What do domain status codes like clientTransferProhibited mean?
Every WHOIS record carries one or more status codes. They are the single most informative part of the record and almost nobody reads them, which is a pity, because they tell you whether a domain is locked, suspended, expiring or already halfway to being deleted.
They are EPP status codes, defined by the Extensible Provisioning Protocol, and the prefix tells you who set them: client* codes are set by your registrar, server* codes by the registry that runs the TLD. clientTransferProhibited is the most common and it is a good thing — it is the registrar lock that stops anybody moving your domain away without unlocking it first. The ones to worry about are clientHold and serverHold, which remove the domain from DNS entirely, and redemptionPeriod or pendingDelete, which mean it has already expired.
Locks: the codes you want to see
| Code | Set by | Effect |
|---|---|---|
| clientTransferProhibited | Registrar | Blocks a transfer to another registrar. The standard registrar lock. |
| clientDeleteProhibited | Registrar | Blocks deletion of the domain. |
| clientUpdateProhibited | Registrar | Blocks changes to contacts and name servers. |
| clientRenewProhibited | Registrar | Blocks renewal. Rare, and usually a billing dispute. |
| serverTransferProhibited | Registry | Registry-level transfer block. Also applied automatically for the first 60 days. |
| serverDeleteProhibited | Registry | Registry-level deletion block, often from a dispute or a court order. |
| serverUpdateProhibited | Registry | Registry-level freeze on all changes. |
Holds: the codes that take you offline
| Code | Set by | What it actually does |
|---|---|---|
| clientHold | Registrar | The domain is pulled from the TLD zone. Nothing resolves — no website, no email. |
| serverHold | Registry | Same effect, imposed by the registry. Usually legal or policy driven. |
| inactive | Registry | No name servers are delegated, so the domain cannot resolve. Common on a brand-new registration. |
Lifecycle codes: where a domain is in its life
| Code | Meaning | Typical duration |
|---|---|---|
| addPeriod | Just registered, inside the add grace period | 5 days |
| autoRenewPeriod | Auto-renewed at expiry; the renewal can still be reversed | Up to 45 days |
| renewPeriod | Manually renewed, inside the renewal grace period | 5 days |
| transferPeriod | Just transferred in | 5 days |
| pendingTransfer | A transfer request is open and awaiting acknowledgement | Up to 5 days |
| redemptionPeriod | Deleted after expiry; recoverable only by paying a redemption fee | 30 days |
| pendingRestore | A redemption request has been made and paperwork is due | 7 days |
| pendingDelete | Past redemption. The domain will be dropped and released. | 5 days |
| pendingCreate | Registration submitted, not yet complete | Minutes to hours |
How to read a combination
ok → no locks at all. Transferable, and arguably under-protected.
clientTransferProhibited alone → the normal state of a well-kept domain.
clientTransferProhibited + clientDeleteProhibited + clientUpdateProhibited → a fully locked domain. This is what a registrar’s “domain lock” toggle sets.
autoRenewPeriod + clientHold → it expired, the registrar renewed it on your behalf and then suspended it because the invoice is unpaid. Pay it and it comes back.
redemptionPeriod → you have roughly 30 days and a redemption fee, typically ₹6,000 to ₹15,000 in India, between you and losing the name.
pendingDelete → too late to redeem. It will drop in about 5 days.
Sources: ICANN Registrar Accreditation Agreement 2013, ICANN Transfer Policy, ICANN Expired Registration Recovery Policy, ICANN Registry Agreement Specification 4 (RDAP), IETF RFC 9083 and RFC 5731 (EPP status codes), and the EU General Data Protection Regulation as applied by ICANN’s Registration Data Policy.
Check your own numbers
Read the live status codes on any domain before you buy it, transfer it or panic.
Frequently asked
Is clientTransferProhibited bad?
No - it is the normal, healthy state for a domain you intend to keep. It is the registrar lock, and most registrars apply it by default precisely to make domain hijacking harder. You only need to remove it in the few minutes before you start a legitimate transfer out.
My domain resolves nowhere and WHOIS says clientHold. What happened?
clientHold means your registrar asked the registry to remove the domain from the TLD zone, so it does not resolve at all. The three usual causes are an unpaid invoice, an unverified registrant email under the 2013 Registrar Accreditation Agreement - you have 15 days to click that verification link - and an abuse complaint. Contact the registrar; only they can lift it.
What is the difference between a client and a server code?
client codes are set by the registrar you buy from and the registrar can remove them, usually from your control panel. server codes are set by the registry that operates the TLD and neither you nor your registrar can clear them directly - they come from a dispute, a court order, a UDRP proceeding or a registry-level policy action.
What does status "ok" mean?
It means the domain has no other status codes at all - no locks, no holds, no pending operations. Confusingly, that also means no registrar lock, so an "ok" domain is the easiest kind to transfer away. Many registrars treat plain ok as a security weakness rather than a clean bill of health.
Related answers
Need domain and DNS checks inside your own product?
We build WHOIS, RDAP, DNS and SSL lookups as embeddable widgets or a plain JSON API in your branding, wired to your own lead form. Tell us which checks you need and we will send a working demo.
Request received
Thanks — we will reply within one business day. Meanwhile, all 164 tools are free to use, no signup.