ICANN accreditation is a floor, not a rating
The registrar is the retailer; the registry operates the extension and sells wholesale to registrars rather than to you. Your legal relationship is with the registrar, and it is the registrar that controls who is listed as registrant, which nameservers are delegated, whether the domain is locked, and whether it auto-renews.
To offer registration services in generic top-level domains with direct access to the registries, an entity must demonstrate to ICANN that it meets technical, operational and financial criteria, then enter a Registrar Accreditation Agreement. That binds it to ICANN's consensus policies, including the Transfer Policy, the Expired Registration Recovery Policy, the Registration Data Policy and the UDRP; it must escrow registration data with a third party so registrations survive its business failure; and there is a complaints route to ICANN Contractual Compliance. What accreditation does not guarantee is service quality, DNS uptime, support responsiveness, renewal pricing, business longevity, or the security of its account systems.
Two qualifications. Many domains are sold by a reseller sitting on top of an accredited registrar, so your agreement counterparty and your support relationship are different companies. And accreditation covers gTLDs only: country-code extensions run under rules that are not ICANN consensus policy.
The renewal price is the only price that recurs
Introductory and renewal pricing are independent variables. A registrar can price the first year at or below its own wholesale cost, because the economics work on the renewal stream and on attached services. A deep first-year discount is not evidence of a cheap registrar. It is evidence of an acquisition strategy, and it tells you nothing about year two.
- The renewal price for each extension you actually hold. Registry wholesale costs differ enormously, so a registrar competitive on one extension may be uncompetitive on another. Registrants have a right to accurate pricing information and protection from hidden fees.
- Whether renewal pricing is fixed or discretionary, and whether multi-year registration is offered. Pricing is usually discretionary; a multi-year term converts that recurring risk into a fixed one.
- What is bundled and what is billed separately. DNS hosting, privacy, email forwarding, registry lock and API access are included by some and charged by others; a headline renewal figure with four paid add-ons is not comparable to one without.
- Restoration and redemption charges, structurally the largest fee a registrant ever meets and the one you meet on your worst day. The registry restore fee is broadly similar within an extension, so the variability is the markup.
Privacy, now that redaction is the default
Since ICANN's Registration Data Policy took full effect on 21 August 2025, much registrant personal data is redacted from public lookups by default, with registrars publishing an email address or a web form in place of contact details. Redaction is not a privacy service: redaction is data the registrar or registry holds and withholds, whereas a privacy or proxy service substitutes a third party's details for yours by contract.
- Is a formal privacy or proxy service still offered, and is it included or charged? Registrars must disclose pricing for those services as well as for registrations.
- Who is the registrant of record when privacy is on? The provider's details are published in place of yours, so establish your route back to control.
- Does privacy interfere with transfers? Some services must be disabled first, and disabling one can itself change the registrant email, which triggers the mandatory 60-day change-of-registrant transfer lock.
- Does any of this apply to your extensions? Country-code registries set their own rules and are not bound by the Registration Data Policy. Some publish registrant data in full.
How hard is it to leave
Transfer friction is the most reliable indicator of how a registrar treats customers who are no longer growing its revenue, and ICANN policy gives you a standard to measure it against. The Transfer Policy enumerates the grounds on which a registrar of record may deny a transfer — fraud, disputed identity, non-payment for the previous or current registration period, written objection from the authorized contact, the 60-day windows after creation and after a previous transfer, and pending disputes. Anything outside that list is not a permitted denial.
The provisions that matter most concern obstruction. A registrar must either let you generate the authorization code yourself or provide it within five calendar days, and must remove a transfer lock within five days where there is no self-service facility. More usefully, it may not use any mechanism for releasing the code or removing clientTransferProhibited that is more restrictive than the one used for changing your contact or nameserver information. If you can change nameservers in two clicks, it cannot demand a notarized letter for the code, and a payment dispute is not grounds to withhold it.
On fees, be precise, because the common claim is wrong. The Transfer Policy does not address whether a registrar may charge for a transfer out or for issuing an authorization code; it neither permits nor prohibits it. What it does do is close off non-payment of such a fee as a ground for denial, since the permitted grounds are enumerated and a transfer-out fee is not among them. Reform is pending but not in force: the Transfer Policy Review recommendations reached the ICANN Board in 2025 and remain unadopted.
The DNS hosting you get without asking for it
Most small businesses use the registrar's bundled DNS, which means they choose a DNS operator without noticing. The two roles fail separately: an expired registration is a registrar problem, while a site resolving to the wrong address is a DNS host problem.
- Anycast, geographic distribution, and network diversity. Four nameservers inside one provider's single network is one failure domain, not four.
- The minimum TTL the panel permits, since a floor constrains the correct migration procedure of lowering TTLs before making a change.
- Record type support for CAA, SRV and TLSA, and an apex-alias equivalent if you need one. ALIAS and ANAME are proprietary implementations of an Internet-Draft that expired without becoming a standard, so an apex alias is lock-in rather than a portable feature.
- DNSSEC support, and whether DS records are managed automatically through CDS and CDNSKEY or copied by hand between DNS host and registrar. The Internet Society identified that manual process as the root cause of the March 2015 hbonow.com outage.
- API access, zone export, and change logging. The first two are your exit route as much as your automation route; the third is what ICANN's February 2019 hijacking checklist assumes when it recommends verifying record integrity.
Locks, account controls, and the support desk behind them
Registrar lock, which appears as clientTransferProhibited, is free and on by default at most registrars. Two related locks matter more and are usually off: clientUpdateProhibited freezes nameservers and contacts, addressing the fast path in most modern hijackings, where the attacker redirects DNS rather than stealing the registration, and clientDeleteProhibited prevents deletion. Ask whether both are user-settable.
Registry lock is a different class of protection. The registry applies serverUpdateProhibited, serverDeleteProhibited and serverTransferProhibited, and lifts them only after out-of-band verification with a named, pre-authorized individual. Verisign's service covers .com, .net, .cc and .name: Verisign telephones that individual, who must supply a personal security phrase before the name is unlocked. Nominet offers Domain Lock for .uk on similar terms. It only works if your registrar participates, so ask which extensions it covers and what the unlock hours are. It is the only control that cannot be defeated by a stolen password, and the friction is the feature.
Support is the other half of the same question, because transfers, hijackings, expiries and DNSSEC failures are not tier-one script material. Evaluate hours in your own time zone, whether an escalation path exists to someone with registry-level access, and whether there is an emergency out-of-hours contact for a suspected hijacking; ICANN's advisory committee recommended that after finding its absence prolonged recovery of panix.com beyond forty hours. Then evaluate the desk's own authentication discipline, because in April 2005 an attacker simply persuaded support staff to change the administrative contact email on hushmail.com. A desk that is pleasantly accommodating to you is equally accommodating to an impostor.
The single-vendor question
Holding registration, DNS, web hosting and email with one vendor is convenient, cheaper to administer, and a single point of failure. The advisory committee framing generalizes well: all an attacker needs to gain control of an organization's entire domain name portfolio is a user account and a password.
- One account compromise takes everything, including the mailbox you would use to recover.
- Recovery email inside the affected domain. It is not safe to send credential recovery instructions for a domain to an address within that domain. If the DNS is redirected, the reset message goes to the attacker.
- Billing failure, vendor failure, a terms dispute, or a correlated outage removes all four services at once, including the DNS you would use to fail over.
Balance this honestly. Consolidation reduces the number of things a small team can misconfigure, and one well-run vendor with enforced multi-factor authentication may beat three badly run ones. The non-negotiable is narrower: keep the account email on an independent domain at an independent provider, as a role mailbox with its own two-factor authentication.
What switching actually costs
- Direct. A transfer normally adds a year to the registration, billed by the gaining registrar and added to the existing expiry date. You are buying a year, not paying an administrative fee.
- Timing. Transfers are barred within 60 days of registration and within 60 days of a previous transfer, and a change of registrant triggers a mandatory 60-day lock unless opted out of beforehand. Correct the registrant details before you move, never after.
- The real cost is DNS migration, if you move DNS at the same time: recreating every record including SPF, DKIM, DMARC and CAA, finding an equivalent for any proprietary apex alias, and lowering TTLs in advance.
- DNSSEC is the sharpest edge. A change with an uncoordinated DS record takes the domain off the internet for every validating resolver. Remove the DS record, wait out its TTL, transfer, re-establish signing, then publish the new one.
- The costs people forget. Registry lock must be released and re-established, integrations need repointing, and auto-renew must be re-checked, because a domain that was safely auto-renewing can arrive with auto-renew off.
Switching registrars is low-cost and largely administrative; switching DNS providers is real work carrying genuine outage risk. They are two separate decisions that are often, but need not be, taken together.
Warning signs you are with the wrong registrar
None of these is proof of anything alone. Two or three together, on a domain your business depends on, is enough to start planning a move.
- Getting the authorization code requires a ticket, a phone call, or documentation you would not need in order to change your nameservers. That is more restrictive than the Transfer Policy permits.
- Locks you cannot toggle yourself, or locks applied beyond those the policy contemplates.
- Renewal, restoration and post-expiration fees you cannot find published. The Expired Registration Recovery Policy requires all three to be reasonably available on the website, and resellers must display them too.
- Renewal notices you cannot recall receiving. The policy requires one roughly a month before expiry, another roughly a week before, and at least one within five days after.
- No two-factor authentication, no role-based sub-accounts, no per-domain permissions, no IP allow-listing.
- A support desk that changes your contact details without seriously verifying who you are, and no emergency route for a suspected hijacking.
Common questions
What is the best domain registrar?
There is no single answer, because the criteria that matter depend on what you hold and what you would lose if it failed. Evaluate renewal pricing per extension, transfer friction, DNS quality, available locks, account security controls and support hours, rather than a first-year headline figure.
Does ICANN accreditation mean a registrar is trustworthy?
It means the registrar met technical, operational and financial criteria at accreditation, is bound to ICANN's consensus policies, escrows registration data with a third party, and is subject to ICANN Compliance. It says nothing about service quality, uptime, pricing or how it will treat you commercially.
Can a registrar charge me a fee to transfer my domain away?
ICANN's Transfer Policy does not address transfer-out fees, so it neither permits nor prohibits them. It does exclude non-payment of such a fee from the enumerated grounds on which a transfer may be denied, and it requires the authorization code to be supplied within five calendar days. Whether a fee applies is a matter of the registrar's own terms.
Why is my domain renewal more expensive than the first year?
Because introductory and renewal pricing are independent variables and only the renewal recurs. A first-year price at or below wholesale cost is an acquisition strategy, and renewal pricing is usually discretionary and changeable on notice.
Should I keep my domain, hosting and email with the same company?
It is defensible if that vendor is well run and you enforce multi-factor authentication, but it concentrates risk: one account compromise, one billing failure or one vendor outage takes everything at once. The non-negotiable is keeping your recovery mailbox on an independent domain at an independent provider.
How do I find out whether my registrar supports registry lock?
Ask directly, and ask which extensions it covers, what the unlock procedure and hours are, and how long an authorized unlock takes. Registry lock is offered by the registry but can only be used if your registrar is set up to submit and authenticate unlock requests.