White-label tools · supported by real people
Domains

Who actually owns your client's domain? (And why it matters more than you think)

Nearly every domain emergency we've been called into starts the same way: nobody knows who owns it. The person who registered it left the business, or it was set up by a mate in 2011, or it's sitting in a personal account attached to an email address that no longer exists. It's fine right up until the moment it very much isn't.

Registration, hosting and DNS are three different things

Most of the confusion comes from treating these as one. They're separate, they can live with three different companies, and each one can break independently.

The registrar

This is who the domain is rented from — nobody owns a domain outright, you hold it on a renewable licence. The registrar holds the registrant record, and whoever controls that account controls the domain.

The DNS

The address book that says "this domain's website lives here, and its email lives over there." DNS often sits at the registrar, but just as often it's been moved somewhere else entirely, which is why a domain can be perfectly valid while the site is unreachable.

The hosting

The actual server the site sits on. Moving hosting doesn't move the domain, and cancelling hosting doesn't release it. These get conflated constantly.

How to find out where you actually stand

For a .au domain, start with a WHOIS lookup at the auDA registry and check the registrant name and the registrant contact. For other extensions, most registrars offer the same lookup. You're looking for three things:

  • The registrant — is it the business's legal entity, or a person? For .au domains the registrant must have a legitimate connection to the name, usually via ABN, so a domain registered under an ex-employee's own details is a problem waiting to happen.
  • The registrant contact email — this is the address that receives transfer approvals and renewal notices. If it's a mailbox nobody reads, you're one missed renewal from an outage.
  • The expiry date — and whether auto-renew is on, and whether the card attached to it is still valid.

The three failures worth planning for

The renewal that silently fails

A card expires. The renewal notice goes to an old address. The domain lapses, the site and the email go down together, and now you're in a redemption period with a recovery fee and a lot of urgency. This is the most common one and it's entirely preventable.

The person who left

A developer or a former staff member holds the registrar account. Relations may be perfectly cordial — but a domain sitting in someone else's account is leverage, and it's leverage that surfaces at the worst possible time.

The DNS change nobody documented

Someone points a record at a new service to test something, forgets, and six months later the email starts bouncing for reasons nobody can reconstruct. Without a record of what changed and when, this is genuinely hard to unpick.

Sorting it out, calmly

You don't need a crisis to fix this. Work through it in this order:

  1. Establish who holds the registrar account and get the credentials into the business's own password manager, not an individual's.
  2. Correct the registrant details so they name the business entity, not a person. This is the step that actually transfers control.
  3. Point the registrant contact at a monitored mailbox — ideally a shared one, not a single person's.
  4. Turn auto-renew on and put a calendar reminder a month before expiry anyway. Auto-renew fails silently when a card does.
  5. Write down the DNS. A simple record of what each entry does, kept with the account details, saves hours later.
  6. Monitor the expiry so a lapse is something you're told about, not something you discover.

If you look after client domains

The cleanest arrangement is the honest one: the client is the registrant, you have delegated access, and everyone knows it. Holding a client's domain hostage is a short-term win and a long-term reputation problem — and holding one accidentally, because it was registered under your account years ago, is a liability you don't need. Get them named properly, keep the access, and put the whole portfolio somewhere you can see every expiry date at once.

Domains and hosting, managed properly

Domains & hosting →
← Back to all articles