↳ Notes

A website you can rebuild. A domain you can’t

This January a client wrote to me that he needed his site rebuilt. He attached the credentials with the words: “sending you the access details I managed to track down.” A paragraph below he added that he hadn’t found the second domain at all, but reckoned it was “somehow linked” to the first one, and that he’d call support if it came to that.

Nobody had cheated him. The site had been built years ago by a friend, who did a good job and then their lives drifted apart. It just never got written down anywhere. So a few years later the owner of a company was guessing where his own domain was.

This isn’t the exception. It’s the perfectly normal state of a company whose website works. And because it works, there’s no reason to look into it.

The problem is that it only comes out at the moment you need to change something.

One note upfront: I’m writing about Czech .cz domains. The principle holds everywhere, but the specific procedures and deadlines differ with other extensions.

Four things that get muddled together

Most people treat “the website” as a single item. In reality it’s four separate things that need have nothing to do with each other and can quite happily sit with four different companies.

The domain is the address. yourcompany.cz. The thing you read out to people over the phone.

The registrar is the company you pay for the domain. A domain can’t be bought directly from the registry – there’s always an intermediary between you and it.

DNS and nameservers are the signpost. They tell the internet which machine to look for your site on and where to deliver e-mail.

Hosting is that machine. The place where the site physically sits.

If I had to translate it into something tangible: the domain is the address and house number entered in the land registry. Hosting is the house standing at that address – it can be knocked down and rebuilt, by a different firm if you like. DNS is the sign by the road pointing to where that house is.

You need to be the one in the land registry. Who builds the house and who makes the sign is your choice – and it can be changed at any time.

Three of them you can swap yourself. Not the fourth

And here’s the whole point of why I’m writing this.

The registry rules contain two sentences worth reading twice:

“The administrative contact may change all data for a domain name, but cannot change the registrant.”

The registrant of a domain name has the right to handle it at will.

Translated: whoever you let into managing the domain – a supplier, an agency, your brother-in-law – as long as you’re the registrant, they can’t take it from you.

And the other way round, which is the unpleasant half: when you’re not the registrant, it won’t help you that you pay the invoices, have access to the admin and the site is in your name. That one line in the registry decides.

You can swap hosting in an afternoon. You can change the registrar without the old one having any say in it (I’ll show you how shortly). You can switch nameservers within hours. You can’t change the registrant without the consent of whoever that is.

Check it in a few seconds

For .cz domains this is public, the registry has it on its website. Open this:

https://www.nic.cz/whois/domain/YOURDOMAIN.cz/

You’ll see:

  • The registrant – even when it’s a private individual. GDPR hides the address and e-mail, but the name is always visible. For a company you’ll also see the registered address and a contact e-mail.
  • The expiry date – I’ll come back to that
  • The designated registrar – the company the domain runs through
  • The nameservers – where the domain points

I tried it on my own domain so you know what you’re looking at: I’m the registrant, the domain expires on 25 June 2027, the registrar is INTERNET CZ and the nameservers are handled by Cloudflare (as of August 2026). That’s exactly how it should look.

Registry record for the hilgert.cz domain - the Registrant row, expiry date and designated registrar

If the Registrant row shows the name of a former web developer, their company, or someone you don’t recognise, you have something to deal with. Not panic – just something to deal with, while the two of you are still on speaking terms.

How the registrant gets transferred

Before we get to the procedure, one thing that’s better known upfront: a proper transfer of the registrant stands or falls on the other side being willing. No form will compel them.

One client was in exactly this position: the domain was registered to his former web developer, and the only thing that worked in the end was paying the developer off. Technically nothing complicated was going on. What was unpleasant was that he wasn’t the one setting the price.

The procedure itself also differs from registrar to registrar. The registry puts it like this:

“The required form of confirmation (authorisation) of the request, i.e. verification that the change is genuinely requested by an authorised person, depends on your registrar. It may be confirmation from the e-mail held for the registrant, an electronic signature, or an officially certified signature.”

I went through how four Czech registrars handle it:

RegistrarWhat they want from you
VAS Hostingan authorisation link from both e-mails – the old and the new registrant, no paperwork
Active24confirmation by link to the contact e-mail in the registry; or a form with an officially certified signature of the new registrant
Czechia / Zoneronline by e-mail, but only from the 60th day after registration or transfer of the domain; otherwise paper with a certified signature
Common practice elsewhereboth registrants sign the request and have the signatures officially certified

What that means in practice:

If you’re the one transferring the domain, find out in advance what your registrar wants. If they want an officially certified signature, count on a trip to the post office or a notary, and on it not being done that afternoon. You’ll also need the new registrant’s identifier – the code they’re listed under in the registry. If the other side doesn’t have one, it gets created.

And here’s the sentence that makes this worth reading to the end: with some registrars, changing the registrant only takes clicking a link in the e-mail held for the domain. If that’s still the e-mail of a former supplier, they have more power over your domain than you do. So check not only the registrant’s name, but also which e-mail address the registry’s post goes to. You won’t see it in the public record for a private individual, GDPR hides it – you’ll find it after logging in with your registrar or in the Domain Browser.

The registrar, by contrast, you can change any time and ask nobody

Changing the registrar is done with a transfer password, known as AuthInfo. And the key part: the current registrar’s cooperation isn’t needed. They can’t hold you.

You can ask for AuthInfo in four ways: from your current registrar, from the new registrar, by filling in the form at nic.cz, or by pulling it yourself from the Domain Browser after logging in with mojeID.

So: if you’re the registrant, you’re nobody’s hostage. If you don’t like it where you are, you leave.

Nameservers you can safely leave to your supplier

When a supplier tells you “we’ll point the domain at our nameservers” or “at Cloudflare”, there’s nothing suspicious about it. It’s standard practice and it doesn’t touch ownership in the slightest. The change is done within hours and you can take it back at any point.

There’s one thing I’d keep an eye on: have a copy somewhere of what’s in the DNS. An export from the supplier or a plain screenshot will do. If something then breaks during the switch, or the supplier goes quiet, you have something to rebuild it from. And what breaks most often is e-mail – it hangs off DNS exactly the same way the website does, most people just don’t connect the two.

Keep an eye on the expiry date too

Ownership is one thing, not forgetting to pay is another. Expiry isn’t another thing outside your control – that one is entirely in your hands. But it is a route by which someone else can end up as the registrant of your address.

A lapsed domain is worse than a broken website. Company e-mail goes down with it and eventually someone else can register it – someone who noticed, say, that it still gets traffic.

The expiry date is visible in the whois record, so check it right when you’re there verifying the registrant. And make sure the registry’s reminders go to an address somebody actually reads. Not to the e-mail of an employee who left three years ago.

What actually happens to a lapsed domain

It’s worth knowing how things go after expiry – because it isn’t overnight, and because it hides both a risk and one unexpected way out.

For a .cz domain the calendar looks like this:

  • The first 30 days after expiry the domain works normally. The site runs, e-mail arrives, nobody notices a thing. It can be renewed at any time.
  • The next 30 days it’s pulled from DNS. The site is down, e-mail doesn’t arrive. It can still be renewed.
  • On day 61 the domain is deleted for good. Renewal is no longer possible.
  • The deleted domain is then entered into an auction. For fifteen days it sits in the list of upcoming auctions; on the sixteenth day it’s auctioned – for one single day, from noon to nine in the evening.

So roughly two and a half months pass between expiry and auction. And note that first thirty: for the whole first month the site runs normally, so nobody has to notice there’s a problem. It typically comes to light when the post stops arriving.

Domain auctions: a route not many people know about

The fact that deleted .cz domains get auctioned is fairly new – CZ.NIC launched auctions in May 2024. Before that, released domains went back into open registration and the interesting ones were fought over by a handful of firms that knew how to catch them at the right second. Today anyone with a verified electronic identity (mojeID or EU eID) can bid.

What’s auctioned is the right to register the domain, the opening price is CZK 100, and the winner then has seven days to actually register and pay for it with a registrar.

And now why I’m writing this here. Remember the client who had to pay off his former web developer? At least he had someone to negotiate with. With a different client we solved the domain this way: talking got us nowhere, so we let the domain lapse and I then won it back for him at auction. It worked out – the domain is registered to him today.

It sounds like a last resort, and it is one – and it comes with a risk you need to know about beforehand. The moment you let a domain go to auction, it becomes available to anyone. Anyone who notices it can bid. You then either outbid the other interested parties, or you lose the address you have on your signs, vans and business cards.

To give you a sense of the sums: in the first year of operation almost half the domains sold went for the opening hundred crowns and the average sits around CZK 1,350. But the most expensive domain so far went for just under 200,000. It comes down entirely to whether someone notices it.

So: this is a solution of absolute last resort. Try everything else first – talking, your registrar, a proper change of registrant. Letting a domain lapse only makes sense when there’s genuinely nobody left to approach. And even then, count on a month without e-mail and another month of waiting to see how it turns out.

What to have handed over to you

A short list the owner of the company should keep. Not the supplier, not the agency – the owner.

  • who is listed as the registrant, and which e-mail the registry’s messages go to
  • when the domain expires
  • access to the domain registrar (and knowing how to ask for AuthInfo)
  • hosting, or the server administration
  • the website admin
  • e-mail
  • analytics and Search Console
  • the payment gateway, if you run an e-shop

If something on that list is missing, nothing bad need be happening. Most of the time nothing bad really is happening.

And if you keep an eye on a single item from the whole list, make it the domain. Everything else can, at worst, be built again: a new site gets developed, hosting gets moved, mailboxes get created. It’s work and it costs money, but it can be done. The address people know you by is the one thing you can’t build again.

For the sites I look after, this is one of the first things we go through at the start. Not because it’s complicated, but because it doesn’t occur to anyone until it’s too late. And if you’d rather not go through it on your own, you can be walked through it.

↳ Note written by

Need to tweak your website?

I'm not a fan of dozens of plugins that slow a website down. Wherever I can, I solve it with clean code - without unnecessary extra weight.

Discuss a website edit