Notes
How to get your website back when someone will not hand it over.
The order you do this in matters more than any single step. Do it wrong and you tip your hand before you have a copy of anything.
Most advice on this subject opens with "review your contract" and closes with "try talking to them". Both are reasonable and neither tells you what to do first, which is the only part that is genuinely difficult.
What follows is an order of operations. It is written to be worked top to bottom, and the sequence is deliberate: every step assumes you have not yet announced what you are doing.
Stage one: find out what you actually still hold
- Log into everything you believe you have a login for, right now, and confirm each one still works. Do not assume. An account you were added to two years ago may already be gone.
- For each account that works, check whether you are the owner or a member. Owner means you can remove other people. Member means you cannot.
- Look up your domain on a public WHOIS or RDAP service and write down the registrar and the expiry date. This is public and it does not notify anyone.
- Check your domain’s nameservers to find where DNS is really served from. It is often not the registrar.
- Write all of it down in one place, including the gaps. The gaps are the actual problem and you need to see them together.
At the end of stage one you know which of the two situations you are in. Either you hold the domain and this is a recoverable inconvenience, or you do not and it is a negotiation.
Stage two: take a copy while you still can
Whatever you can reach, copy it now, before any conversation happens. Not because anyone is necessarily going to delete anything, but because a copy costs you an afternoon and its absence can cost you years.
- Save the site itself. If you have hosting access, download the files and export the database. If you do not, a full crawl of the public pages at least preserves the content and structure.
- Export your analytics history. It cannot be reconstructed later and it does not travel with the site.
- Copy anything customer-facing that lives only in the admin: form submissions, orders, subscriber lists, uploaded documents.
- Screenshot the current state of every account, including the member lists showing who has access today. This is the evidence that matters later.
Stage three: secure the root
The domain comes first because everything else depends on it. If the registrar account is yours, log in, enable two-factor authentication, confirm the contact email is one you control, and check the transfer lock. That is most of the risk gone in ten minutes.
If the registrar account is not yours, you are asking for a domain transfer, which is a specific and well-defined process: the current holder unlocks the domain and provides an authorisation code, and you initiate the transfer at a registrar of your choice. Ask for exactly that, in those words. Vague requests to "give me my website back" are easy to answer vaguely.
Do the same for DNS, then hosting, then the code repository, then analytics and the business profile, in that order. Each one is less catastrophic to lose than the one before it.
Stage four: ask, in writing, with a date
Now you make the request, and you make it in a form that would read well to a third party who knows nothing about either of you.
- Write it as email, not a phone call. You want a record with a timestamp.
- List each asset by name and say precisely what you are asking for on each one. "Transfer the domain" and "add me as owner of the analytics property" are actionable. "Hand over my website" is not.
- Give a specific date. A deadline that is a real date is a fact; "as soon as possible" is an opinion.
- Stay factual and unemotional throughout. Assume it will be read aloud by someone else later, because it might be.
- Say what you will do if the date passes, and only say things you are actually prepared to do.
A surprising number of these situations end here. The other side is often disorganised rather than hostile, and a clear list with a date is easier to comply with than to argue about.
Stage five: when the date passes
If it does not end there, your options depend entirely on which assets you already control, which is why stage one came first.
- If you hold the domain, you can rebuild elsewhere and repoint it. Painful, survivable, and entirely within your control. Your rankings largely follow the domain.
- If you do not hold the domain, this becomes a legal matter rather than a technical one. Registrars have dispute processes, and there are formal mechanisms for domain disputes, but both are slower than people expect and both benefit from a lawyer.
- If you paid recently by card, ask your card issuer what your options are and what their time limits look like. Those windows are shorter than most people realise, which is a reason to ask early rather than late.
- Keep paying any invoice that keeps your site online while this is unresolved, unless counsel tells you otherwise. Winning an argument about a hosting bill while your site is dark is not winning.
And then do not be here again
Once you have everything back, the rebuild is worth doing properly. Open every account yourself, in your own name, with your own billing, and add whoever does the work as a collaborator you can remove. Get the copyright assignment in writing before the first invoice, not after the last one.
The arrangement that causes this problem is not complicated or unusual. It is just never written down until it has already gone wrong.
Questions
What should I do first if my developer stops responding?
Audit what you can still log into, before you contact them again. Confirm each login works, note whether you are an owner or a member, and look up your domain’s registrar and nameservers, which is public information and notifies nobody. You cannot plan anything until you know which assets you already hold.
Should I email them straight away and demand access?
Not first. A demand tells the other party to start changing passwords. Audit what you hold and take copies of what you can reach, then make the request in writing with a specific list and a specific date.
Can I just build a new website somewhere else?
If you control the domain, yes, and it is often faster than fighting. You lose the old build but your address, your email and most of your search equity stay with you. If you do not control the domain, a new site on a new address means starting over, which is why the domain is the first thing to secure.
What if they are holding my domain?
Ask specifically for the domain to be unlocked and for the authorisation code, which is the defined process for moving a domain between registrars. If that is refused, it stops being a technical problem. Registrars have dispute processes and there are formal domain dispute mechanisms, but they are slow and worth taking to a lawyer rather than improvising.
Will I lose my Google rankings?
Rankings are attached largely to the domain rather than to the build, so keeping the domain protects most of what you have earned. Moving to an entirely new domain is the expensive version and is one more reason the registration matters more than the code.
