A web designer asks for your domain's Registration Code. A registrar calls it an Auth-Code. Your domain dashboard also displays an EPP status. Before sending anything, establish whether you are changing registrars, changing ownership, or simply updating where the website is hosted.

ICANN describes an Auth-Code, also called an AuthInfo or transfer code, as a registrar-created credential used in transfers between registrars. It is not a universal code for initially registering a domain, and it is not the same as an EPP status label. 46A 46B

This Domain Transfer Registration Code guide focuses on the ICANN registrar-transfer context. Check the applicable registry and registrar instructions for your domain, especially for country-code domains with different arrangements.

Define the change before requesting a code

Write down the desired outcome in plain language. Are you moving domain management to a different registrar, transferring the registration to another person, or changing the website's hosting provider?

ICANN distinguishes registrar transfer from a change of registrant and notes that changing hosting or nameserver settings can be a separate option. The required administrative process therefore depends on the change, not on the word “transfer” alone. 46C

Confirm the scope with the person assisting you. Do not send a transfer credential merely because someone uses “Registration Code” as shorthand in an email.

Obtain the Auth-Code from the current registrar

Use the account and support process of the registrar currently managing the domain. ICANN explains that registrars may provide an account interface for obtaining or managing the code, or supply it through a request process. 46A

Start with the ICANN domain-transfer FAQ when you need to understand the overall process or identify the appropriate registrar. 46C

Check the exact domain before requesting its credential. A business may own several similar spellings or extensions. Associate the request with the intended domain and receiving registrar, not just the account holder's name.

ICANN does not generate your transfer credential

ICANN explicitly says it does not provide Auth-Codes. The domain's current service provider or registrar handles that part of the process. 46D

Treat websites promising an instant universal domain Registration Code with caution. A helpful explanation of transfer terminology is not a substitute for the registrar's authorized account process.

If you cannot access the registrar account, address that access problem through the registrar's documented verification and recovery route. Do not treat an inability to sign in as a reason to use another person's credentials or to bypass the current registrant's authorization.

An EPP status code describes a condition

ICANN's EPP guide explains domain status labels. For example, clientTransferProhibited instructs the registry to reject a transfer from the current registrar to another registrar. It is a status to investigate, not a secret to paste into an Auth-Code field. 46B

Save the status wording and ask the registrar what action applies. Do not remove every available protection without understanding why it exists and whether the intended transfer is authorized.

A clean troubleshooting note should distinguish “the credential was rejected” from “the domain is subject to a transfer restriction.” Those are different questions with different resolutions.

Possessing the code does not settle transfer eligibility

ICANN's transfer guidance describes circumstances in which transfers can be restricted, including certain registration, prior-transfer, and registrant-change situations. A correct Auth-Code does not override applicable restrictions or every other required step. 46C

Check eligibility before scheduling a critical business change. Ask the registrar for the reason behind a refusal or restriction and use the documented resolution process.

Avoid promising a completion time based solely on having obtained a code. Keep the project status precise: code requested, request submitted, additional confirmation required, or completion confirmed by the registrar.

Keep the credential inside the authorized transaction

Provide the code only through the intended receiving registrar's verified transfer process or another explicitly authorized arrangement. Do not publish it in a support forum, shared project board, or website launch checklist.

For a business domain, identify who is authorized to approve the transfer and who will control the destination account. Record those responsibilities before making changes, especially when an external contractor is involved.

If the credential has been exposed unexpectedly, contact the current registrar promptly about the appropriate protective action. Do not assume that deleting one message makes every previously shared copy harmless.

Plan website and email continuity separately

Prepare a separate checklist for the services that use the domain. Record the responsible providers, current configuration information, and who will verify website and email behavior after the planned change.

This is a project-management recommendation, not a claim that every transfer changes the same settings. Ask both providers what the proposed operation will and will not alter. Avoid combining a registrar transfer, ownership change, and unrelated configuration edits without a documented reason.

Define what successful completion looks like for each task. Registrar confirmation and a working website are useful checks, but neither should replace the other in the project record.

Example: a hosting move is mistaken for a registrar transfer

Imagine a small business hires a designer to rebuild its site. The designer requests a “Registration Code,” but the business wants to retain its existing registrar and only change the hosting arrangement.

The better response is to clarify the exact technical change and approved access needed before supplying a transfer credential. The parties can then follow the registrar and hosting providers' instructions for that task.

This hypothetical example shows why the safest first step is a question about purpose, not a search for a secret string.

The Domain Transfer Registration Code takeaway

An Auth-Code belongs to a specific registrar-transfer process. An EPP status describes the domain's condition, while hosting and ownership changes may involve different steps. Identify the intended change, use the current registrar's official process, protect the credential, and confirm the actual outcome before calling the transfer complete.

Related Registration Code guides

Explore the Registration Code Security hub for more guidance.