Local Business

How not to lose your domain name

Your domain is the address of your email, your website, and your identity online — and it is the asset small businesses are most likely to lose track of. Here is who should own it, how to lock it down, and why recovery is so much harder than prevention.

October 2, 2026 7 min read domainssmall businessDNScontinuityregistrar

Your domain name is the quiet foundation everything else sits on. It is the address of your website. It is the part of every staff email after the @ sign. It is what customers type, what search engines index, and what your invoices, your sign-in pages, and your reputation are all attached to. And for most small businesses, it is the single most important asset that absolutely nobody is responsible for.

That is the danger. A domain is cheap, it renews quietly in the background, and it works so reliably that it becomes invisible — until the day it does not. Losing it is not like losing a file; it can mean your email stops arriving, your website goes dark, and getting it back ranges from difficult to impossible. Here is how to make sure that day never comes.

Why the domain is the asset everyone forgets

Most critical business assets announce themselves. Payroll has a deadline. The lease has a renewal. The insurance sends a bill someone opens. The domain does none of this. It was registered years ago, probably in a hurry, possibly by someone who no longer works there or a web designer you used once, and it has renewed itself ever since without anyone thinking about it.

Because it is silent and cheap, it never makes the list of things a business tracks. But its importance is inversely proportional to the attention it gets. Everything customer-facing depends on it, and control of it usually rests on a single login that few people at the company have ever seen.

Who should own the registrar account

The registrar is the company you register the domain through — the account that actually controls it. The most important rule is simple: your business must own that account, under a business-controlled login, with more than one person able to reach it.

Where this goes wrong is common and predictable:

  • The web designer or agency registered it in their own account. They did you a favour at the start, and now your domain lives inside a login you do not control. If the relationship sours or they disappear, you are negotiating for your own address.
  • One employee registered it under their personal email. When they leave, the confirmation emails, the renewal notices, and the password reset all go to an inbox you no longer control.
  • Nobody remembers which registrar it even is. The domain works, so the question never comes up, until it urgently does.

The fix is to register — or transfer — the domain into an account that belongs to the business itself. Use a business email address for the account, not a personal one, and ideally one that is not itself hosted on the very domain in question, so a domain problem cannot lock you out of fixing the domain. Make sure at least two trusted people can access it. Turn on multi-factor authentication. Then write down which registrar it is and where the login lives, and store that somewhere your business keeps its important records.

Auto-renew, registrar lock, and DNS

Three settings prevent most domain disasters, and all three take minutes.

Auto-renew. A domain that lapses can, after a grace period, be bought by anyone — including services that snap up expired domains to resell to the previous owner at a steep markup, or worse. Turn on auto-renew, and make sure the payment card on file is current and the renewal notices go to an address a real person watches. A great many “we lost our domain” stories are simply an expired card and an ignored email.

Registrar lock. Most registrars offer a lock — often called a transfer lock or client-transfer-prohibited — that prevents the domain from being moved to another registrar without deliberately unlocking it first. Leave it on. It is a cheap guard against both accidental transfers and the kind of hijacking where someone tries to move your domain out from under you.

DNS access. DNS is the setting that points your domain at your website and routes your email. Whoever controls DNS controls where your traffic goes, so treat that access as seriously as the registrar login itself. Know where your DNS is managed — sometimes it is at the registrar, sometimes at a separate provider — and keep a plain record of the key records so they can be rebuilt if something is misconfigured or lost.

What happens when the person who registered it leaves

This is the scenario that catches businesses out. The domain was set up under one person’s account or personal email. Years later that person leaves — retires, resigns, or parts on bad terms — and takes with them the only working access to the account that controls your entire online presence. Nothing breaks the day they go. It breaks months later, when the card on the account expires, or a renewal notice bounces into an abandoned inbox, and there is no one who can log in to fix it.

Preventing this is part of ordinary offboarding, and it belongs on the checklist you run whenever anyone with access to important systems leaves. Before the departure, confirm the domain sits in a business account, move it if it does not, and verify that someone who is staying can actually get in.

Recovery is hard — prevention is minutes

The reason all of this matters is that recovering a lost or hijacked domain is genuinely painful. Registrars deal with disputes cautiously and slowly, because they cannot easily tell a legitimate owner who lost access from an impostor claiming to be one. Proving you own a domain you can no longer log in to can take weeks of documentation, and if the domain has already lapsed and been bought by someone else, you may not get it back at all. Meanwhile your email is down and your website is dark.

Set against that, prevention is almost trivial: own the account, lock it down, turn on auto-renew, keep two people able to reach it, and write down where everything lives. An hour now against an open-ended crisis later.

Where this fits

Domain control is one of the things that quietly surfaces when a business changes IT providers or web agencies — and one of the things a good handover makes sure you keep. If you are moving between providers, confirming that you, not the outgoing party, hold the keys to your domain is part of doing it cleanly; we cover that ground in switching your managed IT provider. And when you are evaluating any provider, who controls the domain and DNS is exactly the kind of thing worth raising — one of the questions worth asking any managed IT provider.

Send us two paragraphs about where your domain is registered and who can access it, and we will reply in writing within one business day.

— Newsletter

Get the writing by email.

An occasional note from the team — case studies, new free tools, engineering essays. Never daily.

Three fields, no tracking. Privacy policy.

Esc