Registry Lock for Domain Resellers and Hosting Providers: A Practical Guide

Registry Lock is an added security service that blocks transfers, deletion and changes to registration data, such as nameservers, at the registry level. The registry is the central operator of an extension; for .com and .net, that’s Verisign. Standard control-panel or API permissions at the registrar aren’t enough on their own to lift the lock; it takes the additional verification process defined by the registry. For resellers and hosting providers, Registry Lock is both an opportunity and a responsibility: you can give customers with business-critical domains a concrete layer of protection, and because unlock requests pass through your support team, you also become part of the verification process.

What does Registry Lock actually do?

Registries and registrars communicate over EPP (Extensible Provisioning Protocol). Statuses that start with “client” are set and removed by the registrar; those that start with “server” are set and removed by the registry, and the registrar can’t change them. Registry Lock builds on that distinction and usually applies these three statuses together:

Status Rejected operation
serverTransferProhibited Transferring the domain to another registrar
serverUpdateProhibited Updating nameserver, contact and registrant data held at the registry
serverDeleteProhibited Deleting the domain

Scope and exceptions vary by registry. Verisign says all three statuses must be present for the service to count as active on its extensions, but the same statuses can also be applied for other reasons, such as a legal dispute. So rather than telling customers “if you see these codes in WHOIS, the lock is on,” confirm the status through your provider’s records. Renewal is handled by a separate status (serverRenewProhibited) that isn’t part of the standard Registry Lock set, so locked domains can usually be renewed as normal.

The verification chain: your role as a reseller

On a reseller platform, an unlock request doesn’t happen in a single step; it passes through several stages. Being clear from the outset about what is verified at each stage prevents both security gaps and needless delays.

Stage Responsibility What to watch
End customer The authorized person requesting the change The request must come from someone on the pre-agreed list of authorized contacts.
Reseller / hosting provider Confirming the request really comes from the customer and passing it upstream An email in the ticket isn’t enough on its own; use a second channel, such as calling back a registered number.
Registrar Forwarding the request to the registry and running its own checks The procedure varies by provider and is usually handled manually.
Registry Lifting and reapplying the lock under its own procedure Verisign runs this step through a separate verification outside the EPP connection.

The human element is a real risk in this process. Attackers may try to get around verification by pressuring a support team with an urgent change request.

Social engineering safeguards for your support team

  • Accept unlock requests only from people on the written list of authorized contacts.
  • Confirm each request through a second channel using contact details already on file, never a new number or address supplied in the request.
  • Don’t let “urgent” or “the CEO needs this now” requests skip the standard process.
  • Log every request with the name of the person who verified it and the channel used.

What Registry Lock doesn’t protect

Setting the right expectations from the start helps avoid disputes later. Registry Lock protects data held at the registry; the following are outside its scope:

  • DNS records: A, MX and TXT records live in the zone at the DNS provider. Even with the nameservers locked, anyone with access to the DNS panel can redirect web and email traffic.
  • A compromised reseller or hosting panel: Anyone who gets into your panel can change DNS zones, email accounts or hosting files.
  • Moves between accounts: Moving a domain from one reseller account to another at the same registrar isn’t a change of registrar at the registry, so serverTransferProhibited may not cover it. Check with your provider how such moves are protected.
  • Expired domains: A lock doesn’t guarantee that an unrenewed domain will keep working.
  • DDoS and application attacks: These have to be handled at the infrastructure and application layers.

Which customers should you offer it to?

How much Registry Lock is worth depends on what a domain outage would cost the customer.

Customer profile Recommendation Why
E-commerce, payments and finance Strong candidate Even a few hours of misdirection puts sales and customer data at risk.
SaaS and corporate email Strong candidate Single sign-on (SSO) and email verification depend on the domain.
Public sector, healthcare and education Strong candidate Expectations for trust and service continuity are high.
Corporate brochure sites Case by case Depends on how critical the domain is and how often it changes.
Test, campaign and short-lived domains Weigh risk and change frequency Campaign domains can be critical too, but frequent nameserver changes make the unlock process harder.

Which extensions support Registry Lock?

The registry provides the service and the registrar provides access to it, so support varies by extension. Examples from official registry documentation:

Registry Extensions Source
Verisign .com, .net, .cc, .name Verisign Registry Lock Service page
Switch .ch, .li Switch security page

This table isn’t exhaustive; an extension that’s missing from it may still offer the service. For the extensions in your customers’ portfolios, check with the Domain Name API team whether Registry Lock can be provided.

How to handle requests day to day

Changing a locked domain means lifting the lock temporarily, making the change and reapplying the lock. Here’s a recommended workflow on the reseller side:

  1. Set up the authorized list at the start: When the service is activated, have the customer confirm in writing who may request an unlock, along with their contact details.
  2. Log the request: Have the exact change spelled out, such as the new nameserver addresses.
  3. Verify through a second channel: Use a method that’s independent of the request channel, such as calling back a registered number.
  4. Pass it upstream: Forward the verified request following your provider’s procedure.
  5. Confirm the relock: Once the work is done, get confirmation from your provider that the lock is active again, and let the customer know.

The added security doesn’t come from the process taking longer. It comes from an authorization check that runs separately from routine panel and API actions. Because that check usually involves a person, timing varies by registry and provider. So don’t promise “one-click lock and unlock” in your own panel, and ask customers to plan work such as hosting migrations or nameserver changes ahead of time.

How to explain it to your customers

A short, honest explanation makes the sale easier and avoids disappointment later. Three messages are enough:

  • Registry Lock stops transfers, deletion and nameserver changes on your domain, even if your panel password is stolen.
  • It doesn’t protect your DNS records, email or hosting accounts; those also need 2FA and proper access controls.
  • Changes to a locked domain need extra verification, so let us know about planned work in advance.

On pricing, registry and registrar fees vary by extension, so get the current cost from your provider before you quote a customer.

How Registry Lock fits with other security layers

Layer What it protects Limit
Registry Lock Transfers, deletion and updates at the registry DNS zone, hosting and email accounts
Transfer lock (registrar) Unauthorized transfer to another registrar Anyone with panel access can remove it
DNSSEC Integrity of DNS responses Doesn’t stop changes made from an authorized account
2FA Panel and account logins Session theft and mistakes by authorized users

Registry Lock delivers its full value when all of these layers are switched on, both in your own panel and in your customers’ accounts. None of them is enough on its own.

Explore Registry Lock options for your customer portfolio

Share the extensions you’d like to evaluate with the Domain Name API team to learn about availability, reseller pricing and terms.

Ask About Registry Lock

Frequently asked questions

Can I offer Registry Lock to my customers through Domain Name API?

Confirm availability and terms for each extension with the Domain Name API team. Eligibility depends on the registry and the extension.

Can Registry Lock be switched on and off through the API or the WHMCS module?

Standard API or module permissions aren’t enough on their own to lift the lock; the registry’s additional verification is still required. Ask the Domain Name API team how activation and unlocking work on its platform.

Who verifies unlock requests?

Verification happens in several stages: the reseller confirms the request comes from the customer, and the registrar and registry verify authority under their own procedures.

Does Registry Lock lock DNS records?

No. A, MX and TXT records are held at the DNS provider and fall outside the scope of Registry Lock.

Can a locked domain be renewed?

Registry Lock’s standard statuses don’t block renewal; a separate EPP status handles that. Check extension-specific rules in advance.

Can I move a locked domain to another reseller account?

Moves between accounts at the same registrar aren’t transfers at the registry, so Registry Lock may not always cover them. Check with your provider how such moves are handled and protected.

What unlock time can I promise customers?

Don’t promise a fixed time. It depends on the registry, the verification method and the provider’s procedure; ask customers to give you advance notice of planned work.

Sources