The Website Handover Checklist Most Businesses Skip
A practical checklist for verifying domain, hosting, code, database and account ownership when a website changes hands — not just taking someone's word for it.
When a website changes hands, what actually moves?
A website relationship ends for all sorts of reasons — a freelancer stops replying, an agency's retainer lapses, a staff member who "handled the website" leaves the company. At that point, most business owners assume everything they need is already theirs. It usually isn't. A domain name, a hosting account, a codebase, a database and a stack of third-party logins are five separate things, each with its own owner of record, and a handover is only complete when every one of them has actually changed hands — not when someone says it has.
This isn't a legal document. It's a working list of what to check, and how to check it, before you sign off on a handover or move on from an agency or freelancer.
Domain name: the registrant, not the DNS
The domain name is the asset most businesses assume they already control, because they can see it working in a browser. What matters is who's listed as the registrant on the domain record — the party MYNIC (for .my domains) or the relevant registry (for .com and others) recognises as the owner. Whoever registered the domain originally, using their own name, email and payment card, is the registrant of record until that's formally changed.
You can check this yourself. For a .my domain, MYNIC's WHOIS lookup at mynic.my/whois will show what's on file, though contact details are partly redacted — MYNIC restricts how much personal information its WHOIS service displays, for privacy reasons. If you can't get a straight answer on who the registrant is, or the registrant field shows an agency's name or a former employee rather than your own company, that's a handover item, not a footnote.
Two things worth knowing before requesting a registrant change: first, whoever is listed as a domain's Administrative Contact typically has the authority to change the Registrant, so the admin contact matters as much as the registrant field itself. Second, under ICANN's Change of Registrant policy, a genuine change of registrant — as opposed to a small correction like a fixed typo — usually locks the domain against transfer to a different registrar for 60 days. That's a security measure against hijacking, not a fault, but it means a registrant change and a registrar move are two steps you may need to sequence rather than do at once.
DNS: who can point your domain anywhere they like
DNS records decide where your domain sends visitors, mail and API traffic. Whoever holds the login to the DNS zone — whether that's inside the registrar account, a separate DNS provider, or a CDN dashboard — can redirect your entire website or mail flow without touching the domain registration at all. Ask for direct access to wherever the DNS zone actually lives, not a screenshot of the records. If the zone sits inside an agency's own account on a platform you've never used, ask for it to move into an account you control, or for full admin access to it.
Hosting: the account, not just the server
"Where is the site hosted" and "who owns the hosting account" are different questions. An agency might host dozens of client sites under one company account for its own convenience. If that's the case here, you don't own a hosting account — you're a guest inside someone else's. Ask specifically whether the hosting account is registered in your company's name, with your own billing details, and whether you have full administrator access, not a client login with restricted permissions.
Source code and its repository
If the site involves custom code, it should live in a version-controlled repository — typically GitHub or GitLab — that your business owns or controls, not a folder on someone's laptop. If the repository currently sits under a developer's personal account, ask for it to be properly transferred rather than just shared with read access. A proper transfer moves the repository's full history, issues and pull requests to the new owner in one step, which is worth doing rather than starting a fresh copy with none of that context.
The database
For anything beyond a static brochure site, there's a database behind it — customer records, orders, form submissions, content. Confirm where it's physically hosted, who has administrative access, and whether you hold your own current export or backup, not one that's a year old. If the database holds personal data, it also matters who's formally responsible for it: under the Personal Data Protection (Amendment) Act 2024, the provisions extending direct Security Principle obligations to data processors — not just the data controller — came into force from 1 April 2025. Whoever holds and manages that database on your behalf now carries compliance duties for it, so it's worth knowing exactly who that is.
Third-party accounts
Google Analytics, Google Search Console, Google Business Profile, Meta Business Manager, payment gateway dashboards, email service providers — these accumulate over a website's life, and it's common for an agency or a former employee to have set several of them up using their own login. Go through each one and confirm: whose email address owns the account, who else has access, and whether ownership — not just "user" access — sits with your business.
Licences
Premium themes, plugins, stock photography and fonts usually come with a licence tied to a specific purchaser. If that purchaser was the agency rather than you, the licence may not transfer automatically, and continued use might breach its terms once the relationship ends. Ask for proof of purchase and licence keys, and check with the vendor if a formal transfer of ownership is required.
Verify — don't just ask
The theme running through all of this is the same: don't take a verbal or written assurance that "you have everything" at face value. Log into the registrar yourself and check the registrant field. Log into the hosting panel yourself and check the account owner. Ask the repository host to confirm who the owner is. A proper handover leaves you with credentials and confirmed ownership across each of these areas — not a promise that it's all fine.
Where this fits with a system review
Working through this list from scratch, especially without technical help, takes time most business owners don't have. JagaWeb's Essential System Review (RM1,500, or RM999 under the current promotion running until 16 September 2026) checks eight control points across a single site — including domain, hosting and access control — and hands back a decision-ready report with a 30-day action plan. It's one option if you'd rather have someone go through the checklist for you than do it line by line yourself; there's no guaranteed outcome attached, just a documented look at what you currently control. Details at jagaweb.my, or reach sales@jagaweb.my / WhatsApp jagaweb.my.
Ready to verify who owns your website?
Replace uncertainty with a decision-ready ownership and access report. The fixed Ownership & Access Review is RM1,500 before SST and includes a 30-day action plan.