Four locks hang on your domain. Who holds the keys?
Registrar, DNS, certificates, mail routing — four separate accounts carrying your entire public presence. In most companies nobody holds all four, and management does not know.
There is one question that reliably produces silence in advisory conversations: if your current IT service provider became unreachable tomorrow, could you move your domain on your own?
The answer is surprisingly often no. And because your entire public presence hangs on it, this stops being an IT topic. It belongs in the same drawer as banking authority.
The four locks
The registrar. Where is the domain registered, and who is listed as the holder? Often it is still the agency that built the website in 2016 and "took the domain along". Formally the domain is then not yours. Nobody notices while the relationship is good.
DNS management. Who may decide where your domain points? Whoever can do that can redirect website and email in one afternoon. It is the most powerful of the four accounts and the least documented.
Certificates. Who issues them, who renews them, and what happens when the automation fails while the responsible person is on holiday? An expired certificate takes your site down the same day and produces a warning that looks like an attack.
Mail routing. Technically part of DNS management, practically a separate item, because all business correspondence hangs on it. Whoever can change that record can redirect your post.
The test, thirty minutes
Public lookup of the domain: who is registered, when does it expire, which registrar is behind it?
Log in at the registrar — without outside help. If the password sits in a mailbox somebody else administers, the test has already answered itself.
Look at the nameservers: where do they point, and do you have your own account there?
Check certificate management: does renewal run automatically, where does it run, and who receives the alert when it fails?
Anyone who can answer those four in half an hour has more Key control than most mid-sized companies.
The fifth key
Those four come with a fifth that unlocks all the others: the password manager.
It sits almost at the end of every migration plan because it looks small. That is a mistake in reasoning. If that one service locks you out — a failed payment, an automated suspension, a contract dispute — it is not one tool that stops, it is all of them at once.
| Tool | Base | Operation | For whom |
|---|---|---|---|
| Vaultwarden | open-source project | self-hosted | familiar clients, data in your own house |
| Passbolt | LU | self-hosted or hosted | teams with fine-grained permissions |
| Psono | DE | self-hosted or hosted | when logging matters |
| heylogin | DE | subscription | workforces with no master-password practice |
| Uniqkey | DK | subscription | the same, with an admin console |
| KeePassXC | open-source project | a file | when no service should run at all |
Three things routinely go wrong in the move and are avoidable: the export omits attachments; second factors have to be re-enrolled one by one, which is the real time sink; and the emergency password for the new service ends up, once again, only in one person's head.
What is different afterwards
For each of the five accounts, write down: who holds it, who deputises, where the emergency procedure lives, and when it was last tested. Half a page is enough, sealed in the safe, with a date.
It is unspectacular, costs a morning, and is the only measure in this series you can carry out without changing a single vendor. It works immediately — and it is the precondition for every other step actually being in your hands.
Sources
Read next
- From 12 September 2026, the machine has to hand over its dataThe Data Act has applied for close to a year. Connected products placed on the market from September 2026 also carry a design obligation — and with it, the end of closed interfaces.
- European is not a status. It is a subscription.ownCloud, DRACOON, Pipedrive, Affinity, MariaDB, Silo AI — recent European software history, read as a list of ownership changes. Why asking where a vendor is headquartered is the wrong question, and what to ask instead.