How to lock your domain at Cloudflare Registrar

Three registrar settings prevent the two ways domains are most often lost — hijacked by an unauthorized transfer, or silently expired: the transfer lock, auto-renew, and WHOIS privacy. In WHOIS/RDAP, clientTransferProhibited is the transfer lock: it tells the registry to reject transfer-away requests until you remove it via your registrar.

1. Transfer lock

  1. Domains at Cloudflare Registrar stay locked until you explicitly start a transfer-out.
  2. To unlock: dashboard → Manage Domains → your domain → Manage → Configuration → Unlock → Confirm and Unlock, then copy the auth code.

Unlocking is a mandatory first step of Cloudflare's own transfer-out flow — there's no separate lock toggle to remember.

ICANN policy allows registrars to block transfers within 60 days of registration or a previous transfer, and applies a 60-day lock after changing registrant contact details. Some registrars let you opt out of the post-change lock BEFORE making the change; once it applies, it can't be lifted early.

2. Auto-renewon by default at Cloudflare Registrar

  1. Manage Domains page → auto-renew toggle on the domain row.
  2. Disable at least 30 days before expiry if you don't want the renewal charge (first attempt happens ~30 days out).

Keep the payment method current — auto-renew with an expired card is how "locked" domains still lapse.

3. WHOIS privacy

Automatic — Cloudflare redacts WHOIS information by default where the registry permits; there's no toggle.

Steps verified against Cloudflare Registrar: DNSSEC and related Cloudflare Registrar docs on 2026-07-14.

Verify your lock status

The domain report reads your live WHOIS/RDAP status — look for clientTransferProhibited. A domain-expiry monitor warns you long before a renewal can slip.

Check your domain's status →