Who owns what: domain, DNS, hosting, code, content, analytics

Six things make up a website and each has an owner, an account and a login. The map every business should have on one page, and how to fill it in this week.

3 minread 738words last updated

The short answer

A website is not one thing. It is at least six things, each with its own account, owner, billing and logins: the domain, the DNS, the hosting, the code, the content and the analytics. A business can name its web supplier and cannot say whose name is on any of the six. That gap is where outages come from when a card expires, and where lock-in comes from when a supplier leaves.

The fix is one table. It takes an hour, and it should exist for every business website.

The map

ThingWhat it isOwner should beWhere it usually goes wrong
DomainThe name, rented yearly from a registrarYour company, your billing cardRegistered by an agency or a former employee
DNSThe records that point the name at site and emailYour company’s account at the DNS providerWherever it was set up years ago; nobody has the login
HostingWhere the site’s files or server liveYour company’s account, or the supplier’s with the transfer in writingOn the supplier’s plan, one line on their invoice, nothing in writing
CodeThe source the site is built fromA repository under your organisationOn a developer’s laptop or under the supplier’s account
ContentText, images, documents, productsYour account in the content system or platform, with an export pathOnly reachable through the supplier; no export ever tried
AnalyticsVisitor and search dataProperties owned by your companyCreated by an agency under their account

The columns to fill in

For each row: the provider, the account name or email it is registered under, who owns it, who is billed, who has access and at what level, where the two-factor device is, and where the recovery address goes. Seven columns, six rows. If any cell says “not sure”, that is a task.

  1. Domain. A public lookup tells you the registrar; the registrant is in the account. Log in there and check the registrant, the billing card’s expiry and the renewal setting.
  2. DNS. Find the provider from the domain’s name servers. Log in. Export the records.
  3. Hosting. Log in to the platform. Check whose organisation the project sits under and who is billed.
  4. Code. Find the repository. Check which organisation owns it and who has admin rights.
  5. Content. Log in to the content system or platform. Try an export. Confirm it contains everything.
  6. Analytics. Open the analytics and search tools. Check who the property owner is, not just who has access.

Keeping it current

The table changes when a supplier changes, an employee with access leaves, a card is replaced, or a tool is added. Review it at each of those events and once a year regardless. Store it with your documentation, not in one person’s head, and make sure two people in the company can open every account on it.

What this means for you

Fill in the six rows this week. Where your company is not the owner, plan the transfer, domain and DNS first. Where nobody knows the login, recover it now rather than during an outage. An hour of work turns “our agency handles it” into a page that says exactly who owns what, and that page is worth more than the contract.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Where does the content live, and why is it separate from the code?

Content is the text, images and documents. On some sites it lives in a content system, on others in files next to the code, on a shop in the platform. It has its own account and export path. Knowing that you can get all of it out, in a usable format, is separate from owning the code that displays it.

Our partner manages everything. Do we still need this?

Especially then. A good partner will fill in the table for you in an hour, and every line will say your company under owner. If a partner cannot or will not fill it in, you have learned what you needed to know.

What about form submissions, email and integrations?

Add rows. Form service, email provider, newsletter tool, payment provider, booking system, CRM. The six in the title are the core; anything the business depends on gets a line with the same columns.