Domains
Transferring Your Domain to Another Registrar
You can move any domain registered with Kapsule to another registrar whenever you want, and the auth code you need to do it is one button away in KPanel.
Kapsule does not hold domains hostage. The panel states the policy on the button itself: "Move this domain to another registrar. We'll email you the auth code. We never withhold it." What this guide adds is the ordering, because a transfer touches DNS, DNSSEC, renewal dates and your registrant email all at once, and doing the steps out of sequence is what causes outages.
What a Transfer Actually Moves
A transfer changes which registrar holds the registration. That is all it changes at the moment it completes. It does not:
- Move your DNS records
- Move your website, your files or your databases
- Move your mailboxes
- Cancel your hosting subscription
Your DNS zone lives with whoever hosts your DNS, not with whoever holds the registration. If your domain is on Kapsule nameservers and you transfer the registration away without arranging DNS at the other end, your records keep answering only for as long as the new registrar leaves the nameservers alone. The moment they are repointed, everything the domain resolves to stops working. Plan DNS BEFORE you start the transfer, not after.
Before You Start
Work through all five of these while the domain is still fully under your control.
1. Check the Expiry Date
Open Domains, click the domain, and read the expiry date on the Overview tab. A transfer that is still in flight when the registration expires can fail outright, and you then have both an expiry problem and a stalled transfer.
If the domain expires within the next month or so, renew it first. On the Settings tab, the Renew Domain add-on row adds a year to the registration on demand. For most TLDs that year travels with the domain when it moves.
2. Deal With DNSSEC First
If DNSSEC is Active on this domain, sort it out BEFORE the transfer, never during it.
A transfer moves who publishes the DS record while Kapsule is still the one signing the zone. If the two fall out of step, validating resolvers stop answering for your domain entirely, and your site and email go dark for a large part of the internet.
Either plan the DNSSEC handover with your new registrar deliberately, or turn DNSSEC off in the correct order first, which means removing the DS record at the registry and letting it genuinely clear from the parent BEFORE disabling signing in KPanel. The full sequence is in Enabling DNSSEC for Your Domain.
3. Confirm Your Registrant Email
The auth code is emailed to your Kapsule account email, and your new registrar will usually send its own approval email to the registrant address on the public record. Check both are inboxes you can actually read right now, on the domain's Overview tab under Registrant Contact.
4. Turn Off WHOIS Privacy
If WHOIS privacy is on, turn it off on the domain's Security tab before you start. Most registries reject a transfer while privacy masking hides the registrant details the gaining registrar needs to verify. You can turn it back on at the other end once the transfer completes.
This step does not apply to .nz domains, which have no WHOIS privacy at all. See Registering and Managing .nz Domains.
5. Unlock the Domain
The registrar lock exists precisely to stop an outbound transfer, so it has to come off.
- Open the domain's Security tab.
- Find the Registrar Lock row: "Locked against transfers to another registrar (recommended). Unlock before you transfer out."
- Switch it off. It now reads "Unlocked: this domain can be transferred away. Lock it to prevent unauthorised transfers."
.nz domains have no registrar lock. The row shows Not available with the note "The .nz registry does not support registrar lock. Transfers are protected by the UDAI auth code instead." Skip this step for any .nz name and go straight to the auth code.
Getting Your Auth Code
The auth code goes by several names depending on the registrar: auth code, EPP code, transfer code, auth key, and on .nz, the UDAI.
- Open Domains and click the domain.
- Go to the Settings tab.
- Find the Transfer Out section inside the Renewal & Transfer card.
- Click Get Auth Code.
- Confirm the dialog headed "Email transfer-out auth code for {domain}?": "We will send the auth code to your account email so you can move this domain to another registrar." Click Email Auth Code.
- KPanel confirms: "Auth code emailed to {your email}. Check your inbox."

Treat the auth code like a password. Anyone holding a valid one can move your domain. Send it only to the registrar you are moving to, through their own transfer form, and never paste it into a public forum, a chat thread, or an unencrypted email you did not initiate.
Completing the Transfer at the New Registrar
- Sign in to the gaining registrar and start a domain transfer for your name.
- Paste in the auth code when prompted.
- Pay their transfer fee. For most TLDs that fee includes an extra year on the registration.
- Approve the confirmation emails. Both registrars may send one, and the transfer will not proceed until you act on them.
How Long It Takes
| TLD | Typical time |
|---|---|
| Most TLDs (.com, .net, .org and similar) | 5 to 7 days |
| .nz (.co.nz, .nz, .net.nz and the rest) | Same day, often within hours |
Approving the confirmation email promptly is the single biggest lever you have on that time. Ignoring it means waiting out the registry's automatic approval window instead.
Your domain stays fully functional throughout. DNS keeps resolving, the site keeps serving and mail keeps flowing for as long as the nameservers are unchanged.
Most generic TLDs enforce a 60-day minimum age before a domain can be transferred, an ICANN rule. A domain you registered or transferred in the last two months will be refused, and there is no way around the wait. .nz has no such rule.
After the Transfer Completes
Once the registration lands at the new registrar:
- Kapsule no longer manages the registration, its renewals, or its registrar-level settings.
- DNS answers from wherever the nameservers point. If they still point at Kapsule and your zone is still here, records keep resolving; if the new registrar switches them to its own DNS, you need to have recreated your records there.
- Any hosting, mailboxes or SSL certificates you bought from Kapsule are separate products and are unaffected. They keep running and keep billing.
Tidying Up in KPanel
The domain stays listed in KPanel after it moves. To clear it from your list, open the domain's Settings tab and use Remove from KPanel in the danger zone, then Confirm remove.
The panel is precise about what that button does: "Remove this domain from KPanel. This does not unregister it from Kapsule. To fully remove this domain, contact support." It is a tidy-up of your view, not a registry action. If you need the record fully removed from Kapsule's side, open a support ticket.
Troubleshooting
The Get Auth Code button is greyed out. It is only enabled for domains in the Active status, and only for users with write access to domains. If the domain shows Expired, Pending or Transfer out, resolve that first. If it is a permissions problem, ask an account Owner or Admin.
"Email send failed. Your code is: {code}". The email did not go out, so KPanel shows you the code on screen instead. Copy it immediately: it is displayed for this attempt only. Then fix your billing or account email so future notifications arrive.
The auth code did not arrive. It goes to your Kapsule account email. Check spam, confirm the address under Settings, and request it again.
My new registrar says the code is invalid. Copy and paste rather than retyping, watch for a trailing space, and confirm the registrar lock is actually off. Auth codes can also be regenerated: request a fresh one and use that.
The transfer was rejected. The usual causes, in order of likelihood: the domain is still locked, it is inside the 60-day post-registration window, WHOIS privacy is still on, or it is too close to expiry. Fix the cause and start again.
My website went down after the transfer. The nameservers changed, so your DNS records went with them. Recreate your records at the new DNS host and point the domain back at whatever serves your site. See Nameservers and DNS Basics.
I changed my mind and want to bring it back. You can transfer it back into Kapsule, subject to the same 60-day rule at the new registrar. Use Domains, then Transfer in.
If a transfer is stuck for longer than the times above, open a support ticket with the domain name, the date you requested the auth code, and the name of the gaining registrar.