Skip to content

Guide

Auth code or registrar push: which way to hand over a domain

There are three ways a sold domain physically moves: a push inside one registrar, an authorization code transfer between registrars, or a country-code registry token. When to use which.

Updated · Tom Reitsma, Triton IT

What are the three ways a domain moves?

PathHow it worksSpeedNotes
Registrar push (same registrar)The seller pushes the domain to the buyer’s account at the same registrarMinutesFree, and no 60-day lock. The buyer usually has to open an account there first
Authorization code transfer (gTLDs: .com, .net, .org, .io, .dev…)Seller unlocks the domain, obtains the EPP AuthInfo code, gives it to the buyer or the escrow service; the buyer’s registrar initiates the inbound transferInstant if the seller approves at the losing registrar, otherwise up to five days on auto-approvalICANN forbids a transfer within 60 days of registration or of a previous transfer. Some registrars add their own lock after a registrant change
Country-code token (.nl, .de, .eu…).nl uses a SIDN token, which the current registrar must hand out within five days; .de uses a DENIC AuthInfo code; .eu uses an EURid codeHours to daysNo ICANN 60-day rule. Each registry has its own

Which one should I use?

If the buyer already has an account at your registrar, or is willing to open one, push. It is the fastest path, it is normally free, it cannot be blocked by a transfer lock, and there is no five-day window in which nothing visibly happens. The buyer can move the domain to their preferred registrar afterwards, on their own time.

Otherwise, the authorization code. And if the domain is a .nl, .de or .eu, the registry’s own token: see the guides for .nl, .de and .eu.

What does an authorization code transfer actually involve?

  1. The seller unlocks the domain at the losing registrar.
  2. The seller obtains the EPP AuthInfo code and passes it on.
  3. The buyer’s registrar initiates the inbound transfer with that code.
  4. The seller approves it at the losing registrar. If nobody approves and nobody objects, it auto-approves after up to five days.
  5. RDAP shows the new registrar, and the handover is done.

The common failure is step 4 being nobody’s job. Agree in advance who is watching for the approval email.

What goes wrong, and what it means

Where nics.dev sits in this

Nowhere in the mechanics, deliberately. An offer on a nics.dev page becomes a thread you own; when you accept, the thread shows the checklist for that extension: unlock, code, initiate, approve, confirm. You tick the steps off as you do them at your registrar. Money, when there is any, goes through a third-party escrow service. We never hold funds.

Questions

Which is faster, a push or an auth code?

A push. If buyer and seller are at the same registrar the domain moves between accounts in minutes, it is normally free, and it does not start a 60-day transfer lock.

Should I ask the buyer to open an account at my registrar?

It is worth offering. A push is the simplest, fastest and least breakable handover, and the buyer can transfer the domain onward later at their own pace.

What if the buyer's registrar never initiates the transfer?

Nothing happens; an authorization code by itself does not move anything. Codes expire, so the usual fix is to reissue and try again. It is not a fraud signal by itself.

Does nics.dev do the transfer for me?

No. nics.dev keeps the thread, records what was agreed and shows the checklist for the domain's extension. The transfer happens at your registrar, between you and the buyer.

Free while nics.dev is in beta

Point a domain's nameservers at ns1.nics.dev and ns2.nics.dev and it gets a clean page with a make-offer form. No card, no per-domain fee, no commission on a sale.