Domain Names and Website Transfers: Registrar Locks, Escrow, and Disputes
A domain is a registration, not a deed. Understanding auth codes, transfer locks, and the gap between a registrar transfer and a change of registrant prevents most stalled website sales.
Key points
- A domain is a contractual registration held through a registrar, governed for generic top-level domains by ICANN policy rather than by ordinary property law.
- Moving a domain between registrars needs the name unlocked and an authorization code from the losing registrar, and locks commonly apply for sixty days.
- A registrar transfer and a change of registrant are separate operations, and a website sale usually needs both plus hosting, code, and content.
- Disputes over a name run either through ICANN's UDRP, which can transfer or cancel, or through a federal court action requiring trademark rights.
Most domain transfers fail for one of three reasons: the name is locked, the authorization code was never issued, or the buyer paid for a "website" and received only the domain. A domain is not property in the ordinary sense. It is a contractual registration held through a registrar, and for generic top-level domains such as .com it moves under policy set by ICANN. Completing a transfer means unlocking the name, getting the code, and running a separate change of registrant.
The point where a transfer usually stalls
A typical failure looks like this hypothetical. A buyer wires funds for a small e-commerce site, the seller says the domain will follow "in a day or two," and the buyer then learns the name moved between registrars five weeks earlier and sits inside a sixty-day lock.
Nothing there is unusual. Transfer locks are a normal anti-hijacking feature, not a defect, and no support desk can waive an ICANN policy lock. The problem is sequencing.
Watch out: Never release payment before the name has landed in the buyer's registrar account and the buyer has logged in to confirm it. A promise to transfer later, a dashboard screenshot, or a forwarded email proves nothing.
How a registrar transfer actually runs
A transfer between registrars is a defined technical sequence. The registrar the name is leaving is the losing registrar; the one receiving it is the gaining registrar.
- Confirm eligibility. Check for a transfer lock — commonly sixty days after an initial registration, after a prior registrar transfer, and after certain registrant contact changes.
- Unlock the domain. Registrars apply a registrar lock status by default; the registrant turns it off in the account control panel.
- Verify contact details. The administrative email on file receives the confirmations. If it is a dead mailbox, fix that first.
- Request the authorization code. The losing registrar supplies this auth or EPP code. It is a password for the name and should be treated as one.
- Start the transfer at the gaining registrar. The buyer enters the domain and code and pays the transfer fee, which adds a renewal year in most generic top-level domains.
- Respond to confirmation messages. Approving at both ends completes the move faster; ignoring them leaves the request to time out or auto-approve later.
- Re-lock and verify. Once the name appears in the new account, turn the registrar lock back on and confirm the nameservers.
Country-code registries — the two-letter extensions run by national authorities — set their own rules. They are not bound by ICANN's transfer policy, and some impose local presence requirements.
Changing the registrant is a different operation
People routinely conflate two things. A registrar transfer moves the name from one company's platform to another's. A change of registrant changes who is recorded as the holder. A sale usually needs both, processed separately.
The change of registrant is the one that matters legally, because it records who holds the registration agreement. Under ICANN policy it can itself trigger a sixty-day transfer lock, though the parties can often decline that lock at the time of the change. Details vary by registrar and top-level domain, so confirm the current procedure with your registrar and against ICANN's policy pages rather than assuming a fixed day count for every scenario.
Note: A domain is only one asset in a website sale. Hosting, source code, the database, content, email, ad accounts, trademark rights, and social handles each transfer by their own mechanism. Copyright in the text and code is federal and moves by written assignment, as the U.S. Copyright Office explains.
Escrow and what the purchase agreement has to say
Escrow solves the sequencing problem: a neutral service holds the buyer's funds and pays out only once the transfer is confirmed. It works only if the agreement describes the steps precisely, because "seller shall transfer the domain promptly" gives an agent nothing to act on. The same discipline governs any staged handover of a digital asset, which is why the mechanics resemble source-code escrow between software vendors and customers.
- An exact list of every asset included, and of what is excluded.
- Who requests the auth code, who holds it, and how it reaches the buyer.
- The order of operations and a deadline for each step, including any lock period.
- What happens if the transfer fails: refund, extension, or termination.
- A written assignment of copyright in the code, text, images, and design.
- Assignment of any trademark rights, with the goodwill of the business.
- Seller representations that the name faces no pending dispute or court order.
- Transfer of hosting, DNS control, email, and third-party service accounts.
Operating the site under a different business name triggers state filing duties separate from anything the registrar does, covered in our guide to registering a fictitious business name. If the site's value comes from collected data, check how it was gathered — see our piece on automated data collection, access, and copyright.
When someone else holds the name you need
Two routes exist for taking a domain from a registrant who should not have it, and both require trademark rights. Without a mark, neither is available.
The UDRP — the Uniform Domain-Name Dispute-Resolution Policy — is an ICANN administrative process built into the registration agreement. A complainant must show the domain is identical or confusingly similar to a mark in which it has rights, that the registrant has no legitimate interest, and that the name was registered and used in bad faith. The remedy is transfer or cancellation; it cannot award money.
The Anticybersquatting Consumer Protection Act is a federal statute supporting a lawsuit against someone who registers or uses a domain in bad faith with intent to profit from a mark. It also permits an in rem action against the domain itself when the registrant cannot be located, and a court can award damages as well as order transfer.
| Feature | UDRP | ACPA court action |
|---|---|---|
| Nature | Contractual policy administered by approved providers | Federal statute litigated in federal court |
| Requirement | Trademark or service mark rights | Trademark or service mark rights |
| Remedy available | Transfer or cancellation of the domain | Transfer, injunction, and monetary damages |
| Target | The registrant | The registrant, or the domain itself in rem |
| Process | Documents only, no live hearing; a loser may still sue | Full litigation with discovery and appeal rights |
Which layer of law is doing the work
Trademark registration and the ACPA are federal. Marks are registered through the USPTO, and federal registration strengthens both routes. Some states keep their own trademark registers and unfair-competition statutes, which operate alongside federal law rather than replacing it.
The sale contract, the escrow arrangement, and any breach claim are state contract law. The UDRP is neither: it is a private policy the registrant accepted at registration and enforced through the registrar, which is why the registrar's click-through terms matter — a question taken up in our explainer on when a clickwrap agreement actually binds a user.
Advertising claims made on the site after purchase add a federal layer under the FTC's advertising rules, alongside the general obligations in the FTC's business guidance. As of mid-2026, ICANN's transfer framework remains the controlling policy for generic top-level domains and is revised periodically, so check the current text before relying on a specific waiting period.
Common questions
My registrar says the domain is locked and I never locked it — what happened?
Two different locks look identical from the account panel. A registrar lock is applied by default and the registrant can switch it off. A policy lock follows a registration, a prior transfer, or certain contact changes, and support staff cannot lift it on request. Check which one you are looking at before assuming the registrar is stalling — and note that the registrant-change lock can often be declined at the time of the change.
Who should hold the auth code between signing and closing?
Whoever the agreement says, and the agreement should say. A common approach is for the seller to deposit the code with the escrow service rather than send it to the buyer, so code and funds release against each other. If the code goes to the buyer early, the seller loses leverage; if it never issues, the buyer has paid for nothing. Name the holder and the deadline in writing.
Does buying the domain give me rights in the brand name too?
No. A registration is a technical right to use a string in the domain name system. Trademark rights come from use of a mark in commerce and, optionally, from federal registration. A seller who never used the name as a brand has no mark to assign, and a buyer who starts using it may still meet an existing owner elsewhere. Search for conflicts before committing.
Can I get a domain back after it expired and someone else registered it?
Usually not through the registrar. Expired names pass through renewal grace and redemption stages before release, and once a third party registers the name the original holder has no automatic claim. Recovery then depends on trademark rights plus a UDRP complaint or court action, both requiring bad faith. Preventing the lapse is far cheaper than any dispute.
Sequencing a domain or website purchase
- Verify who holds the name. Confirm the registrant of record and the registrar, and ask when the name last moved.
- Check for locks and expiry dates. A recent transfer or registrant change can make your intended closing date impossible.
- Search for conflicting trademarks. Do this before signing, not after launch.
- List every asset in the agreement. Domain, code, content, hosting, accounts, marks, and data, with a written copyright assignment.
- Open escrow and set the sequence. Define who holds the auth code, what confirms completion, and what happens on failure.
- Confirm control before release. Log in, change the password, enable two-factor authentication, re-lock the name, then authorize payment.
Practical step: After closing, set auto-renew on a card the new owner controls and put the expiry date in a shared calendar. More names are lost to a lapsed payment method than to any dispute.
Sources
This is general information, not legal advice. Beacon Legal News is a publication, not a law firm, and reading it creates no attorney–client relationship. Law differs by state and changes; check the linked primary sources or speak with a licensed attorney in your jurisdiction before acting.
Beacon Legal Newsroom
Beacon is an independent legal-information publication. Articles are researched against primary sources and revised when the law moves. How we source · Corrections
Related articles
More in Technology, Privacy & Media →-
Technology, Privacy & Media
Terms of Service and Clickwrap: When an Online Agreement Binds
Courts deciding whether online terms bind rarely argue about the clauses. They argue about the screen: what it showed, where the link sat, and what the user had to click.
8 min readAnalysis -
Technology, Privacy & Media
Software Escrow and Source-Code Access in Vendor Agreements
A source-code escrow is only as good as its trigger clause and its deposit. Here is what actually arrives on release day, and what a customer usually discovers is missing.
8 min readExplainer -
Technology, Privacy & Media
Recording Calls and Meetings: One-Party and All-Party Consent
Federal law lets a participant record a call. A number of states do not. When the two people are in different states, courts have not agreed on which rule wins.
8 min readGuide -
Technology, Privacy & Media
Web Scraping and Automated Data Collection: Access, Contract, and Copyright
Whether an automated collector is lawful is really four separate questions. Federal access law has narrowed, which pushed the fight toward contract, server burden, and copyright.
8 min readAnalysis -
Technology, Privacy & Media
Deepfakes and Synthetic Media: Emerging State Rules on Likeness and Elections
Synthetic media law is not one rule but three clusters, each with its own enforcer and its own remedy. Sorting which cluster a problem belongs to is the first practical step.
8 min readAnalysis -
Technology, Privacy & Media
Email Marketing and the CAN-SPAM Rules Senders Overlook
The federal email statute is misunderstood in both directions: it demands less consent than marketers think, and it reaches further up the chain than they expect.
7 min readExplainer