In this guide
Your domain is the address people use to find your co-op and often the foundation of its email. Paying for the website does not automatically prove that the co-op controls the domain. A developer, founder or previous secretary may have registered it using an account that only they can access.
Separate three questions: who is recorded as the domain registrant, who controls the registrar account and who can change the technical settings. A co-op can have the correct name on an invoice while lacking the access needed to renew the registration or recover the account. Resolve all three questions before an urgent change is needed.
Know the parts you are checking
The registrar is the provider through which the domain is registered. DNS settings direct services such as the website and email. Hosting is where the site runs. These may come from one supplier or several, and changing one does not necessarily change the others.
For .uk domains, Nominet publishes registration terms and renewal information. Other endings have different registries and procedures. Ask your registrar to explain the records and recovery process for your actual domain rather than applying .uk instructions to every extension.
Start with the provider's known website and existing records. Unexpected renewal emails can be sales approaches or fraud attempts. Verify an unfamiliar request through a contact route you already trust before paying or disclosing access information.
Use this ownership checklist
- Registration: confirm the recorded registrant and that the arrangement reflects the co-op's legal position. If a founder holds it temporarily, document the intended transfer.
- Account: verify that authorised people can sign in through named access where the provider supports it.
- Contact details: check that notices reach a monitored address and the correct responsible people.
- Recovery: identify the recovery email, phone or evidence the provider would require.
- Renewal: record the expiry date, renewal setting, payment method and person who checks success.
- Technical control: identify who can edit DNS and where the current settings are documented.
- Exit: ask how to move to another registrar or supplier and whether any contractual conditions apply.
Keep payment card details and recovery secrets out of a general committee document. Record where authorised people can find them securely. A secretary needs to know a renewal is handled; that does not necessarily mean they need permission to alter every DNS record.
Remove single-person dependency safely
Consider an illustrative housing co-op whose domain renews on a former treasurer's card. The site still works, so the issue is easy to overlook. The immediate work is to confirm registrar access, update the authorised payment arrangement and ensure renewal notices reach the current officers. Rebuilding the website would not resolve that dependency.
A second example is recovery mail sent only to an address on the same domain. If domain or email access fails together, recovery can become difficult. Ask the provider which independent recovery options are supported, then protect and document the chosen option. The backup contact should be an accountable role or authorised person with a succession process.
Use strong authentication and tested recovery. Where the registrar offers only one login, restrict the credential in a managed vault and record who may use it. Prefer a provider with delegated or named access when a future move is practical.
Make changes with a record and a fallback
Before a supplier changes DNS, ask them to state which records will change, which services could be affected and how they will verify the result. Save the existing configuration in a secure location. A domain can serve email, verification, payment integrations and other services beyond the visible website.
Record completed changes, the authorising person and the support contact. Test the website and send email in both directions using accounts outside the co-op. Check again after the planned change window, because some problems only appear when different networks pick up the new settings.
Add the domain entry to your digital handover register and verify it at each change of responsible officer.