Do you actually own your website?
Website ownership isn't one thing, it's five: the domain name, the hosting account, administrative access to the CMS, the code, and the analytics. Many established companies own none of them; everything sits in a vendor's accounts, and the arrangement works until the day it matters. Each of the five can be verified today, without asking your vendor, and the checks below take about fifteen minutes end to end.
What it usually means
This situation is rarely malicious. It's the default outcome of convenience: the agency registered the domain because it was setting things up anyway, hosting went on the agency's plan because that was faster, and analytics lives under the agency's account because they configured it. Each choice was reasonable on the day it was made. The sum is that the company's primary marketing asset exists inside someone else's logins.
There's also a version of this that's a business model rather than an accident. Some vendors structure engagements so that ownership never transfers: the domain stays registered to them, the site runs on their proprietary platform, and the monthly fee buys continued existence rather than accumulating equity. The checks below distinguish the two, and the vendor's response to a transfer request distinguishes them further.
Ownership matters at exactly the moments you're least able to push back: when you want to leave, when the vendor is slow or unreachable, and when the vendor's business changes hands or shuts down. A site you don't own can't be moved, and a domain you don't control isn't yours in any sense that counts.
What it costs while it stays this way
The cost is mostly invisible until an exit is on the table, and then it's the exit. A company that controls its five pieces can change vendors in weeks: point the vendor at the repository, hand over CMS credentials, done. A company that controls none of them is quoted a migration, and the party quoting it's the party with every incentive to make it expensive. The lock doesn't have to be enforced to work; it only has to exist, and it quietly prices every renewal negotiation you have.
Code has a specific trap in it. Under US copyright law, work created by an independent contractor isn't automatically work for hire; absent a written assignment, the contractor owns the copyright in the code they wrote, even though you paid for it. Plenty of agency agreements are silent on this, which means plenty of companies have paid in full for websites they don't legally own. The content you supplied, your text and photographs, is yours; the implementation may not be.
And when a vendor disappears, ownership is the difference between an inconvenience and an emergency. Agencies close, get acquired, and lose key people. A domain in a defunct company's registrar account, or a site on hosting nobody is paying for, can take your web presence and any email on that domain down with it, on somebody else's timeline rather than yours.
None of that is hypothetical; we've watched clients live each version of it. The worst cases we've seen up close: a company recreating its entire website from scratch because nothing could be recovered, a site frozen for several months because nobody left could make changes, and weeks spent tracking down one former employee of a defunct vendor because they were the only person who had ever held the access. Every one of those started as a fifteen-minute check nobody ran.
How to confirm it yourself
- Look up your domain registration. Run your domain through ICANN's public lookup at lookup.icann.org and read two fields: the registrant organization and the registrar. A privacy service in the registrant field is normal and fine; the real question is whether the account at that registrar is yours or the vendor's, which the next check settles.
- Find the registrar login. Ask internally who can log in to the account where the domain is managed (GoDaddy, Cloudflare, Namecheap, or whatever the lookup named). Domain renewal emails go to the account holder, so if nobody at your company has ever seen one, you're not the account holder.
- Find the hosting account. Who has the hosting login, and whose card pays for it? If hosting appears as a line item on the vendor's invoice rather than an account your company holds, the site runs at their pleasure. Ask which host it is; not being able to answer that question is itself the answer.
- Check your CMS role, not just your login. Log in to the CMS and read your own role. In WordPress: Users, then your profile, then Role. Editor access isn't ownership, because an administrator can remove an editor at will. Someone with a company email should hold the administrator role, and you should know who.
- Ask where the code lives. For a custom-built site, ask for read access to the repository (GitHub, GitLab, Bitbucket) or, at minimum, a current export of the codebase. If the honest answer is that the code exists only on the vendor's infrastructure, note it, and read your contract for an assignment or work-product clause.
- Open your analytics directly. Can anyone at the company log in to the analytics platform itself, or do you only ever see a monthly PDF? This one is its own warning sign with its own checks: why can't you see your own website analytics?
What the vendor's answers actually mean
Raise ownership with a vendor and the replies fall into a few familiar shapes. None of them is a technical fact; each is a position, and each tells you something.
“It's simpler if everything stays under our management.”
Simpler for whom is the whole question. Delegated access gives them identical working convenience on accounts you own; the only thing consolidation under their accounts simplifies is retention.
“You own all your content, of course.”
True, and narrower than it sounds. Your text and images were always yours. The statement is carefully silent about the domain, the code, the theme, and the accounts, which is where ownership actually lives.
“There's a release fee for the site files.”
A fee invented at exit is a tell about how the engagement was structured. Check the contract: if no such fee appears in it, this is an opening position, not an obligation.
“We'll hand everything over whenever you decide to leave.”
Possibly sincere, and worth nothing until it's in writing. The time to convert this promise into transfers is while the relationship is warm, because a verbal assurance is precisely the thing that evaporates in a dispute.
What actually fixes it
The fix is an inventory and a set of transfers, and a professional vendor cooperates without friction: the domain moved to a registrar account your company owns, hosting in your name with the vendor holding delegated access, an administrator CMS role held internally, repository access or a code assignment confirmed in writing, and the analytics property under your account with the vendor added as a user. Delegated access gives a good vendor everything they need to keep doing the work; ownership is the only thing that changes hands.
Sequence it by irreplaceability: domain first, because it's the one asset that can't be rebuilt, then analytics, because its history accrues to whoever holds it, then hosting, CMS, and code, which are recoverable with effort. Do it during calm. Every one of these transfers is routine while the relationship is healthy and contested while it's not.
How the vendor responds is itself diagnostic. Cooperation within days is the norm and the end of the story. Delay, surprise fees, or warnings that things will break tell you the arrangement was load-bearing for them, and that the next contract, with them or anyone else, needs the ownership clauses it apparently lacked.
The message to send
The whole request, written to be unremarkable. It asks for everything at once so the follow-ups can't be split and stalled one at a time.
Hi [name],
We're consolidating ownership of our accounts as a matter of housekeeping. Could you help us with the following: the domain transferred to our registrar account (we will send the destination), hosting moved into an account in our name with your team keeping access, confirmation that someone here holds the administrator role in the CMS, read access to the code repository, and our Google account granted ownership of the analytics property.
Nothing about the working relationship changes; your access stays in place for the ongoing work.
Can we have this wrapped up by [date two weeks out]? Happy to get on a call if any piece is easier to do together.
Common questions
Who owns the code if the contract never mentioned it?
By default in the US, the developer does. Contractor work isn't automatically work for hire, so without a written assignment the copyright in the code stays with whoever wrote it, even though you paid the invoices. Your remedy is practical rather than legal: get an assignment clause into the current or next agreement, and get a copy of the code either way. Most vendors sign the assignment without argument; the ones who refuse are telling you something.
Is it legal for an agency to keep my domain?
Usually, yes. Registrars treat the account holder as the registrant, so if the agency registered it under their account, your recourse is contractual rather than automatic. That's why the check matters before a dispute exists: transfers are routine when the relationship is healthy and contested when it's not. If the domain predates the vendor, dig out the original registration; it may still be yours.
What happens to the site if the vendor goes out of business?
If you own the five pieces, almost nothing: you grant a new vendor access and continue. If you own none of them, the site and any email on the domain are hostage to an administration process, and recovery depends on whoever is winding the company down answering support tickets. This is the scenario that turns ownership from principle into continuity planning.
What should ownership look like in a contract?
Four clauses cover most of it: the domain is registered to your company, hosting is in an account you control, all work product including code is assigned to you on final payment, and vendor access is delegated rather than owning. If a proposal is silent on ownership, ask. The answer tells you a great deal about the engagement you're entering, and our [website RFP template](/resources/website-rfp-template/) carries these clauses ready-made.
We're mid-contract. Should we wait until it ends to do this?
No. Ownership transfers are orthogonal to the service relationship, and mid-contract, on good terms, is exactly when they're cheapest. Waiting until the end bundles the transfers into an exit negotiation, which is the most expensive possible time to discover which parts were never yours.