For agencies and freelancers
Who actually owns your client's domain?
Paying the renewal makes you the owner of nothing. Holding the password does not either. One role decides everything, it is written down at the registry, and plenty of agencies find out which one they hold at the worst possible moment.
What you leave with: a decision tree that starts from your real situation and gives you the next move, plus the email to put a misplaced registrant right.
Four roles, potentially four different people
A domain name has a registrant, an administrative contact, a technical contact, and a registrar that holds the registration. Then, in practice, there is whoever pays the bill — and paying is not one of those roles.
Inside an agency, these roles blur without anyone deciding to. You register the name during the project, with your address and your card, because the client has no account yet. Two years later the name is still in the agency's name, and nobody noticed because everything works.
It only becomes a problem at three moments: when the client leaves, when you stop trading, and when somebody has to sign a decision. At those three moments, it becomes a very large problem.
What each role can actually do
The exact labels change from one extension to the next, but the distribution of power does not.
| Role | What it can decide | What it cannot |
|---|---|---|
| Registrant | Holds the name. For generic extensions, ICANN's Transfer Policy states that the Registered Name Holder is the only party with the authority to approve or deny a transfer request to a gaining registrar. | Nothing can be done over their objection. It is the only role that carries weight in a dispute. |
| Administrative contact | Receives notifications and acts as the day-to-day point of contact on the record. | Is not the owner. Being the admin contact grants no rights over the name. |
| Technical contact | Works on the configuration: name servers, records, signing. | Decides neither the transfer nor the change of registrant. |
| Registrar | Executes operations at the registry, supplies the authorization code to the registrant, applies the locks. | Does not own the name, and may only deny a transfer in the cases the applicable policy allows. |
| Whoever pays | Nothing at all. Payment is not title. | Fronting ten years of renewals creates no right over the name. |
That last role is the one that traps agencies, in both directions: paying for ten years does not make you the registrant, and being the registrant without paying relieves you of nothing — if the name expires, it is your name on the record.
Checking in two minutes, without asking anyone
For many extensions, part of this information is public. Since GDPR came into force, the contact details of individual registrants are usually redacted: what remains visible is still enough to answer the two questions that matter.
- 1
Read off the registrar
It is almost always displayed, even when the contact details are not. It determines who you will be talking to, and under which rules.
- 2
Read off the expiry date
That is the number that decides how urgent this is. Write it down somewhere: it will not remind you.
- 3
Check whether an organization appears as registrant
If your agency's name shows up, you have your answer. If nothing shows up, that is not an answer: that is redaction.
- 4
If it is redacted, log into the account
The registrar's own interface shows the real registrant to whoever holds the login. If you hold it and the client does not, note that down: it is already a situation in itself.
- 5
Ask the client what they believe
A good share of disputes start as a quiet misunderstanding: they think it is theirs, you think it is theirs, and it is in the name of an intern who left years ago.
Your situation, and the move that follows
Six cases, and only one of them needs no action at all. Find yours.
The domain is in the client's name and they have account access
- What it means
- This is the healthy case. You are a supplier, not a custodian, and your client can leave without asking your permission.
- What you do
- Nothing to fix. Just confirm somebody actually reads the domain's contact address, and that the renewal is covered.
The domain is in the client's name, but only you have access
- What it means
- On paper everything is fine. In practice you are a single point of failure: if you are unreachable, nobody can act on the name.
- What you do
- Give them their own login on the account, or move the name to an account they own. Then write and tell them it is done.
The domain is in your agency's name and the client does not know
- What it means
- The most common case, and the most dangerous. There is nothing illegal about it; it is simply untenable the day you disagree.
- What you do
- Put it right before anyone asks. A change of registrant you propose is a professional gesture; the same change demanded by a lawyer looks like an admission.
The domain is in a former provider's name and they do not answer
- What it means
- You have neither the name nor the leverage. Neither does the client. And the expiry date keeps moving toward you.
- What you do
- Put everything in writing to the client, including the expiry risk and what it would cost. Depending on the extension, dispute resolution procedures exist at the registry: that is lawyer's territory, not yours.
The domain is in the name of someone who left the client's company
- What it means
- The registrant may still be reachable, but they are no longer the right person. Every operation will need their agreement.
- What you do
- Start putting it right while the relationship is still good. A change of registrant requires the consent of both parties, for generic extensions and for .fr alike.
You do not know
- What it means
- A very common answer, and it counts as “no”.
- What you do
- Inventory every domain you manage this week. The list is almost always longer than you think, and it almost always contains at least one name in the wrong place.
Why it should be in the client's name, almost always
The simple rule: a domain name belongs to whoever's name it is. It is the client's identity, not a deliverable of your engagement. A logo can be assigned, a site can be assigned; a domain is registered in the right name from the start.
The argument you hear against it — “if it sits with me, I manage it better” — confuses ownership with access. You can perfectly well manage a domain you are not the registrant of: delegated access to the account, or a written mandate, is all it takes. You lose the leverage and you keep the work. That is exactly what you are paid for.
The one case worth discussing is where you finance the name inside an operation whose risk you carry: a brand you registered, a portfolio you run. There, the logical registrant is you. That goes in the contract — beforehand, not after.
The email that puts the registrant right
It neither apologizes nor dramatizes. It presents an ordinary piece of housekeeping, because that is what it is.
Subject: Tidying up: the [domain] domain name
Hi [first name], I'm tidying up the domain names I look after, and I want yours in the right configuration. Today, [domain] is registered in [agency]'s name. That's a common situation — the name was registered during the project, before you had an account with the registrar — but it isn't the right one: this name is yours, it should be in your name. So I'd like to move it over. In practice: — you become the registrant, and you keep control of the name whatever happens between us; — I stay listed as technical contact and keep looking after it exactly as I do now; — you'll get a confirmation message to approve: that's the normal procedure, both parties have to consent. Two things worth knowing before I start. First, depending on the extension, a change of registrant can temporarily block any move of the name to a different registrar — so if you ever plan to hand it to someone else, that move has to happen first. Second, the contact address you give has to be one you genuinely read: that's where expiry notices will arrive. Just let me know if I should go ahead. [signature]
What belongs to a lawyer, and not to us
This page describes technical roles and registry procedures. It says nothing about your rights: who owns what in a dispute, what a contract that never mentions the domain is worth, what you can demand from a former provider — those are legal questions, and the answers depend on your contract and your jurisdiction.
Three questions to put to a lawyer if things get tense. Does the signed contract say anything about ownership of the name and the accounts? What does it provide for at the end of the relationship? Does the name reproduce a registered trade mark, and whose?
Where the facts on this page come from
- ICANN — Transfer Policy: the Registered Name Holder is the only party authorized to approve or deny a transfer to a gaining registrar (section I.A.1.1), and a Change of Registrant requires confirmation from both the prior and the new registrant (section II.C).
- Afnic — Technical and operational procedures guide (in French): for .fr, the registrar collects the agreement of both the outgoing and the incoming registrant, and keeps timestamped proof of it.
Know, across every domain, without opening them one by one
For each domain you hand it, DomainVigil reads the registrar, the expiry date and the public registry data, and warns you before the deadline. The inventory is done once; after that it keeps itself.
Inventory your domainsNo card required. The first reading arrives in seconds.