How to choose a reputable domain registrar: Grace periods, transfer locks, and ICANN compliance compared across 10 registrars
Choosing a reputable domain registrar means weighing five cost-and-recovery dimensions where registrar lifecycle policies diverge:
- Grace duration runs 18 days at GoDaddy to 30 days across the rest of the market.
- Auto-renew grace extension spans 0-10 days.
- Total recovery window spans 53-70 days.
- Renewal pricing runs $9.95-$21.99 retail.
- Redemption fees run ~$40 at-cost at Cloudflare to $195 at Name.com once a domain enters the registry Redemption Grace Period.
The ICANN ERRP 2024 framework requires registrar implementation by 21 August 2025.
The ICANN 82 vote (12-13 March 2025) eliminates the legacy 60-day transfer lock and introduces a 720-hour (30-day) lock on newly created or transferred domains.
Four distinct transfer lock types operate today: ICANN 60-day new-registration, ICANN 60-day contact-change, registrar Client lock, and high-security Registry Lock.
SEO Domains operates the 220,000+ aged-domain catalogue above the registrar policy layer: buyers acquire through ICANN-accredited transfer and route inventory to any preferred registrar after purchase.
What makes a reputable domain registrar across lifecycle policy?
A reputable domain registrar is measured across 8 lifecycle-policy dimensions that shape acquisition and ownership decisions. The chips below name all eight, from grace duration through security tier.
The variation produces a 17-day spread in recovery windows and a 4x spread in renewal costs.
Grace period variation produces a 17-day acquisition spread.
GoDaddy operates an 18-day grace period; the rest of the surveyed market runs 30 days. Combined with auto-renew grace extensions (0-10 days), total recovery windows span 53 days at GoDaddy through 70 days at Porkbun.
The variance documented in How to recover an expired domain: 4-phase timeline and registrar restoration costs determines the buyer's effective renewal-decision window.
Transfer lock implementations follow ICANN policy with registrar variations.
The four-tier transfer lock taxonomy operates across all ICANN-accredited registrars:
- ICANN mandates the 60-day new-registration lock and the 60-day contact-change lock.
- Registrar-level Client lock (
clientTransferProhibited) is user-controlled. - High-security Registry Lock requires out-of-band verification through the registry.
WHOIS privacy basic tier is free across all 10 surveyed registrars.
Cloudflare, Porkbun, Dynadot, NameSilo, Namecheap, Squarespace, Name.com, Hover, Hostinger, and GoDaddy include basic WHOIS privacy at no additional cost following recent industry changes.
GoDaddy charges $9.99 per year for the "Full Domain Privacy & Protection" enhanced tier (extra features beyond basic privacy).
The privacy-by-default pattern reflects industry consolidation post-GDPR (May 2018) and the ICANN Temporary Specification on registration-data publication.
Pricing transparency varies across at-cost, flat-rate, and promotional models.
Renewal pricing sorts the surveyed registrars into four models:
- Cloudflare runs an at-cost model: $10.44 per .com year, no markup over wholesale.
- Porkbun, Dynadot, and NameSilo run flat-rate models at $9.95-$10.49.
- Namecheap, Squarespace, Name.com, and Hover apply moderate markup at $12.99-$14.99.
- GoDaddy uses promotional first-year pricing ($0.01-$11.99) followed by a $21.99 renewal.
The 4x renewal-cost spread compounds across multi-year holdings.
How do grace periods compare across 10 major registrars?
Grace periods cluster around 30 days across 9 of 10 surveyed registrars. GoDaddy stands as the single outlier at 18 days.
Combined with auto-renew grace extensions, total recovery windows span 53 days at GoDaddy to 70 days at Porkbun. The grace duration sets the standard-price renewal window before redemption fees apply.
| Registrar | Grace | Auto-renew grace | Total recovery | .com renewal | Redemption fee | WHOIS |
|---|---|---|---|---|---|---|
| Cloudflare | 30 days | 0 days | 60 days | $10.44 (at-cost) | ~$40 (at-cost) | Free |
| Porkbun | 30 days | 10 days | 70 days | $10.28 (flat) | $120 | Free |
| Dynadot | 30 days | 0 days | 60 days | $10.49 (flat) | $125-140 | Free |
| NameSilo | 30 days | 0 days | 60 days | $9.95 | $161-176 | Free (lifetime) |
| Namecheap | 30 days | 7 days | 67 days | $13.98 | $160 | Free |
| Squarespace | 30 days | 7 days | 67 days | $12 (flat) | $150 | Free |
| Name.com | 30 days | 0 days | 60 days | $12.99 | $195 | Free |
| Hover | 30 days | 0 days | 60 days | $14.99 (flat) | $175 | Free |
| Hostinger | 30 days | n/a | varies | $19.99 | $80 | Free |
| GoDaddy | 18 days | 5 days | 53 days | $21.99 | $179.99 | Free basic; $9.99 upsell |
GoDaddy's 18-day grace is the shortest among major US registrars.
GoDaddy applies an 18-day registrar grace period followed by a 5-day auto-renew grace extension. The total recovery window of 53 days is 17 days shorter than Porkbun's 70-day window.
The shorter grace reduces the registrant's renewal decision time and increases the risk of unintended expiration documented in How to recover an expired domain: 4-phase timeline and registrar restoration costs.
Porkbun offers an extended 70-day total recovery window.
Porkbun operates a 30-day standard grace at renewal price, followed by a 10-day auto-renew grace extension that holds standard pricing through day 40 post-expiry.
The standard 30-day Redemption Grace Period then runs at the registry, producing a total recovery window of 70 days per the published Porkbun knowledge base.
The extended structure provides additional renewal-decision time for registrants who miss the initial expiry notification.
Cloudflare and Porkbun lead the at-cost / flat-rate pricing model.
Three registrars combine for the lowest 5-year total cost among the surveyed market:
- Cloudflare passes the Verisign wholesale .com renewal fee directly to the customer at $10.44 per year.
- Porkbun applies a flat $10.28 rate across registration and renewal.
- NameSilo charges $9.95 with lifetime free WHOIS privacy.
Namecheap renewal pricing now runs $13.98 in the standard tier.
Namecheap's published .com renewal pricing currently runs at $13.98 across the standard offering documented in industry comparisons. The renewal cost positions Namecheap in the mid tier alongside Squarespace ($12), Name.com ($12.99), and Hover ($14.99).
The increase from earlier sub-$11 promotional renewals narrowed Namecheap's historical pricing advantage over the lowest-cost registrars.
Redemption fees span ~$40 to $195 across the surveyed registrars.
The registrar redemption fee (the restoration charge once a domain enters the registry Redemption Grace Period after the standard window closes) runs from ~$40 at Cloudflare to $195 at Name.com.
Cloudflare passes the $40 Verisign wholesale restore fee through at-cost. The rest of the surveyed market climbs from there:
- Hostinger $80, Porkbun $120, Dynadot $125-140.
- Squarespace $150, Namecheap $160, NameSilo $161-176.
- Hover $175, GoDaddy $179.99, Name.com $195.
The full restoration-fee mechanics and per-registrar totals are documented in How to recover an expired domain: 4-phase timeline and registrar restoration costs and Redemption period (RGP) explained.
How does auto-renew grace differ across registrars?
Auto-renew grace varies across 3 patterns. The extension sets how long after the standard 30-day grace the registrant keeps standard-renewal pricing.
- No auto-renew grace: Cloudflare, Dynadot, NameSilo, Name.com, and Hover.
- Short auto-renew grace at 5-7 days: GoDaddy, Namecheap, and Squarespace.
- Extended auto-renew grace at 10 days: Porkbun.
Auto-renew grace extends the standard-pricing recovery window.
The standard 30-day grace period at registrars operates under ICANN's auto-renew grace framework (0-45 days at the registrar's discretion).
The registrar-specific auto-renew grace extension adds days beyond the initial 30-day standard window, during which renewal still completes at the standard rate without restoration fees.
Beyond the auto-renew grace, the domain moves into the Redemption Grace Period documented in Redemption period (RGP) explained.
Porkbun's 10-day auto-renew grace produces the longest total recovery.
Porkbun extends the auto-renew grace by 10 days beyond the 30-day standard. The 40-day pre-RGP window plus the 30-day RGP gives a 70-day total recovery window.
Registrants who miss the initial 30-day grace keep a longer secondary window at standard pricing before the redemption fee applies.
Five registrars operate without an auto-renew grace extension.
Cloudflare, Dynadot, NameSilo, Name.com, and Hover end the standard-pricing window at the 30-day mark. After day 30, the domain enters RGP and restoration fees apply.
Registrants at these registrars factor the absence of extension into their renewal tracking workflow documented in Domain lifecycle tracking: WHOIS, RDAP, and the workflow tools that monitor every status code.
GoDaddy's 5-day extension compounds with the shortest 18-day grace.
GoDaddy's 18-day grace plus 5-day auto-renew grace extension produces a 23-day pre-RGP window. The total recovery window of 53 days (23 + 30 RGP) is the shortest among the surveyed registrars.
Operators acquiring domains held at GoDaddy plan renewal tracking with 7-day tighter margins than at other major registrars.
What does the ICANN 2024 ERRP require of every registrar?
The ICANN Expired Registration Recovery Policy (ERRP) effective 21 February 2024 requires every accredited registrar to implement the updated policy by 21 August 2025. All accredited registrars operate under the same ERRP framework regardless of size or jurisdiction.
The 2024 update modernises four areas:
- Notification requirements.
- Restoration mechanics.
- Fee disclosure.
- Registrant rights.
ERRP 2024 requires notifications at minimum 2 points before expiry.
The framework requires every accredited registrar to send at least 2 renewal notifications: approximately 1 month before expiry and approximately 1 week before expiry.
Registrars exceed the minimum with notifications at 60, 30, 15, 7, and 1 days in the documented practice.
The notification cadence aligns with the alert thresholds documented in Domain lifecycle tracking: WHOIS, RDAP, and the workflow tools that monitor every status code.
RGP at the registry remains 30 days across all gTLD registries.
The Redemption Grace Period at the registry layer continues to operate at 30 days standard for all gTLDs operating under the standard ICANN registry agreement. The RGP framework predates ERRP 2024 and remains unchanged in the update.
The RGP duration is a registry-set policy independent of the registrar's grace period documented in section H2 above.
ERRP 2024 strengthens fee disclosure requirements for registrars.
The updated framework requires registrars to disclose three fee types at the time of registration:
- Renewal fees.
- Post-expiration renewal fees, where they differ from standard renewal.
- Redemption fees.
The disclosure appears on the registrar's published help article or in the registration agreement. The transparency requirement supports the per-registrar pricing matrix in this article.
Registrant-of-record rights extend through the RGP window.
ERRP 2024 affirms the registrant-of-record's right to restore a deleted domain during the 30-day RGP at the registry. The restoration completes through the registrar that deleted the registration.
The right cannot be transferred to a third party during RGP. The framework prevents drop-catcher extortion patterns identified during the early-2000s policy reviews.
How does the 60-day transfer lock change in 2026?
The ICANN 82 vote on 12-13 March 2025 in Seattle eliminates the legacy 60-day transfer lock and replaces it with a 720-hour (30-day) mandatory lock on newly created or recently transferred domains.
The vote unanimously approved a 163-page working group report containing 47 policy recommendations. Implementation runs through an 18-month transition window pending ICANN Board final approval.
ICANN is set to kill off its unpopular 60-day transfer lock policy, following a vote at ICANN 82 in Seattle. The newly approved changes introduce two new locks that registrars currently choose to impose at their discretion.
The updated policy mandates 720-hour (30-day) locks on domains that have just been created or just transferred in.
Domain Incite · ICANN 82 vote coverage · March 2025
The legacy 60-day lock retires after 10 years of operation.
The 60-day transfer lock entered effect in 2016 as an anti-fraud measure preventing rapid successive transfers of stolen domains. The 10-year operational record showed the lock added legitimate-registrant friction without proportional fraud-reduction benefit.
The ICANN 82 vote reflects industry consensus that 30 days achieves the anti-fraud purpose with less mobility cost.
The new 720-hour lock applies to newly created and transferred domains.
The replacement 720-hour (30-day) lock attaches at registration creation and at transfer completion. Both events trigger the 30-day mobility restriction. The lock cannot be bypassed by any registrar under ICANN policy.
The new framework runs in parallel with the existing registrar-level Client lock and registry-level Registry Lock documented later in this article.
DNS abuse joins the transfer-denial reason set in the ICANN 82 framework.
The 2025 transfer policy update adds DNS abuse as a permissible transfer denial reason. Registrars receiving transfer requests for domains flagged for DNS abuse (malware distribution, phishing, command-and-control infrastructure) can deny the transfer to prevent abuse continuation.
The change closes a long-standing loophole that allowed abusive operators to evade enforcement through registrar hopping.
Bulk transfer fees receive a cap for large portfolio holders.
The ICANN 82 vote introduces a cap on bulk transfer fees for portfolios exceeding 50,000 domains. The cap protects large portfolio holders from prohibitive transfer fees that block legitimate registrar consolidation.
The exact fee threshold appears in the ICANN GNSO final policy text and applies at the registry-bulk-transfer layer documented in standard registry agreements.
What are the 4 types of transfer locks operators track?
Four distinct transfer lock types operate across the gTLD landscape. The grid below names each one with its policy layer and opt-out rule.
Each lock sits at a different policy layer with its own opt-out rules and security guarantees. Operators acquiring domains track all four layers in their transfer-readiness workflow.
1. ICANN 60-day NEW-registration lock
Activates upon initial domain registration. Prevents transfer to another registrar for 60 days. No opt-out available. Replacement by 720-hour (30-day) lock under ICANN 82 vote pending implementation.
2. ICANN 60-day CONTACT-CHANGE lock
Triggers on changes to registrant name, organisation, or email. Specific registrars including Name.com and NameSilo offer opt-out through verification at the time of change. WHOIS privacy updates are exempt from the lock.
3. ClientTransferProhibited (Client lock)
EPP status flag set by the registrar at the customer's discretion. Default ON at the major registrars (GoDaddy, Namecheap, Cloudflare, Porkbun, Squarespace). Disables outbound transfer attempts until the customer toggles it OFF through the registrar's account interface.
4. Registry Lock (high-security)
Separate high-security feature operating at the registry layer. Requires out-of-band verification (phone, code, or signed authorisation) before any change. Used by enterprises holding domain assets at premium-value risk.
The ICANN 60-day new-registration lock cannot be bypassed.
The lock attaches at registration creation and prevents outbound transfer for 60 calendar days. No registrar can override the lock under ICANN policy. The 60-day counter starts from exact registration completion time, not from initial process start.
Newly registered domains acquired through aged-domain operations are unaffected because the lock applies to fresh creations only.
The ICANN 60-day contact-change lock offers limited opt-out at registration.
Changes to registrant name, organisation, or email trigger the lock. The registrar prompts the registrant at the time of change to accept or decline it.
Specific registrars implement the opt-out through verification; others enforce the lock without opt-out. WHOIS privacy updates are exempt from the lock per ICANN policy clarifications.
The ClientTransferProhibited flag is user-controlled at the registrar layer.
The EPP status flag is the registrar-level transfer lock. The default is ON at the major registrars (GoDaddy, Namecheap, Cloudflare, Squarespace, Porkbun) as a security best practice.
The customer toggles the flag OFF through the registrar's account interface before initiating an outbound transfer. The flag operates independently of ICANN policy locks.
Registry Lock operates as the highest-security tier for premium-value domains.
Registry Lock attaches at the registry layer (Verisign, Identity Digital, PIR) and requires out-of-band verification before any change. It prevents domain hijacking through compromised registrar accounts, because changes require verification beyond the registrar's normal authentication.
Premium-domain holders and brand-protection operators adopt Registry Lock as standard practice.
How do security and WHOIS policies differ across registrars?
Security and WHOIS policies vary across 4 dimensions:
- WHOIS privacy default: free at 9/10 surveyed registrars, paid at GoDaddy.
- 2FA support: TOTP, SMS, and hardware keys.
- Registry Lock availability: a premium feature.
- DNSSEC implementation: free at Cloudflare and Porkbun, paid or absent elsewhere.
The combined security tier sets the operator's exposure to account compromise and domain hijacking risk.
WHOIS privacy basic tier is free across all 10 surveyed registrars.
Cloudflare, Porkbun, Dynadot, NameSilo, Namecheap, Squarespace, Name.com, Hover, Hostinger, and GoDaddy include basic WHOIS privacy at no additional cost. NameSilo extends the offer to lifetime free privacy across all owned domains.
GoDaddy charges $9.99 per domain per year for the "Full Domain Privacy & Protection" upsell tier with additional protection features. The basic-privacy-free industry baseline reflects post-GDPR consolidation.
Hardware-key 2FA support varies across registrars.
Two-factor support splits across the surveyed registrars:
- Cloudflare supports TOTP plus hardware-key 2FA (U2F, FIDO2).
- GoDaddy supports TOTP, SMS, and hardware keys.
- Namecheap supports TOTP and SMS.
- Porkbun and Dynadot support TOTP.
Hardware-key 2FA is the industry-recommended baseline for premium-domain operators. It resists the SIM-swap and phishing attacks that defeat TOTP and SMS authentication.
Registry Lock availability is limited to enterprise-tier services.
Registry Lock requires out-of-band verification at the registry and operates as a separate paid service at the retail-tier registrars. Markmonitor, CSC Digital Brand Services, and other enterprise registrars include it as a standard offering.
Retail registrars (GoDaddy, Namecheap, and similar) offer Registry Lock through dedicated enterprise tiers or premium support packages.
DNSSEC default varies between automatic and manual configuration.
Cloudflare enables DNSSEC by default for domains using Cloudflare DNS. Porkbun supports DNSSEC at no additional cost. Other registrars implement it as a manual configuration through the DNS settings panel.
The variance affects operators managing domains across mixed-registrar portfolios, because DNSSEC implementation differs per registrar's DNS infrastructure.
Industry consensus shortlist combines Cloudflare and Namecheap for the operator majority.
Multi-source industry coverage in 2026 converges on Cloudflare plus Namecheap as the registrar shortlist for the operator majority:
- Cloudflare for long-term cost (at-cost pricing) and security (DNSSEC, hardware keys).
- Namecheap for TLD breadth and domain-parking infrastructure.
Cloudflare publishes a dedicated "alternatives to Namecheap" page that confirms the comparative positioning in the market.
What questions do owners ask about registrar policy choice?
Operators raise six recurring questions about registrar policy choice. They span grace-period length, the four transfer lock types, the ICANN 30-day lock timing, GoDaddy's 2026 standing, Cloudflare's long-term savings, and the transfer procedure. The cards below answer each.
Q1Which registrar offers the longest grace period for recovery?
Porkbun offers the longest total recovery window at 70 days (30-day grace + 10-day auto-renew extension + 30-day RGP).
Cloudflare, Dynadot, Name.com, and Hover offer 60 days. GoDaddy operates the shortest at 53 days (18-day grace + 5-day auto-renew + 30-day RGP).
Q2What is the difference between the 60-day NEW lock and CONTACT CHANGE lock?
The 60-day NEW-registration lock activates at domain registration and cannot be bypassed. The 60-day CONTACT-CHANGE lock triggers on registrant name, organisation, or email changes and offers opt-out at specific registrars. WHOIS privacy updates are exempt from the contact-change lock.
Q3When does the ICANN 30-day lock replace the 60-day lock?
The ICANN 82 vote on 12-13 March 2025 approved the replacement. Implementation runs through an 18-month transition pending ICANN Board final approval.
The new 720-hour (30-day) lock applies to newly created or transferred domains. It takes effect across the gTLD landscape during 2026-2027.
Q4Why is GoDaddy no longer recommended in 2026?
The February 2026 GoDaddy Terms of Service update reclassified 21 million customers as "Business Customers" and stripped EU consumer protections. Multi-source 2026 industry coverage marks GoDaddy as no longer recommended for new registrations on the basis of the ToS change.
Q5Is Cloudflare meaningfully cheaper than other registrars long-term?
Cloudflare operates an at-cost pricing model with no markup over wholesale registry fees. The .com renewal at $10.44 per year is lower than the surveyed market average ($14-$18).
For 5-year holdings the cost advantage compounds to $20-$40 saved per domain compared to mid-tier registrars.
Q6How do I switch registrars without losing the domain?
The transfer runs as a five-step procedure:
- Unlock the domain at the current registrar (toggle
clientTransferProhibitedOFF). - Request the auth code (EPP transfer code).
- Initiate the transfer at the gaining registrar.
- Approve the transfer request.
- Wait for the 5-7 day transfer-completion window.
The 60-day new-registration or contact-change locks block the transfer if active.
How does SEO Domains operate above the registrar policy layer?
SEO Domains lists 220,000+ curated aged-domain inventory acquired through ICANN-accredited drop-catching at registry release. Buyers acquire through the catalogue at fixed prices and route the inventory to any preferred registrar after acquisition.
The catalogue operates policy-agnostic above the 18-70 day grace variance, the four transfer-lock types, and the multi-registrar pricing spread.
The catalogue is acquired through ICANN-accredited drop-catching at registry release.
SEO Domains operates as a drop-catching leader. The 220,000+ aged-domain catalogue is acquired through ICANN-accredited drop-catching at the registry release moment (day 81+), after the pending-delete window completes.
The acquisition point sits above the registrar policy layer, because the registry release operates at the registry, not the registrar.
Buyers transfer to any preferred registrar after acquisition.
Acquisition completes through standard ICANN-accredited EPP transfer to the buyer's registrar of choice. Buyers select the registrar that matches their portfolio strategy:
- Cloudflare for at-cost long-term holding.
- Porkbun for the longest recovery window.
- NameSilo for lifetime free WHOIS.
- An enterprise registrar for Registry Lock-protected premium assets.
The catalogue does not lock buyers into any specific registrar.
Listed prices replace multi-registrar pricing comparison.
Each domain in the catalogue carries a listed price. Buyers compare prices, registration history, Domain Authority, Domain Rating, referring domains, country, and topical category in a single interface.
The pricing structure replaces the multi-registrar comparison documented across the 10-registrar matrix in this article.
ICANN-accredited transfer preserves aged-domain SEO value for 301-redirect strategies.
For 301-redirect strategies, a 301-redirected aged domain passes accumulated link equity to the new destination when the prior active history is topically relevant and documented.
The SEO Domains analytical desk verifies the curated history records that support the transfer-and-redirect workflow, regardless of which registrar holds the destination domain.
Policy-agnostic acquisition: browse 220,000+, transfer anywhere. The SEO Domains catalogue lists curated aged-domain inventory acquired through ICANN-accredited drop-catching above the registrar policy layer.
Buyers route inventory to Cloudflare, Porkbun, Namecheap, or any other ICANN-accredited registrar after acquisition. Search the SEO Domains marketplace →

Español
Deutsch
Français
Nederlands
Português
Italiano
Norsk bokmål
Svenska
Dansk
Suomi
Lietuvių
Latviešu
Eesti
Magyar
Polski
Čeština
Български
Slovenščina
српски
Hrvatski
Українська
Română
Ελληνικά
Türkçe
Русский
日本語
한국어
简体中文
Indonesia
Melayu
ไทย
Tiếng Việt
العربية
עברית