Website Rescue: Recover Your Domain, Hosting & Site From a Developer Who Won’t Let Go

Three of the things you need can be obtained without the developer’s cooperation at all — and the domain, which matters most, is often already yours without your knowing it. Work the order below, and send the access request framed as records-keeping rather than as a departure.

One piece of encouragement before the steps: almost nobody in Delhi NCR advertises for this work. Top-of-page bids on website transfer searches sit under ₹8. You’ll need to look for migration specialists deliberately, and you’ll get better attention than you would in the crowded new-build market.

Step 1: Find out what you actually hold

Ten minutes, and it changes the whole plan.

1. Run a WHOIS lookup. Search “whois” plus your domain. Read two things: the registrant email and the expiry date.

2. Search your own inbox for a registrar welcome email — GoDaddy, BigRock, Namecheap, Hostinger. If one exists, the account may already be yours and need only a password reset via your own address. This resolves more cases than people expect.

3. Try logging in to hosting. Not “you forgot the password” — check whether you were ever given one.

4. Try your site admin — usually your address followed by /wp-admin on WordPress.

5. Check the expiry date urgency. If the domain has already lapsed, this becomes time-critical: grace period at normal cost, then a costlier redemption window, then release to anyone. The renewal blackout piece.

Step 2: The recovery order

Priority matters, because the items are not equally valuable.

Priority What Why it ranks here
1 Domain Your business name, your email, every link pointing at you. Can’t be recreated
2 Hosting Where the site lives. Gives you items 3 and 4
3 A backup Files and database. With this plus the domain, any developer can restore you
4 Site admin Recoverable through hosting
5 Design source files Weakest claim, and usually livable without

Notice that items 2 to 4 collapse into one. Hosting access gives you the backup and the admin login. So there are really two objectives: the domain, and the hosting.

Step 3: What you can get without them

This is the part that unblocks most people.

The domain, if it’s in your name. Log in to the registrar and reset the password via your own email. Done.

The domain, if it’s in theirs. Registrars have ownership-claim processes. Contact the registrar directly, explain you’re the business owner, and ask what evidence they need — typically GST registration, invoices, payment records, and any trademark.

Hosting. Contact the hosting company directly as the account owner. Where the plan sits inside the developer’s reseller account, ask the host what recovery requires.

A backup. Once you have hosting, the control panel will generate one. Download it and keep your own copy off the server. Why the backup matters.

Admin access. Resettable through hosting.

So the genuinely hard case is narrow: both domain and hosting inside the vendor’s own accounts, with no cooperation. Even then a registrar claim backed by your payment records and business registration is a real route.

Step 4: The message that decides the outcome

Framing matters more than entitlement. Send this — one message, in writing, civil:

Hi [name]. For my records, could you please send: the domain registrar login or transfer code, the hosting login, the website admin login, and a full backup of the site as a zip? Also, please confirm whether anything — Google Business Profile, analytics, business email, payment gateway — is registered under your account for my business. Happy to settle any pending amount on receipt.

Four deliberate choices in there. It states no grievance. It lists items specifically, so “I sent you everything” isn’t available. It asks about registrations you may not know exist — often the most valuable line, since that’s where a hidden dependency usually sits. And the last sentence gives them a reason to reply.

Timing is decisive. The same request has very different odds sent on a quiet Tuesday versus during a payment argument, because the access is the leverage. If there’s a genuine unpaid balance, pay it — a few thousand rupees to end a hostage situation is the cheapest option available.

Step 5: What’s realistically yours

So you don’t spend three weeks fighting for something you don’t need.

Clearly yours: the domain if registered in your name, your content and photographs, your business’s data — enquiries, orders, customer records — and a copy of the live site you paid for.

Usually yours in practice: the hosting account if bought in your name, and admin access to the site itself.

Contested without a contract: design source files, custom code, and template licences the developer purchased. Most small projects have no written agreement, which is exactly why these become arguments. Read anything you do have in writing.

Not yours: their internal tools, and template or plugin licences bought under their own account across clients.

A new developer can almost always work from the live site without the design files. The full ownership breakdown.

Step 6: If nothing works

Two routes, in order of cost.

A legal notice listing the specific items with a deadline. Modest one-time cost, and it works more often than the price suggests — handing over a login is far cheaper for them than responding to a documented claim.

Rebuild on a clean base. New hosting, and either your domain or a close variant, reusing your own content. Unsatisfying, and sometimes the fastest route to actually having a website. If the existing build was thin you lose very little, and you get to set the ownership up properly.

Set a date by which you stop asking and start rebuilding. Open-ended pursuit costs more than the thing you’re pursuing.

Step 7: Migrating cleanly once you have access

Six friction points, and five are cheap to clear:

The 60-day transfer lock. Domains recently registered or transferred are typically locked for around sixty days. Standard, not obstruction — and you can still change hosting during it, since that’s separate.

DNS propagation. Keep the old hosting running for a week after switching. Turning it off immediately is how sites go dark mid-migration.

Page addresses changing. Ask any new developer, in writing, how they’ll handle redirects from old URLs to new ones. The most commonly skipped step and the costliest to fix later.

The order that avoids downtime: secure access → download a backup → note every current page address → get the site working on new hosting at a temporary address → then point the domain → keep old hosting live a week → check redirects and forms from your phone. The detailed migration guide.

Step 8: Make it impossible next time

Four things, about twenty minutes total:

  1. Domain in your own registrar account, your email, auto-renew on, current card, expiry date in your calendar with a 30-day reminder.
  2. Hosting in your own name, on your own card, with its own expiry date noted.
  3. Give developers access, not ownership. Registrars and hosts both support adding a user or sharing DNS without handing over the account. Most buyers don’t know this exists.
  4. Get the nine-item handover in writing at launch, and test each item rather than filing it. The checklist.

What to do this week

  1. Run a WHOIS lookup and read the registrant email and expiry date.
  2. Search your inbox for a registrar welcome email and try a password reset.
  3. Contact your hosting company directly as the account owner.
  4. Send the records-keeping message today — not during a dispute.
  5. Download a backup and keep your own copy off the server.

If you want it done the certain way

Send us your domain name and tell us what access you hold. We’ll tell you within a day what’s recoverable without the old developer, which renewal window you’re in if it’s lapsed, and what a clean migration or rebuild would cost. Domain, hosting and logins end up in your name either way. WhatsApp us; we reply in about five minutes between 9am and 7pm.

Related reading

FAQ

How do I recover my website from a developer who won’t give access?
Start with a WHOIS lookup and check your inbox for a registrar welcome email — the account may already be yours. Contact the hosting company directly as the account owner, and where the domain sits with them, use the registrar’s ownership-claim process with your invoices and business registration.

What can I get without the developer’s cooperation?
The domain if it’s registered in your name, hosting via the hosting company directly, and — once you have hosting — a full backup and the site admin login. Only design source files genuinely depend on their cooperation, and a new developer rarely needs them.

Should I tell my developer I’m leaving before asking for access?
No. Secure the domain, hosting and a backup first, framed as routine records-keeping. The same request gets answered when things are calm and ignored during a dispute, because the access is the leverage.

What do you think?

What to read next