OneWebDesk

Domain Status Code Decoder

Explain EPP domain status codes like clientTransferProhibited.

Codes you see in WHOIS or your domain dashboard — like clientTransferProhibited, serverHold or pendingDelete — are EPP status codes. Enter a code and this tool explains its meaning, severity and what to do. You can paste an entire WHOIS / Domain Lookup result; only the codes are read.

It helps when a domain suddenly stops resolving, a transfer is blocked, or you're considering recovery after expiry.

clientTransferProhibitedOKTransfer lock (registrar)
A registrar lock that prevents unauthorized transfers. Recommended for security; remove it before transferring.
serverHoldCriticalServer hold
Set by the registry; the domain is deactivated, often due to disputes or legal reasons.
Show all EPP status codes
okOKOK
inactiveWarningNo nameservers
linkedInfoLinked
clientHoldCriticalClient hold
serverHoldCriticalServer hold
clientTransferProhibitedOKTransfer lock (registrar)
serverTransferProhibitedWarningTransfer lock (registry)
clientUpdateProhibitedOKUpdate lock (registrar)
serverUpdateProhibitedWarningUpdate lock (registry)
clientDeleteProhibitedOKDelete lock (registrar)
serverDeleteProhibitedWarningDelete lock (registry)
clientRenewProhibitedWarningRenew lock (registrar)
serverRenewProhibitedWarningRenew lock (registry)
addPeriodInfoAdd grace period
autoRenewPeriodInfoAuto-renew period
renewPeriodInfoRenew grace period
transferPeriodInfoTransfer grace period
pendingCreateInfoPending create
pendingRenewInfoPending renew
pendingTransferWarningPending transfer
pendingUpdateInfoPending update
pendingDeleteCriticalPending delete
pendingRestoreWarningPending restore
redemptionPeriodCriticalRedemption period

client* vs server*

client* codes are set by the registrar and can usually be removed by you; transfer/delete locks are actually recommended. server* codes are set by the registry, often tied to disputes or legal reasons, and are hard to remove yourself.

Red flags needing action

  • clientHold / serverHold: the domain isn't in DNS, so site and mail stop.
  • redemptionPeriod: a ~30-day recovery window after expiry — act fast or lose it.
  • pendingDelete: deletion underway; it will soon be re-registrable by anyone.

EPP status codes at a glance: meaning and action

Here are the codes you'll meet most often, sorted by what they mean and what to do. client* codes can normally be toggled in your registrar dashboard, while server* codes and lifecycle states (redemptionPeriod, pendingDelete) have to go through the registrar or registry.

Status codeMeaningAction
okNo restrictions or locks at all (shown only when no other code is present).Nothing required. But with no locks set, turning on a transfer lock is wise to prevent hijacking.
clientTransferProhibitedRegistrar-set transfer lock. Blocks moving the domain to another registrar.Leave it on day to day. Only unlock at your registrar when you actually transfer.
clientDeleteProhibitedRegistrar-set delete lock. Prevents accidental or malicious deletion.Keep it on. To delete intentionally, remove the lock at the registrar first.
clientUpdateProhibitedRegistrar-set update lock. Blocks changes to nameservers, contacts, etc.Keep it on. Temporarily remove it to change NS or contact details.
clientHoldRegistrar pulled the domain out of DNS — usually non-payment or a policy issue. Site and mail go down.Risky. Contact the registrar, fix the cause (unpaid invoice, unverified contact), then it clears.
serverHoldRegistry pulled the domain out of DNS — often a dispute or legal matter.Risky. You can't clear it yourself; ask your registrar to query the registry for the reason and steps.
autoRenewPeriodThe window (~45 days) right after an automatic renewal, during which a refund/cancel is still possible.Normal. Leave it if you're keeping the domain; cancel within this window for a refund.
addPeriodA grace window (~5 days) right after registration; deleting within it refunds the registration fee.Normal. If you registered by mistake, delete inside this window to get a refund.
redemptionPeriodA recovery window (~30 days) after expiry/deletion. Out of DNS, so the site is down.Urgent. Ask the registrar to redeem it and pay the redemption fee, or it's deleted for good.
pendingDeleteFinal deletion stage (~5 days). No recovery; soon re-registrable by anyone.Effectively nothing to do. To get it back, watch for the drop and re-register.

Worked example: a site that suddenly won't load

Say example.com was fine yesterday but today won't open in any browser and email has stopped too. The WHOIS result shows these under Domain Status:

  • Input: clientHold plus clientTransferProhibited
  • Reading it: clientTransferProhibited is a normal transfer lock you can ignore. The culprit is clientHold — the registrar has removed the domain from DNS, so the delegation itself is gone. Even with perfect DNS settings, the domain isn't published, so a DNS Lookup returns empty A/NS answers or looks like NXDOMAIN.
  • Cause: almost always an unpaid renewal, or a new registration whose ICANN WHOIS email verification wasn't completed in time.
  • Fix: check billing and verification in the registrar console; paying the invoice or clicking the verification email clears clientHold. Once delegation is restored it takes time to propagate, so track it with DNS Propagation Check.

Frequently asked questions

Is clientTransferProhibited a problem?
No. It's a recommended security lock against unauthorized transfers. To transfer the domain, remove it at your registrar first.
Can I recover a domain in redemptionPeriod?
Usually yes. For about 30 days after expiry you can restore it for a fee. After pendingDelete it is permanently deleted.
What does inactive mean?
No nameservers are set, so the domain isn't delegated and site/mail won't work.
Where do I find these status codes?
They appear under Domain Status in a WHOIS / RDAP result. To see the full domain metadata alongside them, use the WHOIS / Domain Lookup tool.
Is it OK to have several codes at once?
Yes, that's common. For example, clientTransferProhibited, clientDeleteProhibited and clientUpdateProhibited together are a normal security lock bundle. The risky ones are the hold, redemption and pendingDelete codes.

Related guides

Related tools

DNS / Domain