How to lock your domain at Squarespace Domains
Three registrar settings prevent the two ways domains are most often lost — hijacked by an unauthorized transfer, or silently expired: the transfer lock, auto-renew, and WHOIS privacy. In WHOIS/RDAP, clientTransferProhibited is the transfer lock: it tells the registry to reject transfer-away requests until you remove it via your registrar.
1. Transfer lockon by default at Squarespace Domains
- Open the Domains dashboard (account.squarespace.com/domains) and click the domain.
- Switch the Domain lock toggle.
⚠ The ICANN 60-day lock after registration or transfer is separate — Squarespace can't lift that one.
ICANN policy allows registrars to block transfers within 60 days of registration or a previous transfer, and applies a 60-day lock after changing registrant contact details. Some registrars let you opt out of the post-change lock BEFORE making the change; once it applies, it can't be lifted early.
2. Auto-renewon by default at Squarespace Domains
- Domains dashboard → the domain → Auto-renew toggle (charged ~15 days before expiry).
Keep the payment method current — auto-renew with an expired card is how "locked" domains still lapse.
3. WHOIS privacy
Domains dashboard → the domain → Whois Privacy toggle (free and automatic for most Squarespace-managed domains).
Steps verified against Squarespace: domain locks and related Squarespace Domains docs on 2026-07-14.
Verify your lock status
The domain report reads your live WHOIS/RDAP status — look for clientTransferProhibited. A domain-expiry monitor warns you long before a renewal can slip.
Check your domain's status →