Skip to main content
General Tech
4 min readβ€’

Who Owns Your Domain and DNS? A Small-Business Audit

A practical continuity checklist for domain registration, renewals, DNS access, website and email records, and agency handoffs before an outage occurs.

By Alain Vartanian

Share:

If your website or email stopped working tomorrow, who could log in and fix the domain settings? β€œOur web person handles it” is not a recovery plan. Domain registration, DNS hosting, website hosting, and email are related but often live in different accounts.

This is an evergreen audit for the missed publishing window, not a claim that a particular August or September outage affected your business. The goal is simple: prove that the business can renew its domain, inspect its DNS, and make a controlled change without depending on one employee, agency, or expired card.

Registrar access, renewal, and DNS changes support one domain used by the website and email

Visual: The domain is a shared dependency. Website and email may have different vendors but still rely on correct domain and DNS settings.

Find the four owners

Write down the registrar where the domain is registered, the DNS provider that hosts its authoritative nameservers, the website host, and the email provider. These may be the same company, but do not assume they are. Check the registrar account directly for the registration contact, renewal status, payment method, and nameserver settings. An old invoice is not proof of current control.

At the DNS provider, identify who can view records, edit them, and change nameservers at the registrar. An agency can manage the site while the business retains ownership and delegated access. If the only admin login belongs to a former vendor or employee, document a recovery path before making changes.

Know which records matter

Your website commonly depends on address or alias records such as A, AAAA, or CNAME. Email delivery depends on MX records, and sender-authentication settings often use TXT records. The exact setup varies. Cloudflare's DNS record management guide explains how records are created and edited and how TTL affects caching. Its email-record guidance covers the mail side.

Export or document the current record set before a migration. Capture nameservers, record names, types, values, TTLs, and the date checked in a secure operations location. Do not paste private service tokens into a public document. A screenshot alone can miss records or hide exact values.

Run a safe access test

Have two authorized people independently confirm they can reach the registrar and DNS accounts, with MFA and recovery methods that belong to the business. Confirm renewal notices go to a monitored business mailbox and the payment method is current. Then verify the team knows where changes are requested, approved, logged, and rolled back.

Do not test control by changing live nameservers or MX records. A read-only login and exported record list prove access without creating an outage. If a change is needed, schedule it with a known before-state and a way to restore the previous values.

Handoff checklist for a new provider

  1. Confirm the business is the registrant and has direct account access.
  2. Give the provider scoped access where supported, rather than sharing the primary owner login.
  3. Record the current nameservers and export DNS records.
  4. Map which website and email services depend on each record.
  5. Agree on the cutover, rollback, and who watches web and mail delivery afterward.
  6. Remove old vendor access only after the new route is working and ownership is verified.

One broken DNS change can affect more than a homepage. The point of this audit is to make recovery boring. If you need a second set of eyes on registrar access, DNS records, and continuity, ask about managed IT support.

Need a second set of eyes on your tech?

Talk through the risks, access, and next practical fix for your business.