Here is a question we ask every new client, usually in the first meeting: who owns your domain name? The answers we get range from “we do, obviously” to “our web guy handles that” to a long pause. That pause is the one that worries us.

Whatever the legal fine print says, the practical answer to “who owns your domain” is simple. It is whoever can log into the registrar account. Not whoever paid for it. Not whoever the invoice is addressed to. Not whoever has it on a business card. The person holding the login is the person with control, and if that person is not you, you have a real problem sitting quietly in the background.

Your Domain Is the Foundation, Not a Detail

People think of a domain as the address of the website. It is much bigger than that. The domain is the root of your company’s digital identity, and several critical systems hang off it.

Your email runs on it. The records that tell the internet where to deliver mail addressed to your company live in your domain’s settings. Your website points to it. Your security records that keep others from spoofing your email live there too. In a lot of businesses, single sign-on and app logins are tied to the email domain as well.

Follow that chain and you land somewhere uncomfortable. Whoever controls the domain can redirect your email. Whoever controls your email can request password resets for nearly every other service you use, because password resets go to email. The domain sits above your entire technology stack, and it is usually the least defended thing you own.

The Horror Scenario Is More Common Than You Would Guess

It almost always starts innocently. A web designer builds the site in 2014 and registers the domain under their own account because it is faster than walking a client through signup. An office manager sets it up with their personal email. An IT contractor bundles it into their own registrar account with fifty other clients. Nobody is scheming. It is just convenience.

Then time passes. The designer moves on, the office manager leaves on bad terms, the contractor retires or the relationship ends badly. Now the thing your email depends on is controlled by someone who does not work for you, might not answer your calls, and in the worst cases knows exactly how much leverage they have.

Recovering from this is not impossible, but it is slow and it is at someone else’s mercy. ICANN’s guidance is that to update the registrant information or transfer a domain to a different registrant, you contact the registrar the domain is registered with. If you cannot log in, that conversation starts with proving who you are to a company that has no record of you. Transfers are also gated on approval. ICANN describes the process as the registrar confirming your intent using an authorization form, and notes plainly that if you do not respond or return the form, your transfer request will not be processed. Whoever holds the registrant email address holds a veto.

How to Check Your Ownership Today

This takes about ten minutes and you can do it right now. Do not delegate it. The point of the exercise is confirming that you personally can get in.

  1. Find out who your registrar is. A public domain lookup will name the registrar of record, which is the company the domain is actually registered with. Note that this is often not the same company that hosts your website or your email. Registrar, web host, and DNS provider are three separate roles that people constantly assume are one.
  2. Log in yourself. Go to that registrar and sign in with credentials you hold. If you do not have credentials, or the only way in is to text someone, you have found your answer and it is not the one you wanted.
  3. Check the registrant email address. Open the domain’s contact details and confirm the registrant email is a mailbox you control and monitor. This is the single most important field on the page. Renewal notices and transfer approvals go there.
  4. Check the expiration date. Write it down. Then keep reading, because you are about to make it matter less.

One timing note before you start changing things. ICANN requires registrars to impose a lock preventing transfer to another registrar for 60 days following a change to a registrant’s information, and registrars also have the option to deny a transfer request within 60 days of the domain’s last transfer. So if you plan to both correct the registrant details and move to a new registrar, sequence those moves deliberately rather than doing everything on the same afternoon.

Five Settings to Turn On Once You Have Control

  • Registrar lock. This flag blocks the domain from being transferred away. ICANN’s transfer guidance lists lock status as a valid reason for a registrar to deny a transfer request, and requires registrars to give name holders a readily accessible and reasonable way to remove the lock when they legitimately need to. Leaving it on costs you nothing and stops a whole category of theft.
  • Auto-renew, with a payment method that will not expire. Domains lapse for the dumbest reason imaginable: an old credit card on file. Businesses lose their email over a card that expired.
  • Multi-factor authentication on the registrar account. The registrar login deserves the strongest protection you have, because it sits above everything else. If you are weighing the options, we compared them in YubiKey vs Passkey vs MFA.
  • A monitored mailbox on the account. Registrar notices should land somewhere more than one person reads. Not a departed employee’s inbox, and not a personal address.
  • Respect for the authorization code. ICANN describes the Auth-Code as a code created by a registrar to help identify the domain name holder and prevent unauthorized transfers, and says your registrar must provide it within five calendar days of your request. Treat it like a password, because functionally that is what it is.

Write Down Your DNS Records

The last piece is the one people skip. Your DNS records are the settings that route mail to your email provider, point visitors to your website, and prove your email is legitimate to other mail servers. They are usually configured once, by someone else, years ago, and never documented.

Export or screenshot the full record list and store it somewhere your team can find it. It costs ten minutes now and saves hours during a migration, an outage, or the day you discover your email is going somewhere unexpected. If you have never seen this list, that is exactly the reason to go look.

The Bottom Line

Domain control is not a technical detail to hand off. It is a business asset, and it belongs in the same mental category as your bank account and your business filings: something the owner controls directly, even if someone else does the day to day work on it. Your MSP or web developer should absolutely help manage it. They should not be the only ones who can get in.

Nothing here requires a project or a budget. Log in, confirm the registrant email is yours, turn on the lock, turn on auto-renew, add strong multi-factor authentication, and save your DNS records. If you want the hardware key version of that last step, we explained it in What Is a YubiKey. One afternoon removes a risk most businesses do not know they carry.

If you are not sure where your domain lives, who holds the account, or what your DNS records should look like, we help businesses across Denton County untangle exactly this and hand the keys back to the owner. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).