The emails go unanswered, the phone number is disconnected, or the freelancer simply took a new job. The website still runs. But nobody can change it, and nobody knows how long it will keep running.
That is unpleasant, but rarely an emergency. As long as the site is up, you have time to work through it step by step. This article sets out the order that tends to work.
What you still control
Before you request anything, take stock. Go through your records and note what you find:
- Invoices. Who bills you for what? A domain, a hosting plan, a maintenance fee? Every invoice names a provider, and every provider is a possible way back in.
- Emails with login details. Many agencies send a message at launch with the login for the content management system. Search for "login", "password", "access" or the agency's name.
- Contracts and quotes. They often state who owns the domain and the source code, and what has to be handed over when the contract ends.
- Logins that still work. Can you sign in to the site's admin area? Do you have access to the mailboxes on your domain?
You end up with a list in three columns: have it, know of it but no access, unknown. The third column is usually longer than you hoped, and that is normal.
Domain first
The domain matters most. Whoever controls it decides where your website and your email point. A new server can be set up in a day. Getting a lost domain back takes effort and does not always work.
First find out which registrar holds the domain. For .at domains, nic.at is the central
registry, and the whois lookup on nic.at shows which registrar manages the domain. For .com
and other generic top-level domains, the ICANN lookup at lookup.icann.org gives the same answer.
Then the key question: who is registered as the domain holder, your company or the agency? For privacy reasons, the public whois often no longer shows this. The registrar can tell you whether you are the holder, and if you are, set up an account for you or transfer the domain to another registrar.
If the agency is registered as the holder, it takes more work. You then need the agency's cooperation or proof that the domain is yours. Invoices you paid for the domain help.
Note: this is not legal advice. If the contracts are unclear or you cannot agree on what is handed over, talk to a lawyer.
Server and hosting: who pays the bill?
A simple rule of thumb: whoever pays the hosting bill is usually the host's customer.
If you pay for hosting yourself, go straight to the host. As the customer, you get access to the account, and through it to the server, the database and the backups.
If you pay the agency for hosting, the site runs on a server the agency rents. If that contract ends, your website goes offline with it. Save a copy as soon as you can: files and database, not only what you see in the browser.
If you don't know where the site is hosted: your domain's DNS records show the IP address it points to, and the IP address belongs to a host. You can look this up with free tools, or have someone who does this regularly check it for you.
Recovering logins
With the domain and hosting under your control, the other logins can almost always be restored:
- Content management system. Anyone with access to the database or the server can create a new administrator or reset a password.
- Email. If the mailboxes are with the same host, you reach them through the account. If they are elsewhere, the same question applies as for hosting: who is the customer?
- Certificate. Most websites now use certificates that renew automatically. What matters is that the renewal is set up again after a move. Otherwise the browser shows a warning a few weeks later.
- Source code. For a site with a content management system, the code usually sits on the server. Custom applications often also have a repository, on GitHub or GitLab for example. Ask for it if you do reach the agency.
If you do get hold of them, put a specific request in writing: which logins, by when, in what form. A vague request for "all the documents" is easy to overlook.
When to rebuild instead
Not every website is worth saving. A rebuild is often the better choice when:
- the content management system has had no updates for years and updating it amounts to a rebuild,
- the site depends on plugins or extensions that are no longer maintained,
- nobody documented the code and it is so tangled that every change is a risk,
- you were planning to rework the content or the design anyway.
The reverse also holds: a current site on a widely used system can usually be taken over and kept running. The decision should rest on a review of the code and the server, not only on the wish for a fresh start.
If you do rebuild, the domain stays the same, and ideally so do the addresses of the individual pages. Redirecting old URLs instead of dropping them keeps the search rankings the old site built up.
So it doesn't happen again
Most of these steps would be unnecessary if the logins had been in your hands from the start. Write them down and keep the list current:
- the domain's registrar and account, with your company as the holder
- the host and account, with your company as the customer
- an administrator login for the content management system
- access to email, DNS and, where there is one, the code repository
- who looks after the site, and who covers for them on holiday
Our website access checklist covers what exactly belongs on that list and where to keep it safe.