“Transferring a domain” sounds like something that could go wrong quietly, in the background, while a business keeps running its site and email as if nothing were happening. In the large majority of cases nothing does go wrong — but the transfers that do stall or fail almost always trace back to the same handful of preventable mistakes: a domain still locked, an approval email nobody could see, an auth code that's already expired, or a transfer started days before the domain was due to renew. None of that takes any real technical skill to avoid; it just takes doing the steps in the right order, and knowing what a transfer does and doesn't touch along the way.
What transferring a domain actually does (and doesn't do)
Transferring a domain moves who manages the registration — the account it renews through, and where add-ons like privacy protection are bought — from one registrar to another. It does not move the domain's DNS records, nameservers, website or email unless those are deliberately changed too. A domain pointing at the same hosting before a transfer still points at that same hosting after one, provided the nameservers aren't touched along the way. This is different from domain lock, a setting that only controls whether a transfer can start at all; that guide covers what the lock does and why it should normally stay switched on. It's also different from changing the registrant — the named owner of the domain — which is a separate action some registrars bundle into the same screen but treat under its own rules.
Why businesses actually transfer a domain
A transfer is rarely about the domain itself; it's almost always about the account it sits in. The most common reasons: a renewal price that has crept up at the current registrar and is cheaper elsewhere; several domains bought over the years from different registrars that a business wants consolidated into one account for easier management; a domain still sitting in a web designer's, freelancer's or former employee's account that the business wants to bring under its own control; or simply wanting a registrar that includes domain lock, privacy protection and transfer-in at no extra cost, rather than as paid add-ons. None of these reasons require urgency or technical skill — they're account-management decisions, and the transfer itself is a mechanical process once the groundwork below is done.

Before you start: the pre-transfer checklist
- Confirm the domain isn't inside a post-registration or post-transfer lock window. Registry transfer policy typically blocks a new transfer for around 60 days after a domain is first registered, after it was last transferred, or after its registrant contact details last changed. There's no way around this one — it just needs waiting out.
- Unlock the domain at the current (losing) registrar. Nearly every registrar shows this as a “Transfer Lock” or “Domain Lock” toggle in the domain's settings — the same protective setting covered in our guide to domain lock, explained. Switching it off to start a genuine transfer is the one legitimate reason to ever do it.
- Make sure the WHOIS/registrant email address is one that's actually checked. The transfer approval message (sometimes called a Form of Authorization, or FOA) is sent to that address. If WHOIS privacy is masking it behind a stale forwarding address, or the registrant email itself is outdated, the approval message never reaches anyone and the transfer stalls or is automatically cancelled.
- Check auto-renew if the domain is close to its renewal date. Some registrars pause auto-renewal automatically once a transfer starts; others don't. It's worth confirming rather than assuming, so the domain doesn't renew mid-transfer and complicate the timing.
- Settle the billing at the losing registrar first. An outstanding invoice, an expired card on the account, or a domain flagged for non-payment can block a transfer request outright, independently of the domain's own lock status.
Step-by-step: the transfer-in process
- Request the transfer authorisation code (also called an EPP code, auth code or transfer key) from the current registrar. It's often shown directly in the domain's management panel, or delivered by email within a few days of the request.
- Start the transfer at the new registrar, entering the domain name and the authorisation code.
- Approve the transfer. Depending on the registrar, this means clicking a confirmation link in the approval email sent to the WHOIS/registrant address, or approving the request directly inside the losing registrar's account.
- Wait out the transfer window. If nobody actively approves or rejects the request, most transfers complete automatically after about five days.
- Confirm the move once it's done. Check the new registrar's dashboard shows the domain, and that DNS and email are still resolving correctly if anything was changed along the way.
- Re-lock the domain at the new registrar. Transfer lock isn't always carried over automatically, so it's worth checking rather than assuming it switched back on.
The four things that most often break a transfer
- Domain lock left switched on. The single most common reason a transfer request is rejected outright before it even starts — see the checklist above.
- WHOIS privacy hiding the approval email. Privacy protection is genuinely useful day-to-day, but during a transfer it can mean the approval message goes to a masked address nobody checks. Confirming the registrant email is current and reachable before requesting the auth code avoids this entirely.
- An expired or mistyped auth code. Auth codes are usually only valid for a limited window and can only be used once. If the transfer wasn't started promptly after receiving the code, it's simpler to request a fresh one than to troubleshoot an old one.
- Starting the transfer too close to expiry. A transfer that's still pending when the domain expires can stall considerably, since most registries won't process a transfer on an already-lapsed domain until it's renewed. Leaving at least two to three weeks of runway before the renewal date avoids this entirely.
How long it actually takes
Most domain transfers complete within five to seven days of the new registrar submitting the request — faster if the losing registrar actively approves it, and defaulting to that same roughly five-day window if nobody responds either way. A transfer can be rejected within that window, usually because the domain is still locked, the auth code is wrong, or the account details don't match; a rejected transfer has to be corrected and restarted rather than automatically retried. Country-code extensions sometimes run to a different timetable than generic ones, so if a .my domain seems to be taking longer than a .com would, that's often normal rather than a sign something has gone wrong.
Choosing a new registrar: what actually matters
Picking where to transfer to matters as much as doing the transfer correctly, since the next few years of renewals, support and account access all depend on it. Price is the obvious factor, but it's rarely the one that causes regret later — the items below are.
| Factor | Why it matters | What to check before committing |
|---|---|---|
| Transfer-in fee | Some registrars charge for the privilege of moving a domain in, on top of the year it usually adds | Whether transfer-in is free and whether a year is added to the current expiry at no extra cost |
| Domain lock & privacy | Paid add-ons elsewhere can turn a cheap registration into an expensive one once they're added | Whether lock and WHOIS privacy are included as standard, not billed separately |
| Renewal pricing | A low first-year or transfer price sometimes hides a much higher renewal rate | The renewal price for your extension, not just the transfer or first-year price |
| Account & billing control | Determines who can unlock, renew or transfer the domain again later | That the registrant and account owner will be your company, not an agency or individual |
| Support access | A stuck transfer or a billing issue needs a human response, not just a help article | What hours support is available and how a ticket actually gets answered |
DNS and nameservers: what to leave untouched during a transfer
A registrar transfer and a DNS or nameserver change are two completely separate actions that happen to be possible at the same time — which is exactly why they get confused. A transfer on its own never changes where a domain's website or email actually lives; it only changes which company bills for and manages the registration. If the website or email also needs to move providers, do that as a second, deliberate step once the transfer itself is confirmed complete, rather than changing nameservers in the middle of an in-progress transfer. Mixing the two makes it much harder to tell, if something does go wrong, whether the cause was the transfer or the DNS change.
Transferring a domain you don't yet control
Sometimes the domain that needs transferring isn't sitting in the business's own account at all — it's in a web designer's, a freelancer's, or a former employee's registrar login, left over from however the domain was first set up. This needs an extra step before the transfer process above can even start: the current account holder has to either update the registrant details to the business's own information, or initiate the transfer themselves using their access. Neither step is technically hard, but both require that person's cooperation, which is why it's worth sorting out registrant and account ownership as soon as a domain is first set up, rather than only when a relationship with whoever registered it has already ended. A domain whose registrant was never corrected after a handover is also more likely to run into the 60-day post-change lock mentioned in the checklist above, so fix the registrant details first and transfer once that window has passed.
Common mistakes
- Changing nameservers and transferring registrars in the same sitting. If anything breaks, there's no way to tell which change caused it. Do one, confirm it worked, then do the other.
- Requesting the auth code weeks before starting the transfer. Codes expire; request it shortly before you actually begin, not as a first step done "just in case."
- Assuming WHOIS privacy will forward the approval email. It sometimes does and sometimes doesn't, depending on the privacy provider. Confirm the registrant email directly instead of assuming.
- Starting a transfer the week a domain is due to renew. Leave two to three weeks of runway; a transfer racing an expiry date is the single most avoidable way for one to stall.
- Forgetting to re-lock the domain after the transfer completes. A domain left unlocked at the new registrar is exposed to exactly the risk transfer lock exists to prevent.
- Leaving the registrant as an agency or former employee. Fix who the registrant is before transferring, not after, so the business controls the domain at both ends of the move.
Where Gotka Technologies fits
Gotka's domain registration service includes free transfer-in on every domain, alongside domain lock and privacy protection, from RM10 a year — so moving a domain across doesn't carry an extra transfer fee on top of the usual registration cost. For the setting that protects a domain against being moved without permission in the first place, see domain lock, explained, and for keeping it from lapsing afterwards, our guide to never missing a domain renewal. Once the transfer is done, Gotka's Cloud Hosting on LiteSpeed servers is worth considering if the domain's website or email is moving providers too, not just the registration.
Key terms used in this guide
- Registrar: the company a domain is registered and paid through, and the one that actually processes a transfer request.
- Registry: the organisation that runs an extension itself, such as MYNIC for .my or Verisign for .com, and sets the rules registrars must follow.
- Registrant: the person or company recorded as the domain's owner, separate from who happens to be paying or managing it day to day.
- EPP/auth code: a one-time code the losing registrar issues to prove the request to transfer is authorised; also called a transfer key.
- Form of Authorization (FOA): the confirmation email sent to the registrant address that has to be approved before a transfer can proceed.
- Domain lock: a registrar-level setting, shown as clientTransferProhibited, that blocks a transfer until it is switched off.
- WHOIS: the public record of a domain's registration details; privacy protection masks the registrant's personal information in it.
- Nameservers: the records that tell the internet which servers answer for a domain's website and email; unrelated to which registrar manages the registration.
How do I transfer a domain to a new registrar without losing it?
Unlock the domain at the current registrar, request its EPP or authorization code, and start the transfer at the new registrar with that code. Approve the confirmation email sent to the domain's registrant address once it arrives, then wait for the transfer window — usually five to seven days — to complete. As long as DNS isn't changed, the website and email behind the domain keep working the entire time.
What is an EPP or authorization code, and how do I get mine?
An EPP code — also called an auth code or transfer key — is a one-time passcode the current registrar issues to prove you're authorised to move the domain elsewhere. Request it from the current registrar's dashboard, where it's often shown directly, or by contacting support; registrars are required to provide it within a few days of a request. It's normally valid for a limited window, so request it shortly before actually starting the transfer.
Will my website or email stop working during a domain transfer?
No, not if the domain's DNS records and nameservers are left untouched during the transfer. A registrar transfer only changes who manages the registration itself; the domain keeps pointing at whatever hosting and mail servers it already pointed at, before, during and after the move. Downtime during a transfer almost always comes from someone also changing nameservers at the same time, not from the transfer process itself.
Why do domain transfers get rejected or fail?
The four most common causes are: the domain still being locked at the losing registrar, the approval email going to an outdated or privacy-masked WHOIS address nobody sees, an auth code that's expired or was typed incorrectly, and a transfer started so close to the domain's expiry date that it can't complete before the domain lapses. All four are avoidable by working through the pre-transfer checklist before requesting the code.
How long does a domain transfer take?
Most transfers complete within five to seven days of the new registrar submitting the request. It can finish sooner if the current registrar actively approves it, and it defaults to completing automatically around the five-day mark if nobody approves or rejects it in the meantime. A rejected transfer has to be corrected and restarted rather than retried automatically.
Can I transfer a domain that's about to expire?
It's possible but risky, and best avoided. A transfer still pending when a domain expires can stall until the domain is renewed, and some registries won't process a transfer on an already-lapsed domain at all. Starting the transfer with at least two to three weeks of runway before the renewal date avoids the issue entirely.
Does Gotka charge anything to transfer a domain in?
No — Gotka's domain registration includes free transfer-in on every domain, alongside domain lock and privacy protection, from RM10 a year, so moving a domain across doesn't add an extra transfer fee on top of the standard registration cost.
Do New Domain Extensions Hurt Your SEO Ranking? (.my, .asia, .online & More)
Domain extension SEO for Malaysian businesses: .my, .asia and .online won't hurt your Google ranking versus .com — the TLD itself isn't a ranking factor.
DomainsHow to Make Sure You Never Miss a Domain Renewal
How to make sure your domain never lapses: turn on auto-renew with a valid card on file, keep your registrant email current, and set a calendar backup too.
DomainsWhat Happens When Your Domain Expires — Grace Period, Redemption and Getting It Back
Your domain doesn't vanish the day it expires. Here's the grace period, the costlier redemption period, and exactly what to do to get it back in time.


