Domain portfolio consolidation: how to plan your domain migration
Running a large domain portfolio across several registrars is not always reasonable. It pays off to bring it together under one roof. Learn how to consolidate your portfolio by migrating your domains without interrupting your web or mail services.
Published by
Simone Catania
Date
Many organizations own 50, 500 or even 5,000 domains across three or four providers and without a clear process lose track of the general view. Deciding to consolidate the entire domain portfolio justifies the effort. This is possible without interrupting the services these domains carry, even for a second.
This article explains why domain portfolio consolidation pays off, when it’s not worth it, and how to run the domain migration safely in six phases.
What domain portfolio consolidation means
Domain portfolio consolidation is the process of migrating all your domains to a single registrar. This way, you should be able to manage all your domains with renewals, settings and security all in one place.
There are three layers of information of a domain portfolio
- Registration: Who the registrar is, who sends you the invoice and where, the contact person at your organization
- DNS: Which nameservers answer queries for your zone and resolve your website and mail.
- Governance: Who has access to the portfolio within the organization with what audit trails.
Why domains get spread across different providers
The causes why a domain portfolio is fragmented across different providers are several. The main ones can be:
- Mergers and acquisitions. Different brands relied on different providers for their domain needs.
- Pricing. Some domains were registered with the cheapest provider at a certain moment.
- Unavailable TLDs: a provider did not offer a certain niche TLD or couldn’t offer local requirements for certain ccTLDs.
- Independent registrations: A marketing team or a regional office registered domains with a different provider.
- Agency and vendor registrations: A web agency, hosting provider, or freelancer (e.g. SEO) registered domains on the company’s behalf. Maybe even in the agency’s own account. Bundled hosting is a typical reason: someone bought a website + domain as a package, so the domain is where the hosting is.
- Legacy registrations: Domains registered 10 or 15 years ago at whichever registrar the then-admin preferred. Many bigger companies grabbed all the domains they could get in order to protect their domain names and block competition or malicious actors from acquiring relevant domains.
- Aftermarket. A domain bought through a marketplace like Sedo often lands in whatever registrar the transaction settled in.
- Personnel change: The person who managed one registrar account left, credentials went with them. Instead of untangling it someone opened a fresh account elsewhere.
When consolidating your domain portfolio pays off
If you use more than one provider, you might end up managing your domains through different dashboards, losing track of renewal cycles and other important settings. If you want to change a DNS record or the billing system, you have to do the same tasks several times in different places, while keeping all your domains with the same security and compliance standards. Consolidating all your domains in one managing system has several advantages.
- Less operational overhead: A contact change or a nameserver change can be executed as a bulk operation for your entire domain portfolio with a single click.
- One security baseline: Transfer Locks, DNS settings, Registry Locks, DNSSEC, all of them can be managed in a single dashboard keeping security policy easy to track.
- Domain lifecycle and billing in one place: Having one single provider means fewer tabs and clicks to monitor your domains and a single invoice and payment method.
- Clear audit: Audit trail becomes easy when all inventory is connected to a single dashboard, where you can change the contact, the role-based permissions and have one consolidated change log.
- Compliance: NIS2 and DORA are EU-wide rules, not national ones, though each member state transposes NIS2 into its own law with its own thresholds. Germany’s version is the NIS2UmsuCG. Article 21 of the NIS2 Directive requires asset management, access control, multi-factor authentication and supply-chain risk management, and domains, DNS zones and your registrar all fall under those headings. A consolidated portfolio produces the evidence directly: one inventory, one access model, one processing relationship. Article 28 puts registration data accuracy and 72-hour disclosure on the registrar, so choosing one with published procedures counts towards your diligence, even though your own obligations stay yours. DORA (Regulation 2022/2554) applies to financial entities and adds a register of ICT third-party providers, with audit rights and an exit plan. Your registrar is one of those third parties. One provider means one entry and one exit plan instead of three or four.
For the wider picture, see our overview of domain management as a discipline for your domain portfolio.
How to migrate a domain portfolio in six phases
Domain portfolio consolidation is nothing more than a domain migration program. We can divide it in six phases.
Phase 1: Create the full inventory of your domain portfolio
It’s important you create the full list of your domain inventory with all essential information, such as which domain lies by what provider, its expiry date, nameserver, whether DNSSC or a Transfer or Registry Lock are activated. To create such an inventory it might be necessary to reach out to different departments. Finance might inform you about recurring payments to a registrar you were not aware of, marketing might have registered a domain for a quick landing page, legal might have a list of domains the brand needs to protect. Pair this activity with continuous domain monitoring.
Phase 2: Classify your domains and decide what to keep
Having a classification ranking of your domains helps you decide the order of migration and their security standards. You will find out some domains might not be worth moving at all.
- Critical domains carry web traffic, corporate mail or TLS/SSL certificates. A failure here means a critical incident. These are often the candidates for Registry Lock and other high-security measures.
- Defensive domains protect the brand without carrying traffic. Ask if they earn a renewal, or whether domain blocking services get you covered at a lower cost. Our guide to defensive domain registration will help you.
- Dormant domains are parked, redirect-only or no longer in use. You will let them expire rather than migrate them.
Phase 3: Choose the target registrar and domain management platform
Choosing a new registrar or a known one where you will consolidate your domain portfolio is a task on its own. Evaluate candidates against requirements like bulk transfer and management, role-based access, services, TLD portfolio, API, compliance and support. Our overview of domain management tools compares the feature set. Consider AutoDNS: one all-in-one platform for all professional domain needs, with bulk operations, role-based access and an API, on EU infrastructure.
Phase 4: Snapshot the DNS configuration before you migrate domains
Before moving your domains from one provider to the other, export their full zones, even for domains you decide not to migrate. Document the A and AAAA records then resolve your website, the CNAME records aliasing your subdomains, the MX records routing your mail, the TXT records holding SPF, DKIM and DMARC. Our full guide on the DNS records guides you on this topic.
Phase 5: Transfer domains in waves keeping DNS unchanged
Migrating domains and changing DNS settings are two separate operations. A registrar transfer changes who bills you and where you manage your domains. A DNS change decides which nameservers will resolve your domains. Since they are independent from each other, you can transfer your domains while leaving the nameservers exactly as they were, and nothing goes offline. Consolidating DNS is a different task for later.
Order the waves with domains from low risk to high: start with a pilot batch of dormant domains to validate your procedure, then defensive domains. Finally move your secondary live domains, then critical domains attached to web, mail and certificates one at a time.
Reading the status codes that block a transfer
EPP status codes record the state of a domain at the registry. Reading them before a wave prevents most stalled transfers. Our reference on EPP status codes covers all 23.
| Status code | What it means | Who can lift it |
|---|---|---|
| clientTransferProhibited | Your registrar has set a Transfer Lock | You, in your registrar account |
| serverTransferProhibited | The registry has locked the domain, usually via Registry Lock e.g. for 60 days after initial domain registration or last transfer | The registry only, after verification |
| pendingTransfer | A transfer is already in progress | Wait for it to complete or fail |
You can remove a client-side lock yourself. A server-side lock is set at the registry and your registrar cannot remove it, so plan that lift accordingly. The authorization code (AuthCode), also called the Transfer Authorization Code, comes from the losing registrar and is unique for a single domain.
Under the ICANN Transfer Policy as it stands in late 2026, a domain is locked against further transfer for 60 days after a transfer, and after certain registrant data changes. Schedule waves so no domain moves twice inside 60 days, and complete registrant corrections well in advance. Expired domains must be renewed before they can move.
Phase 6: Apply one policy for the whole domain portfolio
After the migration the job isn’t done yet. Locks and permissions do not travel with the domain. For each domain that has been transferred:
- Re-apply the Transfer Lock, and re-establish the Registry Lock on critical domains.
- Make sure SPF, DKIM and DMARC works, and TLS/SSL certificate renewals are set correctly.
- Confirm the domain verification records still validate for every connected service.
- Re-activate DNSSEC if it was disabled, checking the DS record now matches the current keys.
- Set role-based access to the new domain management tool for IT, legal and marketing including two-factor authentication.
- Confirm auto-renewal and billing information.
Domain portfolio consolidation is complete when all domains carry the same protection measures, the access model has been defined, and platform settings have been confirmed.
When not to consolidate the whole domain portfolio
Consolidating the whole domain portfolio under a single registrar is not always necessary. Here are a few examples:
ccTLDs requirements. Some ccTLD registries require a registrant established in the country. You’ll need a trustee arrangement not all providers offer. Our Domain Trustee Service lets you register a ccTLD in those countries where you do not have an office.
TLD not available. The TLD portfolio might differ from registrar to registrar and this is why you need to keep domains split if you have domains under a certain extension. The solution is choosing a registrar with the largest TLD portfolio like InternetX.
Deliberate redundancy. Splitting a few business-critical domains across two providers can be sound resilience, but only if both follow the same security policy and appear in your inventory.
Regulatory constraints. Some domains must remain with a given provider or jurisdiction due to compliance. Record the reason and revisit it if the constraint changes in the future.
There are situations where a consolidation can wait, this is the case of a portfolio with fewer domains. If the company acquisition is not fully closed, it’s worth waiting before having to move everything again. If your company is in the middle of a DNS change, it’s best to wait because if something goes wrong, it’s hard to detect where the problem was. If you couldn’t produce a full documentation of all your domains, start here. Consolidating a portfolio on an incomplete list will require you to analyze the inventory one more time.
3 questions to Marius Wunner, Product Manager B2B Domains, InterNetX
Almost never the transfer itself. Transfers are routine, and if a wave is prepared properly nobody notices it happened. What causes trouble is everything nobody wrote down. A TXT record for a service somebody set up four years ago, a CAA record that only matters the next time a certificate renews, a Registry Lock that has to be lifted at the registry and takes longer than the customer planned for.
The other one is impatience with the critical domains. Teams want to move the main domain first, because that is the one that bothers them. I always ask them to move it last. Once you have run three waves you know where your own process is weak, and you would rather find that out on a domain nobody is using.
Ask who actually does the work. Some providers give you a platform and wish you luck. With a domain portfolio of a few thousand domains spread over three or four accounts, the planning is the difficult part. That is where a Partner Success Manager earns their keep. Ours go through the TLD portfolio, the lock statuses and the DNS dependencies before anyone requests a single AuthCode.
Then the practical things. Does the TLD coverage match where you actually operate, because a portfolio you cannot fully move is not consolidated. Is there a Trustee Service for the ccTLDs that require a local registrant. Is there an API, so the same operation you do once by hand can be repeated across a thousand domains. And where does the data sit, which matters more and more to European customers.
The variety, not the volume. A thousand .com domains is one procedure repeated a thousand times. A thousand domains across sixty TLDs is sixty different sets of registry rules, and that is what enterprise portfolios look like.
Some ccTLD registries need documents, some need a local registrant, some process transfers by hand with their own office hours. A few still ask for a signed form. So a wave that would take five days for gTLDs can run for weeks if you put the wrong extensions in it. We group waves by registry behaviour rather than by business importance for exactly that reason.
The second thing is that large portfolios have history. Domains registered fifteen years ago sit in accounts with contact data that no longer resolves, and you cannot get an auth code sent to a mailbox that does not exist. Fixing the registrant data has to happen first, well before the transfer, or you trigger the 60-day lock at the worst possible moment.
How domain portfolio consolidation supports compliance and audit readiness
A consolidated domain portfolio lets you apply uniform access control, multi-factor authentication, logging and incident response to every domain at once, which is what the NIS2 Directive assumes on asset management and supply-chain risk. Audit readiness follows the same logic: an auditor asks for a complete inventory and evidence of who can change what, and consolidation produces both. On GDPR, one EU-based provider leaves a single processing relationship to document.
Consolidate your domain portfolio with InterNetX

Move your domains onto one EU-based, API-first platform, or talk to a partner manager about your migration.
Frequently asked questions
It is the process of bringing all your domains and their connected services under one registrar and one management platform, so ownership, renewals, DNS and security policy are governed in one place. In practice, it is a domain migration from one registrar to the other.
Yes. A registrar transfer and a DNS change are independent operations. As long as the nameserver delegation and zone contents stay identical, the domain keeps pointing at the same nameservers, so your website and mail continue to resolve.
Current policy locks a domain against further transfer for 60 days after a transfer, and after certain registrant data changes. Sequence waves so no domain moves twice inside that window, and complete registrant corrections before a wave begins. The revision replacing this with a 30-day lock was not implemented as of September 2026.
A single transfer of a generic top-level domain usually completes in about five days, while country-code domains vary by registry. For several hundred to a few thousand domains, plan for several months, since waves need verification and the 60-day lock might influence your actions.
Changing the registrar and the DNS settings at the same time. Both alter how a domain behaves, so when a service stops working there is no way to tell which change caused it. Transfer the registrar first with DNS untouched, verify, then move DNS separately.