Domains usually fail for administrative reasons long before technical ones. The renewal card belongs to a former employee, notices go to an unmonitored mailbox and nobody knows which registrar holds the account. The problem becomes visible only when a change or recovery is urgent.
Run this review while the website and email are healthy. Save evidence in the business’s controlled records without placing passwords or recovery codes in the checklist itself.
Identify the registrar and registrant
The registrar is the company providing the registration service. The registrant is the person or organisation holding the registration rights under the agreement. These are not necessarily the web host, designer or DNS provider.
ICANN describes the registrant as the contracting party with rights and responsibilities for managing, transferring, renewing and restoring a domain. Confirm that the registrant details reflect the intended business control and keep the contact information current.
Put access under organisational control
Use an email account the business controls and can recover when staff change. Avoid relying on the domain itself as the only recovery route; an outage affecting email could make registrar recovery harder at the exact moment it is needed.
Enable 2-step verification with the registrar. The NCSC identifies this as its most important recommendation for protecting access to domain-management accounts. Store recovery material securely and document an authorised recovery process.
Check renewal as a complete process
Record the expiry date, renewal term, expected cost, payment method owner and notification addresses. Auto-renewal is useful but not a substitute for review. Cards expire, accounts are frozen and renewal notices can be filtered.
Add a calendar checkpoint well before expiry. Confirm the renewal completed in the registrar record rather than relying only on an email receipt. Treat unusual renewal or transfer messages as potential phishing and sign in through a known route.
Map DNS before making changes
DNS connects the domain to websites, email and other services. Export or document the current records, provider, nameservers and purpose of important entries. Note who is allowed to approve a change.
A website migration can break email when records are replaced wholesale. Compare records before and after a nameserver change, including mail routing and domain-verification entries. Reduce time-to-live only as part of a planned change, then restore the agreed value.
Remove access after roles change
Review registrar, DNS and recovery access when an employee, agency or developer leaves. Rotate shared credentials that could not be attributed to one person. Remove obsolete API keys and app connections as well as visible users.
Keep at least two appropriately authorised people able to start the documented recovery process. That is different from giving every administrator unrestricted daily access.
Prepare for a transfer without initiating one
Know how to unlock the domain, obtain the transfer code and approve a request, but do not leave it unlocked. Record any relevant waiting periods or registry rules. A planned supplier change should have a named owner and an agreed maintenance window.
Before transferring, verify the receiving account, contact email, DNS responsibility and renewal status. Preserve records and monitor the website and email afterwards.
Keep an evidence sheet
- Domain name, registrar and registry or suffix.
- Registrant organisation and verified contact route.
- Expiry date, renewal setting and payment owner.
- Registrar and DNS administrators with review dates.
- 2-step verification and recovery process status.
- Nameservers, DNS provider and latest record export date.
- Change approver, technical contact and incident contact.
Practise one recovery question
Ask: if the primary administrator became unavailable today, could an authorised person identify the registrar and begin recovery without using that person’s phone? If the answer is no, fix the ownership route before adjusting cosmetic DNS settings.
Repeat the check after restructuring, rebranding or changing web suppliers. Domain control is a business continuity responsibility, not merely a line item on a website invoice.
Two recoveries, one easy and one not
A recruitment firm ran the ownership check and found its main domain registered to an agency that had closed two years earlier, with the registrant email at a dead domain. Recovery took eleven weeks, a company registration document, two escalations and a solicitor’s letter.
Its second domain, used for a campaign microsite, was registered to a marketing manager’s personal Gmail account. She still worked there. That one took twenty minutes: she logged in, added the company account as an additional contact, and the billing moved to the company card.
The difference between eleven weeks and twenty minutes was entirely whether someone reachable still had access. The checklist exists to find the first case while it is still the second.
Sources and further reading
- NCSC guidance on managing public domain names — the source for account protection, registry locking and secure DNS management.
- ICANN information for domain registrants — the primary reference for registrant rights, responsibilities, renewal and transfer information.
We can include domain, DNS and renewal control in a documented website maintenance arrangement without taking ownership away from the business.