Brian Reich

Own Your Domain Name

Quick Summary Your domain is the one asset your online presence hangs on. Why it belongs in your name, what can happen if it's not, and how to get it right from day one.


Seen from inside a darkened shop, a business owner in a work apron stands outside the locked glass door, holding up keys that do not work and looking defeated. Inside, in the foreground, another person stands with their back turned, the working keys hanging from their hand.

The short version

If you run a business, your domain name should be registered in your business’s name, with your name and contact information. The email address should be an account you can log into, even when the domain itself is broken. The domain shouldn’t be registered to your web designer, your tech savant nephew, or even your IT person.

Letting someone else deal with it is today’s minor convenience, paid for with next year’s existential crisis.

When you eventually want to change designers, move your email, or just update contact information, the person holding the domain becomes a gatekeeper. Sometimes that works out. Sometimes they’ve moved on, lost interest, gone out of business, or died. Occasionally they use it as leverage, and getting access to your own stuff costs time, money, and patience.

(Put another way: you can’t conduct business because you gave someone else the only key to your digital storefront.)

Some radical candor before the advice: I have been the problem. Early in my career I registered domains on behalf of my customers — good intentions, strong dose of naivety — and years later I watched some of those people struggle because of it. The full story is at the end of this post. It’s the reason I write about this one with some heat.

So what should you do?

Register it yourself

Create the registrar account yourself. Register the domain name yourself. You own the account and access to it.

Set ownership & contacts

You are the owner, and administrative contact. You can set others as technical, security, and billing.

Delegate access, not ownership

Designers, developers, and IT may need access. Delegate access and permission. Not ownership.

The rest of this post is how to do each of those properly, and what to do if you’re already stuck.

Get it right the first time

This half is about prevention. If you’re already tangled up in someone else’s account, skip ahead — the second half is for you.

Domain ownership

You keep using that word. I do not think it means what you think it means. — The Princess Bride

Let’s start by making it clear what domain ownership does and doesn’t mean. Because it matters when things go wrong.

You don’t own a domain the way you own a desk. In fact, you don’t own a domain at all.

You register a domain. When you register a domain, you purchase the exclusive right to use that domain for a period of time through a company accredited to sell the registration (a Domain Registrar).

What matters practically is who is listed as the Registrant. Sometimes the registrant is referred to as the owner. When rights to use a domain come under dispute, this is the information that truly matters.

Domain registration records can also have Administrative, Technical, and Billing contacts. Those contacts can be set to other people. But the registrant is the one that counts during a dispute and in court, should it ever come to that. That registrant should be your business.

This is where things can go quietly sideways.

A designer registers the domain during a website build, puts their own details in every field because they’re the one filling out the form, and never revisits it. No bad intent. The site launches, everyone is happy. A fact about who owns the domain is set, incorrectly, and the mistake causes damage years later when the person listed as registrant can’t or won’t correct it.

The three recommendations above are the whole defense. Here’s what each one actually involves.

Register it yourself

Create the registrar account before anyone else does it for you. It takes about ten minutes. The registrar account is typically free — you just pay for the domain registration and any other services you buy inside it.

Use the business’s legal name. Not a personal name, not a trade name you might stop using. If the business is an LLC, the LLC is the registrant.

Use an email address you control at a different domain. This is the one people get wrong. If your domain is example.com and your registrar login is owner@example.com, then a DNS problem that breaks your email also locks you out of the account you need to fix it. Use a personal address or a separate business address for registrar contact.

Pay with the business’s card. Whoever’s card renews it has a claim on the account and will get the receipts.

Turn on auto-renew, then register for several years. Auto-renew fails when cards expire. A longer registration term is inexpensive insurance, and it’s a mild positive signal that you’re a real business rather than a throwaway.

Turn on registrar lock and two-factor authentication. Registrar lock (clientTransferProhibited) blocks transfers until you deliberately unlock. Both are free and take a minute.

Set ownership & contacts

Registrars collect several contact roles, and they aren’t decoration. One of them is ownership. The rest are jobs.

  • Registrant — your business. This is ownership. Never delegate it.
  • Administrative — you as well. This contact can authorize changes, including transfers.
  • Technical — reasonable to hand to your developer or IT provider. This is the person who should be getting the DNS alerts.
  • Billing — whoever actually pays. Often you, sometimes a bookkeeper.

Some registrars also expose a security or abuse contact. Same rule applies: it’s a job, not ownership.

Keep WHOIS privacy on, but keep the underlying details accurate. Privacy hides your information from the public, not from your registrar. The real record still needs to be correct — inaccurate registrant data is grounds for suspension.

Write down where it is. Registrar, account email, renewal date. Put it wherever your business keeps its important records. The person who needs this information someday may not be you.

Delegate access, not ownership

“I just want one vendor to handle all my stuff.” — My Typical SMB Customer

I’ve heard this dozens of times in my career, and it’s a completely reasonable instinct. You’re not a technical person. You don’t want a bunch of logins to remember, vendors to manage, renewal notices to understand. You want a dude that just handles that stuff.

You can have that. Mostly.

If you want a single point of contact, that’s a service arrangement with your vendor and it doesn’t require them to have ownership of your domain.

The confusion is between two different things:

  • Who manages it — makes changes, sets up email, handles renewals, deals with the technical mumbo jumbo. Absolutely delegate this.
  • Who holds it — appears as the registrant, controls the account, can authorize a transfer or let it lapse. Never delegate this.

Most registrars support delegated or sub-account access, which covers the first one without touching the second. If yours doesn’t, making the DNS changes your developer requests is a five-minute task a handful of times a year.

A good technical partner won’t want ownership. It’s a liability for them as much as an exposure for you. If someone insists that holding your domain is the only way they can work, treat that as information about the relationship rather than a technical requirement, because it isn’t one.

What goes wrong when you don’t

None of these are hypothetical. Every one is a real pattern.

You want to change providers. The most common one. The relationship has run its course, you have found someone new, and now the transfer requires cooperation from the person you’re leaving. If they’re prompt, this is a week’s inconvenience. If they’re slow or unreachable, your migration stalls indefinitely.

They stop responding. People retire, get sick, change careers, or simply lose interest in a client they haven’t billed in three years. The domain is still theirs on paper, the renewal notices go to an email they no longer read, and nobody is watching.

The renewal lapses. A domain that expires doesn’t vanish immediately, but it does enter a redemption period with a steep restoration fee, and after that it drops. Expired domains with any traffic history get picked up quickly. If the renewal notice goes to someone else’s inbox, you’ll find out when your email stops working.

You cannot prove it is yours. Since GDPR, most registrant details are redacted in public WHOIS records. You may not be able to see who holds your own domain, and a registrar has no reason to take your word over the account holder’s. Being the one who paid for the website doesn’t make you the registrant.

It becomes leverage. The least common and the most unpleasant. A soured relationship plus an asset your business depends on is a bad combination, and the person holding it knows exactly how much it’s worth to you.

Your business is worth less. If you ever sell, a domain registered to a third party is a live issue in diligence — one that has to be resolved before closing, on someone else’s schedule.

How to check what you actually have

  1. Look up your domain at ICANN Lookup. It will show the registrar, the creation and expiry dates, and the status codes. Registrant details are probably redacted — that’s expected.
  2. Go to that registrar’s site and try to log in or reset the password using your email address. If a reset email arrives, the account is likely yours. If nothing arrives, the account is under someone else’s address.
  3. Confirm the expiry date is far enough out that a lapse isn’t imminent.

That’s a ten-minute exercise, and most business owners have never done it.

If you’re already stuck

First: Ask plainly and in writing. Several times. To paraphrase Hanlon’s Razor:

Never attribute to malice what is adequately explained by emails going to Spam.

Most of the time this is inattention, not malice. A client and vendor can drift out of contact for months or years. Often a clear written request to be made the registrant of record resolves it. Give a deadline and keep the paper trail.

If that doesn’t work, contact the registrar directly. They generally won’t override the account holder for you, but they can tell you the process and whether anything about the registration is irregular.

Be realistic about the rest. There’s no ICANN button that returns a domain to the person who feels they should have it. ICANN’s dispute processes largely address transfers between registrars and trademark abuse, not “my contractor registered it and will not hand it over.” If your business name is trademarked, a UDRP complaint may apply. Otherwise this becomes a contract and negotiation matter, and possibly a lawyer.

And plan for the worst case honestly: sometimes the pragmatic answer is to register a new domain, move, and accept the cost. It’s painful — reprinted materials, lost search history, an email change to communicate — and it’s occasionally still cheaper and faster than the fight. That decision is easier to make early than after two years of stalling.

The point

This isn’t complicated, and it isn’t expensive. A domain costs somewhere around twenty dollars a year. The entire problem is that the right moment to handle it is at the beginning, when nobody is thinking about it, and the moment you notice is the moment it’s already become difficult.

If you’re having a site built, ask one question before work starts: whose name will the domain be registered in? A good answer is “yours, and we’ll need access to manage the DNS.” Anything else is a red flag.

When we take on website design and development work, the domain stays in the client’s name. Full Stop. We’re happy to help you get it set up the right way on day one.

Epilogue

If you’re a business owner educating yourself on how to correctly set up your web presence, this article is a goddamn gem. If you’re a web or IT professional, this probably feels like table stakes level advice. Anyone not doing it this way is committing professional malpractice.

I said up top that I have been the problem. Here’s the whole of it.

I took pride in taking care of my customers. And in this case, maybe I cared a little too hard.

I assumed they’d always be my happy customers. Nobody would leave. I’d be in business forever. But customers’ needs change, and unexpected life changes can upend a career in an instant.

It wasn’t until later, when I took a hiatus from self-employment and saw folks I “helped” in this regard struggle, that I realized the consequences.

So take it from me, someone who’s made the mistake and helped customers recover from this kind of situation: business owners should always register their own domains, under their own accounts. And web & IT professionals should help their clients by holding their hand through self-registration but never, ever register on their behalf, under an account that isn’t owned by the client.

Sources and further reading

Everything above about how registration actually works comes from ICANN’s own policy documents rather than folklore. If you want to verify any of it — or you’re the web or IT professional in this conversation and would rather read the primary text — start here.

  • Registrants’ Benefits and Responsibilities — ICANN’s plain-language summary of what you are entitled to as a registrant, including the right to transfer your domain and to have accurate contact records. The single most useful page on this list for a business owner.
  • EPP Status Codes — what clientTransferProhibited and every other status code on your domain actually means. Worth bookmarking the first time your registrar dashboard confuses you.
  • Transfer Policy — the rules governing registrar transfers, including the lock periods that apply after a new registration or a change of registrant.
  • Expired Registration Recovery Policy — what actually happens when a domain lapses: the grace period, the redemption period, and the restoration fees.
  • Temporary Specification for gTLD Registration Data — why public WHOIS records went dark after GDPR, and what registrars still hold behind the scenes.
  • 2013 Registrar Accreditation Agreement — the contract every accredited registrar signs. The WHOIS Accuracy Program Specification inside it is why inaccurate registrant data can get a domain suspended.
  • Uniform Domain-Name Dispute-Resolution Policy — the trademark-based dispute process, and the narrow circumstances in which it applies to a domain someone else registered on your behalf.
  • ICANN Lookup — the lookup tool from the “how to check” section above.

Have a project in mind?

Tell us what you are trying to build and we will tell you honestly whether we are the right fit.

collaboration@ccglabs.net