Your developer built the site, then replied more slowly, then stopped replying. Meanwhile something needs updating, the renewal reminder went to an email you cannot open, and nobody is sure who owns what. This is more common than most business owners realise, and it is usually fixable. Here is how to regain control, step by step.
Step 1: Work out what you actually own
A website is several separate assets, and the developer may control any of them.
- The domain name (yourbusiness.com), held at a registrar
- DNS settings, which point the domain at your hosting and email
- Hosting, the server where the site lives
- The website admin, meaning your WordPress or other CMS login
- The code and files, including themes and any custom work
- Third-party services: analytics, Search Console, payment tools and plugin licenses
- Email accounts on your domain
Step 2: Start with the domain
The domain is the most important asset, because with it you can redirect everything else. Look up the registration using a public WHOIS lookup (some registrars hide details behind privacy) to see the registrar and, sometimes, the registrant. If the domain is registered in the developer's own name, ask them to transfer it into an account you control. If they cannot be reached, registrars have processes for verified owners to prove their claim, which usually means documents such as a business registration and past invoices.
Step 3: Regain hosting access
Search your email for invoices, welcome messages or renewal notices from a hosting company. They show who the host is and which email address the account uses. If you are the paying customer, the host's support can usually verify you and reset access. If the site sits on the developer's reseller account, ask them to move it, or ask your new provider to migrate a copy of the site.
Step 4: Get an admin login
If you can reach the hosting control panel, a technical person can create a new administrator or use the password-reset flow when the admin email is one you control. Do this only with a full backup in hand.
Step 5: Take a full backup before touching anything
Copy the files and the database and store them in an account you control. Everything after this is much safer with a fallback.
Step 6: Change every credential
Once you have access, change the passwords for hosting, the CMS, the database, FTP and any connected service. Remove accounts that belong to people who no longer work on the site, and add two-factor authentication.
Step 7: Document what you found
Write down which service is where, who owns each account, the renewal dates and what each tool does. This one page saves the next handover from starting from zero.
Step 8: Put someone in charge of care
Once the site is yours, decide who looks after it. Whoever it is, they need monitoring, backups, security and updates in place quickly, because sites that have gone unattended are often several updates behind.
What to ask the previous developer
A short, polite email often works better than a long one. Ask for: the domain registrar and login, the hosting provider and login, the admin logins for the site, a list of paid plugins and their licences, and a copy of any custom work. Say you are not looking to blame anyone, you just want to take care of the site, and that a prompt reply helps everyone. Keep a copy of the message and the date you sent it.
If they cannot be reached
- Domain: look up who the registrar is. Registrars can help you prove ownership and recover access, usually with identity documents and the email on the account.
- Hosting: contact the host's support with the domain name. Hosts have a process for verifying who owns an account.
- The site itself: if you can reach the hosting control panel, you can usually take a backup and reset an admin password from there.
- Licences: contact each plugin maker with proof of purchase or of your business.
Expect some of this to take days, not hours. Start with the domain, because everything else depends on it.
How long a handover usually takes
It depends almost entirely on how organised the previous arrangement was. If the logins are to hand, a handover can be quick. If the domain, hosting and site are each held by a different person, it can take a couple of weeks to untangle. Take a backup early, so the site is safe while you wait.
Common traps
- Domain in the developer's name. Get it moved to your account as early as possible.
- Hosting on the developer's reseller account. You cannot see or move it yourself.
- Premium plugins on the developer's license. Updates and support stop when the license is not yours.
- Unknown admin users. Remove anyone you do not recognise.
- No backups. Assume none exist until you have seen one and restored it.
Let someone else do the chasing
If this sounds like a lot, it is the routine part of what a handover team does. With WebXSentry, switching is free: we find out what you own, work with your host and registrar to get the accounts into your name, set up backups and monitoring first so there is no gap in cover, and keep your logins in a secure vault in your client area rather than in email or chat.