A transfer lock does not protect every domain change. Compare registrar and registry restrictions, approval contacts, DNS boundaries, and post-win handoff checks.
A registrar dashboard can say a domain is locked without telling you everything that is protected. A transfer restriction, a registry-level change restriction, and the security of your DNS hosting account are different controls. The short answer: a registrar transfer lock does not prove that every domain change is protected.
Registry Lock adds a registry-level approval process for covered operations, but the scope, authorized contacts, and change procedure depend on the registry and provider. Before a newly acquired domain becomes business-critical, document who can request a change, who must approve it, and how you will verify the result.
Registrar lock and registry lock are different layers ICANN's EPP status guide distinguishes client codes set by registrars from server codes set by registries. Server restrictions take precedence over client codes. Removing a registrar-side restriction therefore does not clear a separate registry-side restriction.
Transfer restriction: clientTransferProhibited tells the registry to reject an inter-registrar transfer. That code alone does not establish that updates or deletions are blocked. Other registrar restrictions: clientUpdateProhibited and clientDeleteProhibited address updates and deletions separately. A provider's general label of "Registrar Lock" may cover more than its transfer toggle.
Registry restrictions: serverTransferProhibited , serverUpdateProhibited , and serverDeleteProhibited restrict those respective operations at the registry. The registrar must coordinate with the registry when a legitimate change requires a restriction to be lifted. A server prohibition is not, by itself, proof that someone enrolled the domain in a commercial Registry Lock service.
ICANN describes other reasons for these statuses. Ask the provider to confirm the actual cause and service enrollment rather than diagnosing it from a single code. Also, do not confuse a lock with serverHold . ICANN describes that status as a domain not being activated in DNS, not an extra security badge. Who approves a registry-locked domain change? There is no single contact sequence to assume across every TLD.
A useful concrete example is DENIC's .de Registry Lock . Its published process assigns different roles: The domain holder checks the stored data, requests the service through the provider, and designates a lock contact. The provider is the holder's first point of contact and forwards setup or change requests to DENIC.
DENIC checks the request and seeks the lock contact's confirmation when the check succeeds. The lock contact receives an approval token on the recorded mobile number and a message at the recorded email address. The contact authorizes the change by confirming the request to DENIC with the token. DENIC says an unconfirmed request is rejected after seven calendar days.