WILD LOGIC

Save this before you sign off

Website ownership checklist

Knowing a password is not the same as controlling a website. Use this checklist with any provider to identify who owns each account, what access you have, and what another developer would need to take over.

Build your site

01

How to use this checklist

For each item, record the account owner, your access level, renewal date if applicable, and where the documentation lives. Mark anything irrelevant as not applicable rather than leaving it ambiguous. Test access yourself before signing off on handoff.

Keep this record free of passwords, recovery codes, and private keys. Reference entries in your password manager instead. You can print this page or save it as a PDF from your browser without creating an account.

02

Domain registration and DNS

  • Confirm the registrant and registrar account

    Identify the company that holds the domain, verify you can sign in to the registrar, and check that recovery and renewal notices reach an address you control. Record the renewal date and payment owner.

  • Find the authoritative DNS provider

    The registrar and DNS host may be different companies. Verify you can view and edit the active zone. Export or document the records, including website, email, and verification records, before a change.

  • Plan for transfer and recovery

    Know how domain unlocking and transfer authorization work. Keep recovery access independent of a single departing employee or contractor. Do not remove unrelated email records during a website move.

03

Hosting, source code, and CMS

  • Identify the hosting account and billing owner

    Record the production project, deployment process, renewal terms, and required environment-variable names. Keep their values in a secure system. Verify what happens if the agency relationship ends.

  • Inspect the repository or deliverable code

    Confirm you have the access promised in your agreement, including assets and build instructions. Ask a developer to check whether the delivered source can actually build. Record any proprietary platform dependency or export limit.

  • Test CMS and administrator access

    Sign in with your own account. Practice editing a draft and restoring it. Identify who can add users, change billing, and export content; an editor role may not control those functions.

04

Analytics and search accounts

  • Control the accounts you use

    If analytics is installed, identify the property owner and give the business suitable administrator access. Verify who can export reports or revoke a former provider's access. Document privacy and consent settings.

  • Check Search Console and Bing Webmaster Tools

    Confirm the correct site property and an owner-controlled verification method. Record the sitemap URL and retain necessary DNS verification records. Submitting a sitemap is not proof that a page is indexed.

05

Forms and email delivery

  • Follow a submission to its destination

    With an agreed test message, verify the form, confirmation, inbox or CRM record, notifications, and reply address. Check spam handling and failure reporting. Document the provider and who can access stored submissions.

  • Record email dependencies

    List the domain's mail provider and any transactional email service used by the site. Identify the required DNS records without copying credentials into the handoff document. Confirm who monitors delivery failures.

06

Content, media, and licenses

  • Collect original content and media

    Obtain the agreed copy, editable design files, logos, and original images. Record who supplied each item and whether you may publish, edit, and reuse it. A file download alone does not establish permission.

  • List third-party licenses

    Include fonts, stock media, themes, plugins, APIs, and subscription tools. Record license holders, renewal costs, transfer restrictions, and what stops working if a subscription ends. Resolve uncertain rights with the provider before launch.

07

Backups and credentials

  • Verify a backup can be restored

    Identify what is backed up: source, database, uploaded media, and configuration. Record backup frequency, retention, storage owner, and restoration steps. A repository alone may not contain the live site's content or database.

  • Use individual accounts and a password manager

    Enable appropriate multi-factor authentication and store recovery material securely. Check access on your own device. Rotate shared credentials and revoke obsolete access as part of an agreed handoff; do not revoke the only working owner account.

08

Documentation, launch, and handoff

  • Keep an operating record

    Collect build and deployment instructions, a service inventory, update guidance, recurring costs, known limitations, and escalation contacts. Assign someone to renew services and maintain the record.

  • Check the launched website

    Open important URLs on desktop and mobile. Test navigation with a keyboard, forms, downloads, redirects from replaced pages, HTTPS, and access to the production administration tools.

  • Agree what happens next

    Record remaining work, acceptance criteria, final-payment and handoff terms, and support boundaries. Identify who applies updates and checks backups when optional maintenance is declined.

09

The practical handoff test

Could the business recover an account, renew a service, correct its phone number, and appoint another developer without relying on the original provider's personal account? Any uncertain answer deserves a named owner and a next step.

Wild Logic's principle is: It's your website. We just build it. Our transparency record explains the ownership and handoff model; this checklist is useful whether or not you work with us.

Put the plan to work.

Configure a site without sharing your email, or bring your questions to a conversation.