EPP Status Codes Explained: Every WHOIS Status in Plain English
Run a WHOIS or RDAP lookup and you get a line of camelCase jargon: clientTransferProhibited, redemptionPeriod, serverHold. These are EPP status codes, defined by the Extensible Provisioning Protocol that registrars and registries use to talk to each other, and catalogued by ICANN. They are also the single most useful diagnostic in domaining, because the status line tells you a domain's exact legal position: renewable, restorable, doomed, or simply locked. Here is every code you will actually meet, in plain English.
How do you read a status code?
Four rules decode almost everything. A client prefix means your registrar applied the flag and your registrar can remove it. A server prefix means the registry applied it, and only the registry, usually via the registrar, can lift it. Anything ending in Prohibited blocks one specific action (transfer, update, delete, renew). Anything ending in Period is a timed lifecycle window rather than a lock. The lone exception is ok, which simply means no restrictions and no pending operations. Domains routinely carry several codes at once; a healthy, locked domain typically shows clientTransferProhibited and nothing alarming.
The quick-reference table
| Code | Set by | Plain English | What you can do |
|---|---|---|---|
| ok | Registry | No locks, no pending operations, nothing unusual | Nothing needed; many registrars add a transfer lock anyway |
| autoRenewPeriod | Registry | Expiry passed; the registry auto-renewed and is waiting to see if the registrar keeps or deletes the name | Owners can usually still renew at the normal price |
| redemptionPeriod | Registry | The registrar deleted the domain; a 30-day restore window is running | Original registrant can restore via the old registrar, typically $80-200 plus renewal |
| pendingDelete | Registry | Final 5 days before the drop; irreversible | Nothing can save it; buyers place backorders |
| clientHold | Registrar | The registrar pulled the domain out of DNS; the site stops resolving | Fix the cause with the registrar: expiry, unverified contact details, billing or abuse |
| serverHold | Registry | The registry itself removed the name from the zone | Escalate through your registrar; usually policy, legal or ccTLD-specific issues |
| clientTransferProhibited | Registrar | Transfers away are blocked; the default protective lock | Unlock it in your control panel before an intended transfer |
| inactive | Registry | No nameservers are attached, so the domain cannot resolve | Add nameservers; common on freshly caught or parked-nowhere names |
The lifecycle window codes
addPeriod
The first few days after a brand-new registration. It mainly exists so registrars can void mistaken registrations with the registry. Nothing for owners to do.
renewPeriod and transferPeriod
Short bookkeeping windows after an explicit renewal or an inter-registrar transfer. Seeing them means the operation just happened; they clear on their own.
autoRenewPeriod
The registry has auto-renewed an expired name and is waiting for the registrar's decision to keep or delete it. This is the status behind the registrar grace period: the owner can still renew at the normal price, even while the name sits in an expiry auction.
redemptionPeriod
The registrar has deleted the domain and the 30-day redemption window is running. Only the original registrant can restore it, through the old registrar, for a fee that typically lands between $80 and $200. Third parties can only watch.
pendingRestore
A restore has been requested and the registry is waiting for the registrar's confirming report. The domain is on its way back to active; no action needed beyond patience.
pendingDelete
The end of the road: exactly 5 days that nothing can stop. When they end, the name drops and anyone can register it. For hunters this is the most important code in the whole list, because it converts a WHOIS record into a countdown.
The hold codes: why a site goes dark
clientHold is the registrar switching your domain off: it stays registered but leaves the DNS zone. Common triggers are expiry, failed WHOIS contact verification, unpaid invoices, or abuse complaints; the fix is always with the registrar. serverHold is the registry doing the same thing one level up, which usually signals something heavier: policy enforcement, legal action, or a ccTLD process. And inactive just means no nameservers are configured; harmless in itself, but a domain cannot resolve until they exist.
The prohibited codes: locks on specific actions
clientTransferProhibited is the one every domain owner should want to see: it blocks transfers away and most registrars apply it by default. Registrars also use it to enforce the 60-day lock that follows a new registration, a transfer, or a registrant change under ICANN transfer policy. Its siblings clientUpdateProhibited, clientDeleteProhibited and the rare clientRenewProhibited block updates, deletion and renewal respectively; the first two are often part of registrar security packages.
The server versions (serverTransferProhibited, serverUpdateProhibited, serverDeleteProhibited) are registry-level locks. They appear during disputes, court orders and UDRP proceedings, but also as premium registry-lock services that high-value domains buy deliberately. Finally, the pending family (pendingCreate, pendingRenew, pendingTransfer, pendingUpdate) means the named operation is mid-flight at the registry; pendingTransfer, for instance, shows while an inter-registrar transfer awaits confirmation.
How do domain hunters read status lines?
Like a weather forecast. pendingDelete means a drop is scheduled and a backorder decision is due. redemptionPeriod means wait, the owner still holds a veto. autoRenewPeriod plus a listing on an auction platform means the expiry-auction route, not the drop, will decide the name's fate. A stack of server-prohibited codes on an aged name hints at legal history worth investigating before you spend anything. Aggregators bake this logic in: DomCop, a paid research tool with annual plans from roughly $68 per month (2-day money-back guarantee, no free trial), tracks names through these statuses and attaches drop dates and quality metrics, while ExpiredDomains.net offers free status-based filtering across 676 TLDs once you register.
Frequently asked questions
What does ok mean in WHOIS?
No restrictions, no pending operations, no lifecycle windows. Slightly counterintuitively, a domain showing only ok is less protected than one with clientTransferProhibited, which is why registrars add the lock by default.
Why does my domain show clientTransferProhibited?
It is the standard protective lock against unauthorized transfers, and it may also reflect the 60-day lock after a registration, transfer or registrant change. If you are deliberately transferring, unlock the domain in your registrar dashboard first.
Which status means a domain is about to become available?
pendingDelete. It lasts exactly 5 days for gTLDs, after which the name drops and can be registered by anyone. redemptionPeriod comes before it and can still be reversed by the original owner.
Can a domain have several status codes at once?
Yes, and most do. A typical protected domain shows clientTransferProhibited alongside other client locks, and registry operations can add server codes on top. Read the full stack, not just the first line.
What is the difference between clientHold and serverHold?
Who pulled the plug. clientHold is your registrar removing the domain from DNS, fixable by resolving billing, verification or abuse issues with them. serverHold is the registry acting directly, which usually takes longer and involves policy or legal processes.