Ownership and access
Who should own your domain name?
Domains should sit with the business — not a freelancer's personal account. How ownership, renewals, and DNS control protect you.
Josh
The domain name is not a line item on a developer’s invoice. It is the deed to your address on the internet. When it lives in a freelancer’s personal registrar account, an agency’s master login, or a former employee’s Gmail, the business does not truly control its own front door — even if the website looks fine today.
We see this on intake constantly: “Our site works, but we cannot renew the domain” or “We do not know who has the login.” Those are ownership problems, not hosting problems. They become emergencies at renewal time, during a dispute, or when someone leaves and stops answering messages.
What domain ownership actually means
Owning a domain is three separate powers bundled together:
- Registrar account access — the login where the domain is registered, billed, and renewed.
- DNS control — the ability to point the domain at your website, email, and third-party services.
- Transfer authority — the ability to move the domain to a different registrar or account if needed.
You can have a working website while missing one or more of these. That is the trap. Everything appears normal until you need to change DNS, prove ownership to a host, recover from hijacking, or renew after a card expired on someone else’s profile.
The business — not a contractor, not a spouse’s personal account, not a shared “webmaster@gmail.com” inbox — should hold all three.
Why freelancers and agencies often hold domains
It usually starts with convenience. Someone offers to “handle everything,” registers the domain under their own account to save ten minutes of client onboarding, and years pass. Sometimes it is intentional: holding the domain creates leverage for future work or makes offboarding painful.
Neither reason is acceptable for a business-critical asset. A professional can manage DNS without owning the registration. Good handoffs use:
- A registrar account in the business legal name (or a clearly business-owned login).
- The business credit card or billing profile on file.
- The contractor added as a technical contact or delegated DNS admin — not the sole registrant.
If your current setup is the opposite, treat correction as a priority project, not a someday task.
Renewals: where silent failures happen
Domain registration is a subscription with a hard expiry date. Miss it and the site can vanish from DNS — even if hosting and WordPress are healthy.
Common renewal failure modes:
- Auto-renew is on, but the card on file belongs to a person who left three years ago.
- Renewal notices go to an inbox nobody monitors.
- The domain is set to manual renew because someone feared accidental charges.
- Privacy or WHOIS masking hides the real owner from the business itself.
Put renewal on a business-owned registrar login with a business payment method and two people who receive billing alerts. Calendar the expiry date anyway — auto-renew can fail when registrars change policies, cards expire, or accounts get flagged for verification.
This is one row in a proper business digital-asset inventory. If you cannot fill in “registrar, login email, renewal date, payment method” in five minutes, you are exposed.
DNS control: your traffic steering wheel
DNS tells the world where to send visitors and mail. Whoever controls DNS can:
- Point the website to a new host (migration or sabotage).
- Redirect traffic to a competitor or phishing page.
- Break email by changing MX records.
- Add verification records for Google, Microsoft, or payment providers.
DNS does not need to live at the same company as registration, but someone accountable to the business must control it. Cloudflare, the registrar, or the host panel — pick one primary place and document it.
If a former developer still holds DNS at a personal Cloudflare account, read what happens when a former developer controls your hosting — the same dynamics apply even when the server login is fine.
Red flags that the business does not own the domain
Stop and fix ownership if any of these are true:
- WHOIS or registrar records list a contractor’s name with no business entity.
- Password resets for the registrar go to a personal email — see which accounts should never use personal inboxes.
- You pay someone annually to “keep the domain” instead of paying the registrar directly.
- Nobody at the company can log into the registrar without asking an external party.
- You are not sure whether the domain locks against transfer or who holds the auth code.
The fix is not necessarily a confrontation. It is a structured transfer: create a business-owned account, initiate a transfer or internal move, update billing, and revoke the old login once verified.
How to move a domain to business ownership safely
Work in this order:
- Identify the current registrar and registrant — use ICANN Lookup and your last invoice if needed.
- Create a business-owned registrar account — use a role-based email like
admin@yourdomain.comorit@yourcompany.com, not a personal Gmail. - Unlock transfer if moving registrars — obtain the authorization (EPP) code; expect a few days of propagation.
- Lower TTL on DNS records a day before changes if you will repoint services — reduces downtime during migration.
- Transfer or reassign — complete the move; confirm auto-renew and billing on the new account.
- Document — add the domain to your inventory with login location, renewal date, and DNS host.
- Remove contractor access — after cutover, delete their user or rotate credentials if they should no longer manage DNS.
If the current holder refuses, you may need legal escalation with registration proof, trademark evidence, or agency agreement language. That is slow and expensive — another reason to fix ownership before a dispute.
Who should manage DNS day to day?
Ownership and operations can split:
- Business owner or ops lead — owns registrar billing and can remove vendors.
- Technical partner or Care provider — manages records, monitors SSL, handles migrations.
- No single human as sole gatekeeper — break-glass credentials in a company password manager.
Managed care works best when the business holds the keys and delegates thoughtfully. Care can keep WordPress stable, but it cannot renew a domain locked in someone else’s personal account without a recovery project first.
The bottom line
Your domain should sit in an account the business controls: business billing, business-monitored email, documented recovery path, and DNS you can change without permission from a ghost.
Contractors should build on your land, not keep the deed in their drawer. Fix ownership during calm weeks — not the night before expiry, not mid-emergency, not after a relationship ends. The rest of your stack — hosting, email, SSL, analytics — all assume the domain is yours. Make that assumption true on paper and in the registrar panel.
Related in Ownership and access
-
Ownership and access
Which website accounts should never use an employee's personal email?
Personal Gmail on domain, hosting, or payments creates silent lockouts when people leave. Which accounts need business-owned email.
-
Ownership and access
How to create a business digital-asset inventory
Build a living list of domains, hosting, DNS, email, analytics, and SaaS logins — owners, vendors, and recovery paths included.
-
Ownership and access
What happens when a former developer controls your hosting?
When hosting, DNS, or admin logins stay with a past developer, renewals and emergencies become someone else's lever — how to regain control.