Your Namecheap domain transfer failed, and your new registrar dropped a vague “transfer rejected” notice in your inbox. In almost every case, it comes down to three things: a desynced registrar lock, a stale or mistyped EPP auth code, or an ICANN 60-day transfer hold. Here is how to track down the exact blocker and push the transfer through.

Why Namecheap Domain Transfers Fail
Domain transfers rely on the Extensible Provisioning Protocol (EPP) between registrars and the central registry. When a transfer from Namecheap fails, it usually aborts for one of these reasons:
- Registry-level lock: The domain still carries the
clientTransferProhibitedstatus flag because Namecheap’s lock toggle hasn’t synced with the registry. - Auth code mismatch: The EPP code was mistyped, expired, or invalidated because a newer code was generated after initiating checkout.
- ICANN 60-day hold: The domain was registered, transferred, or had its primary WHOIS contact details modified within the last 60 days.
Before cancelling orders or paying re-initiation fees at your new host, check what the registry actually sees.
Step 1: Check Domain Status via Terminal
Registrar web consoles love caching transfer states. To see what the registry actually has on file right now, run a raw WHOIS query from your terminal:
whois yourdomain.com | grep -i "domain status"Look at the domain status lines in the output. If you see this, the registry is actively rejecting transfer attempts:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibitedAs detailed in the IANA EPP status codes reference, the clientTransferProhibited flag stops external registrars from requesting the domain. As long as that flag is present, the transfer cannot start—regardless of what Namecheap’s dashboard displays.
Step 2: Disable Registrar Lock in Namecheap
If you already unlocked the domain in Namecheap, the dashboard toggle may have failed silently or desynced from the registry. You can force an update by toggling it again:
- Log into Namecheap and go to your Domain List.
- Click Manage next to your domain.
- Switch to the Sharing & Transfer tab.
- Scroll down to Transfer Out.
- Find the Registrar Lock toggle. If it shows ON, toggle it OFF.
If the toggle already says OFF, flip it to ON, wait roughly 60 seconds, then flip it back to OFF. This forces Namecheap’s backend to fire a fresh EPP update to clear the lock at the registry.
If you need a closer look at the dashboard settings, check out our guide on how to unlock a Namecheap domain and export the auth code.
Step 3: Refresh and Export a New Auth / EPP Code
EPP authorization codes work like one-time passwords between registrars. If you clicked the auth code button multiple times, every previous code was invalidated immediately. You need the most recent string.
- In the Sharing & Transfer tab, find the Auth Code button right beneath the lock toggle.
- Click Auth Code.
- Pick any reason from the dropdown.
- Click Send Code.
Namecheap emails the fresh code to your primary account address. Copy the code straight into a plain text editor first—rich text clients and browser autocompletes love sneaking trailing spaces or hidden characters into the string, which causes immediate authorization failures at the gaining registrar.
Step 4: Check for the 60-Day ICANN Lock
ICANN enforces a mandatory 60-day hold on domain transfers under specific conditions. If this lock applies, neither Namecheap nor your new registrar can bypass it.
According to the ICANN Transfer Policy, the 60-day hold triggers when:
- New Registration: The domain was registered less than 60 days ago.
- Recent Transfer: The domain completed a transfer between registrars within the last 60 days.
- Registrant Contact Change: You updated the registrant’s name, organization, or email address in the WHOIS contact info without explicitly opting out of the 60-day lock.
You can check your creation and modification timestamps quickly via WHOIS:
whois yourdomain.com | grep -E -i "creation date|updated date"If you are inside that 60-day window, you must wait until day 61. If a contact info update triggered the hold, check your inbox—Namecheap sometimes sends a verification email that lets you approve an early release.
Step 5: Verify DNS Stability During the Move
When a transfer stalls, make sure your production site and email routing stay alive while you troubleshoot.
If your domain uses external nameservers (like Cloudflare, Route 53, or your hosting provider), Namecheap keeps resolving them fine during the transfer. But if you rely on Namecheap BasicDNS, those records will terminate the moment the transfer completes.
Check your live authoritative nameservers with dig before re-running the transfer:
dig yourdomain.com NS +shortIf you are moving web hosting alongside your domain, review our walkthroughs on how to point Namecheap DNS without breaking email and how to point a root domain using A records vs CNAMEs to avoid DNS downtime.
Step 6: Resubmit the Transfer at the Gaining Registrar
Once you verify the lock is gone and you have a fresh EPP code, restart the incoming transfer at your new registrar:
- Log into your destination registrar (Hostinger, Cloudflare, Porkbun, etc.).
- Find the failed transfer in your domain list or transfer dashboard.
- Click Retry Transfer or Re-enter Auth Code.
- Paste your clean EPP code and make sure there are no accidental spaces.
- Submit the request.
Verify that the registry accepted the new request with a quick WHOIS check:
whois yourdomain.com | grep -i "domain status"The status should now show pendingTransfer:
Domain Status: pendingTransfer https://icann.org/epp#pendingTransferSeeing pendingTransfer means the auth code passed validation and the domain is now in the release queue.
Step 7: Speed Up the 5-Day Release Window
By default, Namecheap holds outgoing transfers for 5 calendar days to protect against unauthorized moves. You do not need to wait out that full timer if you approve it manually:
- Check the primary email associated with your Namecheap account.
- Look for an email with the subject line “Domain Transfer Request for [yourdomain.com]”.
- Click the confirmation link inside.
- Select Approve Transfer on the verification page.
Per the Namecheap domain transfer documentation, approving this confirmation email releases the domain to the gaining registrar within 15 to 30 minutes instead of waiting the standard 5 days.
Troubleshooting Specific Transfer Errors
If the transfer still fails, match your error message against these common culprits:
- “Object status prohibits operation”: The
clientTransferProhibitedflag is still active. Toggle the lock on and off in Namecheap and wait 15 minutes for the registry to update. - “Invalid authorization code”: The EPP code was pasted with trailing spaces or overwritten by a newer code request. Request one final code and paste it immediately.
- “Domain has privacy protection active”: Most gTLDs work fine with privacy enabled, but certain ccTLDs (such as
.co.ukor.ca) require turning off Namecheap Privacy before the transfer can start. - “Express transfer rejected by registry”: The domain has pending renewal invoices at Namecheap, an active legal hold, or has slipped past the 30-day redemption grace period.
Frequently Asked Questions
How long do I have to wait after unlocking my domain in Namecheap?
The registry usually updates in seconds, but your new registrar’s interface might cache the old locked state for 15 to 30 minutes. Give it roughly 15 minutes after toggling Registrar Lock to OFF before submitting your transfer order.
Does refreshing the Auth Code cancel my active transfer?
Yes. Generating a new EPP code immediately revokes the old one. If your gaining registrar attempts to verify the old code during an active transfer, the registry will reject it. Always resubmit your transfer right after generating a new code.
Will my website go down while fixing a failed transfer?
No. When a transfer fails, the domain simply remains at Namecheap under its existing DNS configuration. Your site, SSL certificates, and email routing will continue running uninterrupted until a new transfer completes.
Why did my transfer fail without an error message?
Silent failures almost always happen when the Form of Authorization (FOA) approval email bounced or got caught in your spam filter. Check your Namecheap administrative email address and look through your spam folder for transfer confirmation requests.
Next Steps
Once the transfer completes, double-check that your DNS records and nameserver delegation point to your live infrastructure. If you are setting up new hosting or app servers alongside your moved domain, check out our walkthrough on how to deploy a web app with custom DNS and SSL to ensure smooth DNS propagation.

