
Written by
Hasnaat Mahmood
Hasnaat is the founder of Find Cheap Domains and writes from hands-on experience with domain registrations, renewals, transfers and DNS management.
Practical domain management experienceIt means your registrar has placed a transfer lock on the domain, so another registrar cannot transfer it away while that status remains active. In most cases it is a normal security setting, not a sign that anything is wrong.

Quick answer
ICANN describes clientTransferProhibited as a client status code set by the registrar. While it is active, the registry rejects attempts to transfer the domain to a different registrar.
If you have looked up a domain in WHOIS or RDAP and seen clientTransferProhibited, the wording can sound more serious than it is. Most of the time it simply means the domain is locked against an unauthorised registrar transfer.
My own rule is not to treat this status as a warning by itself. If I am not planning to move the domain, I would generally rather see a transfer lock in place than leave the domain unnecessarily open to an outbound transfer.
The status is about transferring the registration between registrars. It does not, by itself, stop the domain resolving, switch off email or prevent visitors reaching the website.
It tells the registry to reject a request to transfer the domain to another registrar.
The word client is important. In EPP terminology, client status codes are set by the registrar, while server status codes are set by the registry. ICANN lists clientTransferProhibited as one of the standard client status codes.
If another registrar tries to submit a transfer request while this status is active, the transfer should be rejected. That is why registrars commonly refer to the setting as a domain lock, registrar lock or transfer lock.
The domain cannot normally be transferred from the current registrar to another until the status is removed.
The restriction makes it harder for an unauthorised party to move the registration away without the lock first being removed.
The code does not tell the registry to remove the domain from DNS. That is a different type of status, such as clientHold.
If you want the wider picture, our guide to how domain locking works explains why registrars use these restrictions and when you would normally unlock a domain.
The most ordinary reason is simply that your registrar keeps the domain locked unless you are preparing to transfer it.
ICANN's current Transfer Policy allows registrars to set clientTransferProhibited at registration or later at the registered name holder's request, provided the relevant terms are covered in the registration agreement.
That last point is why I would not judge a registrar purely by whether this code is visible. A locked domain is often exactly what you want when no transfer is planned. What matters is whether you can remove the lock cleanly when you genuinely need to move the domain.
Seeing a transfer-related status does not tell you the whole reason a domain cannot move.
A registrar-set EPP status. It blocks the transfer while active and can often be removed from the registrar account or by contacting the registrar.
A domain may be ineligible for transfer because of ICANN transfer rules or a change-of-registrant restriction. That is a separate question from whether the visible EPP lock is switched on.
This is set at registry level rather than registrar level. ICANN says it is less common and may be associated with disputes, redemption or a registry-lock service.
This means a transfer request has already been submitted and is being processed. It is not the same as a lock preventing the transfer from starting.
We have a separate explanation of whether nameserver changes trigger a 60-day transfer lock, because that is one of the easiest restrictions to mix up with an ordinary registrar lock.
If another transfer restriction still applies, the domain can remain ineligible even after clientTransferProhibited disappears from RDAP or WHOIS.
Start in the registrar account where the domain is currently registered.
Under ICANN's Transfer Policy, if the registrar does not give you a self-service facility to remove clientTransferProhibited, it must remove the status within five calendar days of your initial request. The policy also requires the AuthInfo code within five calendar days where the registrar does not provide a self-service method for generating it.
Once you are ready to move, it is worth checking the receiving registrar as well as the old one. You can compare domain transfer prices before you unlock anything, rather than leaving a domain open while you decide where it is going.
The status itself is usually routine. The problem is when you cannot control it or it appears alongside something you do not understand.
If the only thing you see is clientTransferProhibited on a domain you are not trying to move, I would usually leave it alone. Unlock it when you have a real transfer to make, complete the move, and avoid keeping a valuable domain unlocked for longer than necessary.
If you are preparing a `.com` move, our guide to how long a .com domain transfer takes explains what happens after the lock has been removed and the transfer has actually started.

My view
The name sounds severe, but the job is simple: stop the registration being moved to another registrar until the lock is removed. I would treat it as a normal security control first, then investigate only if you cannot unlock the domain when you genuinely need to.

Written by
Hasnaat is the founder of Find Cheap Domains and writes from hands-on experience with domain registrations, renewals, transfers and DNS management.
Practical domain management experience