INTEGRITY Cloudflare Docs

Troubleshoot failed domain transfers

After you start the transfer process to Cloudflare Registrar, your previous registrar has five days to release the domain after a successful transfer request. If your transfer has not been completed within that time frame, something has likely gone wrong.

Most issues with a stalled transfer can be solved by checking the following details and restarting the transfer.

Domain is still locked

If clientTransferProhibited appears in your domain WHOIS or RDAP output, the domain is still locked. Unlock it at your current registrar. If you reapplied the registrar lock after requesting the transfer, you will need to remove it again to restart the transfer process.

If you already unlocked the domain but WHOIS still shows it as locked, allow up to 5 hours for the change to propagate. Some registrars may take up to 24 hours. Some registrars have multiple lock types (domain lock, transfer lock, privacy lock) that must each be disabled separately. If your registrar dashboard shows unlocked but WHOIS disagrees, contact your current registrar directly.

DNSSEC is still active

Active DNSSEC at your current registrar will block the transfer. Disable DNSSEC and wait for the DS record TTL to expire (usually 24 hours) before retrying. Refer to Disable DNSSEC for detailed steps.

Authorization code is invalid or expired

Authorization codes are usually only valid for a limited period. If your code is rejected, request a fresh one from your current registrar. Check for trailing spaces or line breaks when copy-pasting the code.

Cannot find where to enter your authorization code

Unlike some registrars, Cloudflare does not allow you to submit an authorization code upfront. Cloudflare requires your domain to be active on its network first so that your site benefits from Cloudflare performance and security features from the moment the transfer begins. You must first add your domain to Cloudflare, update your nameservers, and wait for the zone to show Active status in the Cloudflare dashboard. Only then will the Transfer Domains page allow you to enter your code.

If your zone is still Pending, verify that you updated nameservers correctly at your current registrar and wait up to 24 hours. If you already have an authorization code, keep in mind that most codes are only valid for a limited period. If your code expires while you wait for the zone to activate, request a new one from your current registrar before proceeding.

Transfer rejected

Your transfer has been rejected by your previous registrar. There are several reasons for this to happen:

You will need to restart the transfer and approve the request or contact your current registrar to resolve this issue.

Transfer rejected due to registration limits

Domain registries enforce maximum registration periods. Because every transfer adds one year to your registration, a transfer can be rejected if the extra year would exceed the limit.

Maximum registration periods:

Common reasons for rejection:

What you can do:

Domain was recently registered or transferred

ICANN rules prohibit transfers within 60 days of registration or a previous transfer. Check the domain creation date and last transfer date in WHOIS.

Domain is in a restricted status

Domains with certain WHOIS statuses cannot be transferred:

Other common WHOIS or RDAP statuses include:

WHOIS privacy is blocking the transfer

Most domains can be transferred with WHOIS privacy enabled. However, some registrars may prohibit transfer requests if you have WHOIS privacy services enabled. If your transfer is failing, check with your current registrar to confirm WHOIS privacy is not blocking it.

Payment failed during transfer

If your payment method was declined after submitting the authorization code, the transfer may be in a partially started state. Update your payment method in your Cloudflare billing settings and check the Transfer Domains page for the current status.

Transfer is taking too long

Domain transfers typically take 3-5 business days. Some TLDs (such as .mx) can take up to 10 days. You can speed up the process by approving the transfer at your current registrar when you receive the confirmation email. If the transfer has been stuck beyond these timeframes with no identifiable issue, contact your current registrar to confirm there are no holds or restrictions on their end.

Domain not available for transfer

Your domain may not appear on the Transfer Domains page if:

Cannot update nameservers at your current registrar

Some commerce and site-building platforms (such as Shopify, Block, and Wix) do not allow you to change nameservers while the domain is registered with them. Because Cloudflare requires your nameservers to point to Cloudflare before a transfer can begin, a direct transfer from these platforms is not possible. For the recommended workaround, refer to Transfer from Shopify, Block, or Wix.

Email verification required

Cloudflare may send a verification email to your registrant contact email address when you register or transfer a domain, or when you update your registrant email. Per ICANN requirements, if the registrant email is not verified within 15 days, a hold is placed on the domain and nameservers are replaced with a parking server until verification is complete. After successful verification, nameservers are automatically restored.

Verification is triggered when your registrant contact email differs from your verified Cloudflare account email.

Some TLDs — including .mx, .nz, and .ca — may send verification through a third-party service. In these cases, the verification email will come from noreply@emailverification.info rather than Cloudflare. Check your spam folder if you do not receive it.

For these TLDs, if verification is not completed in time, the registry may temporarily replace your nameservers with ns1.emailverification.info and related hostnames until the registrant email is verified.

.uk transfer uses an IPS tag, not an auth code

.uk, .co.uk, and .org.uk domains do not use the standard auth-code transfer flow.

Instead, the losing registrar changes the domain's IPS tag to the gaining registrar. If you are transferring a .uk family domain to Cloudflare and cannot find an auth-code field, this behavior is expected.

If the transfer does not proceed, contact the current registrar and confirm that they have updated the IPS tag correctly.

Restart your transfer

  1. In the Cloudflare dashboard, go to the Manage Domains page.

    Go to Manage domains ↗
  2. Find the correct domain and select Manage.

  3. Select Cancel Transfer and Retry. After you initiate the retry, you must re-enter your auth code and confirm your WHOIS information.