Locked out

You lost access to your website. Start by working out what you lost.

A website is not one account. It is at least four, held in different places, and people usually only lose one of them. Identify which layer you are locked out of and the path back gets short.

The four layers, in order of power

  • The registrar: who your domain name is registered with. Whoever controls this controls everything else eventually.
  • DNS: which nameservers answer for the domain, and therefore where the website and email actually point.
  • The web host: the server holding the files and the database.
  • The CMS: your WordPress or site editor login. The least powerful of the four, and the one people think of first.

Find out what you already control, before you call anyone

Every one of these is a public lookup. You do not need a password to do any of it, and knowing the answers before you pick up the phone changes the conversation.

  1. Find your registrar with an ICANN lookup

    Go to lookup.icann.org and enter your domain. It will tell you the registrar of record, the creation date, and the expiry date. Contact details are usually redacted for privacy, so it will not tell you which person holds the account, but the registrar name is what you need. That is the company you have to deal with, whatever your developer used to say.

  2. Note the expiry date immediately

    While you are on the lookup, write down when the domain expires. If it is close, that is now your most urgent problem, ahead of everything else on this page. A domain that lapses goes through a roughly 30-day auto-renew grace period, then a redemption period of about another 30 days where recovery is possible but costs a restore fee, and then it can be registered by anyone.

  3. Find who runs your DNS

    Look up the domain nameservers. Any online DNS lookup tool will show them, or run a DNS query for the NS records. The nameserver names usually say the company outright, and that tells you whether DNS lives at the registrar, at your host, at Cloudflare, or somewhere a former developer set up.

  4. Find who hosts the site

    Look up the A record for the domain to get the IP address, then look that IP up. It will usually name the hosting company or the data center. Combine that with any old invoices or card statements: hosting is a recurring charge, and the card statement often names the host when memory does not.

  5. Find where the email goes

    Look up the MX records. Email frequently lives somewhere completely different from the website: Google Workspace, Microsoft 365, or the host mail server. This matters because the recovery emails for every other account go to a mailbox controlled by whichever of these it is.

  6. Work out which mailbox holds the keys

    Every account here recovers through email. If the registrar account is registered to an address at your own domain, and your email is broken, you have a loop. Break it by starting at the registrar with identity documents rather than an email reset, or by recovering mail first.

Which layer you lost, and what the way back looks like

Read the row that matches your situation. The proof each company asks for is different, and asking for the wrong thing wastes a week.

Easiest

You lost the CMS login only

How to check: The site is up and fine. You just cannot log in to edit it. You still have hosting access, or your host still recognizes you as the account holder.

The fix: Use the password reset if the admin email still works. If it does not, hosting access outranks the CMS: from the hosting control panel you can reset a WordPress password directly in the database, or create a new admin user. This is a same-day fix and it costs nothing.

Common

You lost the hosting account

How to check: You know the host but not the login, or the account was opened in a developer name. The site still works, because hosting keeps running while the bill is paid.

The fix: Call the host, do not email. They will want proof you are the account holder: the account number or username, the invoice or billing email, the last four digits of the card on file, or a security PIN set on the account. If the account is genuinely in someone else name, the host will not hand it over, and the real route is to move the site rather than fight for the account.

Common

You lost the DNS but still have the domain

How to check: The nameservers point at a service you cannot log in to. The site works until something needs changing, and then nothing you do has any effect.

The fix: This one is straightforward, because control of the domain overrides DNS. From the registrar you can point the nameservers somewhere new. Copy every existing record first, including MX records, or you will take email down with the website.

The hard one

The domain is in someone else account

How to check: The ICANN lookup names a registrar you never signed up with, or the account is in a developer or agency name. Everything else depends on this, so it comes first.

The fix: Ask, in writing, for the domain to be pushed to an account in your name, or for the authorization code so you can transfer it to your own registrar. If that fails, contact the registrar directly and open a dispute. What decides it is who is recorded as the registrant and who can document paying for it. Keep invoices, emails, and payment records: they are the case.

Urgent

The domain already expired

How to check: The site and the email both stopped at once, on the same day, with no warning. That combination is nearly always domain expiry rather than a hack or a host failure.

The fix: Get to the registrar today. During the auto-renew grace period, paying the renewal fixes it. After that, in redemption, it can still be recovered but there is a restore fee that is much larger than the renewal. After redemption ends the name can be registered by anyone, and there is no route back.

Varies

You have the domain but not the site files

How to check: You control the domain and DNS, but nobody can get into the server that holds the site. Nothing you own contains the pages.

The fix: The domain is enough to rebuild. Pull whatever pages survive from search engine caches and the Internet Archive, rebuild on hosting you control, then point DNS at it. It is not free, but it is a fixed amount of work with an end date, which a hosting dispute is not.

What proving ownership actually takes

Every company here has a process. None of them will accept your word alone, and knowing what they need up front saves days.

  • At a registrar: identity documents matching the registrant on record, or business formation documents matching the registrant organization. Registrars can and do lock a name for about 60 days after a change of registrant, so plan around that if you have a launch coming.
  • At a web host: account number, billing email, invoice history, the last four of the card on file, or a support PIN. Payment history is the strongest single thing you can bring.
  • Anywhere: written evidence that you paid. Card statements, invoices, and the email thread where the work was agreed. Save it before you start, not after.
  • If a former developer is unresponsive rather than hostile, keep it civil and in writing. Most of these end with someone finding an old password, not with a dispute.
  • If customer email is down as well as the website, treat that as the emergency. A business can survive a dark website for a week. It cannot survive missing every inbound email.

Questions about lost website access

How do I find out who my domain is registered with?

Use the ICANN lookup at lookup.icann.org. It names the registrar of record and gives the creation and expiry dates. Personal contact details are normally redacted, but the registrar name is public and that is the company you need to contact.

My developer registered the domain. Is it mine?

It depends on who is recorded as the registrant and what you agreed. Paying an invoice that includes a domain registration is strong evidence, but it does not automatically move the record. Ask for the domain to be pushed to your own account first. If that fails, the registrar has a dispute process, and your invoices and emails are the case you bring to it.

Can I just rebuild the site somewhere else?

If you control the domain, yes, and sometimes that is genuinely the fastest route. A rebuild has a known cost and a finish date. Chasing an unresponsive person for an old hosting password has neither. If you do not control the domain, get the domain first.

My website and email both went down on the same day. What happened?

Look at the domain expiry date before anything else. Website and email failing together, on the same day, with nothing else changing, is the signature of an expired domain. Hosting problems usually take down the site and leave email alone.

Why can I not just reset the password by email?

Because the recovery email often lives at the domain you have lost control of, which makes a loop. Break it at the layer above: hosting access lets you reset a CMS password, and registrar access lets you repoint mail. Or recover through identity documents rather than email.

What is a transfer authorization code?

A code your current registrar issues that authorizes moving the domain to a different registrar. Whoever controls the registrar account can generate it. Getting that code from a cooperative former developer is by far the cleanest ending to this whole situation.

Send me the domain name and I will tell you what you still control.

A public lookup takes me ten minutes and costs you nothing. You get a plain list of registrar, DNS, host, and mail provider, plus which door to knock on first.