Checklist

The seven things you should own for your website

You can check every one of these yourself, today, without asking anyone's permission. Most owners have never seen the list.

When a website project finishes, there's a set of things that should end up in your hands. Most owners never get a list, so they never notice what's missing until they need it — and by then the person who has it may be gone.

This is the list. Seven items. You can check every one of them yourself, and you can ask for them at any point — before you hire anyone, in the middle of a project, or five years after one finished.

1. The domain name

Registered at a registrar, in an account whose login email is yours, with your business as the listed registrant and your card on the renewal.

How to check: look it up at lookup.icann.org, then try a password reset at that registrar using your own email. If the reset email arrives, you're in control.

Why it's first: it's the only item on this list that can't be replaced. Everything else can be rebuilt.

2. The hosting account

The server the site actually runs on — Vercel, Netlify, SiteGround, Bluehost, whatever it is. Your account, your login, your card.

How to check: can you log in right now without asking anybody? If your developer is paying for it, you don't have this.

The tell: a developer who hosts your site on their account and bills you monthly for "hosting" has made you a tenant. That may be fine while the relationship is good. It's the thing that hurts when it isn't.

3. Control of DNS

DNS is the settings layer that points your domain at your hosting and routes your email. It usually lives at the registrar or the host.

Why it matters more than it sounds: DNS is what decides where your email goes. People focus on the website and forget that the same settings control whether messages to your business address arrive at all. Losing DNS control is worse than losing the website.

4. The source code and the content

The actual files — HTML, CSS, images, and any templates or components. Ideally in a repository you own (a private GitHub account is free), or at minimum as a zip you keep somewhere the business keeps records.

How to check: ask for a copy. The response tells you everything. "Here you go" is the right answer. "You don't need that" is not.

You do not need to know how to read the code. You need to have it, so that any competent developer can pick up where the last one left off. That is the entire point.

5. The database, if you have one

Not every site has one. If yours takes bookings, stores customers, runs a portal or a quote system, or lists inventory, it does.

What you want: access to the database, and an export of it. Ask how backups work and where they go. "It's backed up" is not an answer — ask where, how often, and how you'd get one.

6. Every third-party account

This is the one people always miss, because it's not one thing, it's a scattering of small things:

  • Google Business Profile — frequently created by an agency and never handed over
  • Google Analytics, Search Console, and any tag manager
  • Your email service — Google Workspace, Microsoft 365
  • Anything the forms depend on — a form service, a mail sender
  • Payment processing, booking tools, chat widgets, review platforms
  • Social accounts set up on your behalf

The Google Business Profile is the one to check today. For a local business it's often the single biggest source of calls, and it's routinely created by whoever did the marketing and never transferred. If you don't have owner access, you can request it — Google has a process, and it takes a few days.

7. The passwords, written down somewhere the business keeps records

Not in one person's head. Not in one person's inbox. Not in a text thread.

A free password manager works. So does a document in your business's drive, if access to it is properly controlled. The standard to aim for: if you were unreachable for a month, could someone else keep the business running?

The one-page version

Ask before you hire anyone

"When the project's finished, will the domain, the hosting, the database, the accounts, the passwords and the source code all be in my name? And can I have that in writing?"

Any developer who says yes without hesitating has done this before. Any developer who explains why you don't need it has told you what the relationship will be like in three years.

What this isn't

Owning all of the above doesn't mean doing the work yourself, and it isn't a lack of trust. A good developer wants you to own it — it removes the awkward conversation later, and it means their work stands on being worth paying for rather than on being hard to leave.

It also doesn't mean you can't have someone maintain the site. It means that if you stop paying for maintenance, you still have a website. Those are two different things, and plenty of arrangements quietly blur them.

If you're checking an existing site

Work down the list and mark each one have it, don't have it, or don't know. The "don't know" items are the ones to chase first, because they're the ones where you'd be surprised at the worst moment.

Then fix them while everything is fine. Every one of these is easy to sort out during a good relationship and hard to sort out during a bad one.

If you'd rather not do this alone

I build websites for small businesses around Chicago, and every project is handed over completely — domain, hosting, database, accounts, passwords, and source code, all in your name on the last day. Pricing is published before you call: $750 for a one‑page site, $1,200 for a business site.

I'll also just answer the question. If you're stuck on any of the above and you're not looking to hire anyone, call or email me and I'll tell you what I'd do. No pitch.

Ask me about your situation (815) 262-5440