A domain can support your website, email and other services while receiving little attention between renewals. A useful review asks which registrar manages the registration, when renewal needs attention and who receives the notices if a payment fails.

The original setup may have happened years ago, through a staff member or provider whose role has since changed. When the registration continues to renew, a gap in the records may stay unnoticed. Bringing it into your ordinary operational review helps keep the arrangements visible.

Our walkthrough covers finding the information. This article is about what to do with it once you have it: putting the domain into your records like the asset it is.

What makes it an asset

A domain can support several important services: your website, business email addresses, verification records for other systems and mailboxes used in some account-recovery processes. List the actual dependencies rather than assuming they are the same for every business.

Account recovery deserves particular attention. A loss of domain control may affect email delivery and create risks for services that rely on those addresses. Review the recovery settings for important accounts, including what authorized staff can do if the domain or its mail service is unavailable.

There may also be established uses to consider: years of search history, printed material, vehicle signage, business cards, third-party listings, and links from other sites. Changing a domain may therefore require coordinated updates across technology, marketing and customer communications.

What belongs in your records

Keep this somewhere durable and shared — not a personal note file, and not only in one person's password manager.

  • Every domain the business uses, including redirects, retired brand names, and defensive registrations of common misspellings.
  • The registrar holding each one, and the account it sits under.
  • The registration and expiry dates shown at the registry, and separately the date your registrar bills you.
  • Whether auto-renew is on, and which payment method is attached.
  • The address renewal and account notices are sent to.
  • Whether a transfer lock is applied.
  • Where DNS is hosted, which is frequently a different company from the registrar.
  • The named person responsible, and a named deputy.

The distinction between the registry expiry date and your billing date is the one that catches people out. The registry expiry field is part of the registration record; confirm the actionable renewal deadline and any renewal state with your registrar. It says nothing about whether your card is valid, whether auto-renew is enabled, or whether the notice is going to a mailbox that still exists. Consider a hypothetical company whose lookup shows a comfortable expiry eight months out, while the card on file expired last month and the renewal warnings are being delivered to a former employee's address. The lookup alone would not reveal those account-level issues.

Registrars also differ in what happens after a lapse — grace periods, redemption windows and restoration charges vary by registrar and by top-level domain. Rather than trusting a figure from an article, find your registrar's stated policy and record it alongside the rest.

What the public record will not give you

Registration data for generic top-level domains is now published through RDAP, which ICANN designated as the definitive service for gTLD registration data at the start of 2025, with some legacy WHOIS obligations continuing for certain contracts and country-code domains following their own rules.

Depending on the record and applicable rules, the registrant’s identity may be redacted. Public output is commonly stripped of name, email and address for privacy reasons, and even where a name appears it is a directory entry rather than legal proof of entitlement. A lookup can identify the sponsoring registrar as a starting point, even if you deal through a reseller. Confirm access and administrative arrangements with the authorized account holder. Entitlement may require separate contractual or company records; logging in does not by itself establish legal ownership.

Continuity is the real subject

Records exist for the day the person who knows things is unavailable. Build for that case.

Use company-approved contact and recovery arrangements that remain accessible to authorized staff after a departure. Where supported, provide named delegated access rather than sharing a single login. Put renewal checks on a shared calendar with a responsible role and backup. Include domain and DNS responsibilities in relevant handovers. When working with an agency, agree in writing who will hold and administer the registration, and document the process for any future account or provider change.

A repeatable domain review

  • Run a lookup on every domain on your list and reconcile it against your records.
  • Confirm you can sign in to each registrar account today.
  • Confirm multi-factor authentication is enabled on those accounts.
  • Check auto-renew, payment method and notice address.
  • Confirm transfer locks are applied where appropriate.
  • Review dependencies before retiring a registration. Old email addresses, redirects and account-recovery settings may still depend on it.
  • Update the responsible person and deputy.

What this does not cover

Good records do not make your DNS correct, your mail authentication sound, or your website resilient. Those are separate pieces of work. And documentation does not resolve a genuine dispute over entitlement — that runs through your contracts, the registrar's processes, and where appropriate professional advice.

Keep the record useful without exposing credentials

The domain inventory should point authorized people to the approved credential store, not contain passwords, MFA recovery codes or payment-card details itself. Record the account owner and access process, and restrict the inventory appropriately if it describes sensitive infrastructure.

For each domain, add a short purpose statement. A legacy domain may redirect visitors, receive mail or support an older integration even when no website appears at its address. Ask the relevant service owners to confirm those dependencies before treating it as unused. This makes a renewal decision easier to review and reduces the chance of overlooking a less visible service.

Your next step

Watch the walkthrough, then create the record. One page, current, shared, with a named owner. Confirm gaps with the responsible parties and set a date for the next review.

If you would like help assembling the picture across scattered registrars and inherited accounts, that is ordinary work for the ALCO team alongside managed hosting, development and IT support.

Sources and further reading

ALCO training on domain ownership: https://alcohq.com/training/domain-ownership
Video walkthrough: https://youtu.be/vPLz6TuYsuE
ICANN on the move from WHOIS to RDAP: https://www.icann.org/en/announcements/details/icann-update-launching-rdap-sunsetting-whois-27-01-2025-en
ICANN Lookup FAQ on redacted registration data: https://lookup.icann.org/en/faq