By AldoMedia · August 2026
Taking over a website you did not set up, stated plainly
A working website is not one account. It is four, usually held in four places by whoever set each one up. When a business inherits a site, the problem is rarely that something is broken. It is that nobody knows where the controls are. That is common and usually fixable, and far easier to settle while everything still works.
The four things you are taking over
Before you chase anybody, fill in these rows with what you know. The blanks are the job.
| Who tends to hold it | If you never get it | |
|---|---|---|
| The domain | A registrar account, often in the builder's name | You lose the name when it lapses |
| The hosting | A hosting account, sometimes shared with other clients | The site can be rebuilt elsewhere from a copy |
| The email | A mailbox provider, the host, or a separate account | Mailboxes and their history can be lost |
| The website | Files on the host, plus an admin login for the site | Content can be recovered from what is published |
If the difference between the first two rows is not obvious, read domain name vs web hosting first.
What you can find out with no logins at all
Two public lookups answer most of the opening questions, and neither needs permission.
WHOIS gives you the registrar and the renewal date
Every registered domain has a public record. Look yours up in a WHOIS search and read two fields: the registrar, the company you will be dealing with, and the expiry date, which tells you how long you have. If domain privacy is off it may name the registrant too, which is often how a business learns the name is not in its own.
The DNS records show where the site and the mail live
Where the domain points is public as well. The records name the server answering for the website and the service handling the mail, and those two are frequently different companies. It is how people discover their email sits with a provider nobody mentioned. Our DNS management guide explains how to read what is live now.
None of this gives you access. It gives you a map, which makes the next conversation specific.
The order to take control back in
Work from the thing that cannot be replaced to the thing that can.
-
The domain, first and without exception
Everything else can be rebuilt. The name cannot. A domain that lapses and is taken by somebody else is gone, and your customers, listings and printed materials all point at it. If you win only one of these four, win this one.
-
The email, because the loss is silent
Mailboxes hold years of correspondence and nobody notices they are at risk until an account closes. Find out who provides them and get that account into the business's name. Moving them later is covered in the email migration guide.
-
The hosting, or simply a copy of the site
You need a complete copy of the files and the database. With that, the hosting account stops being leverage. Ask for a backup even if you do not intend to move.
-
The website admin, last
This matters least. Given the first three, an administrator account can be made from the back end.
Asking the person who holds it
Most handovers are cooperative. Usually nothing has been handed over because nobody asked, or because it was set up years ago under a personal account. So ask properly. A short, specific, friendly request is answered far more often than a legal-sounding one, which tends to end the conversation and start a slower one. Make it easy to say yes:
- Ask them to unlock the domain and send the authorisation code. Our transfer guide sets out what that involves, so send the link with the request.
- Ask where the email is hosted and whose name that account is in.
- Ask for the hosting login, or a full backup instead. Some people will not hand over a control panel holding other clients, and a backup is an easier yes.
- Offer to do the work, and give a date. Removing the effort is what unsticks this, and a renewal coming up is a reason anybody understands.
Keep it civil even if the relationship ended badly. Being difficult first never makes this faster.
When they cannot be reached
Sometimes the person has genuinely gone. Be realistic: recovery is a process with an uncertain outcome, and it turns on evidence rather than persistence.
The registrar holding the domain is the party that can act, not the designer and not the host. Registrars have procedures for account recovery and for disputes, and they generally want documentation before they will act. What helps is the boring paperwork: invoices for the registration, the bank or card records behind them, formation documents matching the name, and old correspondence showing who the domain was registered for. Gather it before you call.
Two things matter more than the argument while that plays out:
- Keep the domain registered. If a renewal is close, that comes before ownership, and what happens when a domain expires shows how quickly the stages pass.
- Do not let the mail go down while you wait. Make sure current correspondence reaches somebody.
Where ownership is contested rather than unreachable, that is a conversation for your own attorney. We can read the public record and tell you what state a domain is in. We cannot advise you on your rights to it.
What to change once you are in
Access is not control. Control is when the recovery path belongs to you as well.
- The contact email on the domain, first. Every reset and renewal notice goes there, so until it is an address you read you depend on somebody else. Use something durable such as info@, not one person's address.
- The account password, then two-factor authentication, on the registrar account before anything else.
- The registrant details, so the registration sits in the organisation's name rather than an individual's. How domain registration works explains those fields.
- Registrar lock back on after any transfer, and privacy on if you want your details out of the public record.
- Every password that was ever shared by email.
The accounts people forget to remove
This is where an inherited site stays quietly exposed:
- Administrator users belonging to former staff or the previous designer.
- Extra FTP or control panel users on the hosting account.
- Mail forwarding rules quietly copying your mail somewhere else.
- Third-party services still verified against your DNS, which nobody remembers adding.
- A payment method belonging to somebody who has left.
The WordPress security checklist covers the site side of this, including why an old admin account is a bigger risk than most plugins people buy.
The parts you should leave alone
Once ownership and the logins are settled, these can stay as they are:
- DNS records that already work. If mail arrives and the site loads, the records are right. Tidying them is how email goes down.
- The hosting, if the site is fine on it. Move hosts when there is a reason, and follow the migration checklist.
- The website itself. A dated design is a business decision, not an emergency.
Writing it down is the real deliverable
You are in this position because nobody ever recorded it. Keep one document listing, for each of the four parts: which company provides it, which account it sits under, which email address that account uses, when it renews, and who at your business can get in. Keep passwords out of it and in a password manager the business owns, which two people can reach.
The test is simple. If the person who handles your website stopped answering tomorrow, somebody else should be able to pick it up from that document alone.
When rebuilding beats recovering
Recovery is not always the cheaper path, and it is honest to say so. Rebuilding makes sense when the site sits on a builder platform tied to an account you cannot reach, when no copy of the files exists, or when it was due for replacement anyway. That is design work rather than hosting, and aldomedia.com is the design side of the same company.
The domain is the exception. A new name is not a fresh start, it is a reset: search results, links from other sites, vehicle lettering and everyone who already knows where to find you. Rebuild the site if you must. Fight for the name.
If you would rather not
Tell us the domain and we will read the public record and say which of the four parts are at risk. If something is broken now, the support page has the first checks, or call 716-771-2536.