A-R53-14

ICANN Domain Status is Indicating a Transfer

Risk:
High
CWE:
None

Domains marked as 'pendingTransfer' should have their transfer request confirmed as legitimate or cancelled and the domain locked if not intended


Details

Domains provide the backbone for all online services. ICANN (the Internet Corporation for Assigned Names and Numbers) is the ultimate authorative body for domains and the individual registrars and hold their own records tracking the status of domains. This tracking is useful for monitoring domains that are migrating between registrars and serves as a definitive source of truth regarding the status of a domain.

The status pendingTransfer means that ICANN is tracking an outstanding transfer request to migrate the domain to a new registrar.

If this transfer is intended, it indicates that the process is not yet complete and there may be further action needed from your current registrar, your destination registrar, or yourself. Best to check and track this process.

If you do not intend to transfer this domain, it’s possible that either an old transfer request has not been completed or that there’s an illegitimate transfer request made against the domain that should be cancelled. You should investigate the situation as your ownership of the domain is considered in a transitional state by the ultimate domain authority.

Remediation

You can contact your registrar to find out the details of the transfer request which you can then follow up with inside of your organisation to determine if the transfer is legitimate and intended. If the transfer is not intended, then contact your registrar and confirm a denial of the transfer request. You’ll also want to determine what transfer locks you can enable for the domain and to proceed to enable them to prevent this occurring again.

SkySiege’s Cloud Assessments detect the status of all your registered domains and can find out if any of your domains have pending transfer requests. Get an assessment today and discover the status of your domains:

Discover if you're vulnerable

SkySiege Cloud Security Assessments scan for this issue and provide same-day reports..
Available for individual projects or organisations.

Related Tests