Many small business owners assume that paying for a website means owning every part of it. In practice, a website is several separate things, and each one sits in a different account. If those accounts are in someone else's name, a change of developer can get awkward fast. This guide explains the parts, who usually holds them, and how to check.
A website is not one thing
When people ask "who owns my website", they usually mean the whole package. But the package is made of pieces. Your domain name, your hosting, your files, your tools and your email can each have a different owner. Owning one does not mean owning the rest.
The parts and who normally holds them
Who holds each part depends on how your site was set up. These are common patterns, not rules.
- Domain registration: the name itself, such as yourbusiness.com. It is held at a registrar. Sometimes it is in your name, sometimes in your developer's.
- DNS: the records that point your domain to your site and email. They may sit at the registrar, at your host or at a service such as Cloudflare.
- Hosting account: the server space where the site runs. Agencies often keep this under their own account and bill you for it.
- Website files and database: the pages, settings and content that make the site work. They live on the hosting account.
- Theme and plugin licences: paid tools are often bought under the developer's licence key. Licence terms vary by product.
- Content and images: your text, logos and photos. Who holds rights to these depends on your agreement.
- Analytics and Search Console: these are tied to a Google account, which may be yours or your developer's.
- Email: business mailboxes may be with your host, with Google Workspace, or with Microsoft 365.
Why it matters when a provider changes
While things are going well, nobody asks who holds which account. The question appears when a developer retires, goes quiet or you simply want a change. If the domain is registered in their name, you may need their help to move it. If hosting is in their account, you may need them to export your files.
The fix is usually simple when the relationship is friendly. It is much harder when it is not. That is why it is worth knowing where you stand now, before you need anything. For a wider view of moving on, see our guide on how to switch website maintenance providers.
How to check who owns your domain
The domain is the most important item to check, and it takes two minutes.
- Go to lookup.icann.org, the official ICANN lookup tool.
- Type in your domain name and run the search.
- Look at the registrar, the registration dates and the registrant details.
Some registrars hide personal details behind a privacy service, so the registrant name may be redacted. That is normal. It does not mean the domain is not yours. The registrar name tells you where the domain lives. Then log in there, or ask who holds the login. The registrant is the person or business recorded as the holder of the domain, so it should be you or your company.
Why being the account owner matters
An account owner can change passwords, update billing, add other users and transfer things away. A user added by someone else usually cannot. The best setup is simple: you hold the account, and your developer is added as a user with the access they need. Then you can remove them in one step if you ever need to.
The same goes for your Google account for analytics and Search Console. Google explains how site ownership is verified in its help page on verifying your site ownership. For WordPress sites, the administration screens guide shows where users and their roles are managed.
A note on contracts. Terms differ from one agreement to the next, so check your own agreement and ask your adviser if you are unsure about content, licences or rights. This article is general information only.
A one-afternoon ownership audit
Set aside a few hours and work through this list. Write down the answer to each item.
- Look up your domain at lookup.icann.org and note the registrar and expiry date.
- Find out whose email address is on the registrar account, and make sure you can log in.
- Note where your DNS is managed and who can edit it.
- Find your hosting company and check whose name is on the account and the invoices.
- List every paid theme, plugin and tool, and whose licence each one uses.
- Check that you have a recent copy of your files, database and images.
- Confirm that you own the Google account behind analytics and Search Console.
- Check who controls your business email accounts.
Our website maintenance glossary explains any term on this list that is new to you. If you are also preparing for a change of developer, the handover checklist covers what to ask for, and our guide on what to do when a developer has gone quiet helps if you cannot reach them.
How we handle access at WebXSentry
At WebXSentry, logins are shared through a secure vault in the client area, and they are returned to you in writing when you leave. Migration and handover are free. Plans are month to month, with a 30-day money-back guarantee.
What to do next: spend one afternoon on the audit above. If you find gaps, ask your current provider to move the accounts into your name, and keep a written record. If you would like a second pair of eyes, you can request a free website maintenance audit.