Who Actually Owns Your Website?
When we start working with a new organization, the first month is mostly inventory. Not the interesting work — just finding out what already exists and who controls it.
It is consistently the part that surprises people. Not because anything is wrong, usually, but because nobody has ever written it down. The website works, the email arrives, the bills get paid, and so nobody has needed to ask who actually holds the keys.
Then someone leaves, or a card expires, or a designer stops answering email, and it turns out the answer matters quite a lot.
The first thing worth knowing is that “my website” is not one thing. It is at least four, and they are often controlled by four different people.
The domain name
Your address. Registered with a registrar — GoDaddy, Namecheap, Cloudflare — and renewed on a schedule. The single most important one.
The hosting
The computer your site actually lives on. Often a different company from your registrar, and frequently signed up for by whoever built the site.
The email
Usually separate again. Google Workspace, Microsoft 365, or bundled with hosting. Losing this hurts faster than losing the website.
The site itself
The WordPress or Squarespace login, and everyone who has one. Including people who left in 2019.
You can lose any one of these independently. The most common version we see: an organization has perfectly good access to their WordPress admin, and no idea who registered the domain eleven years ago.
You do not need anyone's help for most of this.
Start with the domain. Go to lookup.icann.org and enter your web address. It will tell you which registrar holds it and when it expires. It will probably not show a person's name — most registrations are privacy-protected now — but the registrar is the useful part.
Then see whether you can log in to that registrar. If nobody at your organization can, that is the finding. Write it down and keep going.
Then the money. This is the shortcut people miss. Pull up your bank or credit card statements and look for the annual charges: the registrar, the host, the email provider. Whoever's card is being charged is usually whoever controls the account. If none of those charges appear on any card you control, someone else is paying — and that someone else has the account.
Then the accounts. Log in to your website's admin and look at the user list. Most systems have one; in WordPress it is under Users. Read the list properly. Ask about anyone you do not recognise.
Then write it down. One page. What exists, where it lives, who administers it, what it costs, when it renews. That page is worth more than it looks.
Almost every organization we have done this with finds at least one account belonging to someone who is no longer involved. A staff member who left. A volunteer. A vendor from two websites ago.
This is normal and it is not usually sinister. People leave, and nobody's job is to remember which logins they had. But it is worth fixing, for a reason that has nothing to do with trust: those people are no longer expecting your problems. If your site goes down on a Friday and the only administrator account belongs to someone who moved to Denver in 2021, the issue is not that they are hostile. It is that they are on holiday and do not answer.
Remove the access. Keep it friendly. Most people are relieved to be taken off a list they forgot they were on.
You are not aiming for anything elaborate. Good looks like this:
The domain is registered in the organization's name, not an individual's, and definitely not a former vendor's. It renews automatically on a card that will not expire when a staff member leaves. Two people can get in.
You know where the site is hosted and can prove it. Someone other than your web person can log in if they have to. There is a written list, kept somewhere findable, of what you have and who runs it.
None of that requires you to understand how any of it works. It only requires that somebody wrote it down.
You probably will, and it is almost always recoverable. Domains can be transferred. Hosting can be moved. Access can be recovered, though it is easier while the person who set it up is still returning your calls — which is a decent argument for doing this exercise on a quiet Tuesday rather than during an emergency.
The organizations that struggle are not the ones who found a problem. They are the ones who found it three years later, at the worst possible moment, with a lapsed domain and nobody to ask.
If you would rather not do this alone, it is the first thing we do with any new client — there is a short form that walks through it, or you can just get in touch. But genuinely, most of it is twenty minutes and a credit card statement. Worth doing either way.