1 Sep 2026 11 min read

How to Transfer a Domain Name Without Losing It

Domain transfers fail for predictable reasons: locked names, stale auth codes, the 60-day rule, and expired-domain timing. This guide walks through both transfer types step by step — and the traps that catch people at each stage.

Transferring a domain should be simple: get a code from the old registrar, give it to the new one, wait a few days. And most of the time it is. But the transfers that go wrong go wrong in ways that are genuinely painful — websites offline for days, email silently bouncing, names stuck in limbo for two months, and in the worst cases, domains lost outright because a transfer was attempted at exactly the wrong moment.

Every one of those failures is predictable, and every one is avoidable if you understand what is actually happening under the surface. This guide covers both kinds of transfer — moving between registrars, and moving between accounts — along with the timing rules, the DNS trap, and a pre-flight checklist that turns a nervous process into a boring one. Boring is what you want.

Two Very Different Things Called "Transfer"

The word "transfer" covers two operations that behave completely differently, and confusing them is the source of half of all transfer questions:

A registrar transfer moves the domain from one registrar company to another — say, from GoDaddy to Cloudflare. It is governed by ICANN rules for generic TLDs, involves an authorisation code, takes up to a week, costs roughly a year's registration fee, and adds a year to the domain's life.

An account push (also called an internal or account-to-account transfer) moves the domain between two accounts at the same registrar. No auth code, no ICANN process, no fee at most registrars, and it usually completes in minutes. When you buy a domain from someone who uses the same registrar as you, a push is faster and safer than a full transfer — and it neatly sidesteps the 60-day lock discussed below.

Rule of thumb for buyers: if the seller's registrar is acceptable to you, take delivery by push first and decide about a registrar transfer later, on your own schedule.

How a Registrar Transfer Actually Works

Understanding the mechanics explains the delays and failure points. A .com transfer runs through these stages:

  • Unlock: you disable the transfer lock at the current (losing) registrar. The lock exists to block unauthorised transfers, so it must be deliberately switched off
  • Auth code: you request the authorisation code (also called an EPP code or transfer key) from the losing registrar. This is the password for the transfer itself
  • Initiate: you start the transfer at the gaining registrar, supply the auth code, and pay the transfer fee — which includes a year's renewal on top of the current expiry date
  • Verification: the registry checks the code and the losing registrar is notified. The losing registrar can release immediately, or sit on the request for up to five days before it auto-approves
  • Completion: the domain appears in your account at the gaining registrar, with the lock re-enabled and a year added

Total elapsed time: minutes if the losing registrar offers instant release and you approve promptly, five to seven days if every timer runs its full course.

Gotcha: the auth code has a shelf life

Some registrars regenerate auth codes periodically or invalidate them after account changes. If you requested a code two months ago and only now start the transfer, there is a fair chance it no longer matches. A rejected transfer with "invalid authorisation" almost always means a stale code — request a fresh one, don't assume the transfer is blocked.

Gotcha: the confirmation email race

Transfers involve emails to the registrant's contact address — approval requests, security notices, sometimes an explicit confirmation link with a deadline. If that address is old, unmonitored, or (worse) hosted on the domain being transferred and broken mid-move, the transfer silently stalls or gets denied. Verify that the registrant email in WHOIS is one you actively read before starting anything.

The 60-Day Locks — Where Deals Get Stuck

ICANN imposes two separate 60-day restrictions on generic TLDs, and they trip up more domain purchases than everything else combined:

The registration lock: a newly registered domain cannot be transferred to another registrar for its first 60 days.

The change-of-registrant lock: when the registrant name, organisation, or email changes, most registrars impose a 60-day transfer lock from the date of that change. Some registrars let the prior registrant opt out of this lock at the moment of the change — but the seller has to do it then; it cannot be undone after the fact.

The gotcha inside the gotcha: completing a purchase often is a change of registrant. Buy a domain, update the ownership details into your name at the seller's registrar, and you may have just started a fresh 60-day clock — even though the domain itself is years old. If your plan was "buy it Monday, transfer it to my registrar Tuesday", the lock turns that into "transfer it in November".

How to plan around it:

  • Take delivery by account push at the seller's registrar whenever possible — pushes are not restricted by the 60-day rules
  • If you need the name at your own registrar urgently, ask (before payment) whether the seller's registrar supports opting out of the change-of-registrant lock
  • Otherwise, simply run the domain from the interim registrar for two months — you have full control of DNS regardless, so the website and email work from day one

The DNS Trap: Why Sites Go Dark Mid-Transfer

Here is the single most common way a transfer takes a working website offline. The domain uses the losing registrar's free DNS hosting. The transfer completes. The losing registrar — no longer being paid — deletes the DNS zone. The nameservers recorded at the registry still point at that registrar, which now answers with nothing. The site and email fail not during the transfer, but immediately after it succeeds.

The transfer process moves the domain's registration. It does not move the DNS zone contents — the A records, MX records, TXT verifications and everything else that makes the domain actually do things. Those live wherever your nameservers are, and they are your responsibility.

The safe sequence:

  • Export every DNS record first. Screenshot the zone, or copy it into a text file: A, AAAA, CNAME, MX, TXT, SRV — everything. TXT records are the ones people forget, and they carry your email authentication (SPF, DKIM) and service verifications
  • If you use third-party DNS (Cloudflare, your host, a dedicated DNS provider), you are largely safe — nameservers carry over with the transfer and nothing changes. This is one of several good reasons to keep DNS separate from your registrar
  • If you use the losing registrar's DNS, recreate the zone at the gaining registrar or a third-party provider before initiating, then switch the nameservers, let them propagate, and only then start the transfer
  • Lower your TTLs (time-to-live values) to 300 seconds a day or two before any nameserver change, so mistakes correct themselves in minutes rather than days

Transferring Near Expiry: The Danger Zone

A transfer started weeks before expiry is normally fine — the pending year gets added on completion. A transfer started days before expiry is gambling. If the domain expires mid-transfer, behaviour varies by registrar and registry: some transfers complete anyway, some fail, and the domain can slide into the redemption period where recovering it costs $80–$200 in redemption fees and the transfer must start over.

The counterintuitive safe play: if expiry is inside 30 days, renew at the current registrar first — even though it feels like paying the registrar you are leaving. The renewal year and the transfer year both stack onto the expiry date. A $12 renewal is cheap insurance against a $150 redemption and a fortnight of downtime. (If you are hunting names that have already expired, that is a different game entirely — see our expired domains guide.)

Special Cases Worth Knowing

Country-code TLDs play by their own rules

Everything above describes generic TLDs (.com, .net, .org and friends). Country codes are governed by national registries with their own procedures: .uk uses an IPS-tag change instead of auth codes, .de and .eu have their own transfer mechanics, and some ccTLDs impose residency requirements or handle the "extra year" differently. Before buying or moving a ccTLD, read the specific registry's transfer policy — assumptions imported from .com are the leading cause of ccTLD surprises.

Buying through escrow changes the order of operations

In an escrow-protected purchase, the transfer happens during the escrow window: funds are secured first, then the seller initiates the push or supplies the auth code, and funds release only after you confirm the domain is in your control. Never accept "payment first, code afterwards" outside escrow, and never release escrow funds before the name is actually in your account. Our escrow guide covers the full sequence.

Privacy services can hide the confirmation emails

WHOIS privacy replaces your contact details with a forwarding service. Most forward transfer-related emails reliably; some do not. If a transfer stalls with no email arriving, temporarily disabling privacy at the losing registrar often shakes the confirmation loose. Re-enable it after completion.

A Worked Example: Moving a Live Business Domain

To make the sequence concrete, here is how a careful owner moves a domain that carries a production website and company email — the highest-stakes version of the task — from Registrar A to Registrar B.

Two weeks out: they confirm the expiry date is months away and that no registrant details have changed in the last 60 days. They log into the DNS control panel and export the complete zone: four A records, two CNAMEs, three MX records, and five TXT records they had half-forgotten about — SPF, DKIM, a Google verification, a Microsoft 365 token, and an old site-verification string. Because DNS currently lives on Registrar A's free nameservers, they set up the same zone at an independent DNS provider and drop every TTL to five minutes.

One week out: they switch the nameservers at Registrar A to the new DNS provider — while the domain is still at Registrar A. This is the step most people skip. By separating the DNS move from the registrar move, any mistake in the zone shows up now, while everything is still reversible in minutes, rather than mid-transfer when nothing is. They watch the site and email behave normally for a few days on the new nameservers.

Transfer day: they verify the registrant email one more time, disable WHOIS privacy temporarily, switch off the transfer lock, request a fresh auth code, and initiate at Registrar B within the hour. Registrar A sends its confirmation email; they approve the release from inside their Registrar A account rather than waiting out the five-day timer. The domain lands at Registrar B the same day. The website and email never blink, because the nameservers — already pointing at the independent DNS provider — were untouched by the whole affair.

Aftercare: they re-enable the transfer lock and WHOIS privacy at Registrar B, confirm the expiry date gained a year, restore TTLs to an hour, and delete the now-dormant zone at Registrar A so a stale copy can never answer queries again. Total elapsed risk to the business: zero. The entire drama of the transfer happened at the registration layer, which visitors never touch.

Notice what made this uneventful: the DNS migration happened before and separately from the registrar migration. Almost every horror story you will read about transfers collapses into a single root cause — those two moves were attempted simultaneously, so when one wobbled, both fell.

The Pre-Transfer Checklist

Run through this before touching anything. Ten minutes here prevents essentially every failure mode in this article:

→
Check the expiry date

More than 30 days away? Proceed. Less? Renew at the current registrar first, then transfer.

→
Check the 60-day clocks

Registered or registrant-updated in the last 60 days? A registrar transfer will be refused — use an account push or wait it out.

→
Verify the registrant email

It must be an address you read today, and never one hosted on the domain being moved.

→
Export the full DNS zone

Every record type, especially TXT. If DNS is hosted at the losing registrar, rebuild it elsewhere before initiating.

→
Unlock and get a fresh auth code

Request the code immediately before initiating, not weeks in advance.

→
Keep both accounts accessible

You may need to approve the transfer from the losing side to skip the five-day wait.

💡 The Transfer Reality Check

A domain transfer moves the registration — nothing else. Your DNS records, your email routing, and your site's uptime are separate systems that you must carry across yourself. Treat the transfer as a three-part move: registration, DNS, and email. Plan all three and nothing goes dark.

Frequently Asked Questions

How long does a domain transfer take? +
A registrar-to-registrar transfer takes up to 5–7 days, because the losing registrar may wait out a five-day approval window. Many complete much faster when the losing registrar offers instant release and you approve from both sides. An account push at the same registrar usually completes within minutes to hours.
What is the 60-day transfer lock? +
ICANN rules block registrar transfers for 60 days after a domain is registered or after registrant details change. Buying a domain often triggers the registrant-change clock — plan to hold the name at the current registrar (via account push) until the lock expires, or ask about the opt-out before ownership details are changed.
Does transferring a domain add registration time? +
Yes — a registrar transfer of most gTLDs adds one year to the existing expiry, included in the transfer fee. Account pushes add nothing. Some country-code TLDs handle renewal-on-transfer differently, so check the registry policy first.
Will my website go down during a domain transfer? +
Not if DNS is handled correctly. Third-party nameservers carry over untouched. The danger case is using the losing registrar's free DNS: the zone can be deleted the moment the transfer completes. Export every record first and rebuild the zone at the new provider before initiating.

Browse our priced domain listings → — every purchase includes guided, escrow-protected transfer to your account.

Share: X LinkedIn

Continue Reading

Ready to find your premium domain?

400+ hand-picked names with transparent pricing. Buy now, make an offer, or lease to own.