ZeroTaken
← All posts
Domains7 min readBy ZeroTaken Team

Who Should Legally Own Your Domain? The Co-Founder, Freelancer and Agency Trap

Most domain disasters don't start with a hacker or a squatter. They start with a friendly favor: a co-founder who 'just grabbed the domain on his card,' a freelancer who set everything up in her own registrar account, an agency that registered it 'to make things easy.' Two years later the relationship ends, and the company discovers that the legal owner of its most important digital asset is someone who no longer works there. This guide explains who actually owns a domain in the eyes of the registry, the four setups that go wrong most often, and the boring, ten-minute configuration that keeps control with the business, no matter who does the clicking.

Añade ZeroTaken como fuente preferida en Google
Who Should Legally Own Your Domain? The Co-Founder, Freelancer and Agency Trap

Who actually owns a domain name?

Whoever is listed as the registrant. That's it. A domain isn't owned the way a laptop is; it's a registration record, and the name in the 'registrant' field is the legal holder. Your receipt, your invoice, your Slack message saying 'it's for the company', none of that overrides the record. If a dispute reaches a registrar, the first thing they look at is who the registrant is and who controls the account.

That makes two separate things matter, and founders constantly confuse them: the registrant (the legal holder named in the record) and the account owner (whoever can log in at the registrar and change DNS, transfer the domain, or let it expire). You want both of them pointing at the business, not at a person.

Privacy services blur this further. With WHOIS privacy on, the public record shows a proxy, so nobody can see that the registrant is 'Dave, personally.' Everything looks fine until the day it isn't.

What are the four setups that go wrong most often?

These are the patterns that produce the sad 'how do I get my domain back' threads, in rough order of how common they are:

  • The co-founder's credit card. One founder registers the domain personally before the company exists. The company is incorporated later, but nobody ever moves the domain. If the founders fall out, the domain walks out the door with one of them.
  • The freelancer's registrar account. A designer or developer buys the domain inside their own account 'to get the site live,' and hands over a website, not the domain. The business pays for the name but cannot transfer it without the freelancer's cooperation.
  • The agency that registers on your behalf. Some agencies bundle the domain into a retainer and list themselves as the registrant. Cancel the contract and you may be asked to pay a 'transfer fee' for a name you've paid for every year.
  • The ex-employee's login. The domain is in the company's name, but the account email is a personal address of someone who left. Renewal notices and transfer codes go to an inbox nobody monitors.

Why does it matter more than the price of the domain?

Because the domain is the root of everything else. Your email, your website, your app's login links, your SSL certificates, your search rankings and your customers' bookmarks all hang off it. Losing control isn't losing a $12 asset; it's losing the ability to receive email as your company and to prove you are who you say you are.

Recovery is also slow and uncertain. If the registrant simply won't cooperate, your options are a negotiation, a lawyer, or a formal dispute, and a dispute procedure like UDRP is built for bad-faith cybersquatting, not for 'my ex-partner owns it.' A former insider with a plausible claim is the hardest case to win. Prevention costs ten minutes. Recovery can cost months of lost email and thousands in fees.

Investors notice too. In due diligence, 'who owns the domain and the code repo' is a standard check. A domain registered to an individual is a small red flag that costs founders time and credibility at precisely the wrong moment.

What is the right setup for a business?

Make the company, not a person, the owner at both levels, and make sure it survives anyone leaving. Concretely:

  • Registrant: the legal entity's name and a role address, such as the company's registered address, not someone's home.
  • Account email: a shared, company-controlled mailbox like domains@yourcompany.com, never a personal address. But note the chicken-and-egg problem: don't host this mailbox on the same domain it depends on. Use a second address on a different domain as the recovery contact.
  • Two-factor authentication on the registrar account, with the recovery codes stored in the company password manager, not in one person's phone.
  • Registrar lock on, auto-renew on, and a payment method that belongs to the company, not a founder's personal card that will expire or be cancelled.
  • At least two people with documented access, so one person leaving, or one person being unreachable, never blocks a renewal or a DNS change.

How should founders handle a domain bought before the company existed?

Move it as soon as the entity exists, and don't wait for a 'convenient moment.' The simplest route is an account-to-account change inside the same registrar, which most registrars call a 'push' or 'change of account.' It is free, instant, and doesn't alter the domain's age or DNS. If you're also changing registrars, a standard transfer works, but you'll typically need to wait out a 60-day lock if the domain was recently registered or its contact details were recently changed.

If two co-founders are involved, put the transfer in writing. A one-paragraph note in your founders' agreement or IP assignment that says 'the domain and related accounts are assigned to the company' removes any argument later. People assume this goes without saying right up until it needs saying.

While you're sorting out ownership, check what else you're missing. A quick WHOIS lookup on your own domain shows exactly who the registrar thinks the registrant is and when the registration expires; ZeroTaken's free WHOIS tool takes about ten seconds and is the cheapest audit you will ever run.

What should you ask a freelancer or agency to do?

Treat it like any other asset in the contract. Two options work, and the choice depends on how technical you are.

  • Best: you register the domain yourself in a company account, then give the freelancer delegated access, or just the DNS settings they need. They build the site; you own the name from day one.
  • Acceptable: they register it, but the contract states the client is the owner, the registrant is the client's legal name, and the domain will be transferred on request or on final payment, within a set number of days and with no extra fee.
  • Avoid: any arrangement where the domain sits in their account indefinitely, listed under their business, 'included' in a hosting retainer.
  • Always get the authorization (EPP) code and a confirmation email on handover, and test a transfer or push early, not on the day you terminate the contract.

What if someone already holds your domain and won't hand it over?

Start by confirming the facts: look up the WHOIS record, the registrar, and the registration date. If the person is a former co-founder or contractor, the first move is a calm written request that cites your agreement. Most disputes end there, because the other side usually just wants to be paid for the hassle or hasn't thought about it.

If that fails, escalate in order: a lawyer's letter, then the registrar's dispute process, and only then a formal proceeding. Be realistic about what dispute procedures cover. They are designed for bad-faith registration of someone else's trademark; an ownership dispute between partners usually belongs in contract law, which is exactly why the paperwork up front matters more than any remedy afterwards.

Meanwhile, protect the business: set up email on a temporary secondary domain, point customers to it, and avoid doing anything rash like registering lookalike names, which can weaken your case.

What is the ten-minute ownership checklist?

Run this once for every domain your company relies on. It's genuinely ten minutes, and it's one of the highest-return admin jobs you can do this quarter.

  • Look up your domain and confirm the registrant is the company, not a person.
  • Confirm the registrar account email is a company-controlled address with a recovery contact on a different domain.
  • Enable two-factor authentication and store recovery codes in the company password manager.
  • Turn on registrar lock and auto-renew; put the expiry date in a shared calendar for 60 days ahead.
  • Make sure at least two named people can log in, and that a company card pays the renewal.
  • Put one line in every founder, contractor and agency agreement: the company owns the domain and all related accounts.
Añade ZeroTaken como fuente preferida en Google