How to lock your domain at Squarespace Domains

Three registrar settings prevent the two ways domains are most often lost — hijacked by an unauthorized transfer, or silently expired: the transfer lock, auto-renew, and WHOIS privacy. In WHOIS/RDAP, clientTransferProhibited is the transfer lock: it tells the registry to reject transfer-away requests until you remove it via your registrar.

1. Transfer lockon by default at Squarespace Domains

  1. Open the Domains dashboard (account.squarespace.com/domains) and click the domain.
  2. Switch the Domain lock toggle.

The ICANN 60-day lock after registration or transfer is separate — Squarespace can't lift that one.

ICANN policy allows registrars to block transfers within 60 days of registration or a previous transfer, and applies a 60-day lock after changing registrant contact details. Some registrars let you opt out of the post-change lock BEFORE making the change; once it applies, it can't be lifted early.

2. Auto-renewon by default at Squarespace Domains

  1. Domains dashboard → the domain → Auto-renew toggle (charged ~15 days before expiry).

Keep the payment method current — auto-renew with an expired card is how "locked" domains still lapse.

3. WHOIS privacy

Domains dashboard → the domain → Whois Privacy toggle (free and automatic for most Squarespace-managed domains).

Steps verified against Squarespace: domain locks and related Squarespace Domains docs on 2026-07-14.

Verify your lock status

The domain report reads your live WHOIS/RDAP status — look for clientTransferProhibited. A domain-expiry monitor warns you long before a renewal can slip.

Check your domain's status →