What EPP lock and auth codes are for
EPP lock (transfer lock) reduces unauthorized transfers away from NextShopper. When lock is on, another registrar should not be able to pull the domain without you unlocking first. The EPP / auth code is the secret transfer password you give only to a gaining registrar when you intentionally transfer out.
This guide covers locking, unlocking, revealing the auth code, and basic outbound transfer controls on Lock & transfer.
Who this guide is for
- Domain owners hardening security after registration or inbound transfer
- Customers preparing to transfer away to another registrar
- Anyone who cannot reveal the auth code because the domain is still locked
Before you start
- Sign in and open the domain under Domains.
- For outbound transfers: unlock, reveal the code, and start the process at the gaining registrar.
- Never share the auth code in public tickets, chat groups, or email to strangers.
- Expect a 60-day transfer lock after some register/transfer events—the domain page shows 60-day transfer lock until [date]. when applicable.
Step-by-step: lock or unlock
- Open the domain → Lock & transfer (action label: Lock & transfer / help text: EPP lock, privacy, auth code).
- Find EPP lock.
- Select Lock or Unlock.
- Confirm status shows locked or unlocked and the flash message (EPP lock enabled. / EPP lock disabled.).
Keep lock On for everyday use.
Step-by-step: reveal the auth code
- Unlock the domain first (required).
- On Lock & transfer, find EPP / auth code (help: unlock first; code is not written to logs).
- Select Reveal auth code.
- Copy the code to a secure place and provide it only to the gaining registrar.
- After the transfer completes elsewhere—or if you cancel—consider locking again.
Outbound transfer controls
If you are leaving NextShopper:
- Unlock and reveal the auth code.
- Use Start outbound transfer if shown (Transfer away section), confirming the prompt that unlock is required.
- Give the auth code to the gaining registrar.
- To stay, use Cancel outbound transfer when available.
What happens next / how to verify success
- Lock state matches your intent on the domain page and list filters (Locked).
- Auth code reveals only while unlocked.
- Unauthorized transfer attempts should fail while locked (registry rules apply).
Common problems
| Problem | What to try |
|---|---|
| Reveal does nothing | Unlock first; refresh; check 60-day lock messages |
| Transfer rejected at gainer | Regenerate code; confirm unlock at registry |
| Accidental unlock | Select Lock immediately |
| Lost code mid-transfer | Unlock and reveal again; old codes may be invalidated |
| Outbound stuck | Use cancel if present; contact both registrars |
Frequently asked questions
Is the auth code the same as my account password?
No. Never use your NextShopper login password as a transfer code.
Does lock affect DNS edits?
No. Lock targets transfers, not ordinary DNS or contact edits.
Should I unlock for FOA?
FOA is email confirmation, not lock-related.
Can staff read my auth code from logs?
The UI states the code is not written to logs—still treat it as secret.
Related guides
- How to transfer a domain into NextShopper
- How to turn WHOIS privacy on or off
- How to renew a domain and manage auto-renew
- How to update domain registrant contacts
Still need help?
For transfer failures, open a support ticket or Contact. Describe the stage (unlock, reveal, gainer rejection)—do not paste the auth code unless support explicitly asks through a secure channel.