Back to blog
Acquisition8 min read2026-09-14

Domain Registration Due Diligence: What Buyers Must Verify

The domain doesn't transfer automatically with the business. A practical checklist for verifying WHOIS records, lock status, and transfer risk before you close.

Editorial illustration of an octopus mascot unlocking a padlock over a stylized domain globe with a golden transfer key, symbolizing domain registration due diligence

Why Domain Registration Status Is a Due Diligence Blind Spot

Buyer checklists cover revenue, traffic, and churn in detail, but the domain itself often gets a single line: "domain: yes, included." That's a mistake specific to this asset class. A domain registration record is a legal and technical object with its own ownership chain, lock states, and transfer rules β€” and unlike revenue, which you verify with bank statements, domain control has to be verified inside a registrar account you don't have access to yet.

This matters because the domain is the one asset that, if mishandled at closing, can take the entire business offline. Get the transfer wrong and you inherit a site with no way to update DNS, renew the registration, or prove you own it. This guide walks through what to check before you wire funds, in plain terms, whether you're buying a content site, a SaaS product, or an ecommerce store.

What "Buying a Business" Actually Means for Its Domain

When a deal closes, the domain doesn't automatically follow the business β€” it has to be explicitly transferred between registrar accounts, or the seller's registrar account itself has to change hands. Both paths are common, and both carry different risks:

  • Full domain transfer to your own registrar account gives you clean, independent control, but takes time and requires cooperation from the seller during a defined transfer window.
  • Registrar account handover (the seller gives you login credentials and updates billing) is faster but means you're inheriting an account that may hold other domains, may be tied to the seller's personal payment method, and may have two-factor authentication set up in ways only the seller can reset.

Neither approach is automatically wrong, but the contract and the closing checklist need to say explicitly which one is happening, because "the domain is included" is not an instruction a registrar can act on.

The WHOIS and Ownership Check

Before you negotiate anything, pull the current WHOIS record (via your registrar's lookup tool or a public WHOIS service) and confirm three things:

  • The registrant name or organization matches the seller or the seller's business entity, not an unrelated third party, a former partner, or an agency that built the site years ago and never transferred it
  • The creation date is consistent with the business's stated history β€” a "10-year-old brand" running on a domain registered eight months ago is worth asking about
  • The registrant contact details (even if privacy-shielded) resolve to something the seller can act through, since you'll need that access during the transfer

WHOIS privacy services hide the underlying details from the public but not from the registrar, so a privacy shield isn't a problem by itself β€” an unresponsive or unreachable seller behind one is.

Registrar Lock Status: OK vs. clientTransferProhibited

Every domain has a status code visible in its WHOIS record. The one that matters most before a transfer is whether the domain is locked. A domain sitting in `clientTransferProhibited` is protected against unauthorized transfers β€” which is good security hygiene, but it also means the seller must unlock it before your transfer request will succeed. A status of `OK` (or `active`) means it's unlocked and transferable.

Ask the seller to unlock the domain and confirm the status change before you request the authorization code β€” trying to transfer a locked domain is a common source of delays that get blamed on "registrar problems" when the real issue is a checkbox nobody unchecked.

The Auth Code and the 60-Day ICANN Rule

To move a domain to a new registrar, the seller generates an authorization code (also called an EPP code or transfer secret) from their current registrar's control panel. You use that code, plus approval through the administrative email on file, to complete the transfer at the new registrar.

Two rules trip up more deals than anything else here:

  • A domain that was registered, transferred, or had its registrant changed within the last 60 days is generally not eligible for another transfer under ICANN policy. If the seller recently "cleaned up" the registration ahead of the sale, this can quietly delay closing by weeks.
  • The transfer approval email goes to whatever address is listed as the administrative contact in WHOIS β€” if that's an old employee's inbox or an agency the seller no longer works with, the transfer stalls until someone can update it, which itself may require registrar-side identity verification.

Confirm both of these during due diligence, not during the week you planned to close.

Common Red Flags in Domain Registration Records

A few patterns are worth flagging before you get further into a deal:

  • A domain registered or re-registered very recently relative to the business's claimed age or traffic history
  • A registrant name that doesn't match the business, the seller, or any entity mentioned in the data room
  • Multiple related domains (misspellings, alternate TLDs, old brand names) that aren't included in the sale but redirect meaningful traffic to the main site β€” find out who controls those before you close, because losing them post-sale can quietly cut off backlink equity and direct traffic
  • A domain still registered to a web agency or freelance developer who built the original site, with no documented handoff of registrar access

None of these automatically kill a deal, but each one is a reason to get registrar-level proof, not a verbal assurance, before funds move.

Coordinating the Transfer With Escrow

The safest sequencing pairs the domain transfer with your escrow or payment milestone, rather than doing it before or well after funds change hands:

  • 1. Confirm the domain is unlocked and the auth code is available, but don't execute the transfer yet
  • 2. Fund the deal into escrow
  • 3. Initiate the domain transfer and confirm the seller has approved it via the administrative email
  • 4. Release funds from escrow once the domain shows the new registrant information and you have working access to the registrar account

Doing the transfer too early, before funds are secured, hands over your main point of leverage. Doing it too late leaves you holding a paid-for business you can't yet control technically.

Renewal Traps and Auto-Renew Surprises

Check the domain's expiration date and renewal price before closing, not after. A few specific traps show up repeatedly:

  • A domain expiring within the transfer window β€” some registrars won't process a transfer within a set number of days of expiration, forcing a renewal first
  • Auto-renew turned off, with the expiration date closer than it looks
  • A multi-year "promotional" registration rate that resets to a much higher price at the next renewal, which changes your ongoing cost model slightly but is worth knowing upfront

None of these are dealbreakers, but each is a small cost or timing issue that's far easier to handle before closing than to discover the week the site goes down.

Frequently Asked Questions

Do I need the seller's registrar login, or is the auth code enough?

The auth code is enough to complete a standard transfer to a new registrar. A full login handover is only necessary if you're taking over the seller's existing account rather than moving the domain to your own β€” and that path brings its own risks around shared billing and other domains on the account.

What if the seller registered the domain through a website builder or hosting bundle instead of a standalone registrar?

This is common with page builders that bundle "free domain" offers. These domains can usually still be transferred, but the process and available auth codes vary by provider β€” confirm this specifically during due diligence rather than assuming it works like a standard registrar.

Can a domain transfer affect the site's SEO? The domain itself doesn't change, so rankings tied to the domain generally survive a clean registrar transfer. The risk comes from what often happens alongside it β€” DNS changes, hosting migrations, or a lapse in availability during the handover. If you're also planning any technical changes around the transfer, it's worth pairing this with a broader look at organic traffic durability so a routine ownership change doesn't quietly cost you rankings. Is domain registration due diligence different for a portfolio of domains versus a single business's domain?

The mechanics are the same, but a portfolio deal usually involves valuing the domains themselves as the asset β€” a different exercise from verifying registration status on the domain that happens to run a business you're buying.

Key Takeaways

  • The domain doesn't transfer automatically with the business β€” the contract needs to state explicitly whether it's a registrar transfer or an account handover
  • Check WHOIS for registrant identity, creation date consistency, and lock status (`OK` vs. `clientTransferProhibited`) before you negotiate
  • The 60-day ICANN transfer restriction and an outdated administrative contact email are the two most common causes of transfer delays
  • Sequence the transfer with escrow: unlock and prepare, fund escrow, transfer, then release funds once you have confirmed control
  • Watch for related domains (misspellings, alternate TLDs) that aren't part of the sale but currently redirect traffic to the main site

Ready to see what's actually for sale? Browse deals across marketplaces, including Flippa listings, or set up deal alerts to get notified when new listings match your criteria.

Related articles