ok status

The domain has no pending operations and no restrictions, so it can be updated, renewed, transferred or deleted normally.

ok at a glance
EPP status codeok
RDAP statusactive (per RFC 8056)
Set byRegistry (automatic)
CategoryLifecycle and pending status
Defined inRFC 5731
ICANN referenceicann.org/epp#ok

What ok means

ok is the standard status of a domain name that is working normally. It means the registry has no operation waiting to complete for the domain (no transfer, renewal, deletion or update in progress) and that no prohibition or hold status is set on it.

In RDAP responses the same status is called active. RFC 8056, which maps EPP statuses to RDAP, translates EPP ok to RDAP active, so a WHOIS record showing ok and an RDAP record showing active describe exactly the same state.

The registry adds and removes ok automatically. As soon as the registrar or the registry sets another RFC 5731 status (a lock such as clientTransferProhibited, a hold or a pending operation), ok disappears, and it returns when those statuses are removed. Of the RFC 5731 statuses, only inactive may appear together with ok.

Grace-period statuses are different: addPeriod, renewPeriod, autoRenewPeriod and transferPeriod are reported through the RFC 3915 grace period extension and appear alongside ok rather than replacing it.

Official definition: ICANN, EPP Status Codes: What Do They Mean, and Why Should I Know? (ok)

Why a domain has this status

  • Nothing unusual is happening: the domain is registered, no operation on it is pending and no lock or hold is set. It may still be in a grace period, such as the few days after it was registered or renewed, which shows up as a separate status next to ok.
  • The registrar has not applied any of its optional locks (transfer, update or delete prohibited), and the registry has not set any restrictions of its own.

What you should do

  • Nothing is wrong. A domain with status ok works normally as long as it has name servers.
  • Consider turning on your registrar's domain lock. ICANN points out that statuses such as clientTransferProhibited, clientDeleteProhibited and clientUpdateProhibited help prevent unauthorized transfers, deletions and changes.
  • Keep an eye on the expiration date: ok says nothing about how long the registration has left. Look the domain up to see its expiry date, and read our domain expiration guide to learn what happens if it lapses.

Check a domain's status

Look up any domain to see its current status codes, registrar, expiration date and name servers from the registry's RDAP or WHOIS service.

  • clientTransferProhibited: The registrar has locked the domain against transfers to another registrar, the standard protection against domain hijacking.
  • inactive: The domain has no name servers delegated at the registry, so it is not published in DNS and does not resolve.
  • addPeriod: The domain was registered within the last few days (usually 5 for gTLDs) and is in its add grace period. This status is informational only.

Frequently asked questions

Is the ok domain status good?

Yes. ok means the domain has no pending operations and no restrictions, so it can be renewed, updated or transferred normally. The only drawback is that nothing blocks an unauthorized transfer, which is why many registrars add clientTransferProhibited by default.

What is the difference between ok and active?

There is none. ok is the name used in EPP and WHOIS output, and active is the RDAP name for the same status, as defined in RFC 8056.

Why doesn't my domain show the ok status?

The registry removes ok as soon as another RFC 5731 status is set: a lock, a hold or a pending operation. A domain that shows only the registrar's transfer, update and delete locks is still working normally; it simply has those protections turned on. Grace-period statuses such as addPeriod do not remove ok; they appear alongside it.

Further reading