What Should You Do If Someone Gets Your Domain Auth Code?

Treat the code as compromised. Lock the domain, replace or regenerate the Auth Code if your registrar allows it, check for a transfer you did not request, and secure the registrar account and email address tied to it.

By Hasnaat Mahmood Published Updated
Ech, the Find Cheap Domains mascot

Do this first

Re-lock the domain and make the exposed code useless.

An Auth Code is used in registrar transfers. If somebody else has yours, do not wait to see whether they use it. Secure the domain first, then check whether a transfer request is already underway.

  • Lock the domain
  • Replace the Auth Code
  • Check for a pending transfer

A domain Auth Code is sometimes called an EPP code, transfer code, AuthInfo code or authorisation code. Whatever your registrar calls it, the purpose is the same: it is one of the credentials used to move a domain registration from one registrar to another.

When I am not actively transferring a domain, I treat its Auth Code like a temporary password. If I knew somebody else had seen it, I would assume it was compromised even if no suspicious transfer email had arrived yet.

Do not send the code to a hosting company just to connect a website.

A hosting provider normally does not need your domain Auth Code unless you actually intend to transfer the domain registration to it. DNS or nameserver changes are separate.

First 10 minutes

What should you do as soon as the Auth Code is exposed?

The aim is to block an outbound transfer and invalidate the code before it can be used.

  1. Lock the domainTurn on Domain Lock, Registrar Lock or Transfer Lock at the current registrar. In RDAP or WHOIS, this commonly appears as clientTransferProhibited.
  2. Replace the Auth CodeIf the registrar lets you generate a new code, do it. If not, contact support and ask whether the existing code can be invalidated and replaced.
  3. Check the transfer areaLook for any pending outbound transfer, approval request or recent transfer notification that you did not start.
  4. Check your email immediatelySearch for transfer, unlock and Auth Code messages. Make sure nobody has gained access to the mailbox used with your registrar account.

ICANN's Transfer Policy requires registrars to support the use of unique AuthInfo codes on a per-domain basis and says registrars should follow secure practices when generating and updating them. It also allows clientTransferProhibited to be used as the registrar-level transfer lock.

If the lock terminology is unfamiliar, our guide to clientTransferProhibited explains exactly what that status does.

If it has gone further

What if somebody has already started the transfer?

At that point, changing the code alone may not be enough. You need to stop the transfer that is already in progress.

Contact your current registrar straight away and tell them the transfer is unauthorised. If the registrar gives you a self-service option to reject or cancel the outbound transfer, use it as well.

Under ICANN's policy, the registered name holder is the party with authority to approve or deny the transfer request. Evidence of fraud, a reasonable dispute over the identity of the person authorising the transfer, or an express objection from the registered name holder are among the circumstances in which a transfer can be denied.

Do not approve a transfer email you were not expecting.

If you receive a legitimate-looking transfer message after the code has leaked, verify it by signing in to the registrar directly rather than following links in the email.

If the transfer is already showing as pending, use our separate guide on cancelling a domain transfer after it has started. The options change once the registry has begun processing the move.

Do not stop at the code

Secure the registrar account and the email behind it

If somebody obtained the Auth Code from your account or inbox, the leaked code may be only one part of the problem.

  • Change the registrar account password to a new, unique password.
  • Turn on two-factor authentication if the registrar offers it.
  • Review recent sign-ins, security alerts and account activity.
  • Check that the account email address and recovery details have not changed.
  • Change the password on the email account linked to the registrar if compromise is possible.
  • Check your other domains for unexpected unlocks, contact changes or transfer requests.

This is also why I prefer leaving valuable domains locked when I am not moving them. The Auth Code is one layer; the registrar lock is another. Our broader guide to domain locking explains how those protections fit together.

Know the risk

What can somebody actually do with your domain Auth Code?

The code is meant for registrar transfers. It is not the password for your website, hosting account or email inbox.

It can help authorise a transfer

A valid Auth Code is a key part of moving many domains between registrars. That is why exposure should be taken seriously.

It does not log someone into your registrar

The code is not normally the username or password for the registrar account itself.

It does not directly alter DNS

Possessing the code alone does not normally let someone edit MX, A, CNAME or nameserver records at your existing provider.

The danger is what can happen after an unauthorised transfer succeeds. Control of the registration can eventually put nameservers and DNS at risk too, which is why I would not dismiss an exposed Auth Code simply because the website still works normally.

Namecheap also warns that an Auth/EPP code should not be handed to a hosting provider merely to verify a domain; if the provider is given the code in the context of a transfer, the registration itself may be moved.

A UK exception

What if the domain is .uk or .co.uk?

As of September 2026, the current .UK transfer process still uses registrar tags rather than the standard Auth Code flow.

For domains such as .uk, .co.uk and .org.uk, the current legacy transfer process is different from the usual gTLD Auth Code system. That means somebody knowing a generic “EPP code” is not the normal route for transferring one of those domains today.

That is changing. Nominet has announced that on 9 February 2027 .UK transfers will move to Transfer Authorisation Codes as part of .UK standardisation. Nominet says those future codes will be valid for 14 days.

The date matters here.

This article is published in September 2026. If you are reading it after 9 February 2027, check Nominet's current transfer guidance because the .UK process will have changed.

Once the immediate risk is handled

What should you do after the domain is safe?

Work out how the code escaped, otherwise the replacement may end up exposed in exactly the same way.

  • Was it copied into an email, chat or support ticket? Remove it where possible and consider whether anyone else could still access that conversation.
  • Was the registrar account accessed? Review the whole account, not just the one domain whose code you noticed.
  • Was the mailbox compromised? A new Auth Code sent to the same compromised mailbox does not solve the underlying problem.
  • Was it shared with a legitimate provider? Confirm in writing whether they attempted or intend to attempt a registrar transfer.

If you decide to move the domain yourself afterwards, compare the destination before unlocking it again. Our domain transfer comparison is a better place to choose the receiving registrar than leaving the domain unlocked while you shop around.

My preference is simple: keep the domain locked, obtain an Auth Code only when I am actually ready to transfer, and avoid storing transfer codes permanently in general notes or messages. They are supposed to be transfer credentials, not long-term reference information.

Ech, the Find Cheap Domains mascot

My view

If the Auth Code has leaked, I would replace it even if nothing suspicious has happened yet.

Waiting for an unauthorised transfer to appear gives away the advantage. Locking the domain, invalidating the exposed code and securing the account is quick compared with trying to recover a domain after control has moved elsewhere.

Hasnaat Mahmood

Written by

Hasnaat Mahmood

Hasnaat is the founder of Find Cheap Domains and writes from hands-on experience with domain registrations, renewals, transfers and DNS management.

Practical domain management experience