A registrar dashboard shows a domain's status as a short, technical-looking string of words — clientTransferProhibited being one of the most common — and most owners scroll straight past it without a second thought. That string is actually one of the more useful protections a domain owner has, and understanding what it does takes about two minutes. Anyone who has recently read about a domain being stolen, or who has simply noticed a “Domain Lock” toggle sitting in their account and wondered what happens if they touch it, is really asking the same underlying question: what is this setting actually for, and is it safe to leave alone?
What “domain lock” actually is
Domain lock — also called registrar lock or transfer lock — is a status a registrar sets on a domain that blocks it from being transferred to a different registrar until someone deliberately switches that status off. The technical name for it, visible in most registrar dashboards and in a domain's public WHOIS record, is clientTransferProhibited: an EPP status code (EPP is the protocol registrars use to talk to domain registries) meaning the registrar applied the lock at the account holder's request, rather than the central registry restricting the domain for some other reason.
It's worth being precise about what the lock actually blocks, because it's easy to assume it does more than it does. Domain lock only affects outbound transfer requests — an attempt to move the domain to another registrar. It has no effect on renewing the domain, updating its nameservers or DNS records, changing contact details, or running a website or email on it through the current registrar account. A locked domain works exactly the same as an unlocked one for every normal task; the only door it closes is the transfer-out door.
How domain hijacking actually happens
Losing a domain to an unauthorised transfer sounds like it should require serious technical skill, but in practice almost every real case comes down to one of three much more ordinary things.
- A compromised registrar account. This is the most common path, and it usually traces back to a compromised or reused email address rather than the registrar's own systems being broken into. If an attacker can read or reset the email tied to a registrar account, they can usually reset the account's password too, and from there unlock and transfer a domain like any legitimate owner would.
- Social engineering. An attacker impersonates the domain owner convincingly enough — over a phone call, a support ticket, or a forged document — to talk a registrar's support team, or the owner themselves, into unlocking a domain or approving a transfer that was never actually requested. Fake domain renewal emails are one well-documented version of this trick, designed to get an owner to unlock a domain or hand over login details without realising what they've actually done; that pattern is covered in our guide to spotting fake domain renewal scam emails.
- A domain caught unlocked. Sometimes it's simpler still — a domain left unlocked after a previous transfer, an overlooked reminder to re-lock it, or a moment of forgetting, right when a transfer request happens to come through, legitimate or not.
None of these three paths involves anyone breaking into the domain registry system itself, which is exactly why domain lock — a setting entirely within an owner's control — is such an effective defence against all three.
Why domain lock should almost always stay switched on
Given that domain lock has no downside, the sensible default is simple: leave it switched on permanently, and only turn it off for the few minutes a genuine transfer actually needs.
There's no cost to keeping it on — a locked domain renews normally, its DNS and email keep working without interruption, and nothing about running a website changes. The only situation lock ever gets in the way of is precisely the one it's meant to get in the way of: someone, including an attacker, trying to move the domain to a different registrar without going through the proper unlock step first.
The one moment you need to turn it off
The single legitimate reason to switch domain lock off is transferring the domain to a different registrar on purpose. The general sequence looks similar across most registrars: log into the current registrar's account directly, find the domain's status or transfer settings, switch the lock off, and request the transfer authorisation code — often called an EPP code or auth code — that the new registrar will ask for to start the move.
That unlock window should stay as short as possible. Unlock it, retrieve the code, start the transfer at the new registrar promptly, and treat the domain as more exposed than usual for however long it takes to complete. Most registrars automatically re-lock a domain once a transfer finishes, but it's worth logging in afterwards to confirm the new registrar shows the lock switched back on rather than assuming it happened.
Domain lock doesn't help if the account itself is compromised
It's important to be clear about what domain lock can't do, because relying on it alone creates a false sense of security. Domain lock is a setting on the domain, not on the account — anyone already logged into the registrar account, legitimately or otherwise, can simply switch the lock off themselves before attempting a transfer. It cannot stop someone who already has the keys to the account from turning it off.
That's why the account's own security matters more than the lock setting itself. The email address a registrar account is tied to is effectively the master key: whoever controls that inbox can usually reset the account password and get in. Keeping that email account secure with a strong, unique password, and turning on two-factor authentication wherever the registrar or the email provider offers it, does more to prevent hijacking than the lock setting alone ever could — the two protections work together, not as substitutes for each other.
A short checklist
None of this requires any technical background to act on:
- Check the domain's current status and confirm it shows locked (clientTransferProhibited) right now, not just at some point in the past.
- Use a strong, unique password for the registrar account — never one reused from another site.
- Turn on two-factor authentication on the registrar account, and on the email account it's tied to, wherever either offers it.
- Treat the account's email address as the real security boundary, since whoever controls it can usually reset everything else.
- Only unlock a domain immediately before a genuine transfer, and confirm it's locked again once that transfer has actually completed.
Where Gotka Technologies fits
Domain lock is included as standard with every domain registered through Gotka's domain registration service, alongside free transfer in and WHOIS privacy protection, from RM10 a year — so the protection described above is active from the moment a domain is registered, without needing to request it separately. Recognising a fake renewal or transfer-related scam email in the first place, often the first step toward getting a domain unlocked under false pretences, is covered in our related guide on spotting fake domain renewal scam emails.
What is domain lock?
Domain lock is a status set on a domain — shown in most registrar dashboards as clientTransferProhibited — that blocks the domain from being moved to a different registrar until it is deliberately switched off. It doesn't affect renewing the domain, editing its DNS records, or running a website or email on it; it only blocks an outbound transfer request from being accepted.
What does clientTransferProhibited actually mean?
clientTransferProhibited is the technical EPP status code registrars display when a domain's transfer lock is switched on, “client” meaning the registrar (rather than the central registry) applied it at the owner's request. Seeing it in a domain's status field is a good sign — it means the standard protection against unauthorised transfers is currently active.
How does domain hijacking actually happen?
In practice, almost all real cases trace back to one of three things: an attacker getting into the registrar account itself (often through a compromised or phished email address), a social-engineering call or message convincing registrar support or the owner to unlock a domain, or a domain that happened to be sitting unlocked when a fraudulent transfer request went through. Breaking into the domain registry system directly essentially never happens.
Should I ever turn domain lock off?
Only when deliberately transferring the domain to a different registrar — that's the one legitimate reason to unlock it. Outside of that specific, short window, domain lock should stay switched on permanently; it costs nothing, doesn't affect the domain's normal use, and closes off one of the main routes an unauthorised transfer could otherwise take.
How do I unlock my domain to transfer it?
Log into the current registrar's account directly, find the domain's status or transfer settings, and switch the lock off — then request the transfer authorisation code (also called an EPP code) the new registrar will ask for. Keep the unlock window as short as possible, and confirm the domain is locked again once the transfer has actually completed.
Does domain lock stop someone from renewing or editing my domain?
No. Domain lock only blocks transfer requests to a different registrar; it has no effect on renewing the domain, changing its nameservers or DNS records, updating contact details, or anything else done through the current registrar account. There's no operational reason to ever leave it switched off.
Does Gotka include domain lock with domain registration?
Yes — domain lock is included as standard with Gotka's domain registration on every domain, alongside free transfer in and privacy protection, from RM10 a year, so protection against unauthorised transfers is active from the moment a domain is registered, without needing to request it separately.
.my vs .com: Which Domain Should a Malaysian Business Register?
A .my domain signals you are local; a .com is the one people type by habit. How to choose between them, and when registering both is the sensible answer.
DomainsFake Domain Renewal Invoices and “Your Domain Has Expired” Emails: How to Spot the Scam
Fake domain renewal invoices use urgency and official-sounding names to trick owners into paying. How to spot the pattern, verify your real registrar, and stay protected.
DomainsBuying an Expired or Aftermarket Domain: Costs, Risks and What to Check First
Buying an expired domain in Malaysia? What happens when a name lapses, why aftermarket prices hit hundreds of ringgit, and how to check its history first.

