On December 1, 2016, ICANN enforced a new Transfer Policy that modified the process of changing domain ownership from one registrant to another. Under this policy, any update to a domain’s registrant contact data must be approved by both the current and new registrant via email. Once both parties have approved the change, each receives a confirmation email that the Change of Registrant is complete. We call this process “Change of Registrant” or COR, for short. What’s important to note is that the current and new registrant are often the same registrant: a simple update to a registrant’s first name, last name, organization, or email address on a particular domain also triggers the same notification and confirmation emails. In May 2018, OpenSRS temporarily suspended our COR process because of concerns around data privacy and GDPR compliance. On March 31, 2020, OpenSRS will re-enable our COR process with a few important changes.
Designated Agent: minimizing the impact of COR
The request-for-approval emails sent to both the current and new registrant have proven to be a nuisance for end-users and reseller support teams. The registrant can have OpenSRS—or, more accurately, Tucows—act as their “Designated Agent” (DA), with the ability to auto-approve requested changes to the registrant’s contact set. Registrants that have DA enabled do not receive COR request-for-approval emails. As a reseller, you can pre-enable the Designated Agent option for all registrants of all future and existing gTLD domains you have with us as a registrar.
How will COR impact your business?
When OpenSRS re-enables COR, changes to the first name, last name, organization, or email address for the owner of any gTLD domain will trigger the COR process. OpenSRS will obtain explicit confirmation from the current and new registrants before completing a change, send completion notices to both parties, and apply a 60-day registrar transfer lock by default after the change. Registrants for whom Tucows is the Designated Agent are auto-approved and do not receive request-for-approval emails.
How is the new COR process different?
The updated process is similar to the version introduced in 2016, with three important changes: Designated Agent can be applied to all future and existing domains; COR will not apply to domains protected with Whois Contact Privacy; and the end-user COR email templates have been updated in the Reseller Control Panel.
How does the new process work?
The reseller submits a request to modify the owner of a domain. OpenSRS checks whether the New Registrant has accepted Tucows as Designated Agent. If so, the change is auto-approved for that registrant; otherwise, OpenSRS sends an approval email. After the New Registrant approves, OpenSRS repeats the check for the Prior Registrant. Once both approvals are recorded, OpenSRS completes the Change of Registrant and sends confirmation to both parties. If either party declines, or the request times out after seven days, the process is aborted and the current owner details remain in place.
How the approval paths differ
The approval path depends on whether the New Registrant and Prior Registrant have already accepted Tucows as Designated Agent. An accepted DA relationship lets OpenSRS auto-approve that side of the request; otherwise, the registrant must approve by email.
Change of Registrant scenarios
Open each scenario to view the process for the matching Designated Agent status of the New and Prior Registrants.
Scenario B
Scenario C
Scenario D
Scenario E
Preparing for the updated COR process
Enable Designated Agent for all existing and future domains in your account. Review the COR-specific API commands in the ICANN Trade documentation. Customize the three COR end-user email templates in the Reseller Control Panel. Update the branding and destination URL used on confirmation pages. Review the COR Knowledge Base articles before re-enablement.
What is a Designated Agent in the context of this policy?
How can I enable the Designated Agent option for my reseller account?
What is the process if both the New and the Prior Registrant have accepted Tucows as a Designated Agent?
What happens if the current registrant email is invalid or not accessible?
How will I know if my request has timed out or has been denied? How will I know when the change is “approved” by the prior and new registrant contact?
Questions our resellers have been asking
Where do I find details about the new APIs that OpenSRS is providing for this policy?
What happens if I don’t re-enable DA at the reseller account level?
Is it correct that once a Registrant accepts Tucows as Designated Agent (DA), the Registrant itself has no way to revert this decision, and only the reseller can disable the DA setting?
Will a Current Registrant be able to accept Tucows as a Designated Agent when confirming a Change of Registrant?
Consider the following scenario: Alice as a New Registrant approves a Change of Registrant and accepts Tucows as a DA. The change completes, and the domain is transfer-locked for 60 days.
Is there any way for Alice to still opt-out of the transfer lock?
As all our existing registrants will have accepted the registration agreement, Tucows will be the Designated Agent and auto-approve Change of Registrant requests for them as the Current Registrant. Due to the auto-approve, they will not have the option to opt out of the transfer-lock. Does this mean that in this scenario the transfer lock will apply to all domains coming out of a Change of Registrant process?
Why do I need to submit a domain name when setting the Designated Agent option for an existing registrant via the modify_trade_lock_setting API?
Can I automatically opt-out of the 60-day transfer lock for all of the domains in my reseller account?
What happens if all I do as a reseller is to update the Registration Agreement to include the Designated Agent option, without implementing any technical changes?
Does this implementation of the new transfer policy also apply to country-code top-level domains (ccTLDs)?
How does this new policy affect using whois privacy on domains?
Am I able to customize the emails that go out to new and current registrants?
Am I able to customize the confirmation page that new and current registrants will see after they click the emails?
End-user FAQs
As we have stated before, this is a complex policy that has the potential to disrupt your current processes. To help your end-customers understand these changes, we have developed questions and answers. This section will constantly be updated to ensure your customers have the most current information.