Most failed transfers come down to one of five things: the domain is still locked, the auth code is wrong or stale, WHOIS privacy is hiding the info the losing registrar needs, the domain is too close to expiry, or the registrant's contact email was never verified with ICANN. Check these in order before you open a ticket, because four of the five are things you can fix yourself in a few minutes.
1. The domain is still locked
The most common blocker. A registrar lock is a toggle on the domain, usually on by default, that has to be switched off before any transfer can start. Turn it off and request a fresh auth code to clear it.
If you recently updated contact details on the domain or it was recently registered or transferred, there may also be a registry-level hold that has to run its course before a transfer can go through. See Domain locks explained for how to tell which lock you're dealing with.
2. The auth code (EPP code) is wrong
The auth code, sometimes called the EPP code or transfer code, is a one-time secret the losing registrar issues to prove you control the domain. Transfers fail constantly because of a bad code:
- It was copied with a trailing space or line break.
- It expired. Most registrars only keep a code valid for a limited window after issuing it.
- It was regenerated after you copied it, which invalidates the old one silently.
- It's for the wrong domain, if you're transferring more than one at once.
The fix is to request a fresh code right before you start the transfer, not to reuse one from a week ago. In our portal, that's under the domain's card: Transfer out → Reveal transfer code. Generate it, copy it directly into the new registrar's transfer form, and start the transfer the same session.
3. WHOIS privacy is hiding what the gaining registrar needs
ID protection (WHOIS privacy) masks your registrant email in public WHOIS lookups. Most transfer systems handle this fine now, since the auth code is what actually authorizes the move, not a public WHOIS match. But it still causes two real problems:
- Some gaining registrars run an automated check against public WHOIS data before submitting the transfer, and a masked or proxy email can trip that check.
- If the transfer ever needs manual confirmation, the confirmation email goes to whatever address is on file, and a proxy address you don't monitor means you never see it.
If a transfer stalls and you have ID protection on, check the domain's Registrant → Edit contact details card to confirm the underlying contact email is one you actually read, and temporarily toggle protection off if the gaining registrar's support asks you to.
4. The domain is too close to expiry, or already expired
Registries generally won't process a transfer within a certain window of the domain's expiry date, and some registrars refuse to even submit one. If your domain is expiring soon, renew it first, then transfer, rather than trying to do both in one motion. If the domain has already lapsed, the transfer request itself may not be your first problem; see When auto-renew fails for how to recover a domain that's already past its expiry date, including the grace and redemption windows.
5. The registrant's contact email was never verified with ICANN
If the registrant email on the domain was never confirmed, or was changed and the new confirmation was ignored, ICANN's rules can put the domain into a suspended or restricted state that blocks transfers along with everything else. This is easy to miss because the verification email looks like routine registrar mail and often lands in spam. See ICANN verification emails: why you must click them for what the email looks like and the deadline attached to it. If you suspect this is the issue, check whether the registrant email on the domain is current and confirmed before doing anything else.
Working through it in order
- Confirm Registrar lock is off.
- Confirm the domain isn't inside a registry-level hold tied to a recent registration, transfer, or registrant change.
- Generate a fresh auth code right before starting the transfer.
- Check the registrant contact email is current and was verified with ICANN.
- Confirm the domain isn't inside the pre-expiry transfer restriction, and isn't already expired.
When to contact support
If you've checked all five and the transfer is still rejected, or the gaining registrar's error message doesn't map to anything above, open a ticket from the portal's Support section. Include the exact rejection message from the gaining registrar and the domain name. A real person can check the registry-level status directly, which sometimes shows a hold or dispute that isn't visible from your side at all.