If your domain transfer failed, the first moves are to unlock the domain, pull a fresh EPP/auth code, turn off WHOIS privacy, and confirm your admin email can receive messages. Most of these fixes let you resubmit right away, but a 60-day restriction or an active DNSSEC record means you have to wait before trying again. ICANN sets the rules registrars must follow, and if you'd rather skip the troubleshooting, our team at inSave Hosting handles transfers directly.
TL;DR:
- A 60 day restriction applies only within 60 days of registration, a prior transfer, or certain registrant changes unless the registrant opted out.
- WHOIS can take 5 to 24 hours to reflect an unlock, while DNSSEC removal may require the DS record’s TTL, often about 24 hours.
- Most transfers finish in about five to seven days, but expired domains, unpaid invoices, or unresolved locks, codes, and DNSSEC can delay submission.
- Resubmit only after WHOIS confirms the domain is unlocked, you have a fresh EPP code, privacy is disabled, and the administrative email works.
- If the losing registrar does not respond to a registry transfer notice within five calendar days, ICANN policy defaults to approval; keep evidence for escalation.
Table of Contents
- Quick checklist: the most common reasons transfers fail
- Step-by-step fixes for each common failure
- How to verify status and correctly resubmit
- When to escalate: registrars and ICANN complaints
- Practical pro tips and common mistakes
- A note from Ihor on getting transfers right
- How we can help with your transfer
- FAQ
- Sources
Quick checklist: the most common reasons transfers fail
Before you dig into fixes, run through this list to spot the likely cause in a few minutes.
- Domain lock active: check WHOIS or RDAP for
clientTransferProhibitedorserverTransferProhibited. - Invalid or expired auth code: confirm the EPP code in your registrar's domain panel, not an old email.
- 60-day restriction: recent registration, prior transfer, or registrant change within 60 days blocks a new transfer.
- WHOIS privacy or stale admin email: approval emails bounce or go unseen.
- DNSSEC enabled: an active DS record at the losing registrar can block the move.
- Expired, redemption, or pendingDelete status: the domain needs restoring before it can transfer.
- Payment holds: unpaid invoices at the losing registrar can trigger an automatic deny.
Check your registrar's transfer dashboard alongside a WHOIS/RDAP lookup tool to confirm which flag applies.
Step-by-step fixes for each common failure
Once you know the cause, work through the matching fix below rather than resubmitting blindly.
- Unlock the domain. Log into your current registrar's panel and look for a transfer lock or domain lock toggle, separate from any privacy lock. Switching it off can take up to 24 hours to show cleanly in WHOIS, according to Cloudflare's registrar troubleshooting documentation, so recheck before resubmitting.
- Get a clean auth code. Request the EPP code from your current registrar's domain management screen rather than reusing an old one from email. Copy it directly into the transfer form: trailing spaces and line breaks are a frequent, avoidable cause of rejection, and codes often expire while you're sorting out other issues, so request it again right before you submit. A guide to getting EPP codes right walks through the common mistakes.
- Fix WHOIS and the approval email. If WHOIS privacy is active, disable it temporarily so the Form of Authorization email has a clear path to your inbox. Confirm your admin contact email is current and check spam folders and any mail filtering rules that might catch registrar notices.
- Clear DNSSEC. If DNSSEC is active on the domain, disable it at the losing registrar first. The DS record's TTL, often around 24 hours, needs to expire before the registry will accept the transfer, per the same Cloudflare troubleshooting notes. A primer on DNSSEC and DS records explains why this step gets skipped so often.
- Resolve expired or suspended status. A domain in redemption or pendingDelete cannot transfer. Renew or restore it at the current registrar first, then wait for the status to clear before trying again.
- Check for payment holds. An outstanding invoice at the losing registrar can trigger an automatic deny regardless of lock status. Settle the balance, then confirm the account shows no holds before resubmitting.
- Watch for manual approval requests. Some transfers need you to click a confirmation link sent by the losing registrar. Approving manually, instead of waiting for the automatic default, can push a stalled transfer through faster.
Pro Tip: Fix one issue at a time and recheck WHOIS between each change. Stacking fixes without verifying each one makes it hard to tell which step actually solved the problem.
How to verify status and correctly resubmit
Your gaining registrar's dashboard shows the live transfer status, and matching it against WHOIS or RDAP output tells you exactly what's blocking progress. A code of pendingTransfer means it's in process, clientTransferProhibited or serverTransferProhibited points to a lock, and pendingDelete or redemptionPeriod means the domain needs restoring before anything else matters.
Give changes time to take effect before resubmitting:
- WHOIS updates after an unlock can take 5 to 24 hours to propagate.
- DS record removal needs its TTL, often about 24 hours, to fully expire.
- A new Form of Authorization may need to be reissued by the gaining registrar if the first one lapsed.
Work through fixes in this order for the cleanest resubmission: unlock the domain, pull a fresh auth code, disable WHOIS privacy, confirm the admin email is reachable, then submit the transfer and watch both your inbox and WHOIS for the next update. If a transfer gets stuck mid-process, canceling and restarting without addressing the root cause just repeats the same failure. A downtime-avoidance checklist covers the full sequence in more detail.
When to escalate: registrars and ICANN complaints
Before contacting support, gather your transfer ID, the exact error message, a WHOIS or RDAP snapshot, and a short list of what you've already tried. That record speeds up any conversation with support and matters if you need to escalate further.
Ask the losing registrar for the specific reason your transfer was denied. ICANN's transfer policy limits registrars to a short list of allowed reasons, including suspected fraud, a court order, or a 60-day restriction, and requires them to state which one applies.
If a losing registrar does not respond to a registry transfer notification within five calendar days, the transfer defaults to approval under ICANN's transfer policy. That default-approval rule is your leverage if a registrar goes silent instead of formally denying the request.
If a registrar denies without a valid reason or ignores the default-approval timeline, you can file a complaint with ICANN. Bring your documented timeline and evidence that you followed the required steps; expect the process to take time rather than produce an immediate reversal.

Practical pro tips and common mistakes
A few traps catch even careful site owners. Some registrars run separate transfer locks, domain locks, and privacy locks, so switching off one doesn't clear the others. Auth codes can expire while nameserver changes are still propagating, forcing a reissue mid-transfer. Privacy services sometimes intercept approval emails in ways that are specific to the registrar, not the standard WHOIS privacy toggle.
Document everything as you go: save WHOIS and RDAP snapshots before and after each change, keep support ticket numbers, and note the exact time you requested each new auth code. That timeline is what makes an escalation, if you need one, fast instead of frustrating.
Pro Tip: Screenshot the WHOIS record the moment a transfer fails. It's the clearest evidence you'll have if you need to show a registrar or ICANN what the domain's status actually was.

A note from Ihor on getting transfers right
I've seen the same pattern over and over: people resubmit a failed transfer three or four times without fixing the actual cause first. Work through the checklist, confirm each fix in WHOIS, then submit once. If you'd rather hand it off, our domain transfer page is where our support team picks it up from here.
— Ihor
How we can help with your transfer
If the back-and-forth of unlocking, reissuing codes, and watching WHOIS isn't how you want to spend an afternoon, we handle the whole process for you. Our support team manages the transfer request, confirms your EPP code, and tracks approval emails so nothing sits unresolved in a spam folder.
What's included when you transfer a domain:
- Migration assistance for your site alongside the domain move.
- A support ticket with a person tracking your transfer status.
- Guidance on DNSSEC, locks, and WHOIS settings specific to your losing registrar.
- Access to hosting plans once your domain and site are both transferred.
Start the process on our domain transfer page, and if you're checking a registrar's reputation first, a directory like Verified's hosting and domain rankings is a reasonable place to look.
FAQ
Do I have to wait 60 days to transfer a domain?
Only in specific cases: within 60 days of initial registration, within 60 days of a previous transfer, or sometimes after a change of registrant unless you opted out. Outside those windows, ICANN's 60-day rule does not apply and you can transfer right away.
Why is my email not working after a domain transfer?
This usually happens when DNS or MX records weren't carried over correctly during the move, or when a brief propagation delay is still in progress. Check your MX records against your email provider's requirements and give DNS changes a few hours to fully propagate.
Why can't I transfer my domain?
The most common blockers are an active registrar lock, an invalid or expired auth code, WHOIS privacy intercepting the approval email, or a 60-day restriction tied to recent registration or registrant changes. Checking WHOIS or RDAP status codes will usually point to the specific cause.
How long does it take for a domain transfer to complete?
Once submitted correctly, most transfers complete within about five to seven days, largely driven by the ICANN default-approval window that kicks in if the losing registrar doesn't respond within five calendar days. Locks, invalid codes, or DNSSEC issues can extend that timeline until they're resolved.
Sources
For deeper reference, ICANN's transfer policy is the governing document behind every rule discussed here. Registrar-level troubleshooting guides from Cloudflare and DomainDetails cover the same fixes in more technical depth, and our domain transfer page is a direct next step if you'd rather have us manage it.
