A business website may involve several separate services: domain registration, DNS, website hosting, SSL certificates and email.
These services often work together, but they are not necessarily provided or managed by the same company.
The domain may be registered through one supplier, DNS hosted by another, the website placed on a cloud server and email delivered through a separate platform. When responsibilities are unclear, a routine change can cause website downtime, email failure or loss of control over an important business asset.
Every organisation should know who owns each account, who can make changes and who is responsible for renewals, security and technical support.
What Is a Domain Name?
A domain name is the address people use to find a business online, such as example.com.
The domain is registered through a domain registrar for a defined period. The registrant receives the right to use it while registration remains active and renewal requirements are met.
The domain does not contain the website or email itself. Instead, it provides the name that connects users to those services.
A business domain may be used for:
- Company website
- Employee email addresses
- Customer portals
- Online shops
- Application access
- Marketing campaigns
- Verification of online services
Because so many services depend on it, the domain should be treated as an important business asset.
Who Should Own the Domain?
The business should normally be listed as the domain registrant and retain direct control of the registrar account.
The account should use:
- A company-controlled email address
- Accurate business contact information
- A strong unique password
- Multi-factor authentication
- More than one authorised administrator
- Documented recovery information
A website developer, employee or external IT supplier may manage the domain, but it should not be registered solely in that person’s name or personal account.
If the relationship ends, the business could face delays or disputes when trying to transfer, renew or update the domain.
Who Is Responsible for Domain Renewal?
The domain owner is ultimately responsible for ensuring the registration remains active.
A registrar or managed-service provider may process renewals, but the business should still know:
- Renewal date
- Renewal period
- Payment method
- Account owner
- Administrative contact
- Recovery procedure
Automatic renewal is useful, but it should not be the only control. Payment cards expire, employee addresses change and automated messages can be missed.
Domain expiration can affect both the website and email, making it one of the most disruptive administrative failures a business can experience.
What Is DNS?
DNS stands for Domain Name System.
DNS records tell internet services where to find the website, email platform and other systems connected to the domain.
Common DNS records include:
- A record: Points a name to an IPv4 address
- AAAA record: Points a name to an IPv6 address
- CNAME record: Connects one name to another hostname
- MX record: Identifies the email service
- TXT record: Stores verification and email-security information
- NS record: Identifies the authoritative DNS provider
DNS is effectively the routing layer for the domain.
An incorrect change can make a website unavailable, stop email delivery or prevent third-party services from verifying the domain.
Who Should Manage DNS?
DNS may be managed by:
- Domain registrar
- Website hosting provider
- Cloud provider
- Managed IT provider
- Dedicated DNS service
- Internal IT team
The appropriate manager depends on the business’s technical resources and infrastructure.
What matters most is that responsibility is clearly assigned.
The organisation should know:
- Where DNS is hosted
- Who has administrative access
- Who approves changes
- How records are backed up
- How changes are documented
- Who responds during an outage
DNS credentials should not be shared informally between employees and suppliers.
Domain Registration and DNS Hosting Are Different
The domain registrar and DNS provider may be the same company, but they perform different functions.
The registrar maintains the domain registration.
The DNS provider hosts the records directing traffic to the business’s online services.
A business can transfer DNS management without transferring the domain registration. It can also move the domain to another registrar while keeping the same DNS service.
Understanding this separation is useful when changing hosting providers.
Moving a website does not necessarily require transferring the domain itself.
What Is Website Hosting?
Website hosting provides the server environment where the website files, database and application operate.
The hosting provider may supply:
- Shared hosting
- Virtual private server
- Cloud virtual machine
- Dedicated server
- Managed application hosting
- Storage and network connectivity
- Backup and monitoring
The website host does not automatically control the domain or DNS.
To make a new website live, the relevant DNS records must be updated to point users to the new hosting environment.
Who Is Responsible for the Website?
Responsibility may be divided between several parties.
Hosting Provider
The hosting provider may manage:
- Physical infrastructure
- Network connectivity
- Virtualisation platform
- Server availability
- Agreed backup or monitoring services
Website Developer
The developer may manage:
- Website design
- Application code
- Content-management system
- Plugins and integrations
- Database structure
- Website updates
Business
The business may remain responsible for:
- Content
- User accounts
- Access approval
- Data protection
- Software licences
- Supplier coordination
- Final change approval
These responsibilities should be documented, especially when the hosting company and website developer are different suppliers.
What Is an SSL Certificate?
An SSL certificate enables HTTPS, which encrypts data exchanged between the website and its visitors.
Modern certificates are technically based on TLS, but the term SSL remains widely used.
HTTPS helps protect:
- Login credentials
- Contact forms
- Customer information
- Payment-related traffic
- Website administration
- Browser trust
Without a valid certificate, visitors may receive a browser warning that the connection is not secure.
Who Is Responsible for SSL?
SSL responsibility may sit with:
- Hosting provider
- Website developer
- Managed IT provider
- Internal administrator
- Content delivery or security provider
The responsible party should manage:
- Certificate issuance
- Domain validation
- Installation
- Renewal
- HTTPS configuration
- Expiration monitoring
- Replacement after domain or server changes
Many hosting platforms support automatic certificates and renewal. However, the business should still know who will respond if renewal fails.
An automatically issued certificate can still stop working because of DNS errors, account changes or incorrect server configuration.
What Is Business Email Hosting?
Business email hosting provides mailboxes using the company’s domain, such as [email protected].
Email may be hosted through:
- Microsoft 365
- Google Workspace
- Dedicated email provider
- Website hosting package
- Cloud or on-premises mail server
Website hosting and email hosting are separate services, even when one supplier provides both.
Moving the website does not always require moving email. Careless DNS changes, however, can interrupt email if MX or authentication records are removed.
Which DNS Records Support Email?
Business email commonly depends on several DNS records.
These can include:
- MX records: Direct incoming email to the correct platform
- SPF record: Identifies systems authorised to send email
- DKIM record: Adds a cryptographic signature to outgoing messages
- DMARC record: Defines how receiving systems should handle authentication failures
- Autodiscover records: Help devices locate mailbox settings
- Verification records: Confirm ownership to the email provider
Incorrect records can cause delivery failure, spam filtering or domain impersonation risk.
Email DNS changes should therefore be completed by someone who understands the existing configuration.
Who Is Responsible for Email Security?
The email provider protects the underlying platform, but the business remains responsible for areas such as:
- User accounts
- Passwords
- Multi-factor authentication
- Access permissions
- Former employee accounts
- Mailbox retention
- Phishing awareness
- Device security
- Administrative roles
A managed IT provider may perform these tasks under an agreement, but the business should still approve access and retention policies.
Email security is not complete simply because the platform includes spam filtering.
Avoid Using One Person’s Account for Everything
A common small-business arrangement places the domain, DNS, hosting and email administration under one employee or supplier account.
This creates a serious dependency.
Problems can occur if that person:
- Leaves the organisation
- Becomes unavailable
- Loses access
- Uses a personal email address
- Has an account compromised
- Ends the supplier relationship
Important services should use company-controlled accounts with at least two authorised administrators where possible.
Access should be reviewed whenever employees or suppliers change.
Document Every Service
Maintain a simple register containing:
| Service | Provider | Account Owner | Technical Manager | Renewal or Review Date |
|---|---|---|---|---|
| Domain registration | Registrar | Business | IT provider | Annual renewal |
| DNS | DNS provider | Business | IT provider | Quarterly review |
| Website hosting | Hosting provider | Business | Developer or IT provider | Contract review |
| SSL certificate | Hosting platform | Business | Hosting provider | Automatic renewal |
| Business email | Email provider | Business | IT administrator | Licence renewal |
Do not store passwords directly in an ordinary document. Use an approved password manager or secure access-management process.
The register should identify where credentials are held and how emergency access can be recovered.
Plan Provider Changes Carefully
Changing a website, email or DNS provider should follow a controlled process.
Before making changes:
- Record all existing DNS entries.
- Confirm which services depend on the domain.
- Prepare the new environment.
- Test the website or email platform.
- Reduce DNS time-to-live where necessary.
- Schedule the change during a suitable period.
- Monitor website and email operation.
- Keep the previous service available temporarily.
- Maintain a rollback plan.
Do not replace the complete DNS configuration when only one record needs to change.
Deleting unrelated records can interrupt email, verification, remote access and third-party applications.
Common Responsibility Mistakes
The Developer Owns the Domain
The business may lose control when the relationship ends.
No One Monitors Renewals
A domain or certificate can expire even when automatic renewal was expected.
Website Changes Break Email
MX and authentication records may be removed during a DNS migration.
Everyone Has Full Administrator Access
Excessive privileges increase security risk and make changes difficult to trace.
The Hosting Provider Is Assumed to Manage the Website
Infrastructure support may exclude plugins, content and application errors.
Email Is Assumed to Be Backed Up Automatically
Retention and recovery options differ between platforms and service plans.
Responsibilities Are Not Written Down
During an outage, each supplier may assume another party is responsible.
A Practical Responsibility Checklist
Before approving a website or email service, ask:
- Who legally controls the domain?
- Which account is used for registration?
- Who monitors domain renewal?
- Where is DNS hosted?
- Who can change DNS records?
- Is the current DNS configuration documented?
- Who manages the website server?
- Who maintains the website software?
- Who installs and renews the SSL certificate?
- Who responds if HTTPS stops working?
- Which platform hosts business email?
- Who manages user accounts and permissions?
- Are SPF, DKIM and DMARC configured?
- Who monitors email delivery problems?
- Are at least two administrators available?
- What happens when a supplier relationship ends?
- How are credentials stored securely?
- Is there a documented emergency contact process?
Clear answers reduce the likelihood of outages and ownership disputes.
Final Recommendation
The business should retain ownership and oversight of its domain, even when an external supplier manages it.
DNS should be administered by a clearly assigned technical party, with records documented and changes controlled.
SSL certificates should be renewed and monitored by the hosting provider, developer or IT manager named in the service agreement.
Business email should be managed separately from website hosting, with clear responsibility for accounts, authentication, retention and security.
Most importantly, do not allow critical online services to depend on one person’s private account or undocumented knowledge.
Ila Express provides domain, DNS, website hosting, SSL, business email and managed cloud support for company websites and online services.
Contact Ila Express to review your current setup and clarify ownership, access and support responsibilities across your domain, website and email services.













