Who controls your domain, DNS, hosting and recovery accounts?

A website can be lost without a single technical failure. The domain sits in a former supplier's account, the only administrator has left, the recovery mailbox is one nobody can open, or the card on file quietly expired. None of this is dramatic — it's paperwork nobody kept track of — and it can take a business offline for weeks.

Make the business the owner

Your domain, DNS, hosting and business email are assets. Treat them like the lease on your premises.

  • The business is the registered holder. The registrar's records should name your company — not an employee, freelancer or agency — as the domain holder, and the business should have direct access to the registrar account or, at minimum, an independent way to obtain the transfer code and move the domain.
  • Keep each service in a company-controlled customer or organization account. A supplier may manage it day to day, through its own named or delegated login — but it should never be the registered holder or the only party able to transfer, renew or recover the service.

Spread the keys — without sharing them

  • Give each administrator a named account where the provider supports it. A shared username can't be revoked for one person, and hides who changed what.
  • No critical account should depend on one person. Two named administrators is the ideal; where a provider only allows one, keep a tested emergency-recovery procedure, with the recovery codes in a company password manager that the right people can reach. Never let a former employee's phone, authenticator app or personal email be the only way back in.
  • Turn on MFA everywhere, preferring phishing-resistant methods — passkeys or hardware security keys — where available.
  • Use a recovery mailbox that survives the failure it protects against: an address at a separate provider or on an independently managed domain. Then check that every contact field — holder, recovery, billing, security notices — leads to someone who will act. (Renewal mechanics, transfer locks and DNSSEC are tip 2's territory.)

Keep an account inventory

Write down every service the website depends on — registrar, DNS, hosting, email, and any CDN, proxy or security service — and for each one: the customer or organization account it's held under, the named administrators, the recovery route, the billing owner, and who is responsible for renewal. Keep passwords out of the inventory; those live in the password manager. Review it once a year and whenever an employee, agency or IT supplier joins or leaves.

Remove access when relationships end

Offboarding is where control quietly leaks. When an employee, freelancer or agency no longer needs access: remove their accounts promptly, transfer ownership of anything they created or registered, review recovery addresses and MFA methods, revoke API keys and active sessions, rotate any credential that had to be shared — and update the inventory.

Also enable change notifications where the service offers them — new logins, password or MFA changes, nameserver changes, transfers, billing failures — delivered to more than one monitored address, so you notice a problem before it becomes a lockout.

Set the accounts up correctly, document them, and review access whenever people or suppliers change. The goal is simple: no single person, mailbox or company should be able to take your website with them.

What to do

  1. Confirm your business is the registered holder and contract owner at the registrar, DNS, hosting and email providers.
  2. Give every administrator a named account and turn on MFA — passkeys or hardware keys where available.
  3. Make sure no account depends on one person: a second admin, or a tested recovery procedure with securely stored codes.
  4. Point recovery and billing contacts at monitored addresses that don't depend on the domain itself.
  5. Write the account inventory; review it yearly and whenever people or suppliers change.
  6. Offboard promptly: remove access, transfer ownership, revoke keys and sessions, rotate anything shared.

Frequently asked questions

My web designer set everything up. Do I actually own my domain?
Not necessarily. If the domain was registered inside the agency's own account, or with the agency as holder, they control it — log in to the registrar yourself and confirm your business is the registered holder. A supplier can keep managing the domain through its own delegated access, but ownership and the ability to transfer must stay with you.
What is a recovery email and why does it matter so much?
It's the address a service emails to reset a lost password or confirm a login. If it points to a personal mailbox, a former employee's inbox, or an address on the very domain you're locked out of, recovery becomes impossible. Use a monitored business address at an independent provider, not one hosted on the domain you're securing.
What should happen when an employee or supplier leaves?
Remove their access promptly, transfer ownership of anything registered in their name, review recovery addresses and MFA methods, revoke sessions and API keys, and update your account inventory. Do it as part of offboarding, not when access is urgently needed.

Was this helpful?

Questions about your own site? Get in touch — we read every message.

Source: “Who controls your domain, DNS, hosting and recovery accounts?” — https://www.siteadvice.be/tips/who-controls-your-accounts/ · © 2026 EUREGIO.NET AG. All rights reserved.