Moducraft
Small Business 7 August 2026 · 11 min read

Who actually owns your website? What should be in your name

Your website is a business asset, but many small business owners don't actually control the accounts behind it. Domain, hosting, email, CMS access - here's what should be in your name, how to check, and what to do if it isn't.

Your website is a business asset. Do you actually control it?

Most small business owners can tell you who built their website. Fewer can tell you where their domain is registered, who controls the hosting account, or what would happen to their email if they needed to change developers tomorrow.

This isn't a hypothetical problem. We've helped businesses that lost access to their own websites - not through anything malicious, but because their developer held all the accounts and circumstances changed unexpectedly. When that happens, regaining control of your own digital presence can range from inconvenient to genuinely difficult. We've documented one such recovery project where a business lost their website and email overnight through no fault of their own, simply because the accounts weren't in their name.

It doesn't have to be this way. Understanding what you own and checking that the right things are in your name takes less than an hour. Here's what to look for.

What "owning" your website actually means

When we talk about website ownership, we're talking about four distinct things:

Your domain name (e.g., yourbusiness.co.za). This is your address on the internet. It's registered through a domain registrar and renewed annually. Whoever's name and email are on the registrar account controls the domain.

Your hosting account. This is where your website's files actually live - the server space that makes your site accessible on the internet. It has its own account, login, and billing.

Your email accounts. Business email ([email protected]) is often tied to your domain and hosting. If someone else controls the domain, they can redirect your email.

Your website code and content. The actual files, design, and content that make up your website. Who has the source code? Who can log into the content management system? Who has backups?

Each of these can be controlled by a different person or account. In a well-set-up arrangement, you (the business owner) control all four. In a poorly set-up arrangement, your developer controls some or all of them.

The four accounts that should be in your name

1. Domain registrar account

This is the most important one. Your domain name is your identity online. If you lose control of it, you lose your website address, your email, and any search ranking or AI visibility you've built up over the years.

Your domain should be registered in an account that you own, with your email address as the contact, and your payment method for renewals. Popular registrars in South Africa include Afrihost, Domains.co.za, 1-Grid, and Hetzner. International registrars like Namecheap and Cloudflare work well too.

How to check: Do you know which registrar your domain is with? Can you log into that account? Is your email address (not your developer's) the primary contact? If you're not sure, you can look up your domain's registrar using a WHOIS lookup tool - search "WHOIS lookup" and enter your domain name.

Red flag: If your developer registered the domain in their own account, your domain is technically in their possession. This is common and usually not done with bad intent - many developers register domains on behalf of clients for convenience. But it means they control your identity, and transferring a domain after the fact takes time and cooperation from both parties.

2. Hosting account

Your website's files need to live somewhere. That somewhere is a hosting provider, and the hosting account should be in your name with your billing details.

Common hosting providers in South Africa include Afrihost, Hetzner, Elitehost, and 1-Grid. Many developers use international providers like DigitalOcean, AWS, or Cloudflare. The provider doesn't matter as much as who owns the account.

How to check: Do you know where your website is hosted? Can you log into the hosting control panel? Is your credit card or debit order paying for it? If your developer is paying for hosting and billing you as part of a monthly fee, ask them: is the hosting account in my name?

Red flag: If the hosting account is in your developer's name and they go out of business, move overseas, or simply become unreachable, your website goes down when the hosting bill isn't paid. Transferring a site from one hosting provider to another is possible but requires access to the files and database - which you may not have if the account isn't yours.

3. Business email account

If your business email uses your domain name ([email protected]), it's likely managed through your hosting provider, Google Workspace, or Microsoft 365. You need admin access to the account that manages your email.

How to check: Can you log into the admin panel for your email service? Can you create new email addresses, reset passwords, and manage settings? If you use Google Workspace or Microsoft 365, is the admin account in your name?

Red flag: If your developer set up your email and they're the admin, they can read your email, lock you out, or redirect it. This is rarely malicious, but it's a dependency you don't need.

4. CMS or website admin access

If your website uses a content management system (WordPress, Statamic, Shopify, or similar), you should have the top-level admin account - not a contributor or editor role, but full administrator access.

How to check: Can you log into your website's admin panel? What's your role - admin, editor, or something else? Is there an account on the system that belongs to your developer with a higher permission level than yours?

Red flag: If the only admin account belongs to your developer and you have an editor account (or no account at all), you can't install updates, manage users, or make structural changes to your own website.

Warning signs that your setup is at risk

Any of these should prompt a conversation with your developer:

  • You've never logged into your domain registrar
  • You don't know the password to your hosting account
  • Your developer's email address is the admin contact on your domain
  • You pay your developer for hosting but don't have direct access to the hosting account
  • You can edit content on your website but can't access the admin settings
  • You've never seen or been given a backup of your website
  • Your developer handles domain renewals and you just get an invoice
  • You don't know where your website's code lives (GitHub, the server, a hard drive somewhere)

None of these necessarily mean something is wrong. Many developers manage these things professionally and will happily transfer everything if asked. But if you haven't asked, you don't know.

What happens when a developer relationship ends unexpectedly

Developers are people. They change careers, move countries, have health issues, get too busy, or simply stop responding. None of this is unusual and none of it is necessarily anyone's fault. But when it happens and they control your accounts, the consequences can be sudden:

  • Domain expires and isn't renewed - your website goes offline and your email stops working
  • Hosting bill isn't paid - the hosting provider deletes your website files after a grace period
  • CMS password is unknown - you can't update your own website
  • No backups accessible - if the hosting goes down, the website is gone
  • Email admin is unreachable - you can't create new mailboxes, reset passwords, or recover locked-out accounts

The fix for all of this is prevention. If the accounts are in your name from day one, a change in developer is a manageable transition, not a crisis.

How to audit your accounts: a step-by-step guide

Set aside 30 minutes and work through this list:

  1. Find your domain registrar. Search "WHOIS lookup" and enter your domain. The results will show which registrar holds your domain. Note the registrar name and the expiry date
  2. Log into the registrar. If you have an account, log in and check that your contact details are current. If you don't have an account, or the account is in someone else's name, contact the registrar to discuss a transfer
  3. Find your hosting provider. Ask your developer, or check your financial records for hosting payments. If your website uses cPanel or Plesk, the login URL often reveals the hosting provider
  4. Log into the hosting account. Verify you have access, your billing details are current, and auto-renewal is enabled
  5. Check your email admin. Log into the admin panel for your email service (Google Workspace admin, Microsoft 365 admin, or your hosting email panel). Verify you have admin access and your recovery email is set to an address you control
  6. Log into your CMS. Verify your account has full admin permissions. Check who else has admin access
  7. Locate your backups. Ask your developer or hosting provider where backups are stored and how to restore them. Download a current backup and store it somewhere you control
  8. Document everything. Record the registrar, hosting provider, email service, and CMS details in a secure password manager. Include login URLs, account emails, and renewal dates

What we do differently

When we build a website for a client, every account is set up in the client's name from day one:

  • The domain is registered in the client's registrar account
  • Hosting is in the client's name with their billing details
  • Email admin access belongs to the client
  • The CMS admin account belongs to the client
  • We have our own access for maintenance and updates, but the client's account is always the primary owner

If a client ever decides to work with a different developer, everything is already theirs. No transfer negotiations, no waiting for account access, no risk of losing anything. The website is their asset, and they control it completely.

This should be the norm, not the exception.

A practical checklist

  • I know which registrar my domain is registered with
  • I can log into my domain registrar account
  • My contact details (not my developer's) are on the domain registration
  • My domain is set to auto-renew and my payment method is current
  • I know where my website is hosted
  • I can log into my hosting account
  • My billing details are on the hosting account
  • I have admin access to my email service
  • I have a full admin account on my website's CMS
  • I know where backups are stored and how to access them
  • I have a current backup stored independently
  • All account recovery emails point to addresses I control

If you can tick everything on this list, you're in good shape. If you can't, now is the time to sort it out - while the relationship with your current developer is good and transfers are straightforward.

If you'd like help auditing your accounts or untangling a complicated setup, get in touch. We've helped several businesses regain control of their digital assets, and we're always happy to advise.

JP

Johan Pretorius

Johan Pretorius is the founder and lead developer of Moducraft, a Cape Town web studio working with small businesses across the Western Cape. 18 years building for the web.

Want to talk about your project?

Book a 20-minute call. No obligation, no sales pitch.

Book a 20-minute call