How to lock your domain at Cloudflare Registrar
Three registrar settings prevent the two ways domains are most often lost — hijacked by an unauthorized transfer, or silently expired: the transfer lock, auto-renew, and WHOIS privacy. In WHOIS/RDAP, clientTransferProhibited is the transfer lock: it tells the registry to reject transfer-away requests until you remove it via your registrar.
1. Transfer lock
- Domains at Cloudflare Registrar stay locked until you explicitly start a transfer-out.
- To unlock: dashboard → Manage Domains → your domain → Manage → Configuration → Unlock → Confirm and Unlock, then copy the auth code.
⚠ Unlocking is a mandatory first step of Cloudflare's own transfer-out flow — there's no separate lock toggle to remember.
ICANN policy allows registrars to block transfers within 60 days of registration or a previous transfer, and applies a 60-day lock after changing registrant contact details. Some registrars let you opt out of the post-change lock BEFORE making the change; once it applies, it can't be lifted early.
2. Auto-renewon by default at Cloudflare Registrar
- Manage Domains page → auto-renew toggle on the domain row.
- Disable at least 30 days before expiry if you don't want the renewal charge (first attempt happens ~30 days out).
Keep the payment method current — auto-renew with an expired card is how "locked" domains still lapse.
3. WHOIS privacy
Automatic — Cloudflare redacts WHOIS information by default where the registry permits; there's no toggle.
Steps verified against Cloudflare Registrar: DNSSEC and related Cloudflare Registrar docs on 2026-07-14.
Verify your lock status
The domain report reads your live WHOIS/RDAP status — look for clientTransferProhibited. A domain-expiry monitor warns you long before a renewal can slip.
Check your domain's status →