← Back to the blog

How a domain transfer actually works

Published August 21, 2026

An arrow carrying a domain icon from one building to another, representing a domain transfer

"Transferring a domain" sounds like it should mean moving a website from one place to another. It doesn't — a transfer only moves who's in charge of the domain's registration, from one registrar to another. Your website, your email and your DNS records aren't part of that move at all, which is both the reassuring part and the part that trips people up when they expect a transfer to fix problems it was never going to touch.

What a transfer actually changes

Every domain has a registrar of record — the company you pay to keep the registration active. A transfer swaps that company out, and nothing else, by default. Your nameservers keep pointing wherever they already did, which means your website and email can carry on working, uninterrupted, throughout the whole process — as long as nobody changes them at the same time for an unrelated reason.

The steps, in order

  1. Unlock the domain. Registrars lock a domain against transfer by default, as a theft deterrent. This has to be switched off at the current registrar before anything else can happen — usually a single toggle in its control panel.
  2. Get the authorization code. Sometimes called an EPP code or auth code, this is a one-time password that proves you're allowed to move the domain. The current registrar issues it, typically by email, once asked.
  3. Start the transfer at the new registrar. You give them the domain name and the auth code; they take it from there.
  4. Confirm by email. Both the old and new sides typically send a confirmation link to the domain's registered contact email — proof that whoever's approving the move is actually the owner, not someone who merely obtained the auth code.
  5. Wait out the transfer window. Generic endings like .com follow an ICANN rule giving the losing registrar up to five days to notice and object before the transfer completes automatically; country-code endings like .gr or .se set their own timelines, sometimes faster, sometimes with an extra confirmation step.

The waiting period isn't wasted time. It exists specifically so a hijacked or mistakenly-initiated transfer can be caught and stopped before it's irreversible — a genuine safety net, even on the (common) occasion it feels like unnecessary friction.

The snags that catch people

  • The domain is locked, and nobody unlocked it. The single most common reason a transfer stalls at step one — check this before doing anything else.
  • The domain is too new. A widely-followed rule blocks transfers within 60 days of a first registration or a previous transfer — a registry-level rule no registrar can override, so if it's recently changed hands, this is often simply a matter of waiting it out.
  • The confirmation email goes nowhere useful. If the registered contact address is outdated, forgotten, or was never actually checked, the confirmation step can stall indefinitely. Worth verifying — and updating — before starting, not after.
  • WHOIS privacy hides the real contact. Privacy services are genuinely useful, but if the underlying contact details behind one are stale, they can quietly block the one email that actually needs to reach you.

What to actually check before you start

In practice, three checks catch almost every problem before it happens: the domain is unlocked, the registered email is one you actually read, and it's been more than 60 days since it was last registered or transferred. Clear those, and a transfer is mostly a matter of starting it and waiting.

Our own domain transfer is free — no matter which registrar a domain is coming from — and walks through exactly these checks upfront, rather than letting a preventable snag surface halfway through.