Digital Evolution Italy
WebsitesBots & AssistantsAutomationSolutionsContactRequest a demo
All articles

Who owns your website: domain, hosting, passwords

Open a tab, search for "whois" followed by your address, and look at the Registrant field. If your name or your business name is not there, the site you have been paying for is not yours. It takes a minute and almost nobody does it.

This is not a theoretical point. It is the difference between changing supplier in two days and starting over from scratch, losing the address every customer has reached you through so far.

Three separate things we all call "the website"

When a restaurant owner says "my website" they are talking about three separate contracts, which can sit in three different hands.

The domain is the address: yourrestaurant.it. It has an official holder, the registrant, and that name is public.

The hosting is the space where the files live. It can belong to whoever built the site, to a provider they resell, or to you.

The credentials are the keys: control panel, database, email. Whoever has them can change anything. Whoever does not can only ask nicely.

The worst combination is also the most common: domain in the supplier's name, hosting on their account, passwords only theirs. In that case you own nothing, not even the text you wrote yourself.

How to check, right now

Domain whois is public and free. Search for "whois yourrestaurant.it" and read two lines: registrant and the associated email.

Three possible outcomes.

The registrant is you or your business: good, everything else can be sorted out.

The registrant is the agency or the person who built your site: the domain is theirs. Not illegal, very common, and it only becomes a problem on the day you want to part ways.

The details are masked or nothing recognisable shows up: ask in writing who the registered holder is, and ask before there is an argument in progress.

If the registrant is not you

Here comes the good news. The rules of the Italian .it registry leave little room for interpretation.

Transfers run on a code, the authinfo. It has to be released to the registrant and sent to the email address shown in the whois. The registrar is required to cooperate rather than obstruct, and that duty holds even when a dispute is open between the registrant and the reseller: missed payments, misunderstandings, relationships that ended badly. The code is not a bargaining chip.

Once you have it, the move closes in one or two days. The slow part is never technical.

One distinction matters: if the registrant is the supplier, you are not doing a simple provider change, you are doing a change of holder. Different procedure, and it needs their signature. Which is exactly why the question belongs at the start of a relationship, not at the end.

The worst case: nobody answers any more

It happens more often than you would think. The acquaintance who built the site changed jobs, the small agency closed, the email bounces.

If the registrant is you, you are fine: ask the registrar for the code, meaning the company named in the whois, not the person who vanished.

If the registrant is them, the path is narrower. You go through the registrar with documentation, and if the domain reaches expiry without renewal it becomes free again: whoever takes it first has it. In that case it pays to be ready on the right day instead of finding out three weeks later, when somebody else already grabbed it.

The site files, meanwhile, are their own chapter. Without hosting access you do not get them back. Rebuilding costs money, and it is the cost nobody budgets for, because nobody expects it.

The questions to ask before signing

Four of them, and they apply to us as much as to anyone else. Ask in writing and keep the answer.

  1. Whose name is the domain registered under?
  2. Where are the files hosted, and how do I obtain them if the relationship ends?
  3. Who holds the passwords, and will you hand them over on request?
  4. If I leave, will you release the authinfo code without conditions?

A serious supplier answers in two lines. If the answer comes back vague, or if the question is met with irritation, you already know who you are dealing with.

How we answer those same four questions

The same questions should be put to us, so here are our answers before you ask.

We register the domain in the client's name. You or your business are the holder from day one, even though we pay for it inside the subscription. The whois will show your name, not ours: you can check it yourself the day after launch, without asking anyone.

Everything else follows from that, and not because we are generous. If you are the registrant, the registrar is obliged to send the authinfo code to you, at the email address shown in the whois. It does not pass through us, so we could not withhold it even if we wanted to. That is the difference between a commercial promise and a technical fact: the first can be taken back, the second cannot.

The hosting stays ours for as long as the subscription runs, and that is what you are paying for: server, certificate, updates, changes. The day you decide to leave, the domain travels with you and the site gets rebuilt elsewhere. You lose the service, not the address, and the address is the one thing that has been accumulating value for years.

Building on a domain held by the supplier is convenient for the supplier. It ties the client down better than any contract: if they leave, they restart from a new address, without the history Google has built up, with old links pointing nowhere. We prefer the opposite for a practical reason: a client who stays because leaving is impossible is an unhappy client waiting for an opening, and the opening always turns up eventually.

The pricing page sets out what the subscription covers, domain included; if you are working out what a site will really cost you over three years, we did the full sum here. How we work on sites is described on the websites page.

Run the whois check anyway. Even if somebody else built your site, even if everything is going well. One minute now, instead of an unpleasant discovery on the day you need to move fast.

Frequently asked questions

How do I find out who owns my domain? Search for "whois" followed by your address and look at the Registrant field. If your name or your business name is not there, the domain is not yours, however many years you have paid for it.

Can a supplier refuse to give me the authinfo code? No. The code has to be released to the registrant and sent to the email address shown in the whois. The registrar must not obstruct the transfer, and that duty holds even when there is an open dispute with the reseller.

How long does moving an .it domain take? Once you have the authinfo code and confirm the transfer, it closes in one or two days. The slow part is getting the code, not the technical move.

If I change supplier, do I lose the website? The domain moves if you are the registrant. The site files are a separate matter: you have to ask whoever holds the hosting, and that request belongs in writing before you sign, not after.

What is the difference between domain, hosting and access? The domain is the address, the hosting is the space where the files live, the credentials are the keys to change them. Three separate contracts that can sit in three different hands, often without the business owner knowing.

Do you register the domain in my name? Yes. You or your business are the registrant from day one, even though the domain is paid for inside our subscription. You can check it in the whois the day after launch, without asking us.