{"id":8777,"date":"2026-05-29T13:56:45","date_gmt":"2026-05-29T11:56:45","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=8777"},"modified":"2026-05-29T13:56:46","modified_gmt":"2026-05-29T11:56:46","slug":"what-does-the-clienttransferprohibited-status-mean","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-does-the-clienttransferprohibited-status-mean\/","title":{"rendered":"What Does the clientTransferProhibited Status Mean?"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">When consolidating digital assets, reviewing brand portfolios, or moving your business applications to an alternative hosting vendor, migrating your domain name between registrars is a standard administrative step. Domain migrations are governed by international protocols managed by central registries\u2014such as ROTLD for regional <code>.ro<\/code> domains or ICANN for generic top-level extensions like <code>.com<\/code> or <code>.org<\/code>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you run a WHOIS database lookup to inspect your web address parameters before starting a migration, you will likely encounter a specific Extensible Provisioning Protocol (EPP) flag: the <strong>clientTransferProhibited<\/strong> status.<\/p>\n\n\n\n<\/div>\n\n<div id=\"mybox-2858067951\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">The <strong>clientTransferProhibited<\/strong> status is a security flag applied to a domain name by its current registrar. It acts as an active administrative lock that prevents unauthorized transfer requests or hijacking attempts from being processed at the registry level.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-does-the-clienttransferprohibited-status-mean\/#1_The_Operational_Logic_and_Purpose_of_clientTransferProhibited\" >1. The Operational Logic and Purpose of clientTransferProhibited<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-does-the-clienttransferprohibited-status-mean\/#2_How_to_Manage_and_Disable_the_Domain_Transfer_Lock\" >2. How to Manage and Disable the Domain Transfer Lock<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-does-the-clienttransferprohibited-status-mean\/#3_Safeguarding_Platform_Performance_Post-Configuration\" >3. Safeguarding Platform Performance Post-Configuration<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-does-the-clienttransferprohibited-status-mean\/#Summary_Checklist\" >Summary Checklist<\/a><\/li><\/ul><\/nav><\/div>\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"1_The_Operational_Logic_and_Purpose_of_clientTransferProhibited\"><\/span>1. The Operational Logic and Purpose of clientTransferProhibited<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To protect your digital assets from unauthorized takeovers or fraudulent transfers, registrars apply this status automatically as a primary defense mechanism:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91;Transfer Block Active (clientTransferProhibited)] \u2500\u2500\u25ba Rejects unauthorized migration attempts at registry level.\n                                                                     \u2502\n                                                                     \u25bc\n&#91;Lock Disabled via Panel Settings]                 \u2500\u2500\u25ba Status changes to OK. Domain opens for migration.\n<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>A. Preventing Fraudulent Hijacking<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">If a malicious actor gains access to your public domain credentials or attempts to forge a migration command through an external platform, the registry immediately references the domain&#8217;s EPP flags. If <code>clientTransferProhibited<\/code> is active, the registry automatically blocks the request, safeguarding your domain from unauthorized moves.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>B. Maintaining Service Stability<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Because an active transfer block stops unauthorized changes to your registration profile, it protects your underlying DNS zone paths from accidental disruption. This ensures your active e-commerce storefronts, API interfaces, and corporate communication lines face zero public downtime due to administrative errors.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>C. The Standard Operational State<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">For almost all modern domain extensions, this status is enabled by default the moment a domain is registered or transferred to a new provider. Seeing this flag on a WHOIS lookup is normal and indicates your registrar is actively shielding your web address from external manipulation.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"2_How_to_Manage_and_Disable_the_Domain_Transfer_Lock\"><\/span>2. How to Manage and Disable the Domain Transfer Lock<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you choose to move your web address to an alternative infrastructure provider, you must lift this security lock inside your current dashboard before generating your migration codes:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Disabling the Security Block via Your Administration Panel<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">To open your domain name for a migration handshake, use your provider&#8217;s graphical interface to clear the transfer block:<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>Log into your hosting account control portal using your verified administrative credentials.<\/li>\n\n\n\n<li>Navigate to your central services matrix and enter the <strong>Domeny<\/strong> (Domains) management panel.<\/li>\n\n\n\n<li>Select the specific web address you want to migrate to open its configuration settings.<\/li>\n\n\n\n<li>Locate the <strong>Blokada transferu<\/strong> (Transfer Lock) or <strong>Registrar Lock<\/strong> setting option.<\/li>\n\n\n\n<li>Switch the toggle to the <strong>Wy\u0142\u0105czona<\/strong> (Disabled) state to save your adjustments.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Processing Windows:<\/em> Once disabled, the registrar dispatches an automated update command to the central registry database. The <code>clientTransferProhibited<\/code> status clears immediately or within a few minutes, changing your WHOIS status to <code>ok<\/code>. At this point, you can request your unique AuthInfo migration code (<em>kod authinfo<\/em>) to proceed with your transfer safely.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"3_Safeguarding_Platform_Performance_Post-Configuration\"><\/span>3. Safeguarding Platform Performance Post-Configuration<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Whether you are keeping your domain locked for maximum security or updating records to transfer providers, your underlying hosting hardware must remain highly responsive:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>A. Clear Server-Side Caching Elements After Configuration Updates<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">If your technical team modifies domain configurations, updates DNS record rows, or alters platform variables within your dashboard, visitors in various regions may face inconsistent loading or broken connections if older routes remain cached in network paths.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To ensure your web portal maintains rapid delivery immediately, deploy a robust caching tier on your web host node. High-performance configurations rely on advanced engines like <strong>LiteSpeed Cache<\/strong> to save static snapshots of your dynamically compiled pages, serving them instantly to your visitors and reducing backend database workloads.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The moment you adjust your domain settings or modify site layouts, clear your network snapshots. Log into your account management panel to issue a complete <strong>Purge All LSCache<\/strong> command to flush your server&#8217;s edge cache blocks instantly, forcing the backend infrastructure to compile fresh, highly optimized browse sessions for all global viewports.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>B. Secure Automated Transaction and Notification Mail Streams via SMTP<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">As your account processes registration changes, generates transfer authorization notices, or logs background server actions, your background system communications must remain completely secure. If a critical transfer token or verification notice lands in an administrator&#8217;s spam folder, it can disrupt your migration timeline.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because standalone hosting containers lack native mail transport software, avoid using unauthenticated local mail scripts that can trigger spam filters. Configure your platform&#8217;s notification modules to forward all outbound programmatic alerts, billing sheets, and infrastructure summaries through your verified network lines using <strong>mail.mybox.com<\/strong> (supported seamlessly by <strong>smtp.mybox.com<\/strong>, <strong>imap.mybox.com<\/strong>, or <strong>pop3.mybox.com<\/strong> ports). This routes your system alerts through fully authenticated channels, preserving your domain&#8217;s cryptographic reputation and ensuring your logs deliver safely.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary_Checklist\"><\/span>Summary Checklist<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Understand the Security Lock:<\/strong> Recognize that <code>clientTransferProhibited<\/code> is a default safety status that protects your web address from accidental or unauthorized transfer attempts.<\/li>\n\n\n\n<li><strong>Disable the Lock Before Migrating:<\/strong> Turn off the transfer lock setting within your registrar dashboard to change your domain status to <code>ok<\/code> before using migration codes.<\/li>\n\n\n\n<li><strong>Re-Enable the Lock Post-Transfer:<\/strong> Ensure your replacement provider reactivates the transfer block immediately after your migration completes to restore baseline portfolio security.<\/li>\n\n\n\n<li><strong>Flush Server Edge Caches Post-Update:<\/strong> Clear your server-side LiteSpeed Cache layouts right after saving network configuration updates to deploy your performance upgrades cleanly.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">By structure-mapping your website&#8217;s data routing around organized technical guidelines while keeping your background mail parameters and server-side edge caching variables synchronized, you eliminate environmental friction, shield your applications from performance bottlenecks, and ensure your storefront loads rapidly for all visitors.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[128],"manual_kb_tag":[593,661,921,1013,3953,5001,6700,6701,6702,6703],"class_list":["post-8777","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-domains","manual_kb_tag-domain-transfer","manual_kb_tag-transfer-lock","manual_kb_tag-extensible-provisioning-protocol","manual_kb_tag-domain-name-transfer","manual_kb_tag-registrar-transfer","manual_kb_tag-domain-migration","manual_kb_tag-clienttransferprohibited","manual_kb_tag-registrar-lock","manual_kb_tag-domain-lock","manual_kb_tag-epp-status"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/8777","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/8777\/revisions"}],"predecessor-version":[{"id":8778,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/8777\/revisions\/8778"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=8777"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=8777"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=8777"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}