Skip to content
SOVEREIGNTYBALANE
Blog
2 August 2026 · 3 min read

Four locks hang on your domain. Who holds the keys?

Registrar, DNS, certificates, mail routing — four separate accounts carrying your entire public presence. In most companies nobody holds all four, and management does not know.


There is one question that reliably produces silence in advisory conversations: if your current IT service provider became unreachable tomorrow, could you move your domain on your own?

The answer is surprisingly often no. And because your entire public presence hangs on it, this stops being an IT topic. It belongs in the same drawer as banking authority.

The four locks

The registrar. Where is the domain registered, and who is listed as the holder? Often it is still the agency that built the website in 2016 and "took the domain along". Formally the domain is then not yours. Nobody notices while the relationship is good.

DNS management. Who may decide where your domain points? Whoever can do that can redirect website and email in one afternoon. It is the most powerful of the four accounts and the least documented.

Certificates. Who issues them, who renews them, and what happens when the automation fails while the responsible person is on holiday? An expired certificate takes your site down the same day and produces a warning that looks like an attack.

Mail routing. Technically part of DNS management, practically a separate item, because all business correspondence hangs on it. Whoever can change that record can redirect your post.

Registrar who is listed as holder? DNS management who may redirect? Certificates who renews, who is alerted? Mail routing who can redirect the post? Your domain
Four separate accounts, often held by four different parties. A fifth — the password manager — unlocks all the others.

The test, thirty minutes

Public lookup of the domain: who is registered, when does it expire, which registrar is behind it?

Log in at the registrar — without outside help. If the password sits in a mailbox somebody else administers, the test has already answered itself.

Look at the nameservers: where do they point, and do you have your own account there?

Check certificate management: does renewal run automatically, where does it run, and who receives the alert when it fails?

Anyone who can answer those four in half an hour has more Key control than most mid-sized companies.

The fifth key

Those four come with a fifth that unlocks all the others: the password manager.

It sits almost at the end of every migration plan because it looks small. That is a mistake in reasoning. If that one service locks you out — a failed payment, an automated suspension, a contract dispute — it is not one tool that stops, it is all of them at once.

ToolBaseOperationFor whom
Vaultwardenopen-source projectself-hostedfamiliar clients, data in your own house
PassboltLUself-hosted or hostedteams with fine-grained permissions
PsonoDEself-hosted or hostedwhen logging matters
heyloginDEsubscriptionworkforces with no master-password practice
UniqkeyDKsubscriptionthe same, with an admin console
KeePassXCopen-source projecta filewhen no service should run at all

Three things routinely go wrong in the move and are avoidable: the export omits attachments; second factors have to be re-enrolled one by one, which is the real time sink; and the emergency password for the new service ends up, once again, only in one person's head.

What is different afterwards

For each of the five accounts, write down: who holds it, who deputises, where the emergency procedure lives, and when it was last tested. Half a page is enough, sealed in the safe, with a date.

It is unspectacular, costs a morning, and is the only measure in this series you can carry out without changing a single vendor. It works immediately — and it is the precondition for every other step actually being in your hands.

Sources

Read next