An AuthInfo code (also known as an EPP key, transfer secret, or authorization code) is essentially the master password for your domain. It is a unique string of characters assigned by the registrar to prove that you are the legitimate owner.
In April 2026, as digital security standards have tightened, this code is the only thing standing between a secure domain and a “domain hijacking” attempt. Without it, you cannot move your digital brand from one provider to another.
Table of Contents
What is the AuthInfo Code?
Think of your domain like a bank vault. Your username and password get you into the “lobby” (your hosting panel), but the AuthInfo code is the physical key required to move the contents of that vault to a different bank.
- Unique: Every domain has its own specific code.
- Temporary: Codes often expire after 10–30 days for security.
- Controlled: Only the Registrant (owner) can request or generate it.
When Do You Need an AuthInfo Code?
You will primarily need this code for two critical operations on mybox:
- Transferring to Another Registrar: If you want to move your
.roor.comdomain from another provider to mybox (or vice versa) to consolidate your billing. - Transfer of Ownership (Trade): For .ro domains, this is called a “Transfer of Right of Use.” You generate a key to authorize the change of the person or company listed as the owner.
- Consolidating Assets: If you have domains scattered across multiple registrars and want to manage them all in one place.
How to Get an AuthInfo Code for a .ro Domain
Since .ro domains are managed by RoTLD, the process is highly standardized:
- Log in to RoTLD: Go to rotld.ro and select Domenii .ro ➜ Administrare On-line.
- Authenticate: Enter your domain name and password.
- Generate the Key: * For a registrar transfer: Select Cheie de Autorizare ➜ Transfer la alt registrar.
- For an ownership change: Select Transferuri ➜ Transfer Drept de Folosință.
- Check Your Email: RoTLD will automatically send the code to the registrant email address on file.
2026 Security Warning: Don’t Get Hijacked
The AuthInfo code is extremely sensitive. If a hacker gains access to this code, they can initiate a transfer to a registrar they control, effectively stealing your domain.
- Never share the code in a public forum, chat, or unencrypted email.
- Only give the code to the new registrar’s official transfer form.
- Check for “Transfer Locks”: Most
.comand.netdomains have a “Registrar Lock” enabled by default. You must Unlock the domain in your dashboard before the AuthInfo code will work.
Troubleshooting: What if I can’t get the code?
| Problem | Cause | Solution |
| Code is “Invalid” | The code has expired or has a typo. | Generate a new code and use copy-paste (avoid manual typing). |
| Email Not Arriving | Your WHOIS email address is outdated. | Perform an “Email Reset” on the RoTLD portal first. |
| Registrar Refusal | You may have an unpaid balance. | Settle all invoices; by law (ICANN/RoTLD), they cannot withhold the code if you are paid up. |
| 60-Day Lock | New domains or recent transfers are locked. | You must wait 60 days from the last change before a new transfer is allowed. |
Summary
The AuthInfo code is your domain’s “Get Out of Jail Free” card. It ensures that you, and only you, have the power to decide who manages your digital identity. If you’re planning to move your site to mybox, having this code ready is the first step toward a seamless migration.