What is a registrar lock?

A registrar lock (also called domain lock, transfer lock, or client transfer prohibited status) is a security feature that prevents your domain from being transferred to another registrar without your explicit authorisation.

How registrar lock protects your domain:

  • Prevents unauthorized transfers: Blocks domain hijacking attempts
  • Stops accidental transfers: Prevents you from accidentally initiating a transfer
  • Requires explicit unlock: You must manually disable the lock before transferring
  • Industry standard: Recommended by ICANN for all domain owners

What registrar lock does NOT prevent:

  • Updating WHOIS contact information
  • Changing nameservers
  • Modifying DNS records
  • Renewing the domain
  • Adding or removing services

The lock only affects domain transfers between registrars.

When do you need to unlock your domain?

You must unlock your domain when:

  • Transferring to another registrar: Moving your domain from 0724 Hosting to another provider
  • Transferring between accounts: Moving domain ownership to a different client area account
  • Changing registrars for consolidation: Bringing all domains under one registrar
  • Required by new registrar: Some registrars require unlock before initiating transfer

When to keep your domain locked:

  • All other times when you are NOT actively transferring the domain
  • As a security best practice, always re-lock after completing a transfer

How to check if your domain is locked

Method 1: Check in client area

  1. Log in to https://ca.0724.co.za
  2. Go to Domains β†’ My Domains
  3. Click on your domain name
  4. Look for Registrar Lock or Transfer Lock status
  5. It will show either "Enabled" (locked) or "Disabled" (unlocked)

Method 2: WHOIS lookup

  1. Visit a WHOIS service like who.is or whois.net
  2. Enter your domain name
  3. Look for Domain Status in the results
  4. If you see clientTransferProhibited, the domain is locked
  5. If this status is missing, the domain is unlocked

How to unlock your domain for transfer

Step 1: Log in to the client area

  1. Navigate to https://ca.0724.co.za
  2. Enter your email address and password
  3. Click Login

Step 2: Access your domains

  1. Click Domains in the top menu
  2. Select My Domains from the dropdown
  3. You will see a list of all your domains

Step 3: Select the domain

  1. Find the domain you want to unlock
  2. Click on the domain name (or click Manage)
  3. You will be taken to the Domain Management page

Step 4: Disable registrar lock

  1. Scroll to the Registrar Lock section
  2. Current status will show "Enabled" (locked)
  3. Click Disable Registrar Lock or toggle the lock to "Off"
  4. Confirm the action if prompted

Step 5: Verify unlock

  1. The page will refresh and show "Registrar Lock: Disabled"
  2. You may receive a confirmation email
  3. The unlock is processed immediately by the registry

Domain unlock timing

After disabling the registrar lock:

  • Immediate processing: The unlock is submitted to the registry instantly
  • Registry confirmation: Most registries process unlocks within 5-15 minutes
  • WHOIS update: Updated status appears in public WHOIS within 30 minutes
  • Transfer ready: You can request EPP code and initiate transfer immediately after unlocking

Verifying domain unlock status

Check in the client area:

  1. Return to Domains β†’ My Domains
  2. Click your domain
  3. Confirm "Registrar Lock: Disabled"

Check via WHOIS:

  1. Perform a WHOIS lookup at who.is
  2. Check Domain Status field
  3. If clientTransferProhibited is NOT listed, the domain is unlocked
  4. You may still see other status codes like ok or clientUpdateProhibited

Domain status codes explained

WHOIS results show EPP (Extensible Provisioning Protocol) status codes:

Transfer-related statuses:

  • clientTransferProhibited: Domain is locked, transfer not allowed (registrar lock enabled)
  • serverTransferProhibited: Registry-level lock, contact support to resolve
  • pendingTransfer: Transfer is in progress
  • ok: Domain is in normal status, can be transferred if unlocked

Other common statuses:

  • clientUpdateProhibited: WHOIS updates restricted (security feature, does not affect transfers)
  • clientDeleteProhibited: Domain cannot be deleted (security feature)
  • redemptionPeriod: Domain expired and in redemption (cannot be transferred)
  • pendingDelete: Domain scheduled for deletion (cannot be transferred)

After unlocking: Getting your EPP code

After unlocking your domain, you need the EPP code (also called authorisation code or transfer key) to complete the transfer:

  1. Stay on the Domain Management page in the client area
  2. Look for EPP Code or Auth Code section
  3. Click Request EPP Code or Get Auth Code
  4. The EPP code will be displayed on screen or emailed to your registrant email
  5. Provide this code to the gaining registrar (new registrar) to initiate the transfer

For detailed instructions, see our guide: How to Request EPP/Auth Code

Special considerations for South African (.za) domains

For .co.za, .net.za, .org.za, and other .za domains:

.za domain transfer process:

  • No EPP codes: .za domains do not use EPP codes for transfers
  • Registry-initiated: Transfers are handled directly through ZACR (ZA Central Registry)
  • Registrar lock still applies: You must still unlock .za domains before transferring
  • Email confirmation: Transfer approval is sent to the registrant email address in WHOIS
  • ZACR process: New registrar submits transfer request, you approve via email link

Unlocking .za domains:

Follow the same unlock process in the client area. After unlocking:

  1. Ensure your WHOIS email address is current and accessible
  2. Contact the new registrar to initiate the transfer
  3. Wait for ZACR transfer approval email
  4. Click the approval link within the timeframe specified (usually 5-7 days)
  5. Transfer completes after approval

Security considerations

Re-lock after transfer:

After your transfer completes at the new registrar:

  • Immediately re-enable registrar lock at the new registrar
  • Verify the lock is enabled via WHOIS lookup
  • This prevents unauthorized transfers from your new registrar

Monitor for unauthorized unlock attempts:

  • Most registrars send email notifications when registrar lock is disabled
  • If you receive an unlock notification you did not request, immediately contact support
  • Change your client area password if you suspect unauthorized access

Security best practices:

  • Keep domains locked: Only unlock when actively transferring
  • Use strong passwords: Protect your client area account with a strong, unique password
  • Enable two-factor authentication: If available in the client area, enable 2FA for added security
  • Verify WHOIS email: Ensure your registrant email is secure and accessible
  • Monitor domain status: Periodically check domain status via WHOIS

Common domain unlock issues

Error: "Domain cannot be unlocked"

If you cannot unlock your domain:

  • Domain expired: Expired domains cannot be unlocked. Renew the domain first
  • Domain suspended: Suspended domains must be unsuspended before unlocking
  • Transfer in progress: If a transfer is pending, wait for it to complete or cancel
  • Registry lock: Some domains have registry-level locks (serverTransferProhibited) that require contacting support
  • Recent registration: Some TLDs have a 60-day transfer lock after registration (ICANN policy)

60-day transfer lock

ICANN requires most TLDs (.com, .net, .org, etc.) to be locked for 60 days after:

  • Initial registration
  • Transfer to a new registrar
  • Registrant name or organisation change in WHOIS

This 60-day lock cannot be removed early. You must wait until the period expires before transferring.

Domain unlocked but transfer still fails

If the domain is unlocked but transfer fails:

  • Verify WHOIS email address is current and accessible
  • Check that EPP code is correct (for international domains)
  • Ensure domain has not expired or is not in redemption period
  • Confirm the domain is eligible for transfer (not within 60-day lock period)
  • Contact support for assistance diagnosing transfer issues

Re-enabling registrar lock

If you unlocked a domain but decided not to transfer:

Re-lock in the client area:

  1. Go to Domains β†’ My Domains
  2. Click your domain
  3. Click Enable Registrar Lock
  4. Confirm the action
  5. The lock is immediately re-enabled

Why re-lock immediately:

  • An unlocked domain is vulnerable to unauthorized transfers
  • If you are not actively transferring, keep the domain locked
  • Re-locking is instant and can be disabled again if needed

Transferring domains to 0724 Hosting

If you are transferring a domain TO 0724 Hosting (not away from us):

  1. Unlock the domain at your current registrar
  2. Obtain the EPP/auth code from your current registrar
  3. Visit the 0724 Hosting domain registration page
  4. Select "Transfer" and enter your domain name
  5. Complete the transfer order and provide the EPP code
  6. Approve the transfer via email when prompted

For detailed instructions, see: How to Transfer a Domain to 0724 Hosting

Getting help with domain unlocking

If you need assistance unlocking a domain, troubleshooting transfer issues, or understanding domain status codes, contact 0724 Hosting support. We can help with:

  • Unlocking domains if you cannot access your client area account
  • Resolving registry-level locks (serverTransferProhibited)
  • Verifying 60-day transfer lock status
  • Troubleshooting failed transfer attempts
  • Understanding ZACR .za domain transfer requirements
  • Providing EPP codes for outgoing transfers