ChangeIssue

One reason a change was refused, with what to do about it.

Refusal reasonsEvery value code can carry, the next_step that comes with it, and what clears it. | Code | Next step | What it means | How to clear it | |------|-----------|---------------|-----------------| | not_sponsored | contact_support | The domain is not a registration we manage, so there is nothing here to change. | Nothing on your side clears it. | | not_external | update_request | The domain is not a record of a name held at another registrar, so there is no record to drop. detail names the kind. | A domain registered through us ends a different way; contact support. | | domain_expired | renew_domain | The registration is past its expiry date. | Renew it, then submit the change again. | | domain_locked | clear_lock | A lock on the domain prohibits this operation. detail names the lock. | Clear the lock in the same body: {"locks":{"update":false}} beside the change runs the unlock first. A server-prefixed lock is the registry's and is not yours to clear. | | pending_transfer | await_registry | A transfer of the domain is in flight, and the registry takes no change until it settles. | Wait for it to settle. | | no_pending_transfer | update_request | The change answers a transfer nobody has requested on this domain. | Nothing to answer; read the domain's transfers first. | | transfer_not_answerable | update_request | The transfer the change names is not the one open on this domain. | Read the domain's transfers and name the open one. | | transfer_already_answered | await_registry | This transfer already carries an answer the registry is acting on. | Wait for it to settle. | | transfer_window_elapsed | await_registry | The registry's deadline for answering this transfer has passed. | Nothing on your side clears it; the transfer is completing. | | pending_delete | await_registry | The registry is removing the name. | Nothing on your side clears it. | | pending_operation | await_registry | An earlier command against this domain has not resolved yet. | Wait, then submit again. | | change_in_flight | await_open_request | Another open change already holds the part of the domain this change needs. | Wait for the change named in conflict.change_request_id. | | update_unsupported | contact_support | This TLD's registry does not accept changes of this class through us. | Nothing on your side clears it. | | dnssec_unsupported | contact_support | This TLD's registry runs no RFC 5910 data interface, so no DNSSEC material can be published for the name. | Nothing on your side clears it. | | dnssec_interface_mismatch | update_request | The request states its DNSSEC material through the data interface this TLD's registry does not run, or attaches a DNSKEY to a DS record where the registry does not verify one. detail names what to send instead. | Send the set detail names and submit again. | | dnssec_digest_type_unsupported | update_request | A DS record the request publishes uses a digest type this TLD's registry does not accept for new material. detail names the accepted types. | Recompute the DS record with an accepted digest type and submit again. | | dnssec_algorithm_unsupported | update_request | A record the request publishes names a DNSSEC algorithm this TLD's registry does not accept for new material. detail names the accepted algorithms. | Re-sign the zone with an accepted algorithm and submit again. | | dnssec_ceiling_exceeded | update_request | The DNSSEC set the request publishes holds more records than this TLD's registry accepts on one domain. detail names the count and the ceiling. GET /tlds reports the ceiling under dnssec.max_records. | Publish fewer records and submit again. | | host_ceiling_exceeded | update_request | The subordinate-host set, or one host's glue address list, exceeds this domain's TLD policy ceiling. detail names the value. | Shrink the set or the glue list and submit again. | | tld_not_serviced | contact_support | We do not service this TLD, so there is no policy to judge the change against. | Nothing on your side clears it. | | stale_base_version | resubmit | The domain moved after the change was composed, so base_version no longer matches. | Re-read the domain and submit again. | | registrant_lock_window | await_lock_window | A recent registrant change bars the transfer away this change asks for. | Wait for the window to lapse. | | contact_unusable | configure_contact | A contact the change names is missing, belongs to another organization, or is incomplete for this registry. | Complete or replace the contact. | | team_unusable | update_request | A team the change names is missing, belongs to another organization, or was deleted. detail names the id. | Name a team of your own organization and submit again. | | team_contact_missing | configure_team | Moving the domain to this team would empty a role the registry requires: the domain's contact for it still follows its team, and the team it is moving to names none. detail names the role. | Give the target team that contact, or set the domain's own first. | | host_unknown | create_host | A host the change names is not one we can present to the registry: a nameserver inside the registry's own zone that it holds no host object for, whether or not the parent is yours, or a subordinate host named outside the domain it is being recorded against. detail names the host. | Have the host created at the registry, or name one under the right domain, then submit again. | | host_still_delegated | update_request | The change removes a subordinate host this domain's own nameservers still delegate to. detail names the host. | Drop it from the removal, or repoint the delegation away from it first. | | payload_invalid | update_request | A field in the request is not usable as sent. detail names the value. | Correct the field and submit again. | | payload_unchanged | update_request | Every field the change names asks for the state the domain is already in. | Nothing to do; the domain already reads that way. A field that is redundant beside one that is not refuses nothing. | | unsafe_kind_combination | split_request | Two fields in one request cannot be applied safely in either order. | Send them as separate requests. | | stage_unsatisfiable | fix_rule | An approval rule names a set of people nobody can satisfy. | Ask an administrator to correct the rule. |

  • Resource type identifier

  • What is wrong. Branch on this.

    values
    • not_sponsored
    • not_external
    • domain_expired
    • domain_locked
    • pending_transfer
    • no_pending_transfer
    • transfer_not_answerable
    • transfer_already_answered
  • The remedy. Stable enough to route on.

    values
    • contact_support
    • renew_domain
    • await_registry
    • await_open_request
    • await_lock_window
    • resubmit
    • clear_lock
    • update_request
  • The specific value at fault. Written for a person; never parse it.

  • Which part of the change is at fault, when only one part is. Absent when the whole request is.