Host Talk / Who actually owns a domain, and how transfers work

Who actually owns a domain, and how transfers work

HOST TALK

9 min read · 1,935 words

You do not buy a domain the way you buy a chair. You register the right to use a name for a period, up to ten years at a time, and renew it before the period ends. Nobody sells you the name outright, and nobody can promise you it is yours forever; what you hold is a registration that stays valid as long as the records say so and the fees are paid.

That small shift in thinking explains most of what goes wrong. Domains lapse because a card expired. They are stuck because the contact email belongs to a former employee. They are lost because a freelancer registered them in their own name. The system has three layers, and knowing them explains most transfer problems.

The layers

ICANN coordinates the global system and sets the rules that registries and registrars sign up to. A registry runs each top-level domain: Verisign for .com and .net, for instance, and national organisations or appointed operators for country domains. The registry keeps the authoritative list of every name under its extension and publishes the nameserver information that makes them resolve.

A registrar is the company you deal with, accredited to register names in the registries on behalf of customers. You never talk to the registry directly. You are the registrant, the holder of the registration, and the details recorded against your name decide who can renew, change or move it.

ICANNsets the global rules and accredits registrars Registryruns one extension, such as .com, and keeps its master list Registrarthe company where you register, renew and transfer Registrant (you)the named holder of the registration
Authority flows down the stack; a change of registrar moves you sideways within the same registry.

You can see part of this from a terminal. whois example.com (or the newer RDAP lookup that many tools now use) shows the registrar, the dates and the nameservers. Since the introduction of privacy rules, personal contact details are often redacted, but the registrar and dates remain visible.

Registrar, DNS host and web host are different jobs

Three things get called "the domain" and are often provided by three different companies. The registrar holds the registration. The DNS host runs the nameservers that answer questions about the name. The web host runs the server the website lives on. For many customers one company does all three, which is convenient and also hides the distinction until something breaks.

Registrarregistration, renewal,lock, nameserver list DNS hostA, MX, TXT, CNAMErecords for the zone Web and mail hostfiles, databases,mailboxes NS A / MX Moving one of these does not move the others.
A registrar transfer touches only the left-hand box; the other two carry on unless you change them too.

Moving between registrars

Transfers follow a standard process for generic domains such as .com, .net and .org. Unlock the domain at the old registrar. Request an authorisation code (sometimes called an EPP code, auth code or transfer key). Start the transfer at the new registrar and enter the code. The old registrar usually sends a confirmation email to the contact address, and the transfer completes in anywhere from minutes to five days, depending on how quickly the confirmation is approved. A transfer typically adds a year to the registration, and you pay for that year at the new registrar.

1Unlock atold registrar 2Request theauth code 3Start at newregistrar 4Approve theemail 5Completes,up to 5 days DNS keeps answering throughout, as long as the records stay put.
The usual sequence for a generic top-level domain; country domains can differ.

Country domains have their own procedures. Some use the same auth-code method, some require a change of a registrar tag at the registry instead, and some do not add a year on transfer. Check the registry's rules for your extension before assuming the .com pattern holds.

Rules that trip people up

A newly registered domain, or one whose registrant details were changed recently, is normally locked against transfer for sixty days. The lock exists to slow down thieves who hijack an account, change the owner details and move the name on within the hour, and it also catches honest people who register a name and immediately decide to switch provider. A domain close to expiry may be easier to renew first than to transfer, because an expired name can be blocked from moving until renewed.

The registrar lock itself is a good thing and should normally stay on; it appears in the status as clientTransferProhibited. You switch it off only for the duration of a planned transfer. If the contact email on file is dead, the confirmation never arrives, the transfer times out, and you start again. This is the single most common reason a move drags on, and it is why keeping contacts current matters so much.

Expiry has its own stages, which differ between registries and registrars. Typically there is a short grace period after the expiry date during which renewal is still at the normal price, then a redemption period of around thirty days in which recovery costs extra, and finally the name is released and anyone can register it. Do not plan around the grace period; renew before the date.

When a transfer stalls

Most failed transfers come down to a short list of causes, and the error message from the new registrar is usually less helpful than the table below.

SymptomLikely causeWhat to do
Auth code rejectedTypo, trailing space, or a code that has expired or been regeneratedRequest a fresh code and paste it without spaces
Transfer refused at onceDomain still locked, or inside the sixty-day windowCheck the status lines with whois; unlock, or wait
Nothing happens after paymentConfirmation email sent to an old or dead addressUpdate the contact at the old registrar, then restart
Cancelled after several daysNobody approved the email, or the old registrar denied itApprove early where the old registrar offers an approve button
Site or mail breaks afterwardsDNS lived at the old registrar and was removedRecreate the records from your saved copy, then change nameservers

Privacy services and whose name is on it

Many registrars offer a privacy or proxy service that replaces your personal details in public lookups with those of the service. That is useful, and it also causes confusion. The registration still belongs to you, but the contact addresses that receive transfer and renewal notices may route through the service. If you switch the service off, or move away from the registrar offering it, make sure the real contact email is already set and reachable.

Distinguish a privacy service from a nominee arrangement, where the registrant of record is genuinely someone else, such as a reseller or agency, and you are a customer of theirs. In that case you may have no legal standing to move the name at all. The words on the invoice and the registrant name in the lookup are worth reading side by side, once, when you start.

A worked example: the agency that left

A small bakery has had its website built by a two-person agency. Years later the owners want to change host and discover that nobody remembers where the domain is registered. A lookup shows a registrar they have never heard of, a registrant name belonging to one of the agency's founders, and a contact email at the agency's own domain. That agency has since closed and its mail no longer arrives.

The way out takes patience. First, find the former founder through any channel and ask them to log in and either change the registrant details to the bakery or push the domain to an account the bakery controls (many registrars have an internal push feature that avoids the auth-code dance). Second, if that person cannot be found, contact the registrar's support with evidence of the business relationship, such as invoices naming the domain and the bakery's registration documents; registrars have a process for this but it is slow and not guaranteed. Third, if the name is about to expire, the bakery should consider a backup plan with an alternative domain and keep email forwarding in mind. None of this would have been necessary had the domain been registered in the bakery's name on day one, at a cost of ten minutes.

DNS during the move

A transfer does not change DNS by itself. Your site and mail keep working as long as the DNS records stay in place. The risk comes from a common side effect: if your DNS was hosted at the old registrar, closing the account or letting the old service lapse after the transfer takes your records with it.

So the order matters. Before starting, copy your records from the old registrar's DNS to wherever they will live afterwards, and compare the two sets. Only then change nameservers, if you intend to, and ideally as a separate step days after the transfer so that you can tell which change caused any problem. Lower the TTLs a day beforehand (the TTL planner helps with the timing), and leave the old zone running until the new one is proven. If you want the background on records and propagation, see the DNS cheat sheet.

# What nameservers does the world see?
dig NS example.com +short

# Does the site still resolve?
dig A example.com +short

# Are mail records intact?
dig MX example.com +short
dig TXT example.com +short

Keeping control

Use an account in your own name or your organisation's, not a freelancer's or an agency's. It is common and entirely understandable for a developer to register a domain "to get things going", and it is also the beginning of many unhappy stories years later when that person has left. Keep the registrar lock on, use two-factor authentication on the account, turn on auto-renew with a payment method that will not expire next spring, and record where the domain is registered. A shared mailbox such as [email protected] makes a better contact address than one person's inbox, provided the mail for that domain does not depend on the domain being alive.

If someone else registered it for you years ago, find out now whose name appears on it, before you need the answer in a hurry. If it is theirs, ask them to transfer it to an account you control, and agree who pays for what in writing. For high-value names, some registries and registrars offer a registry-level lock that requires manual verification to change anything, which is slower but very hard to abuse.

What to look at on your own setup

  1. Run whois example.com and note the registrar, expiry date and status lines. Look for clientTransferProhibited.
  2. Log in to the registrar and confirm that the account email is one you read and the contact email is current.
  3. Check that auto-renew is on and the stored card has more than a year left.
  4. Export or screenshot all DNS records, so you hold a copy outside any provider.
  5. Work out who else can change the domain: staff, agencies, former colleagues. Remove access that is no longer needed.

Questions that come up

Will my website go down during a transfer?

It should not. A registrar transfer does not alter the DNS records, so the site and mail continue to resolve. Trouble comes from nameserver changes made at the same time, or from DNS service ending with the old account.

Can I transfer a domain I only just bought?

Not normally. The sixty-day rule applies to new registrations, so plan to wait. Choosing the right registrar on day one saves the hassle.

Do I need to transfer just to change hosting?

No. Changing web host means pointing the domain at a new server, through DNS records or nameservers, and the registration can stay where it is.

What happens if my registrar closes down?

Accredited registrars that cease trading normally have their customers' domains handed to another registrar under ICANN procedures, but you cannot rely on timing or price. Keep your own record of the domain and auth-code process, and move it before trouble arrives. See the glossary for the terms used here.

PreviousBackups: full, incremental, snapshots and the 3-2-1 rule

More from Host Talk

Host Talk

Reading an access log

Your web server writes down every request it handles. This file, the access log, is the most reliable account...

Host Talk

What time to first byte actually measures

Speed tests report a number called time to first byte, or TTFB. It is the delay between the browser sending a...

Host Talk

When a CDN helps, and when it gets in the way

A content delivery network sits between your visitors and your server. It keeps copies of your files in many...