Whose name is on your domain registration?
If the answer is your web vendor, fix it this month. Everything else about a website can be rebuilt: design, content, even rankings, eventually. The domain cannot, and it carries more than the website; your company email routes through it too. If it's registered under someone else's account, your continuity on the internet depends on their cooperation, their solvency, and their bookkeeping. The check takes two minutes at ICANN's public lookup and doesn't require asking anyone.
What it usually means
Vendors end up holding domains through convenience, not conspiracy: they registered it during setup because someone had to, and nobody moved it afterward. The consequences don't care about intent. A vendor who holds your domain can, in practice, delay your departure indefinitely; a vendor who shuts down can strand it in an administrative limbo; a vendor who misses a renewal email can lose it outright.
The stakes are larger than the website because DNS is larger than the website. The domain's records decide where your site lives and where your email is delivered. Whoever controls the domain controls both, which means a domain dispute isn't a marketing problem; it's a company-wide outage waiting on someone else's decision.
DNS also carries the records that make your email deliverable and your tools work: SPF and DKIM entries that keep your messages out of spam folders, and the verification records that services like Google Search Console use to prove the domain is yours. Every one of those lives wherever the domain's records are controlled, which is why the question of whose account holds them keeps turning out to be a business question wearing a technical costume.
This entry is the sharpest special case of not owning your website: every other ownership gap is expensive to fix, and this one is the only one that can become impossible.
What it costs while it stays this way
Expiry is the catastrophic path. Domains that lapse go through a grace window and then to auction or open re-registration, and expired domains with traffic and inbound links are bought quickly, often by parties who monetize your old links and misdirect your customers. Recovery after that's expensive when it's possible at all. Nothing else on this site's list has a failure mode this close to unrecoverable.
Email is the underestimated path. The domain's MX records decide where every message to your company is delivered. A vendor dispute, a lapsed renewal, or a botched records change doesn't just take the website down; it takes down every inbox on the domain, silently, with senders receiving bounces while you receive nothing at all.
And there's a timing rule that punishes procrastination specifically: ICANN policy locks a domain against registrar transfers for 60 days after a change of registrant and after initial registration. Practically, that means ownership cleanup can add two months of waiting, so the worst time to start is when you already need to leave. Do it now, while the clock costs nothing.
How to confirm it yourself
- Run the ICANN lookup. Go to lookup.icann.org and enter your domain. Read the registrant organization, the registrar, and the expiry date. A privacy service in the registrant field is normal; the question the next steps settle is whose account sits behind it.
- Find the registrar login. Ask internally who can log in to the account at the registrar the lookup named (GoDaddy, Cloudflare, Namecheap, or another). If nobody can name the registrar, let alone produce credentials, the domain isn't under your control regardless of whose name appears on it.
- Check where renewal notices go. Registrars send renewal and expiry notices to the account holder's email. If your team has never seen one, you're not the account holder. While you're at it, confirm auto-renew is on and a current payment method is attached, whoever holds it.
- Separate the registrar from DNS control. The lookup names two things people conflate: the registrar, where the domain is owned, and the nameservers, where its records are managed. A vendor can legitimately run DNS on your behalf while the registrar account is yours. The reverse, their registrar account with your records, is the arrangement to end.
- Map what depends on the domain. List what routes through it: the site, company email, any subdomains for tools or portals, and any third-party services verified against the domain. This is the blast radius if the domain is ever contested, and it's the paragraph to reread if the transfer request below ever feels like too much bother. Most companies find the list is longer than they expected, and that email alone justifies the transfer.
What the vendor's answers actually mean
Domain transfer requests surface a standard set of replies. Translations:
“It's registered under our master account for security.”
Registrar accounts aren't more secure for being the vendor's; they're more theirs. Security here means convenient administration, which delegated DNS access provides equally well on an account you own.
“We handle renewals so you don't have to worry.”
Often sincere, and it names the exact risk: renewal depends on their bookkeeping. The fix keeps their convenience and moves the asset: your account, auto-renew on your card, their access delegated.
“Transferring could break your email or site.”
A registrar transfer moves ownership, not records; nothing breaks if the nameservers and DNS records are preserved, which is the transfer default. This reply confuses, accidentally or otherwise, moving the deed with demolishing the building.
“There's an administrative fee for the transfer.”
Check the contract; an exit fee that appears nowhere in it's an opening position. The registrar's own transfer cost is trivial, typically a year's renewal added to your term.
What actually fixes it
The fix is a registrar transfer into an account your company owns, and the process is standard: you open an account at your chosen registrar, the vendor unlocks the domain and provides the transfer authorization code (also called an EPP or auth code), you initiate the transfer from your side, both ends confirm, and the domain moves within days. Nameservers and DNS records carry over unchanged by default, so the site and email don't blink. Then grant the vendor DNS-level access if they legitimately manage records for the work. If replacing the arrangement is on the table, how to choose a B2B web design agency covers what to ask before you sign the next one.
Do it during calm. A cooperative vendor makes this a non-event; a contested transfer is a different and much worse process, and it can stall a whole website migration behind it. And remember the 60-day rule cuts the other way too: once the domain is yours, registrant changes restart the lock, so consolidate ownership once, correctly, into an account that won't need to change again.
Once transferred, treat the domain like the company asset it is: registered to a role email that outlives any employee, auto-renew on a company card, credentials in the company password system, and a calendar note confirming renewal annually. Ten minutes of process for the one asset you can't repurchase.
The message to send
The complete request. The auth-code ask is the operative sentence; the rest is tone.
Hi [name],
As part of consolidating company assets, we're moving the domain into a registrar account we hold. Could you unlock [domain.com] and send the transfer authorization (EPP) code? We will initiate from our side and confirm promptly so it moves quickly.
No DNS changes are planned, so the site and email will be unaffected, and we will set your team up with DNS access from our account for the ongoing work.
Could we have the code by [date one week out]?
Common questions
The vendor registered the domain years ago. Is it theirs?
Administratively, the registrar treats the account holder as the registrant, so yes, even if you have paid every invoice that included it. Practically, most vendors transfer on request without argument, and a history of paying for the domain strengthens your position. If a vendor resists, the resistance is worth reading carefully; a domain held as a bargaining chip tells you what kind of vendor lock-in you're actually in.
What is an EPP or auth code?
A short authorization code the current registrar issues to prove the transfer request is legitimate. The losing side provides it, the gaining side enters it, and both registrars confirm. Treat it like a password while it's live. A vendor who stalls on producing it's stalling the transfer itself, since nothing else is required from them.
Will transferring the domain break our email or website?
Not if the records are preserved, and preserving them is the default: a registrar transfer moves the account the domain lives in, not the DNS records that route your site and mail. The safe sequence is to change nothing else on transfer day, confirm everything resolves, and only later consolidate DNS if you choose to; the same discipline as 301 redirects in a migration, one change at a time. Breakage stories almost always involve someone changing nameservers at the same time.
What is the 60-day transfer lock?
ICANN policy prevents a domain from moving between registrars for 60 days after initial registration and after a change of registrant information. It exists to slow down domain theft, and it means ownership cleanup has a built-in waiting period. The practical takeaway: start transfers when nothing is urgent, because starting them mid-dispute adds two months you won't have.
Should the vendor keep any access after the transfer?
Often yes, and that's fine: DNS management access lets them do real work, deploys, mail records, subdomains, without owning anything. The principle is delegated access on your asset. It's the same distinction as giving a contractor keys to the building versus putting the deed in their name.