EPP status codes — a buyer's guide
Every code that appears in WHOIS or RDAP, organised by what it means for someone watching a domain. The lifecycle codes (pendingDelete, redemptionPeriod) are the ones that actually predict drops. Locks and restrictions usually do not.
Lifecycle codes — actual drop signals
These statuses appear during the natural expiry-to-drop cycle. If you are watching a domain hoping to register it, transitions through these codes are the events that matter.
- pendingDeletehigh signalpendingDelete is the final EPP status before a generic top-level domain (.com, .net, .io) drops back to the public registry. It lasts exactly 5 calendar days for gTLDs. The registrant can no longer redeem the name. At the end of this window the registry deletes the registration and the domain becomes available for anyone to register.Duration: Exactly 5 days (gTLDs)
- redemptionPeriodmedium signalredemptionPeriod is the 30-day phase that follows the auto-renew grace period for most gTLDs. The original registrant can still recover the domain by paying a redemption fee — typically $80-$300 above the normal renewal price. After 30 days the domain transitions to pendingDelete and the recovery window closes.Duration: 30 days (most gTLDs)
- autoRenewPeriodlow signalautoRenewPeriod is the EPP status that follows expiry. The registry has automatically renewed the domain on the registrant's behalf, and the registrar has a 45-day window to credit the renewal back if the registrant does not pay. During this phase the website usually still works.Duration: 0-45 days (registrar discretion, ICANN max 45)
- pendingRestorelow signalpendingRestore is a transitional EPP status indicating that a domain in redemptionPeriod is being restored. The registrar has accepted the restoration request and the registrant has 7 days to provide a restoration report. After that the domain returns to "ok" status. If the report is not filed, the domain returns to redemptionPeriod.Duration: Up to 7 days
Suspension codes — domain has gone dark
The hold codes remove a domain from DNS without deleting it. They often resolve back to active status rather than progressing to deletion.
- clientHoldlow signalclientHold is an EPP status the registrar applies to remove a domain from DNS without deleting it. The domain is still owned by the registrant but does not resolve — sites and email stop working. Common causes are payment disputes, abuse complaints, registrant contact verification failures, or registrar-internal compliance actions.Duration: Indefinite (until registrar removes it)
- serverHoldlow signalserverHold is the registry-applied equivalent of clientHold. The domain is removed from DNS and does not resolve. Unlike clientHold, only the registry can remove this status. It is typically triggered by court order, government request, or registry policy violation. Resolution is usually slow or impossible.Duration: Indefinite (registry-controlled)
Lock codes — security and policy
Lock codes prevent transfers, updates, or deletions. Most active domains have at least clientTransferProhibited set as a normal security posture. They tell you nothing about availability.
- clientTransferProhibitedlow signalclientTransferProhibited is a registrar-applied EPP status that blocks the domain from being transferred to another registrar. It is the standard "transfer lock" most registrars enable by default for security. The registrant can disable it from their registrar dashboard at any time.Duration: Indefinite (registrant-controlled via registrar)
- serverTransferProhibitedlow signalserverTransferProhibited is a registry-applied EPP status that blocks transfer at the registry level. Unlike clientTransferProhibited, the registrar cannot remove it. Common triggers: ICANN-mandated 60-day post-transfer lock, court order, or registry-level dispute resolution.Duration: Variable — 60 days for new registrations, indefinite for legal holds
- clientUpdateProhibitedlow signalclientUpdateProhibited is a registrar-applied EPP status that prevents updates to nameservers, contact information, and other domain attributes. The registrant can disable it from the registrar dashboard. It is typically combined with clientTransferProhibited and clientDeleteProhibited as part of a "registrar lock" feature.Duration: Indefinite (registrant-controlled)
- serverUpdateProhibitedmedium signalserverUpdateProhibited is a registry-applied EPP status that blocks updates to the domain. The registrar cannot remove it. Typical causes: court order, UDRP/URS dispute resolution, or registry compliance action. Often paired with other server-prohibited statuses.Duration: Indefinite (registry-controlled)
- clientDeleteProhibitedlow signalclientDeleteProhibited is a registrar-applied EPP status that blocks the domain from being deleted. It is part of the standard "registrar lock" feature most registrars enable by default. The registrant can disable it from the registrar dashboard before initiating any deletion.Duration: Indefinite (registrant-controlled)
- serverDeleteProhibitedlow signalserverDeleteProhibited is a registry-applied EPP status that prevents the domain from being deleted, even by the registrant or registrar. Typical use cases include registry-reserved names, court-frozen domains, and names under active UDRP/URS dispute resolution.Duration: Indefinite (registry-controlled)
Normal operating state
Watch a domain you want to buy — snooze.domains tracks the lifecycle and emails you when it changes status. Free, up to 100 domains. Start watching — free