You hit transfer on your new registrar, and it immediately demands an EPP code while flagging your domain as locked. Worse, one wrong click in your contact settings can slap a mandatory 60-day transfer hold on the domain—one that Namecheap support cannot lift, no matter how nicely you ask.
I ran through this exact flow yesterday while migrating an API domain. Here is how to kill the registrar lock, grab your EPP authorization code from Namecheap, and avoid the contact-update trap that freezes domains for two months.

The 60-Day Lock Rules You Need to Know First
Before flipping switches in the dashboard, check your timing. ICANN enforces strict transfer policies across all accredited registrars. If you trigger an ICANN lock, Namecheap’s support desk can’t bypass it for you.
Under the ICANN Transfer Policy, you cannot transfer a domain between registrars if:
- You registered the domain less than 60 days ago.
- You transferred it from another registrar less than 60 days ago.
- You changed the registrant First Name, Last Name, Organization, or Email address without checking the opt-out box for the 60-day lock.
- The domain has an active dispute, legal hold, or fraud review on it.
The first two are non-negotiable hard stops. Bought the domain 20 days ago? You’re stuck until day 61. But that third rule—the Change of Registrant lock—is the landmine developers step on right before initiating a transfer. We’ll bypass that in a minute.
Pre-Transfer Audit: Check RDAP and Domain Status via Terminal
Don’t trust the web UI alone. Registrars love showing green checkmarks even when status flags are still active upstream at Verisign or PIR. Pull the actual registry status from your terminal using RDAP or standard WHOIS.
Run this curl against ICANN’s public RDAP bootstrap to see what the registry actually reports:
# Query domain status via ICANN Registration Data Access Protocol (RDAP)
curl -s "https://rdap.verisign.com/com/v1/domain/example.com" | jq '.status'If your domain is still locked at Namecheap, you’ll see the prohibited transfer flag in the response:
[ "clientTransferProhibited"
]That clientTransferProhibited status is set by Namecheap. It blocks incoming transfer requests at the registry level. Our goal is to flip this status back to ok (or clear the lock completely) so the destination registrar can pick it up.
Step 1: Turn Off Domain Registrar Lock in Namecheap Dashboard
Time to unlock the domain. Log into Namecheap and head to your domain management screen.
- Click Domain List in the left sidebar.
- Find your domain and hit Manage on the right.
- Click the Sharing & Transfer tab near the top.
- Scroll down to the Transfer Out section.
- Find Domain Lock. If it reads LOCKED, flip the toggle to OFF (UNLOCKED).
There’s no save button here; it updates instantly. Namecheap fires an update to the central registry to strip clientTransferProhibited. This usually clears up at the root zone within a couple of minutes, though some ccTLDs lag behind by 10 to 15 minutes.
If you’re also migrating hosts, make sure your records don’t drop off. Read our guide on how to transfer a Namecheap domain and prevent DNS downtime so your production apps stay online while the registrar swaps over.
Step 2: Handle WhoisPrivacy and Registrant Email Routing
Old forum posts will tell you to disable WhoisPrivacy before transferring. That used to be true back when the receiving registrar emailed a confirmation link to whatever public WHOIS admin address it scraped.
Thanks to GDPR and modern RDAP protocols, you generally do not need to disable Namecheap WhoisPrivacy for standard gTLDs (.com, .net, .org). Turning it off just exposes your phone number and home address to scrapers within seconds.
That said, Namecheap emails your EPP Auth Code straight to your primary account email address. If you’re running custom MX routing on the domain you’re actively transferring, confirm your inbox can actually receive incoming mail right now.
If you run a custom setup, check our walkthrough on how to set up Namecheap Private Email MX, SPF, and DKIM records to verify your inbox isn’t silently dropping mail. You can also throw together temporary forwarding using Namecheap free email forwarding to Gmail if you need a quick backup address.
Step 3: Request the EPP Auth Code
The EPP Auth Code is essentially a one-time password for your domain. Your new registrar won’t let you submit the transfer payload without it.
Here’s how to pull it from Namecheap:
- Stay on that same Sharing & Transfer tab.
- Right below Domain Lock, find the Auth Code row.
- Click the AUTH CODE button.
- Namecheap throws a short feedback survey at you. Pick an option (like Personal reasons or Price).
- Hit Send Code.
Namecheap doesn’t print the string on screen. Instead, they email it to your registrant address. When I ran this yesterday, it hit my inbox in about 45 seconds under the subject line “Authorization Code for [yourdomain.com]”.
The email looks like this:
Domain Name: example.com
Auth Code: 8aF#9$kL2!zQ9xP
Expiration: 5 days from issuanceCopy that code straight into your password manager. Don’t leave it lying in an open terminal or Slack channel—anyone with this string and an unlocked domain can pull off an inbound transfer.
Dodging the 60-Day Change of Registrant Lock
This is where people get burned. You spot an outdated company address or an old typo in your contact info, and you decide to clean it up right before kicking off the transfer.
When you edit contact info on Namecheap, ICANN treats it as a Change of Registrant. By default, that automatically triggers a 60-day transfer hold.
If you really need to update your details before moving:
- Go to the Domain tab and check under Domain Contacts.
- Hit Edit on the Registrant card.
- Change your name, organization, or email.
- Before hitting Save, look at the bottom checkbox: “Opt-out of 60-day transfer lock”.
- Check that box. If you miss it, your domain is locked down tight for 60 calendar days.
If you already messed up and triggered it, you’ll get hit with Domain cannot be transferred: 60-day Change of Registrant lock active. If that happens, open a live chat ticket with Namecheap immediately. While ICANN rules are rigid, Namecheap support can sometimes email confirmation links to both your old and new addresses to clear the hold—provided you catch it right away.
Verify Registry Status via Bash Script Before Transferring
Before handing money to the new registrar, make sure the lock is actually cleared upstream. I use this quick bash script to check the authoritative nameserver and WHOIS output directly:
#!/usr/bin/env bash
# verify-domain-status.sh DOMAIN="$1" if [ -z "$DOMAIN" ]; then echo "Usage: ./verify-domain-status.sh example.com" exit 1
fi echo "Fetching registry status for ${DOMAIN}..."
STATUS=$(whois "${DOMAIN}" | grep -i "Domain Status:" | awk '{print $3}') echo "Current Status:"
echo "${STATUS}" if echo "${STATUS}" | grep -qi "clientTransferProhibited"; then echo "[ERROR] Domain is still LOCKED at Namecheap." exit 1
else echo "[SUCCESS] Domain is UNLOCKED and ready for transfer." exit 0
fiMake it executable with chmod +x verify-domain-status.sh and run it:
./verify-domain-status.sh example.comOnce you get [SUCCESS] Domain is UNLOCKED and ready for transfer, your new registrar will accept the domain and EPP code without choking.
Avoid Namecheap DNS Breakage During the Transfer
When you transfer out of Namecheap, their free BasicDNS shuts off the second the transfer completes. If your nameservers are set to dns1.registrar-servers.com, your site and APIs will go dark immediately.
To avoid taking an outage:
- Export your DNS zone file from the Advanced DNS tab inside Namecheap.
- Recreate all A, CNAME, TXT, and MX records at your destination provider (or switch to Cloudflare first).
- If you run external apps or custom hosts, make sure your subdomains are mapped ahead of time. Review our guide on creating a subdomain with Namecheap DNS if you need to double-check record syntax.
- If you’re deploying on modern hosts, read our breakdown on how to point a Namecheap domain to Vercel so you know how apex and CNAME records behave before the cutover.
Drop the TTL on your critical DNS records down to 300 (5 minutes) at least a full day before transferring. If an IP changes unexpectedly during the migration, traffic will recover in minutes instead of hours.
Common EPP Code Errors and How to Resolve Them
Even after unlocking, transfers occasionally fail at the new registrar due to formatting bugs or bad timing. Here are three issues I see regularly:
1. Auth Code Invalid or Malformed
Namecheap loves stuffing special characters into auth codes (like $, #, or !). When pasting into checkout forms, extra trailing spaces or broken URL-encoding can mangle the string. Copy the raw text carefully and strip any leading or trailing whitespace.
2. Auth Code Expired
Per IANA RDAP specifications, EPP codes expire. Namecheap codes generally stay valid between 5 and 30 days depending on the TLD. If you requested the code last week and sat on it, just generate a fresh one before submitting your order.
3. Registry Status: pendingDelete or clientHold
If the domain expired recently, Namecheap might still let you click the button and send an auth code, but the registry will reject the transfer. Domains in grace periods or redemption status cannot move until you pay the renewal fees. Make sure WHOIS shows ok or active first.
Frequently Asked Questions
How long does it take for Namecheap to release the domain once transferred?
Once you input the EPP code and pay the new registrar, Namecheap emails you a notice titled “Domain Transfer Request”. If you do nothing, they auto-release the domain after 5 calendar days. To skip the wait, open that email, click the link, and hit Approve Transfer. It will release within 15 minutes.
Does unlocking my Namecheap domain cause any website downtime?
No. Unlocking the domain and generating an auth code only flips an internal registry flag. It doesn’t touch your nameservers, wipe your DNS records, or drop existing web traffic.
Why didn’t I receive the EPP Auth Code email from Namecheap?
Check the spam folder of the primary email registered to your Namecheap account. If WhoisPrivacy is active, confirm the contact email on your profile is verified. If there’s an old typo in your profile email, correct it and trigger the code again.
Can I cancel an EPP Auth Code request?
Yes. Just toggle Domain Lock back to ON in the Sharing & Transfer tab. That slaps clientTransferProhibited back on the registry immediately and invalidates any pending auth codes.
Next Steps for Your Domain Migration
Now that your domain is unlocked and you have the EPP code, you can run the transfer at your new registrar. Just make sure your target nameservers are already populated so you don’t drop traffic during the handover.
Check our full guide on how to transfer a Namecheap domain with zero DNS downtime to see how to stage your records, approve the transfer instantly, and verify the new zone before traffic migrates.

