Business IT Governance
Who Actually Controls Your Business Domain?
A domain name is a business asset. Make sure your company can see, secure and recover the accounts behind it.
7 min read — Altitude IT Support
Who owns your company’s domain name?
Most business owners will answer: “We do.”
Now ask: “Can you log into the registrar account?”
That is often a much harder question.
Businesses frequently inherit arrangements created years earlier by a founder, employee, IT company, web developer, marketing agency or a friend who helped set things up. Everything works, so nobody investigates. Then a supplier relationship ends, an employee leaves, a website needs moving, Microsoft 365 is migrated, a renewal fails, the business is sold, the company rebrands or a cyber incident occurs.
At that point, control matters. Not because a provider managing a domain is automatically a problem, and not because losing registrar access automatically gives someone access to Microsoft 365. It matters because an important business asset should not depend on an undocumented account, an old mobile number or one person who happens to know the password.
The useful question is not only “Who manages our domain?” It is “Who ultimately controls it, and could our business recover it if circumstances changed?”
Your Domain Is More Important Than Your Website
It is easy to think of a domain as simply the address printed on your website and email signature. In practice, it can sit underneath much more of the business:
A domain may be used for a website, business email, Microsoft 365 verification, online services, customer communications, marketing campaigns and third-party applications. That does not mean one person with registrar access automatically controls all of those systems. Each service has its own accounts and permissions.
It does mean that the domain and its DNS are a highly privileged part of the organisation’s technology estate. They can influence where web traffic goes, how email is authenticated and whether a service can prove that it is authorised to use the business’s name. That makes ownership, access and recovery worth documenting alongside other core systems.
Management Is Not the Same as Ownership
There are perfectly legitimate reasons for an IT provider to administer a customer’s domain or DNS. A provider may be responsible for technical changes, renewals, monitoring or coordinating a website migration. The important distinction is between management and ownership or ultimate control.
An accountant may manage your company finances. That does not mean the accountant should own your bank account or be the only person who can recover it. Likewise, an IT provider can administer a domain without the customer losing visibility or the ability to regain control.
A healthy arrangement should make the roles clear:
- the business is recorded as the registrant or account holder where appropriate;
- the business knows which registrar and DNS provider are involved;
- administrator access is limited, named and protected with MFA;
- renewal notices and payment arrangements are understood;
- recovery details are held in an organisational process rather than one person’s private inbox; and
- the business could take control or appoint another provider without starting an emergency investigation.
Ask Your IT Provider These Questions
You do not need to turn this into an adversarial exercise. Ask for a clear record and a sensible explanation. A professional provider should be comfortable answering:
- Which company is our domain registrar?
- What account is the domain registered under?
- Is that account controlled by our business?
- Who has administrator access?
- Is MFA enabled on the registrar account?
- Who receives renewal notifications?
- Is automatic renewal enabled?
- Is the payment method current?
- Who controls our DNS?
- What other business domains do we own?
- Are any domains due to expire?
- Could we take control ourselves if our relationship with you ended tomorrow?
The final question is particularly useful. The answer should describe a documented handover, not a search for one person’s password or a vague promise that “the provider has it covered”.
Don’t Forget DNS
If the domain is your business’s address on the internet, DNS is effectively the directory telling internet services where things belonging to that domain should go. DNS records can help direct:
- website traffic;
- email delivery;
- Microsoft 365 domain verification and services;
- verification records for third-party applications;
- security records such as SPF, DKIM and DMARC; and
- other online services that need to confirm the business controls the domain.
Knowing who can change DNS is therefore important. It does not mean DNS access automatically compromises a business. It means an unauthorised or poorly documented change could affect a service, interrupt email or weaken a control, depending on the record and the system that relies on it.
For the email-security side of this picture, see Altitude IT’s guide to protecting your business email with DMARC and the Email Authentication and Sending Architecture Review. The cyber security services page also explains how identity, email, devices and continuity fit into a broader assurance approach.
Domains and Microsoft 365
Businesses commonly connect their domain to Microsoft 365 for email and other services. DNS records can be used to verify the domain and help route or authenticate email. Microsoft 365 also has its own tenant, administrator accounts, licences and security settings.
These are related, but they are not the same account. Access to a registrar does not automatically provide access to the Microsoft 365 tenant. Conversely, knowing who administers Microsoft 365 does not necessarily tell you who can renew the domain or change DNS.
Document both sides of the relationship. Record the domain, the registrar, the DNS provider, the relevant Microsoft 365 tenant, who can make changes and how recovery works. If the tenant itself has unclear ownership, Altitude’s Microsoft 365 Tenant Ownership Review can help establish administrator control, licensing and provider relationships. The broader Microsoft 365 support service covers the practical administration around the tenant.
What Happens When Your IT Provider Changes?
Changing IT provider should not turn into a hunt for registrar passwords, DNS credentials, domain ownership, missing MFA devices, renewal information or undocumented accounts.
The customer should have a clear record of important technology assets and a planned handover route. Good IT support should make a business easier to manage — including when the customer eventually decides to leave. That is not anti-provider. It is a sign that the provider has managed the relationship professionally rather than making knowledge or access unnecessarily dependent on one supplier.
The same principle applies if a web designer, marketing agency or other supplier registered the domain during a project. Bundling registration with a website project is not automatically bad. The business should still know:
- who registered the domain;
- whose account contains it;
- whose payment card renews it;
- who can modify DNS; and
- how control could be transferred if the supplier stopped working with you.
Former Employees Can Leave More Than a Laptop Behind
A domain or DNS service may originally have been configured using an employee’s personal email address, an old company email address or a personal mobile number for MFA. The person may have left years ago while the account continued to renew quietly.
This can become a continuity problem when the business needs to change a record, recover an account or prove ownership. Where practical, use organisational accounts, named administrators, secure MFA recovery arrangements and documented access reviews. Do not assume that a current employee remembering how the account was created is a recovery plan.
Build a Simple Domain Register
The most useful practical step is often a simple domain register. This does not require an expensive management platform. For many SMEs, a properly secured and maintained record is enough.
| Domain | Purpose | Registrar / account | DNS provider | Renewal / MFA | Owner / status |
|---|---|---|---|---|---|
| example.co.uk | Main website and email | Registrar / business account | DNS provider | Date / auto-renew / MFA | Responsible person / ACTIVE |
Useful status labels might include:
- ACTIVE — currently used and monitored;
- PROTECT — retained because it protects the brand or a related name;
- REDIRECT — points visitors to another domain;
- REVIEW — needs an ownership, usage or renewal decision; and
- RETIRE — approved for retirement after dependencies have been checked.
Do Not Automatically Delete Old Domains
An old domain may look irrelevant but still be connected to traffic, email addresses, backlinks, customer recognition, online accounts, old documentation, QR codes or supplier references. Before retiring it, check those dependencies and record the decision.
Also consider what happens after a domain is allowed to expire. The IT Club’s expired-business-domain guide explains why an expired business domain may still have value to criminals. That article explores what can happen after expiry; this article addresses the earlier governance question: does your business control its domains in the first place?
Keeping every domain forever is not the answer either. Retire domains deliberately, after checking their use, ownership, security and recovery implications.
The 10-Minute Domain Control Test
Ask the business owner or technology lead to complete this short test. The goal is not to expose anyone who does not know an answer. It is to identify assumptions worth replacing with a record.
Can you fill these in without chasing one person?
- Our main domain registrar is: ____________________
- The account belongs to: ____________________
- The recovery email is: ____________________
- MFA is enabled: YES / NO
- DNS is managed by: ____________________
- Automatic renewal is enabled: YES / NO
- Renewal notifications go to: ____________________
- We have a list of our other domains: YES / NO
- Our business could regain direct control without relying on one individual: YES / NO
If several answers are “I don’t know”, that is worth fixing. Not because something is necessarily wrong, but because an important business asset should not depend on assumptions.
Monitor Renewal Dates Without Confusing the Cause
A domain register is much more useful when someone checks it regularly. A separate read-only monitor can look up registration expiry dates and warn before a domain enters its renewal window. It can also report a failed lookup clearly: an unavailable lookup is not proof that the domain has expired, so the date should be confirmed with the registrar.
Renewal monitoring should not hide other problems under the same label. A useful alert distinguishes:
- Registration expiry — confirm automatic renewal, payment details, registrar ownership and recovery access;
- DNS configuration — check nameservers, DNS hosting and records used by the website, redirects or other services; and
- Microsoft 365 configuration — check the tenant’s custom-domain verification and mail-routing records in Microsoft 365 and DNS.
These checks answer different questions. A domain can be active at the registrar while its DNS is wrong, and a domain can have healthy DNS while Microsoft 365 mail routing or verification needs attention. Monitoring credentials and alert routing should be held in the secured monitoring job configuration, never in a public article or domain register shared more widely than necessary.
Customer Control Is Part of Good IT
Altitude IT believes customers should understand and retain appropriate control of important technology assets, including the Microsoft 365 tenant, domains, DNS, licences, backups, security services and documentation.
A provider can manage those services. Management should not require unnecessary customer dependency. The customer should know who has access, why they have it, how it is protected and how another competent person could take over if circumstances changed.
This is also why access and ownership belong in business continuity planning. The domain name recovery and business continuity case study shows the practical consequences when administrative control has been lost. A Microsoft 365 Security Baseline Review can provide a similar structured look at tenant access and security configuration, while Altitude IT’s approach starts with understanding what the business needs to control and recover.
If you are reviewing IT support in Manchester or IT support in Stockport, ask the same ownership questions of every provider. The right answer may be that the provider administers the domain day to day. The important part is that your business can see the arrangement, secure it and recover from it.
Frequently Asked Questions
How do I find out who owns my business domain?
Start by identifying the registrar, then confirm which account holds the domain and which organisation is recorded as the registrant or account holder where appropriate. A public lookup may help identify the registrar, but it will not replace access to the registrar account or confirm every contractual detail.
Should my IT provider control my domain?
An IT provider may legitimately manage a domain and its DNS. The business should still retain appropriate ownership, visibility and recovery access, with named administrators, MFA, renewal information and a documented handover route rather than relying on provider-held exclusive control.
Does domain registrar access give access to Microsoft 365?
No. The registrar account and Microsoft 365 tenant are separate systems with separate permissions. Domain and DNS control can affect verification or routing, but it does not automatically grant access to Microsoft 365 mailboxes, files or administrator settings.
Why is DNS important to a business?
DNS records tell internet services where to find or verify parts of your domain. They can support websites, email delivery, Microsoft 365 verification, third-party services and SPF, DKIM and DMARC records. DNS access is privileged, but it is not by itself proof that a business has been compromised.
What should be in a business domain register?
Record each domain’s purpose, registrar, account holder, DNS provider, renewal date, automatic-renewal status, MFA, responsible person, recovery route and current status. Include domains used for redirects, campaigns, old brands and services, not just the main website domain.
Should a business keep every old domain?
No. Old domains can sometimes still support traffic, email, backlinks, customer recognition, online accounts or documentation, so check those dependencies before retiring one. Retain, redirect or retire it as a documented business decision rather than allowing it to expire unnoticed.
What happens if the employee who set up the domain has left?
The business may still be able to recover the account through the registrar, but an old email address, personal mobile number or missing MFA device can make the process harder. Move recovery details to an organisational arrangement where practical and document who can regain access.
Can Altitude IT help review domain and DNS control?
Altitude IT can help identify domains, registrar and DNS arrangements, Microsoft 365 dependencies, renewals, authentication records and obsolete entries, then document who controls each part. We will distinguish between what can be verified, what needs the current supplier’s cooperation and what requires specialist recovery work.
Sources and Further Reading
Domain registration, DNS and email authentication arrangements vary between providers and services. These first-party and authoritative guides support the technical distinctions in this article: