
Written by
Hasnaat Mahmood
Hasnaat is the founder of Find Cheap Domains and writes from hands-on experience with domain registrations, renewals, transfers and DNS management.
Practical domain management experienceTreat the code as compromised. Lock the domain, replace or regenerate the Auth Code if your registrar allows it, check for a transfer you did not request, and secure the registrar account and email address tied to it.

Do this first
An Auth Code is used in registrar transfers. If somebody else has yours, do not wait to see whether they use it. Secure the domain first, then check whether a transfer request is already underway.
A domain Auth Code is sometimes called an EPP code, transfer code, AuthInfo code or authorisation code. Whatever your registrar calls it, the purpose is the same: it is one of the credentials used to move a domain registration from one registrar to another.
When I am not actively transferring a domain, I treat its Auth Code like a temporary password. If I knew somebody else had seen it, I would assume it was compromised even if no suspicious transfer email had arrived yet.
A hosting provider normally does not need your domain Auth Code unless you actually intend to transfer the domain registration to it. DNS or nameserver changes are separate.
The aim is to block an outbound transfer and invalidate the code before it can be used.
ICANN's Transfer Policy requires registrars to support the use of unique AuthInfo codes on a per-domain basis and says registrars should follow secure practices when generating and updating them. It also allows clientTransferProhibited to be used as the registrar-level transfer lock.
If the lock terminology is unfamiliar, our guide to clientTransferProhibited explains exactly what that status does.
At that point, changing the code alone may not be enough. You need to stop the transfer that is already in progress.
Contact your current registrar straight away and tell them the transfer is unauthorised. If the registrar gives you a self-service option to reject or cancel the outbound transfer, use it as well.
Under ICANN's policy, the registered name holder is the party with authority to approve or deny the transfer request. Evidence of fraud, a reasonable dispute over the identity of the person authorising the transfer, or an express objection from the registered name holder are among the circumstances in which a transfer can be denied.
If you receive a legitimate-looking transfer message after the code has leaked, verify it by signing in to the registrar directly rather than following links in the email.
If the transfer is already showing as pending, use our separate guide on cancelling a domain transfer after it has started. The options change once the registry has begun processing the move.
If somebody obtained the Auth Code from your account or inbox, the leaked code may be only one part of the problem.
This is also why I prefer leaving valuable domains locked when I am not moving them. The Auth Code is one layer; the registrar lock is another. Our broader guide to domain locking explains how those protections fit together.
The code is meant for registrar transfers. It is not the password for your website, hosting account or email inbox.
A valid Auth Code is a key part of moving many domains between registrars. That is why exposure should be taken seriously.
The code is not normally the username or password for the registrar account itself.
Possessing the code alone does not normally let someone edit MX, A, CNAME or nameserver records at your existing provider.
The danger is what can happen after an unauthorised transfer succeeds. Control of the registration can eventually put nameservers and DNS at risk too, which is why I would not dismiss an exposed Auth Code simply because the website still works normally.
Namecheap also warns that an Auth/EPP code should not be handed to a hosting provider merely to verify a domain; if the provider is given the code in the context of a transfer, the registration itself may be moved.
As of September 2026, the current .UK transfer process still uses registrar tags rather than the standard Auth Code flow.
For domains such as .uk, .co.uk and .org.uk, the current legacy transfer process is different from the usual gTLD Auth Code system. That means somebody knowing a generic “EPP code” is not the normal route for transferring one of those domains today.
That is changing. Nominet has announced that on 9 February 2027 .UK transfers will move to Transfer Authorisation Codes as part of .UK standardisation. Nominet says those future codes will be valid for 14 days.
This article is published in September 2026. If you are reading it after 9 February 2027, check Nominet's current transfer guidance because the .UK process will have changed.
Work out how the code escaped, otherwise the replacement may end up exposed in exactly the same way.
If you decide to move the domain yourself afterwards, compare the destination before unlocking it again. Our domain transfer comparison is a better place to choose the receiving registrar than leaving the domain unlocked while you shop around.
My preference is simple: keep the domain locked, obtain an Auth Code only when I am actually ready to transfer, and avoid storing transfer codes permanently in general notes or messages. They are supposed to be transfer credentials, not long-term reference information.

My view
Waiting for an unauthorised transfer to appear gives away the advantage. Locking the domain, invalidating the exposed code and securing the account is quick compared with trying to recover a domain after control has moved elsewhere.

Written by
Hasnaat is the founder of Find Cheap Domains and writes from hands-on experience with domain registrations, renewals, transfers and DNS management.
Practical domain management experience