Skip to content
7 min read

What to do when your web developer stops replying

Your developer has stopped answering emails. Or they answered and said no. Or they have shut the business, taken a job elsewhere, or fallen out with you over an invoice. Either way you cannot get into your own website, you are not certain what you own, and it feels like theft.

Some of it may be. Most of it is a handover that never happened, and accounts opened in the wrong name three years ago by somebody not thinking about this day.

Nobody writes this article, agencies do not enjoy discussing what happens when an agency behaves badly. So here is the order to work through it in.

Start with an inventory, not an email

Before you send anything, write down what exists and who holds it. Against each, note whose email address opened the account, and whether you can log in today. Password resets go to whoever the account believes the owner is, so that address decides most of this.

Six things:

  • The domain registrar. Who you rent the name from, renewed yearly. 123 Reg, GoDaddy, Cloudflare, or a reseller account inside your developer's.
  • DNS. The settings saying where the name points, website here, email there. Usually at the registrar.
  • The hosting. The machine the files sit on, and the panel reaching them. Where a backup comes from.
  • The CMS or admin area. WordPress, Shopify, or something custom. A login here edits pages, not files.
  • The code repository. GitHub, GitLab or Bitbucket, if the site was built rather than assembled, often in a personal account.
  • Email. Google Workspace, Microsoft 365, or mailboxes on the same hosting. The most disruptive thing to lose, and the one forgotten in the panic.

The domain, the hosting and the files are three separate things

Most people treat the website as one object. It is at least three, usually bought from different companies, and each can be lost or recovered independently.

The domain is the name. You do not own it outright, you hold a registration that renews, and it is the only irreplaceable part. The hosting is the machine serving the files, plus the control panel and, on a CMS, the database holding your content. The files are the site itself: templates, images, code, pages and posts.

A copy of the site as visitors see it is not the source it was built from. You can take the first off the public internet in an afternoon, the second exists only where the developer put it. Moving hosting does not touch your domain, and recovering your domain needs nobody's hosting login.

Find out who the domain is actually registered to

There is a public record and you can check it in two minutes. For a .uk domain, Nominet is the registry and publishes a lookup. For .com and others, ICANN's lookup does the same.

The field to find is the registrant, sometimes shown as registrant name or organisation. That is the entity the register treats as holding the domain. The admin, technical and billing contacts beneath it are frequently the developer, and are not the same thing. Privacy services hide these details on many domains, in which case ask the registrar.

The registrant matters more than your invoice. Paying every year does not by itself put your name on the register, and registries act on the register. Keep the invoices, they are evidence and evidence matters in a dispute. But if the registrant reads as Some Web Design Ltd rather than your business, that is the central problem. If it reads as you, contact the registrar, prove you are who the record says, and ask them to reset access.

While you are there, find the expiry date and diarise it. If your developer holds the account and has disengaged, nobody may be watching it. A lapsed domain runs through a grace period, then a redemption period, and after those somebody else can register it. Some registrars will take a renewal payment on a domain you do not control, so ask. And do not cancel the card paying for the hosting until a backup is in your hands, it takes the site down.

What usually comes back without them, and what does not

Plainly, because vagueness here costs money. Not recoverable without their cooperation: the source code, when it lives in a private repository or on their laptop, no process reaches into somebody else's computer. A CMS database, unless you can reach the hosting or the admin area. And anything inside an account they opened in their name on their card, with resold hosting the host's customer is them.

Something people are rarely told: as a general position in the UK, copyright in commissioned work stays with the contractor unless it has been assigned in writing. Paying for it does not automatically transfer ownership of the code. Your own agreement may say otherwise, so read what you signed and take advice on your own facts.

So if the code never left them and nothing in writing says it is yours, budget for a rebuild rather than a fight. If you rebuild, insist the addresses search engines already hold are mapped across: two WooCommerce skip-hire sites we moved onto statically exported builds needed 45 permanent redirects against the old URL inventory.

Usually recoverable on your own:

  • The domain, if you are the named registrant. The important one.
  • Your public content, which is already published and can be copied off the live site.
  • Google Business Profile, Analytics and Search Console, through each platform's own verification routes.
  • Email, once you control DNS.
  • Hosting, if the account is in your name and paid by you.

Ask for the handover in a way that tends to work

One email, to a named person, not the tenth reply in an old thread. "Access to my website" is not a request anybody can action.

Give a date, five working days is reasonable, and say what you will do afterwards in flat terms rather than as a threat: approach the registrar and host directly. Offer to pay for the time. People resist this and it is often what unlocks it. A handover is an hour or two of real work, and where an unpaid invoice sits in the background that, rather than malice, is usually why you are ignored. Settling an invoice you think unfair can still be the cheapest route to your own domain.

By name:

  • The registrar account, or the domain transfer authorisation code, sometimes called an auth or EPP code.
  • The hosting control panel login, or a full backup of files and database.
  • An administrator-level CMS account in your own name and email.
  • A copy of the DNS records as configured, so nothing breaks when the domain moves.
  • The repository, transferred to an account you control, or exported.
  • A list of every account opened for the project, and whose name each is in.

When asking does not work

Work down this list, stopping as soon as something works. Somewhere in it, decide what you are fighting for. If the domain is the asset, and it usually is, spend the money there and let the old site go. If the site was five pages of text you can still read on screen, do not spend three months and a legal bill on the files.

In order:

  • Go direct to the registrar and the host, and ask their process for an account whose holder is unreachable. Have invoices, emails and proof of identity ready.
  • Check Companies House. If they traded as a limited company, its status and any insolvency filings are public, which changes who you are chasing.
  • Send a formal letter before action, or have a solicitor send one. It costs less than most people assume.
  • For a .uk domain, Nominet operates a dispute resolution service, and for other domains the registrar's own process comes first. Read the current criteria.
  • If money was paid and nothing delivered, Citizens Advice can refer a matter to Trading Standards, and small claims exists for smaller sums.

What to put in the next contract

Preventable, and the prevention is boring. Ask any supplier you are about to appoint, us included, to put in writing whose name the domain is registered in, which accounts they will hold on your behalf, and what happens to all of it if you part company. A supplier who will not write that down has told you something useful.

Ask for these in writing before work starts:

  • A named registrant. The domain registered to your business, on an account in your own email, from day one. The developer can hold admin access, the registrant is you.
  • Assignment of copyright in the deliverables to you, in writing, on final payment: source code, design files, content. Expect third-party components to be excluded and listed, nobody can assign you a framework or a licensed font.
  • Access on request. Credentials for any account holding your site or your data, within a stated number of working days, at any point, not only at the end.
  • A live account register: every service opened for you, whose name it is in, who pays.
  • A stated handover on exit: a full file and database backup, a DNS export, transfer of the repository. A deliverable, not a goodwill gesture.
  • Clarity about hosting. If it sits in their account, say so, and say what happens when you leave. Your own name is easy at the start, awkward later.

The domain comes back, because the registrant is either already you or fixable through the registrar. Email sorts itself out once DNS is yours. The old code often does not, and after a fortnight most people stop wanting it, because what they wanted was a site they can get into.

So inventory first, protect the domain second, then decide honestly whether you are recovering a website or replacing one. Different projects, different costs.

If you want a second opinion on your inventory, send us the list at ads@digitalxp.co.uk. Replies come within one working day. If you already hold everything that matters and simply need a password reset, we will tell you that, and you will not hear from us again.

Got a project that needs any of this doing properly? Answer a few questions and get a fixed-price quote back within one working day.

Get a Quote
All notes