Domains
Getting Your Domain Auth Code
An auth code is the password that proves you control a domain, and every transfer between registrars needs one, so knowing where to get yours and what to do when it is rejected saves most of the pain of moving a domain.
The same thing goes by several names depending on who is asking: auth code, EPP code, authorisation code, transfer code, auth key, and on .nz domains a UDAI. They are all the same concept. This article covers getting one from Kapsule, getting one from another registrar, and what to do when a transfer says the code is wrong.
Getting Your Auth Code From Kapsule
Kapsule never withholds an auth code. The domain is yours, and the transfer-out email says so directly: "We will never withhold your code, even if your account has an outstanding balance."
- Sign in to KPanel and click Domains in the left sidebar.
- Click the domain you want to move.
- Open the Settings tab.
- Find the Renewal & Transfer card and the Transfer Out row, which reads "Move this domain to another registrar. We'll email you the auth code. We never withhold it."
- Click Get Auth Code.
- Confirm on the dialog titled "Email transfer-out auth code for {your domain}?" by clicking Email Auth Code.

The code is emailed to your account email address, and the panel confirms with "Auth code emailed to {your email}. Check your inbox." For security, the code is never displayed in the panel and is never stored in your account: it exists in that email and nowhere else.
The domain has to be Active to request a code. A domain that is still provisioning, expired, in redemption, or already mid-transfer cannot issue one. The button tells you which state is blocking it.
Each Request Invalidates the Last
Requesting a new auth code cancels the previous one. This matters more than it sounds:
If you request a code, start a transfer with it, then request another code because the email was slow to arrive, the transfer you already started will fail with an invalid-code error. Request once, wait for the email, and only request again if you genuinely need a fresh code because the old one was lost or leaked.
That behaviour is also your safety net. If you suspect somebody else has seen your auth code, request a new one and the old one stops working immediately.
Getting an Auth Code From Another Registrar
To bring a domain into Kapsule you need the code from wherever it is registered now. Every registrar hides it somewhere slightly different, but it is almost always under a Security, Transfer, or Domain settings section on the domain itself.
Common paths to look for:
- A Transfer or Transfer out tab on the domain
- A Security section with a lock toggle beside it
- A "Get EPP code" or "Email auth code" button
- On some registrars, an option that emails the code to the registrant address on file rather than showing it
Some registrars display the code on screen. Some email it. A few make you contact support, which is legal but obstructive, and worth remembering when you decide where to keep your domains.
The transfer wizard in KPanel describes what you are looking for: "Also called Auth Code, Transfer Code, or Auth Key. Request it from your current registrar."
What an Auth Code Looks Like
Codes are case-sensitive strings, typically between 8 and 64 characters, often containing mixed case, digits and symbols. There is no single format: registries set their own rules.
Copy and paste the code rather than retyping it. Codes are case-sensitive and commonly contain characters that are easy to confuse by eye: the digit one against a lowercase L, the digit zero against a capital O. A rejected transfer that turns out to be a mistyped character is the single most common transfer failure there is. Also check you have not picked up a trailing space from the copy.
Unlocking Before You Transfer
Most domains carry a registrar lock, which exists specifically to stop a transfer happening without the owner's involvement. The code alone is not enough while the lock is on.
On a Kapsule domain, the Registrar Lock switch is on the Security tab, in the same Privacy & Lock card as WHOIS privacy. Its description says it directly: "Locked against transfers to another registrar (recommended). Unlock before you transfer out."
You should also turn off WHOIS privacy before transferring, because most registries reject a transfer while privacy masking is active.
So the full pre-transfer checklist is:
- Unlock the domain.
- Turn off WHOIS privacy.
- Get the auth code.
- Start the transfer at the gaining registrar.
The .nz Difference
The .nz registry works differently, and knowing this saves a lot of confusion.
There is no registrar lock on .nz domains. The .nz registry has no lock concept at all. In KPanel the Registrar Lock row on a .nz domain is greyed out with a Not available pill and the explanation: "The .nz registry does not support registrar lock. Transfers are protected by the UDAI auth code instead."
The code is called a UDAI. It performs the same function: it is the single piece of evidence the registry accepts that you authorised the move. Because there is no lock, the UDAI is doing all the work, which is why it should be treated as a password and never shared casually.
Transfers are much faster. A .nz transfer typically completes the same day, often within hours, where most other top-level domains take five to seven days. See .nz Domain Rules.
When a Code Is Rejected
If a transfer fails on the code, the message you will see is: "The transfer code (EPP/UDAI) is incorrect or has already been used. Please request a fresh transfer code from your current registrar and try again."
Work through these in order:
- Check for a typo or a stray space. Paste it into a plain text editor and look at both ends.
- Check you did not request a newer code. The most recent request is the only valid one.
- Check the domain is unlocked at the losing registrar, if that registry has a lock.
- Check privacy is off at the losing registrar.
- Check the domain is old enough. Most generic top-level domains cannot be transferred within 60 days of registration, or within 60 days of a previous transfer. This is a registry rule that no registrar can override. It does not apply to .nz.
- Check the domain has not expired. A domain that has lapsed at the losing registrar must be renewed there first.
- Request a fresh code and try once more.
If it still fails after all seven, open a support ticket with the domain name, the exact error text, and the time you attempted it.
Keeping the Code Safe
An auth code is a credential. Anyone who has it, on a domain with no lock, can start a transfer. Do not paste it into a chat, a forum post or a ticket with a third party, and do not email it onwards. Once the transfer completes the code is spent. If you requested one and then decided not to transfer, request a new one anyway so the circulated code is dead, and check the lock is back on.
Troubleshooting
The email never arrived. Check junk. Check that your account email address is current under Settings, and that it is not an address on the domain you are transferring. If the email genuinely could not be sent, the panel falls back to showing you the code on screen rather than leaving you stuck.
The Get Auth Code button is greyed out. The domain is not Active, or your role does not include domain write permission on the account.
My new registrar says the code is fine but nothing happens. Approval emails are often the missing step. Both the losing and the gaining registrar may email the registrant address for confirmation, and the transfer waits until somebody clicks. Check the inbox on the registrant address, including junk.
Related reading: Transferring Your Domain to Another Registrar, Transferring a Domain to Kapsule, WHOIS Privacy, and .nz Domain Rules.