Domain name security, theft, recovery and disputes
Abstract nested ring illustration representing Registry Lock

LayerRegistry

Registry Lock

Governing policy
Registry service, not ICANN policy
Layer
Registry
Authority
RFC 5731 section 2.3, August 2009

The only lock your own registrar cannot remove, because the registry sets it and a human at the registry must clear it

What Registry Lock Actually Freezes

Registry lock is a service sold by the registry operator — the company that runs an entire top-level domain's master database, such as Verisign for .com and .net — that freezes a domain in the registry's own records. While it is on, the registration cannot be transferred, deleted or updated through normal channels by anyone, including the registrar you bought the domain from. The lock comes off only after a person at the registry verifies the request out of band, meaning on a different channel from the one the request arrived on: in practice a phone call to a named individual who has to give a pre-agreed security phrase.

That is the entire product. The status codes, the contracts and the contact lists all exist to force any change to your domain through a human being at the registry who cannot be reached from a registrar control panel, an API key or a support ticket. It is the only control in the stack that survives the total compromise of your registrar account, and that is the only reason to buy it.

Why the Word server Is the Entire Mechanism

Domain records in a registry carry status codes — flags that permit or forbid a particular operation on the record. Registrars set and read those flags over EPP, the Extensible Provisioning Protocol, which is the machine language registrars use to talk to registries. The domain object is defined in RFC 5731 (August 2009, part of Internet standard STD 69), and section 2.3 states the rule that makes registry lock possible: "Status values that can be added or removed by a client are prefixed with 'client'. Corresponding status values that can be added or removed by a server are prefixed with 'server'."

In EPP the registrar is the client and the registry is the server. So clientTransferProhibited is a flag your registrar owns and can clear in a single command, while serverTransferProhibited is a flag your registrar has no valid command to clear at all. ICANN's status-code reference says the same thing in plain language: client codes are set by registrars, server codes are set by registry operators, and server codes take precedence.

Registry lock is therefore not a stronger version of registrar lock. It is a different control, at a different layer, enforced against a different party. Everything else on this page follows from that one prefix. Choosing between registry-level and registrar-level protection is the decision most portfolio owners get wrong, and the two are not interchangeable.

All Three Codes, Plus the Nameservers

Verisign's registrar documentation is unambiguous about what counts: "The word 'server' and 'prohibited' must appear for all three statuses (Update, Delete, Transfer) for the domain name to be registry locked." A domain carrying only serverTransferProhibited is not registry locked. It is partially locked, and the gap is usually the one that matters, because an attacker who can update the record can repoint the nameservers and take the traffic without ever moving the registration.

The lock can also be applied to host objects — the registry's separate record of a nameserver, distinct from the domain record itself. Verisign notes that a domain plus its two nameservers is three separate locks, and that host locking works only for hosts inside the top-level domains Verisign operates. Locking the domain object while leaving the host objects editable leaves a glue-record path open in some configurations. If you are paying for the lock, lock the hosts as well, and confirm afterward that all three prohibitions are showing on the domain.

How an Unlock Actually Happens

The process is deliberately slow:

  • An authorized representative at your registrar — a named individual on a list pre-registered with the registry — contacts the registry to request the change.
  • The registry calls that individual back and requires an individual security phrase before it will unlock the domain.
  • The change is made while the lock is off.
  • The lock is re-applied.

Notice who is missing from that sequence: you. Registry lock is a registrar-facing service, so the request runs through your registrar's authorized contacts rather than through you directly. Notice also that no step in it is instant. I have not found a registry that publishes a response-time commitment for unlock requests, so plan nameserver migrations and DNS cutovers around the registry's business hours rather than assuming a 2 a.m. Sunday change window will work.

The friction is the security. Treating it as a defect is how people end up disabling the lock "temporarily" for a migration and never restoring it.

Who Can Actually Buy It

Registry lock is not sold to registrants. Verisign directs registrars, not registrants, to arrange it, because the registrar has to hold the contract, maintain the authorized-contact list and run the operational process. That one fact decides availability for most people: if your registrar has not built the process, you cannot have the product, however much you want it.

Verisign offers Registry Lock across .com, .net, .cc and .name through participating registrars. Nominet sells an equivalent service for .uk called Domain Lock, which blocks nameserver changes, registrant name, address and contact amendments, and transfers to another registrar, and which requires pre-authorized representatives using two-factor authentication to lock or unlock. Corporate registrars — the ones selling to brand-protection and legal departments — market registry lock as a core product; retail registrars generally do not offer it at all.

Adoption lags the risk badly. Reporting in January 2020 found that only 22 percent of Fortune 500 domains had registry locks enabled. These are companies with security budgets.

What Registry Lock Does Not Protect

It does not stop expiry. A registry-locked domain still expires on schedule, still enters the auto-renew grace period, and can still fall into redemptionPeriod — which ICANN describes as holding the domain for 30 days after deletion — and then pendingDelete, after which the name is purged and anyone can register it. Locks defend against unauthorized change. They do nothing about an expired credit card, and in my experience more valuable names are lost to a billing failure than to an attacker.

It does not protect your DNS zone. Registry lock freezes the registration record: the registrar of record, the contacts, the delegation to your nameservers. If the account at your DNS hosting provider is compromised, the contents of that zone — mail records, web records, verification records — can still be rewritten while the registration sits untouched and correctly locked.

And it is not a guarantee. ICANN's Security and Stability Advisory Committee described domain locking in SAC074 (November 2015) as an optional process whose protections "may not always be implemented." The strength of the control is the strength of the registry's out-of-band procedure and your registrar's discipline in following it.

Verifying It, and Keeping It Working

Check the lock yourself rather than trusting an invoice. Look the domain up in RDAP — the modern successor to WHOIS for registration data — or in WHOIS, and confirm that all three of serverUpdateProhibited, serverDeleteProhibited and serverTransferProhibited are present. Verisign also publishes a lock-status check for registrars.

  • Lock the nameserver host objects as well as the domain object.
  • Keep at least two named authorized contacts on file, so one departure does not strand the account.
  • Escrow the security phrase somewhere that is not the registrar account it protects.
  • Host the registration contact email outside the domain being protected and outside the registration account, as SSAC recommended in SAC044, so an attacker who repoints DNS cannot also intercept the notifications.
  • Monitor the status codes and alert on silent removal of any of the three.

The failure I see most often is a stale authorized-contact list. When the only person the registry will call left the company two years ago, an urgent change turns into a multi-day identity-proofing exercise, and it is always discovered during the incident rather than before it.

Whether It Is Worth the Friction

For a domain whose loss would stop the business — the name carrying your email, your customer logins, your payment flows — registry lock is the only control that holds when every layer above it fails. SSAC has recommended it in those terms since SAC044 (5 November 2010): registrants should consider registry locks as a complement to registrar locks, a second level of security against unauthorized transfer, deletion or change.

For a defensive portfolio of typo variants and misspellings, it is overkill and the annual cost is real. This is a per-name judgment, not a per-account policy, and pretending otherwise is how the budget conversation gets lost.

What is not a judgment call is the misconception underneath most of this. The padlock icon in a registrar control panel is almost never registry lock; it is registrar lock, and anyone inside your account can switch it off. That is exactly how the e-hawk.net theft ran in December 2019, when attackers persuaded registrar staff over a messaging app that they had bought the domain, moved it to a reseller account on 23 December and to another registrar on 26 December, and were not discovered until 13 January 2020, when the DNS changed.

Frequently Asked Questions

Is registry lock the same as the lock in my registrar control panel?

No, and the confusion is common enough to be dangerous. The control panel toggle is registrar lock, which sets client-prefixed status codes such as clientTransferProhibited. Your registrar can remove those instantly, and so can anyone who gets into your account. Registry lock is applied by the registry operator using serverUpdateProhibited, serverDeleteProhibited and serverTransferProhibited, which a registrar has no valid EPP command to clear. Removing it requires the registry to verify the request out of band, normally by calling a named authorized contact who must give a pre-agreed security phrase.

How do I check whether a domain is registry locked?

Look the domain up in RDAP or WHOIS and read the status codes on the record. All three of serverUpdateProhibited, serverDeleteProhibited and serverTransferProhibited must be present. Verisign's guidance is explicit that the words server and prohibited have to appear for all three statuses — update, delete and transfer — for the domain to count as registry locked. If you see only one or two, the domain is partially protected, and the missing prohibition is usually update, which is the one that lets an attacker repoint nameservers. Verisign also publishes a lock-status check for registrars.

Can my registrar remove a registry lock?

Not on its own, and not through the normal interface. RFC 5731 section 2.3 defines the rule: status values a client can add or remove are prefixed with client, and status values a server can add or remove are prefixed with server. In EPP the registrar is the client and the registry is the server, so a registrar cannot issue a valid command to clear a server-prefixed status. The registrar can request an unlock, but the registry will only act after an authorized representative on a pre-registered list is called back and gives the agreed security phrase.

Does registry lock stop a domain from expiring?

No. Registry lock prevents unauthorized change to the registration record; it has nothing to do with renewal. A locked domain still reaches its expiry date, can still enter the auto-renew grace period, and can still fall into redemptionPeriod — which ICANN describes as holding the domain for 30 days after deletion — and then pendingDelete, after which the name is purged and available to anyone. Registries charge a redemption fee well above a normal renewal to pull a name back out. Locking and renewal are separate problems that need separate monitoring.

Which registries offer registry lock?

Verisign offers Registry Lock for .com, .net, .cc and .name through participating registrars. Nominet offers an equivalent service for .uk called Domain Lock, which blocks nameserver changes, registrant contact amendments and transfers to another registrar, and requires pre-authorized representatives using two-factor authentication to lock or unlock. Many other registry operators run comparable services under their own names. There is no ICANN consensus policy requiring any registry to offer one; it is a registry service approved through ICANN's Registry Services Evaluation Process, so coverage varies by top-level domain.

Why can't I buy registry lock directly from the registry?

Because the service is sold to registrars, not registrants. The registrar holds the contract with the registry, maintains the list of authorized representatives the registry will call, and runs the unlock procedure. Verisign directs registrars, rather than registrants, to arrange it. In practice this means availability is decided by where your domain is held: corporate registrars serving brand-protection and legal departments generally offer it, and retail registrars generally do not. Moving a critical domain to a registrar that supports registry lock is usually a prerequisite, not an afterthought.

Does registry lock protect my website and email?

Only indirectly. Registry lock freezes the registration record — the registrar of record, the contact data and the delegation to your nameservers. It does not protect the contents of your DNS zone at your DNS hosting provider, so an attacker who compromises that account can still rewrite your mail and web records while the registration stays locked and correct. It also does not protect the hosting account, the mail platform or the certificates. Treat it as one layer that closes the registration-level attack path, not as portfolio-wide security.
Keep reading

Read the guides

The entries describe what a mechanism is. The guides describe what to do with it, in sequence, and where each route closes.

This is a reference, not a practice. Hartzer.net sells nothing, takes no engagements, and is not legal advice. Nothing here creates any relationship or preserves any deadline.

Top