Free tool
Who holds the keys to your website?
A domain rests on half a dozen accounts: registrar, DNS, hosting, email, newsletters… When the person who opened them leaves, nobody can get back in. We draw the map; you note who holds each key.
Why this map matters
The most common scenario is not hacking: it is the volunteer, employee or web designer who opened the accounts with a personal address and is no longer around. The domain expires, the site goes down, and nobody can prove they own it.
01
In the organisation's name
Every account should be in the organisation's name, with a generic address (web@, admin@) that survives departures.
02
Two people, at least
Two administrators on the registrar, DNS and email accounts: one person's absence never locks everyone out.
03
A password manager
Shared passwords belong in a shared vault (Bitwarden, 1Password), with two-step login, not in an email or on a sticky note.
How to use the sheet
- Print it or fill it in on screenOne row per account. Accounts at the same provider (DNS and CDN at Cloudflare, for example) are grouped: it is usually a single login.
- Check each rowLog in to each account: do you still have access? Whose name and address is it in? Is two-step login on?
- Fix what is fragileTransfer accounts held by a single person or a former employee, add a second administrator, update the recovery email.
- Store it and redo it once a yearWith the organisation's important documents, never with the passwords.
Questions
Why are some services missing?
We only see what the domain publishes. A website admin, a Google Analytics account or a social network page leave no trace in DNS. Add them in the “Other” rows.
What is a verification record?
To prove you own a domain, services like Google, Microsoft or Meta ask you to add a code in DNS. The code often stays there long after: it is a good clue that an account exists, sometimes forgotten.