The registrant is the owner. Not the payer
ICANN's Transfer Policy is explicit that the Administrative Contact and the Registered Name Holder are the only parties with authority to approve or deny a transfer, and that where they disagree, the Registered Name Holder's authority prevails. That single field is the mechanism of every hostage situation we are called about: the designer put their own name in it during onboarding, the registrar's contract runs to them, and paying every invoice never made you the registrant.
So the first question is not what your contract says. It is what the registration record says. Look it up using RDAP, the Registration Data Access Protocol that replaced WHOIS when ICANN sunset it on 28 January 2025. Registrant details are redacted by default; the registrar of record and the status codes are not, and those are what you need. The one-minute version: can you log in to the registrar right now, without calling anyone?
Three different things people call the website
Ownership disputes get muddled because the word website covers three assets with three different owners, three bodies of law and three recovery routes. Separate them first.
1. The domain name. A lease from a registry through an ICANN-accredited registrar, governed by ICANN policy and, in a dispute, by United States trademark and property law. Almost always yours in substance.
2. The files and the database. Design, code, photographs and text, governed by copyright — where owners are most often wrong about what they bought.
3. The accounts. Hosting, DNS, the business profile, analytics, licences, mailboxes and social profiles, governed only by each platform's terms.
A proceeding that recovers the domain does not recover the files, and a copyright claim does not get you the domain.
The AuthInfo code, and who is entitled to it
The authorization code — historically the AuthInfo or EPP code, being renamed the Transfer Authorization Code as ICANN's rules are updated — is a registrar-generated secret, unique to one domain, proving to a gaining registrar that whoever holds it may move the name. Four provisions of the Transfer Policy are worth knowing precisely, because they are what a stalling registrar hopes you have not read (ICANN Transfer Policy):
- Codes must be unique per domain.
- The registrar must supply the code and remove transfer locks within five calendar days of the Registered Name Holder's request, unless self-service tools are faster.
- Getting the code may not be made harder than changing a nameserver or a contact.
- A registrar may not withhold the code to collect money. The policy says plainly that it is not a payment collection mechanism.
Now the limit most articles get wrong, and it is the difference between useful advice and three wasted weeks: those rules bind registrars. They do not bind your web designer. A designer who is not an accredited registrar sits outside ICANN's compliance process entirely. If your designer holds the domain in a personal account at a large registrar, complaining to ICANN accomplishes nothing — that registrar is doing exactly what its policy requires, taking instructions from the Registered Name Holder, who is not you.
Two refinements. The code identifies but does not authorize; a separate Form of Authorization is the authorizing instrument. And under revisions approved in March 2025 the code is generated only on request and lives 336 hours, with an effective date still unconfirmed as of August 2026.
Why UDRP is usually the wrong tool
The Uniform Domain-Name Dispute-Resolution Policy is the arbitration process people are pointed at when a domain is being held. It is a real remedy, and occasionally the right one,. It is also a trademark tool, and a contract dispute with a designer is not usually a trademark case.
Under paragraph 4(a) a complainant must prove all three of: the domain is identical or confusingly similar to a trademark or service mark in which the complainant has rights; the holder has no rights or legitimate interests in it; and the domain has been registered and is being used in bad faith (ICANN, UDRP). Miss one and you lose. Three consequences follow:
- You need trademark rights. A federal registration makes that straightforward. An unregistered mark requires showing it has become a distinctive identifier consumers associate with you, and WIPO warns that conclusory allegations will not normally suffice. A lake-area business trading a few years under a descriptive or geographic name may not clear that bar.
- The only remedies are cancellation or transfer of the domain. No money, no files, no hosting account. If what you needed was the files, you win and still have no website.
- Everything else is outside it. Paragraph 5 sends other disputes to court, and the related transfer dispute process is closed to you — only a losing or gaining registrar may file one.
The case law is nonetheless more favorable than that test suggests. In Alaska Health Fair, Inc. v. Chris Jacobson in 2013, a panel ordered a domain transferred back from a developer who had parked the client's site behind a notice saying it was paused for non-payment, holding that retaining a domain as a financial lien exceeded acceptable use under the policy. No public decision appears to go the other way on an if-you-do-not-pay-I-keep-it clause. A contract can create a debt; it cannot manufacture a right to hold property.
United States courts go further. In DSPT International, Inc. v. Nahum (Ninth Circuit, October 2010) a man who handled a company's web work held the registration in his own name and, after a commissions dispute, disabled the site and redirected the traffic. He never offered to sell the domain. The court held that holding a domain for leverage in a business dispute can itself be the bad-faith intent to profit the Anticybersquatting Consumer Protection Act requires, and the award ran into six figures.
The copyright half that everybody forgets
The part that surprises nearly every owner: paying for a website does not automatically buy the copyright in it.
Under United States copyright law a work is made for hire in only two ways: prepared by an employee within the scope of employment, or specially ordered or commissioned and falling within one of nine enumerated categories and covered by a written agreement signed by both parties. The nine are a contribution to a collective work, part of an audiovisual work, a translation, a supplementary work, a compilation, an instructional text, a test, answer material for a test, and an atlas (US Copyright Office, Circular 30). A website is not on that list.
So an independent designer generally owns the copyright in the design and code they created for you unless there is a signed assignment, even though you paid in full. Saying both halves out loud is what makes the rest credible: the domain is almost certainly yours in substance, while copyright in a custom design that was never assigned may genuinely be the designer's. The fix for both is the same document, signed before anybody starts.
If it has already happened, do this, in this order
- Do not send an angry email. Anything you write becomes an exhibit.
- Preserve the evidence today. Capture the RDAP record, screenshot the site as it now appears, export the DNS records while you can still reach them, and collect every contract, invoice, email and text about the domain and about payment.
- Establish who the registrant actually is, and which registrar holds the name.
- Make one written demand separating the two issues: the money is one matter and we will deal with it; the domain is our property and we require it transferred by a stated date.
- Contact the registrar's account recovery team, A registrar will not adjudicate a contract dispute, but it will act on evidence that a record was altered without authority.
- Never pay a demand unless the transfer happens in the same transaction. Paying first funds the next demand.
- Then choose a forum. UDRP only if you hold real trademark rights and the domain is what you need back; court where money, files or urgency matter; a police report and an FBI Internet Crime Complaint Center report where credentials were taken.
- Rebuild what you control — a temporary domain, an updated website field on your business profile, a call to your customers.
Domain recovery is the specialty of our founder, Bill Hartzer, who has been working in search since 1996. The most common outcome, worth saying before anyone reaches for a lawyer, is that a polite and precise written request settles it, because the other side was disorganized rather than hostile.
What to put in writing before any work starts
Six clauses. Each is free, and any one prevents most of what is above.
- Client is and shall remain the Registered Name Holder of the domain, in the client's legal entity name, in an account owned by the client, with a client-controlled email address and payment method. The vendor receives delegated access, not ownership. This clause alone defeats everything above.
- A written assignment of copyright in all deliverables, effective on final payment, plus a licence to pre-existing components the vendor reuses. The phrase work made for hire alone is not enough, since a website is not one of the nine categories.
- An exit clause. On termination, within a stated number of business days the vendor delivers the files and database, the authorization code with locks removed, the DNS records, and any accounts created for the client.
- An accounts schedule — registrar, host, DNS, business profile, analytics, email, social, licences — naming who owns each and who merely has access.
- A no-lien clause. The vendor shall not disable, redirect, withhold or encumber the domain, the site or any client account as a remedy for non-payment. A vendor who refuses to sign this has told you something important.
- Registrar hygiene. Two-factor authentication, registrar lock on, several years registered ahead with auto-renew, and a role address at your domain as the account email.
When this is not a fight worth having
Not every one of these is a case, and pretending otherwise would be dishonest.
- You probably do not need a lawyer. Most of these resolve with one polite, precise written request. Ask first. Pay what you actually owe. Most people hand it over.
- A young business with a generic name may be better off replacing the domain. With no trademark rights worth asserting and little brand equity, buying a better name and updating your listings beats a filing plus counsel.
- You do not need to sue over a site you did not like. If the copyright was never assigned it may genuinely be the designer's.
- Defensive registrations prevent none of this. The protection is the registrant field and one contract clause.
- Do not move registrars in a panic. Transferring during a dispute can trigger a post-transfer denial window.
One more, for the churches and small nonprofits around Cedar Creek Lake, where the pattern is identical and the ending sadder: a domain on a volunteer's personal email and card lapses when that person moves away or dies, taking the site, the email addresses and often the profile verification with it. Register in the organization's legal name, keep the credentials with two officers, and register several years ahead.
Common questions
I paid for my website. Doesn't that mean I own it?
Not automatically, and this is the misunderstanding that causes most of the trouble. The domain belongs to whoever is listed as the Registered Name Holder, which is a field in a registration record and not a consequence of paying an invoice. The design and code belong to whoever holds the copyright, which stays with an independent designer unless there is a signed written assignment, because a website is not one of the nine categories of work made for hire. Both are fixable in advance with one paragraph each in the agreement.
My designer will not give me the AuthInfo code. What can I do?
First establish whether your designer is the registrant or merely has access to an account in your name. If the domain is registered to you and the registrar is stalling, the Transfer Policy requires the registrar to release the code and remove locks within five calendar days of your request and forbids withholding it to collect money, and ICANN accepts complaints about exactly that. If the domain is registered to your designer, ICANN's rules do not reach them at all, because they bind registrars rather than contractors. That distinction determines everything you do next, so check the record before you spend a week complaining to the wrong party.
Can I file a UDRP to get my domain back from a web developer?
Sometimes, and it has worked, but it is a trademark process rather than a contract process. You must prove trademark rights in the name, that the holder has no legitimate interest, and that the domain was registered and is being used in bad faith — all three. If your business name is descriptive or geographic and unregistered, the rights element is the hard part. The remedies are also limited to transfer or cancellation of the domain: no money, no files, no hosting account. Establish what you actually need back before choosing the forum.
What is the single most important thing to do before hiring a web designer?
Register the domain yourself, in the legal name of the business, in an account you personally control, with two-factor authentication on your own phone, and give the designer delegated access. That one step prevents nearly every scenario on this page, takes ten minutes, and costs nothing beyond the registration you were going to pay for anyway.
The person who set up our church website has moved away and we cannot reach them. What now?
Look up the domain's record first to find the registrar and the expiry date, because the deadline that matters is the renewal, not the argument. If the registration is still current you have time to work through the registrar's account recovery process with documentation showing the organization's connection to the name. If it is close to expiry, treat it as urgent: once a name lapses and is deleted it can be picked up by anyone within seconds of dropping, and what was a paperwork problem becomes a purchase.