day wait is required before transferring again.
The change of registrant lock deserves particular attention. ICANN distinguishes between changes to registrant contact information (like updating an email address) and changes of registrant (transferring ownership to a different person or entity). Only the latter triggers the 60-day lock, but registrars interpret and implement this distinction differently.
Some registrars treat any modification to registrant information as a potential change of ownership and impose locks. Others allow minor updates without locks but require explicit confirmation for ownership changes. Understanding your registrar's specific implementation helps avoid unexpected delays.
When planning to transfer a domain, verify it is not within any 60-day lock period. Check the registration date, last transfer date, and any recent registrant updates. Most registrars display lock status in domain control panels, and transfer attempts within locked periods are denied with explanatory messages.
Domain Status Codes and Transfer Eligibility
Beyond the 60-day lock, various EPP status codes affect transfer eligibility. These codes, set by registrars or registry operators, control what operations can be performed on a domain.
Key status codes for transfers:
clientTransferProhibited: Set by the registrar to prevent transfers. Often used as an optional security lock that domain owners can enable or disable. Some registrars automatically enable this status for all domains and require owners to explicitly disable it before initiating transfers.
serverTransferProhibited: Set by the registry, typically for policy violations, legal disputes, or during registry-level security holds. Domain owners cannot directly remove this status and must work with the registrar or registry to resolve underlying issues.
pendingTransfer: Applied automatically when a transfer is in progress. No new transfer can initiate while this status exists.
redemptionPeriod: Applied after domain expiration when the domain enters the redemption grace period. Transfers cannot occur during redemption.
Before initiating a transfer, check your domain's status codes. Most WHOIS lookup tools display these codes. If clientTransferProhibited is set, you need to disable it through your current registrar's control panel. If serverTransferProhibited is set, contact your registrar to understand why and resolve the restriction.
Security Considerations and Best Practices
Domain transfers represent a potential attack vector. If attackers gain access to your registrar account or email, they might initiate unauthorized transfers to move domains under their control. Protecting against this requires multiple layers of security.
Strong authentication at registrars: Use strong, unique passwords for registrar accounts. Enable two-factor authentication if available. Many registrars now support 2FA through authenticator apps, SMS, or hardware tokens. This prevents account access even if passwords are compromised.
Secure email infrastructure: Since transfer notifications go to registrant email addresses, secure your email accounts rigorously. Use strong passwords, enable 2FA, and monitor for suspicious activity. Consider using dedicated email addresses for domain registration separate from general-purpose email.
Registry lock services: Some registries offer enhanced lock services that provide additional protection beyond standard transfer prohibit statuses. These locks require special procedures to remove, making unauthorized transfers extremely difficult even with account compromise. Registry locks are particularly valuable for critical domains like those used for primary business websites or email services.
Monitor transfer notifications closely: Configure email filters to flag transfer-related messages. Set up separate folders or forwarding for important domain notifications so they do not get lost in routine email. If you receive an unexpected transfer notification, act immediately to investigate and cancel if unauthorized.
Keep contact information current: Registrars send notifications to addresses on file. If these are outdated, you will not receive warnings about unauthorized transfers. Review and update contact information regularly, especially after email account changes or staff turnover.
Document authorized transfers: When you initiate a legitimate transfer, document the timing, gaining registrar, and expected completion date. This helps distinguish authorized transfers from potential attacks if you receive notification emails.
Common Transfer Problems and Solutions
Despite standardized policies, transfers sometimes encounter problems. Understanding common issues helps resolve them quickly.
Invalid TAC: If the gaining registrar reports an invalid TAC, verify you copied the code correctly, including all characters without extra spaces. Check if the TAC has expired—some registrars set short expiration periods. Request a new TAC from the losing registrar if necessary.
Domain locked: If the transfer fails due to lock status, check both clientTransferProhibited and serverTransferProhibited codes. Remove client locks through your registrar control panel. For server locks, contact your registrar's support team to understand the restriction and required steps to remove it.
Incorrect registrant information: Some registrars verify that registrant information in the transfer request matches their records. Discrepancies can cause denials. Ensure the gaining registrar uses exactly the same registrant information as appears in your current registration.
Recently transferred or registered: If you are within the 60-day lock period, you must wait. However, registries can waive this lock in special circumstances, such as registrar business closures or emergency ownership changes. Contact your registrar to request a waiver with appropriate justification.
Expired domain: Domains in redemption or pending delete status cannot transfer. If your domain expired, you must renew it before transferring. Some registrars charge premium fees for redemption renewals, so maintaining current registration is more economical.
Registry-level issues: Occasionally, registry systems experience problems processing transfers. If both registrars confirm all requirements are met but the transfer still fails, check the registry's status page or contact both registrars for assistance.
Bulk Transfers and Portfolio Management
Organizations managing many domains face additional complexity in transfers. Moving hundreds or thousands of domains requires planning and often custom processes.
Most registrars support bulk transfer operations where you provide lists of domains and TACs through spreadsheet uploads or API calls. Verify the gaining registrar offers bulk transfer capabilities before committing to move large portfolios.
Timing bulk transfers requires attention to registrar limits and operational capacity. Some registrars process only a certain number of transfers per day. Spreading transfers across multiple days or weeks may be necessary for very large portfolios.
Financial considerations matter for bulk transfers. Each transfer includes a one-year renewal, so transferring 1,000 domains at $10 each represents a $10,000 expense. Budget for this renewal cost in addition to transfer fees if applicable.
For organizations with domains across multiple registrars consolidating to a single provider, coordinate timing to avoid simultaneously managing transfer processes at several gaining registrars. Staging transfers in phases allows you to validate processes and resolve issues before proceeding with the full portfolio.
ICANN Compliance and Registrar Obligations
ICANN requires registrars to comply with transfer policies, and registrars can face sanctions for violations. As a domain owner, understanding registrar obligations helps you identify when problems stem from non-compliance.
Losing registrars must:
- Provide TACs promptly upon domain owner request
- Process transfers within the five-day window
- Not deny transfers except for specific policy-compliant reasons
- Send required notifications to domain owners
- Waive transfer-out fees (though some ccTLDs may differ)
Gaining registrars must:
- Validate TACs before initiating transfers
- Notify domain owners of transfer initiation
- Add one year to domain registration upon successful transfer
- Provide adequate support throughout the process
If your registrar violates these requirements, for example, refusing to provide TACs, denying transfers without valid reasons, or failing to send notifications, you can file a complaint with ICANN. The Registrar Stakeholder Group handles compliance issues and can investigate registrar behavior.
Impact on Related Services
Domain transfers affect services tied to the domain. Understanding these impacts helps you maintain service continuity during transfers.
DNS hosting: Transfers do not automatically change DNS nameservers. Your nameserver settings remain as configured, so websites and email continue working immediately after transfer. However, you may need to update nameservers if the new registrar requires specific settings or if you want to use their DNS hosting services.
Email services: If you use domain-based email addresses through your registrar's email hosting, those services may not transfer with the domain. Email hosting is typically separate from domain registration. Before transferring, verify whether email services continue at the losing registrar or must be migrated separately to maintain continuity.
SSL certificates: Domain validation for SSL certificates often involves registrar-based validation methods. If certificates are set to auto-renew using registrar-specific validation, the transfer might complicate renewal. Document current SSL configurations and ensure validation methods work after the transfer or plan to revalidate certificates.
WHOIS privacy: Privacy protection services are registrar-specific and do not transfer between providers. If you use WHOIS privacy at your current registrar, that protection ends with the transfer. Immediately enable privacy protection at the gaining registrar after transfer completes to avoid exposing personal information in WHOIS records.
Auto-renewal settings: Auto-renewal configurations do not transfer. After completing a transfer, log into the gaining registrar and configure auto-renewal to prevent accidental expiration. This is particularly important if you are used to domains automatically renewing at the previous registrar.
Special Considerations for Premium and Reserved Domains
Some domains carry premium pricing or special restrictions that affect transfers. Premium generic terms, short domains, or category killers may have transfer procedures different from standard domains.
Premium domains at some registrars include enhanced support, additional security features, or special renewal pricing. Verify whether premium status transfers with the domain or if the gaining registrar treats it as standard. Transfer fees for premium domains may also differ from standard domains.
Reserved domains held by registries under special agreements might have transfer restrictions or require registry approval. If you hold such a domain through a grandfathered allocation or special agreement, consult both registrars before initiating transfer to ensure the domain's special status transfers correctly.
International Considerations and ccTLDs
While ICANN policies govern generic top-level domains (gTLDs) like .com, .net, and .org, country code top-level domains (ccTLDs) operate under their own rules. Transfer procedures for ccTLDs vary by country.
Some ccTLDs use registrar systems similar to gTLDs, supporting TAC-based transfers with comparable processes. Others use entirely different mechanisms, such as requiring paper forms, notarized documents, or registry-direct coordination.
If you hold international domains across multiple ccTLDs, research each registry's specific transfer requirements. What works for .com transfers may not apply to .uk, .de, or .jp domains. Many ccTLD registries publish transfer guides, and registrars supporting those extensions typically provide ccTLD-specific instructions.
Looking Forward: Ongoing Policy Evolution
ICANN continues refining transfer policies based on community feedback and operational experience. The Universal Acceptance Steering Group and other ICANN working groups regularly review transfer processes for security improvements and user experience enhancements.
Recent discussions have focused on:
- Reducing the 60-day lock period for certain scenarios
- Standardizing change of registrant procedures across registrars
- Improving notification mechanisms for domain owners
- Enhancing security for high-value domains
Staying informed about policy changes helps you adapt your domain management practices. ICANN publishes policy updates through its website and mailing lists. Major registrars also communicate policy changes affecting customers.
Practical Transfer Checklist
When planning a domain transfer, following a systematic checklist reduces problems:
- Verify the domain is not within a 60-day lock period
- Check domain status codes and remove clientTransferProhibited if set
- Ensure contact information at the losing registrar is current
- Obtain the TAC from the losing registrar
- Initiate the transfer at the gaining registrar using the TAC
- Monitor email for transfer notifications from both registrars
- Approve the transfer through the losing registrar if offering immediate approval
- After transfer completes, verify DNS settings are correct
- Configure auto-renewal at the gaining registrar
- Enable WHOIS privacy if desired
- Update documentation with new registrar information
This systematic approach helps catch issues early and ensures critical steps are not forgotten during the transfer process.
When Transfers Make Sense
Not every domain needs transferring. Evaluate whether a transfer benefits your situation:
Consolidation: If domains are spread across multiple registrars, consolidating to one provider simplifies management, especially for bulk operations or consistent policy application.
Cost savings: Registrar pricing varies significantly. Transferring to providers with lower renewal rates saves money over time, particularly for large portfolios.
Better features: Some registrars offer superior control panels, DNS management, API access, or security features like domain defender. Transferring for improved tooling can streamline domain operations.
Service quality: Poor support, frequent downtime, or unresponsive registrars justify transfers to more reliable providers. Domain registration is too critical to tolerate substandard service.
Consolidating services: If you use hosting and other services from one provider, having domain registration there too can simplify billing and support interactions.
However, transfers involve effort and potential service interruption risk. For stable domains at competent registrars with acceptable pricing, staying put may be the best choice. Transfer decisions should weigh benefits against operational overhead.
Conclusion
ICANN's transfer policies create a framework balancing domain owner rights with security protections. Understanding TACs, notification requirements, lock periods, and registrar obligations helps you navigate transfers confidently. Whether moving a single domain or managing a large portfolio, systematic approaches and awareness of policy requirements ensure smooth transitions between registrars while maintaining security throughout the process.
.png&w=2048&q=75)
NameSilo StaffThe NameSilo staff of writers worked together on this post. It was a combination of efforts from our passionate writers that produce content to educate and provide insights for all our readers.
More articleswritten by NameSilo



