...

ICANN’s Domain Transfer Overhaul Is Coming

If you’ve ever moved a domain between registrars, you know the drill: dig up an auth code, survive a five-to-seven-day lock period, confirm a flurry of emails, and quietly hope nothing goes wrong. ICANN is rethinking this entire experience — and the changes are bigger than most domain owners realise.

How the Current System Works

Today’s transfer process is built on the EPP (Extensible Provisioning Protocol) auth code — a static password your losing registrar generates and hands to you. You paste it into the gaining registrar’s form, both sides exchange emails asking you to confirm, and a mandatory 60-day lock prevents transfers right after a domain is newly registered or just transferred.

In practice, this means auth codes that sit in your inbox for weeks (sometimes expiring quietly), confirmation emails that land in spam, and contact details that don’t match your registrar’s records — each one a potential transfer-stopper. The system was designed for a smaller, simpler internet. It’s showing its age.

Enter the TAC: What’s Actually Changing

ICANN’s proposed overhaul replaces static auth codes with Transfer Authorization Codes (TACs) — short-lived tokens generated on demand and valid for only a limited window (think hours, not weeks). The moment a TAC is used or expires, it’s gone. No recycled codes, no lingering attack surfaces.

Key Improvements at a Glance

  • Time-limited TACs replace static, reusable auth codes
  • Shortened lock periods for recently transferred or updated domains
  • Streamlined confirmation — fewer redundant approval emails
  • Standardised timelines across all ICANN-accredited registrars

The goal is to make legitimate transfers faster while making unauthorised ones harder — a balance the old system increasingly struggled to strike.

What a Future Transfer Will Look Like

Here’s what you can expect when the new policy goes live:

STEP 1

Request a TAC from your current registrar.Log in, navigate to domain management, and hit “Initiate Transfer.” Your registrar generates a TAC valid for a defined window — typically 24–72 hours.

STEP 2

Submit the TAC to your new registrar.Paste the TAC into the gaining registrar’s transfer form. The clock is ticking — don’t sit on it.

STEP 3

Confirm via your verified registrant email.One clear approval email — no duplicate confirmations from both registrars under the new streamlined model.

DONE

Transfer completes — faster than before.With shortened lock periods and reduced back-and-forth, expect a noticeably quicker completion than the current 5–7 day norm.

Avoiding Delays During the Transition

The switchover period — when some registrars have implemented the new system and others haven’t — is where friction lives. To sail through it:

Update your registrant contact details now. Outdated email addresses are the single biggest cause of failed transfers, old system or new. If a TAC confirmation hits a dead inbox, you’ll miss the window entirely.

Don’t request a TAC before you’re ready to act. Unlike a static auth code you can save for later, a TAC expires. Have your new registrar account ready and your payment sorted before you generate one.

Check your domain’s lock status. Transfer locks (Registrar Lock / clientTransferProhibited) still need to be lifted manually. During transition, confirm your registrar has implemented the new policy before assuming shorter lock windows apply to you.

Security Matters More Than Ever

Faster, simpler transfers are a win for legitimate owners — and a potential opportunity for bad actors. TACs reduce the window for misuse, but only if your account security is solid.

Security Checklist

  • Enable 2FA on your registrar account — a compromised password alone shouldn’t be enough to trigger a transfer.
  • Keep your registrant email current and secured with its own strong password and 2FA.
  • Watch for phishing. Scammers mimic TAC request emails. Legitimate transfer emails never ask for your password or payment details.
  • Use registrar lock on high-value domains when transfers aren’t in progress.

 

Scroll to Top