Who Owns Your Domain When You Use a Website Builder? How to Avoid Lock-In
Learn how to verify domain ownership, registrar access, transfer rights, DNS control, and website export options before choosing a website builder.
AI-assisted, source-linked analysis. Product testing is only claimed when explicitly documented. How we work.
Who Owns Your Domain When You Use a Website Builder? How to Avoid Lock-In
Using a website builder does not automatically mean the builder owns your domain. The important question is who is listed as the domain’s registered holder and who controls the registrar account. Before buying, make sure you or your organization can renew the domain, update its contact and DNS settings, unlock it, and obtain the transfer authorization code without depending on a designer, employee, or inaccessible account.
That control is separate from the website itself. A domain can be movable even when a builder’s templates, apps, store features, or layout cannot be exported intact. The safest purchase is one with clear domain-control rights and a realistic exit path for both the address and the site.
What “owning” a domain actually means
A domain is not purchased forever. It is registered for a term under an agreement. ICANN describes the registrant, also called the Registered Name Holder, as the person or entity that registers the name and enters into the registration agreement with a registrar.
For a small business, that registered holder should normally be the business or an authorized person acting clearly for it—not a web designer using a personal account. Practical control also requires access to the account and email address used to manage the registration.
Think of domain control as a bundle of abilities:
- receive renewal and security notices;
- keep the registration contact information current;
- change nameservers or DNS records;
- enable stronger account security;
- unlock the domain when eligible;
- obtain its AuthInfo or transfer code;
- approve a transfer to another registrar.
An invoice bearing your company name does not prove that all those abilities are yours. Confirm the registered-holder details, contract, and account access.
Registrar, reseller, registry, and website builder are different roles
Several companies may sit between you and a domain, which makes a bundled purchase look simpler than it is.
- A registry operator maintains registrations for a top-level domain such as a particular generic extension.
- An ICANN-accredited registrar offers domain registrations to holders and maintains the direct registration relationship.
- A reseller sells or manages registrations through a registrar.
- A website builder provides the system used to create and host a site. It may also be a registrar, work through a registrar, or resell domain service.
The brand on your website-builder bill may therefore differ from the registrar of record. That is not automatically a problem. It becomes a risk when the arrangement does not tell you who the registered holder is, which company handles transfers, or how you regain control if the bundle ends.
Before paying, ask the builder to identify the registrar of record and explain whether the domain will be registered in your name or the provider’s. Put the answer in writing.
Domain, hosting, DNS, and email are separate
A single dashboard can bundle four different things:
| Service | What it controls | What can happen during a move |
|---|---|---|
| Domain registration | The right to use and renew the name | It can remain at the same registrar or transfer separately |
| DNS | Records that direct web and mail traffic | Incorrect changes can interrupt the site or email |
| Website hosting/builder | The pages, files, database, and builder features | Content and design may need a separate migration |
| Mailboxes and message delivery | DNS records and mailbox data may require their own migration |
Moving the domain to another registrar does not automatically copy the website or mailbox. Likewise, moving a website does not require transferring the domain if you can point its DNS to the new host.
This separation is useful. You may leave registration where it is, build the replacement site elsewhere, test it, and then change DNS. But it also means an exit plan must identify every dependency instead of treating “the website” as one object.
How to verify who controls a domain
Start inside the account rather than relying only on a public lookup. Can you sign in directly, see the domain, review the registered-holder information, manage renewal, and change DNS? Is the recovery email controlled by your organization? Is multi-factor authentication enabled with recovery methods the organization can retain?
Then use ICANN Lookup to check the registrar and status information. ICANN’s lookup service uses the Registration Data Access Protocol, or RDAP. Public results may redact personal data, so a missing or masked name does not prove that the builder owns the domain. Privacy and data-protection rules can hide details that remain available inside the registrar account.
Also distinguish privacy from proxy registration. ICANN explains that a privacy service can publish alternative contact information while the customer remains the registered holder. With a proxy service, the service provider is the holder of record and licenses use of the domain to the customer. If a provider proposes a proxy arrangement, read the service terms and the process for recovering or transferring the name.
Can you transfer a domain away from a website builder?
For generic top-level domains covered by ICANN policy, the Registered Name Holder has authority to approve or deny an inter-registrar transfer. A transfer normally requires an eligible domain, an unlocked status, and an AuthInfo code. The gaining registrar also needs authorization.
Transfer rights do not mean every domain can move immediately. Under ICANN’s current Transfer Policy, a registrar may deny a request made within 60 days of the domain’s initial creation or within 60 days after a previous inter-registrar transfer. A separate 60-day lock may follow a material change of registrant if the holder did not opt out before that change. Registry rules, disputes, or court proceedings can also affect eligibility.
Check the domain status before planning a deadline. clientTransferProhibited usually indicates a registrar lock. ICANN policy requires an accessible way for the holder to remove that status; where self-service is unavailable, the registrar must provide the AuthInfo code and remove the lock within five calendar days of the holder’s request. This rule does not override a separate policy-based 60-day restriction.
Ask these questions before buying:
- Where is the transfer control located?
- Can the registered holder obtain the AuthInfo code without contacting a designer?
- Are there extra contractual steps through a reseller?
- Does transferring or canceling affect a bundled free-domain promotion?
- Who must approve the request, and which email receives it?
Do not wait until a launch dispute or account closure to learn the answers.
The agency and designer account trap
An agency may register a domain for convenience while building a site. The arrangement can work, but only if authority and access are explicit.
The highest-risk version places the domain in an individual designer’s personal account, uses that person’s email for recovery, and leaves the client with no direct registrar access. If the relationship ends, the client may have to obtain cooperation before it can renew, edit DNS, or transfer.
A better setup records the client organization as the holder, uses an organization-controlled email address, and gives the client durable account access. The agency can receive delegated access when the registrar supports it. The contract should state who pays renewal fees, who responds to verification requests, what happens when the engagement ends, and how credentials and codes are handed over.
For an existing domain in an agency account, do not casually overwrite contact information on the eve of a move. A material registrant change can trigger a transfer lock. Review the registrar’s current procedure and sequence any holder change and registrar transfer deliberately.
Keeping the domain does not mean the whole website is portable
Domain portability and website portability must be tested separately. A builder may let you direct your domain elsewhere while offering only a partial export of site content. Proprietary layouts, themes, widgets, forms, member records, product data, automation, or app integrations may not recreate themselves on another platform.
Official export documentation is more useful than a vague promise that a site is “portable.” For example, WordPress.com says its standard content export includes posts, pages, comments, and links to images, but not theme design, customizations, plugins, or the image files themselves. Squarespace likewise documents platform-specific export limits. These are examples, not universal rules: inspect the documentation for the exact builder and plan you are considering.
Download a sample export if possible. Check its format, whether media files are included or merely referenced, which content types are omitted, and whether another system can import it. A usable copy of text is valuable, but it is not the same as a deployable copy of the whole site.
If you are still choosing a platform, the existing website-builder comparison can help with product-level tradeoffs. Use the control checks in this guide as a separate part of that decision.
Domain-control matrix
Use this matrix before accepting a bundled domain or agency-managed registration.
| Check | Lower-lock-in condition | Warning sign |
|---|---|---|
| Registered holder | You or your organization is named in the account and agreement | Provider or individual is holder without clear transfer terms |
| Account access | Organization controls login, recovery email, and MFA recovery | Only a designer or former employee can sign in |
| Renewal | You can see dates, fees, payment method, and notices | Renewal depends on an informal third-party reminder |
| DNS | You can view and edit records or nameservers | DNS changes require an undefined manual request |
| Transfer | Unlock and AuthInfo process is documented | Provider will not explain the registrar or transfer process |
| Website export | Format, included data, media, and exclusions are documented | “Exportable” is promised without a usable format or test |
| Exit terms | Contract covers handoff, timing, fees, and responsibilities | Ownership and offboarding are absent or ambiguous |
A warning sign is a reason to investigate, not automatic proof of misconduct. Some managed services intentionally restrict access to prevent accidental outages. The question is whether there is a documented, enforceable route to regain control.
Pre-purchase checklist
Before registering a domain through a builder, host, agency, or designer, record the answers to these questions:
- Who will be the Registered Name Holder? Use the legal person or organization that should control the registration.
- Which registrar is the registrar of record? Do not stop at the reseller or builder brand.
- Who controls the account and recovery email? Prefer an organization-controlled address that will survive staff changes.
- Can you manage renewal and DNS directly? Identify any support-only process and its response time.
- How do you unlock and transfer the domain? Find the AuthInfo-code instructions and current restrictions.
- What happens when a promotion ends? Check renewal fees and whether cancellation separates the domain from the site plan.
- What exactly can be exported? Identify content, media, design, store data, forms, members, and integrations separately.
- Can you test the export? A sample file reveals more than the word “portable.”
- What happens to email? Identify the mail provider, mailbox export options, and DNS records.
- What does the contract require at exit? Include handoff duties, fees, deadlines, and dispute procedures.
Save the registration agreement, receipts, and confirmation showing the original registration date. Keep an inventory of registrar, DNS, hosting, email, and analytics accounts, with organizational access and secure recovery methods.
Exit checklist: move without losing the domain or email
When leaving a builder or agency, sequence the work rather than canceling first.
- Inventory the services. Identify the registrar of record, DNS host, website host, email provider, and any third-party integrations.
- Confirm holder and account access. Update stale contact details carefully and account for any change-of-registrant lock.
- Check expiration and transfer status. Avoid beginning near expiration or while a policy lock applies.
- Export and verify the site data. Keep independent copies of content, media, customer or product data where applicable, and configuration records.
- Build and test the destination. Confirm pages, forms, redirects, analytics, and structured data before switching traffic.
- Preserve email. Record mail DNS settings and migrate mailboxes before changing or canceling service.
- Change DNS or transfer the domain deliberately. These can be separate steps; choose the order that limits downtime.
- Verify renewal and recovery controls. Confirm the new account’s holder data, payment method, security, and notices.
- Cancel old services last. Keep the old platform available until the site, domain, email, and exports have been checked.
DNS changes can temporarily affect traffic while records update. A complex business site or disputed registration may justify help from a qualified migration professional or attorney.
What if the provider will not give you access?
First identify the registrar through ICANN Lookup and collect the registration agreement, invoices, emails, and any contract describing domain ownership. Ask the provider in writing for the exact holder information, account handoff procedure, transfer eligibility, and AuthInfo-code process.
If the issue is with an ICANN-accredited registrar, review the registrar’s support and escalation channels and ICANN’s registrant resources. A reseller may require escalation through its sponsoring registrar. Do not assume that editing the public website, paying hosting bills, or holding a trademark automatically resolves a registration dispute.
Disputes about contractual ownership, business names, fraud, or authorization can turn on facts outside a technical transfer process. This guide cannot determine legal ownership; obtain appropriate legal advice when rights are contested.
Bottom line
The safest website-builder purchase leaves no mystery about the domain. You should know who the registered holder is, which registrar holds the registration, who controls account recovery, and how to renew, edit DNS, unlock, and transfer the name.
Then test the separate portability question: what site content and data can actually leave the builder, in what format, and what must be rebuilt? Keeping control of the domain preserves your public address. A verified export and exit plan determine how much of the website can follow it.
Sources
- ICANN: Information for Domain Name Registrants
- ICANN: Relationship Between Domain Name Industry Parties
- ICANN Transfer Policy
- ICANN: About Auth-Code
- ICANN Lookup FAQ
- ICANN: Privacy and Proxy Service Providers
- ICANN: Expired Registration Recovery Policy guidance
- WordPress.com: Export your website’s content
- Squarespace: Exporting your site