Skip to content

Problem

Taking over a client’s site that somebody else built

It is not the code that stops you, it is the access list. A site taken over without the five accounts that matter hands you the responsibility without the means to carry it.

Before touching a line, run the outside audit — it needs no access and takes ten minutes — then ask for five things and verify them yourself: the registrar account, the DNS zone, the hosting, the mail, the code. Each one takes five minutes to test, and each one costs a month when it is missing.

Do this right now

Four moves, all within the first week. After that the client assumes you accepted the file as it was.

  1. Run the outside audit before asking anyone for anything

    10 min

    With no access at all you can already learn who the registrar is, when the name expires, where the zone is delegated, which provider handles the mail, who issued the certificate and how long it runs. You arrive at the meeting knowing what you are asking for and from whom: it changes the conversation entirely, and it stops you chasing access at a provider who left the file years ago.

  2. Ask for the access in writing, one by one, with what breaks without each

    20 min

    Ask in bulk — “I’ll need all the access” — and you get a bulk answer, which is no answer at all. Five lines, one per account, each with the concrete consequence of its absence: that is the only form that makes the urgency legible to a non-technical client. The table below is that email.

  3. Verify every account by logging in, the day you receive it

    15 min

    A credential handed over is not access: it has to be tested. Log in, go all the way to the screen that matters — the renewal page at the registrar, the zone editor, the database console — and change the password if you can. It is the only way to avoid discovering six months later, on an outage evening, that the account belonged to someone who left.

  4. Write down what you are not taking over

    10 min

    The out-of-scope list is worth as much as the access list: the mail, the hosting, the domain name, the advertising accounts, the paid plugins. If it is not written down, anything that touches this site will be yours — including outages in things you were never allowed to look at.

The five accounts, and what breaks without each

The third column is the useful one: it is what you paste into the client email. A missing account is painless for a month, then it is paid for at the first incident.

  • The registrar account
    What it is forRenewing the name, changing name servers, obtaining the authorization code.
    What breaks without itYou can neither save an expiring domain nor move the site elsewhere. It is the most important account on this list and the one most often forgotten.
  • The DNS zone
    What it is forPointing the site, the mail and domain verifications.
    What breaks without itNo deployment, no migration, no automatic certificate renewal.
  • Hosting and the database
    What it is forDeploying, backing up, restoring.
    What breaks without itYou cannot bring the site back after an outage — which is exactly the day they will call you.
  • The mail administration
    What it is forThe client’s addresses, and the messages the site sends.
    What breaks without itForms silently stop arriving, and nobody knows when it started.
  • The code repository and third-party accounts
    What it is forChanging the site, renewing whatever is paid for.
    What breaks without itEvery change becomes a workaround, and every paid add-on becomes a surprise on its renewal date.

This list doubles as the outline of the takeover email: five lines, one per account, each carrying the sentence from the third column. It turns an administrative request into a list of risks, which is what gets it actioned.

The takeover email

Sent on the day you sign, not at the first incident. It sets the scope, asks for the access and names the consequences — without drama, in one page.

Subject: Website takeover — access to recover

Hello,

Before we start, I need to recover five accounts. They are not for changing the site: they are so that I can act on the day something goes wrong. Without them I will see the problem without being able to fix it.

1. The account at the domain name registrar. Without it I cannot renew the name or move the site. 2. Access to the DNS zone. Without it, no deployment and no certificate renewal. 3. Hosting and the database. Without them the site cannot be restored after an outage. 4. Mail administration. Without it, forms can stop arriving with nobody noticing. 5. The code repository and any paid accounts tied to the site.

If some of these are held by your previous supplier, tell me: I will handle the request, I simply need your written agreement to make it on your behalf.

I check each account on arrival and confirm what works. Anything still missing on [date] falls outside the scope of the maintenance agreement, and I will say so explicitly rather than discovering it along the way.

Kind regards,

The second-to-last paragraph does the work: it gives the client a dignified way out when it is the old supplier blocking, and it authorizes you to write on their behalf. The last one sets a date, which turns a wish list into a deadline.

The four discoveries that always come too late

They share one trait: nothing flags them until you need them, and you need them on an outage day.

  • The account in a former employee’s name

    The account’s email address no longer exists, so password recovery does not either. The day the domain has to be renewed urgently, you first have to prove to a support desk that you are legitimate. Count in days, not hours.

  • Two-factor authentication on a phone nobody has

    The username and password are correct and access is still impossible. Test the full login, all the way to the dashboard, on the day you receive the account — not on the day you need it.

  • Hosting paid by the previous agency

    The site runs on an account that does not belong to the client. The day the direct debit stops, the site goes dark without notice and nobody has the controls. It is the most brutal of the four, and the most frequent.

  • A scope nobody ever wrote down

    You took over “the site”. Six months later an email address stops working and you are the one being called. Writing down what you are not taking over costs ten minutes and wins the argument in advance.

Why it happened

Because a takeover runs on mutual goodwill and nobody wants to open with a list of demands. The client is keen to move on, you are keen to start producing, and the conversation about access is deferred until “we need it”. By the time you need it, it is late.

Because access is scattered across at least four parties — the registrar, the DNS operator, the host, the mail provider — and the client has never had an overall view. They are not hiding anything: they do not know. Asking for “all the access” is asking them to produce an inventory they have never been able to produce.

And because the previous supplier now has no reason to hurry. They no longer invoice, nobody owns the file, and your request lands in a generic inbox. It is not ill will, it is indifference — and the effect is identical.

How to avoid it next time

Make the outside audit the first billable task of the engagement, before the takeover quote. It needs no access, it takes ten minutes, and it tells you what you are actually inheriting. A client who sees that document understands in one page why you are asking for five accounts — and what not having them would cost.

Put a deadline in the takeover email, and hold it. Whatever is still missing on that date falls out of scope, in writing. That is not a threat: it is the only way to avoid carrying a responsibility you have no means to discharge.

And put the portfolio under monitoring from day one, even before you hold every account. You need no password to read an expiry date, a delegation or a certificate: that information is public. You will know a domain expires in three weeks before the client does, which is exactly where you want to be.

The outside audit, in thirty seconds

The report reads the name’s expiry, the certificate, the email authentication and the domain’s reputation in one pass. It is move number one on the list above: enter the domain of the site you are taking over.

No sign-up, no email required. You can paste a full address — we'll pull the domain out of it.

Take over a site without taking over its blind spots.

DomainVigil watches the expiry, certificate, DNS and mail of every domain you inherit, without asking for a single password, and warns you before the client notices. Five domains free, with no time limit.

Five domains free, forever. No card required.