Whois status codes: lock, penalty, or business as usual?
2 min read
clientTransferProhibited, serverHold, clientHold, ok… What EPP status codes mean: which are healthy security locks and which are alarms.
The healthy ones: client* locks
clientTransferProhibited scares many users but is usually good news: the registrar keeps the security lock on, preventing the domain from being moved to another company without authorisation. clientUpdateProhibited and clientDeleteProhibited belong to the same family; virtually every major brand keeps all three enabled. When you genuinely want to transfer, you lift the lock yourself in the panel.
The alarms: server* and hold
serverHold or clientHold is serious: the domain has been removed from DNS — site and email stop working. Causes include payment failure, unverified contact details (ICANN email verification) or an abuse complaint. redemptionPeriod and pendingDelete are the final stages of the expiry calendar — detailed in the expiry lifecycle guide.
"ok" is the plainest state
If the status line shows only ok, the registration is active and unlocked. That also means the transfer lock is off — if the domain is yours, enabling the lock is a five-minute, zero-cost security upgrade.
Look up your own domain
Everything in this guide, our tool shows with live data in seconds: registration and expiry dates, registrar, nameservers, age and value analysis — free, no signup.
Query with WhoisFrequently asked questions
Can I transfer my domain while clientTransferProhibited is set?
Yes; the lock is under your (or your registrar panel's) control. Lift it before the transfer, obtain the auth/EPP code, and re-enable it afterwards.
Where do I see status codes in your tool?
In the raw whois data section, on the "Status" lines. The code names are a registry standard (EPP) and mean the same thing across extensions.