Establish access and ownership first: the domain registration, the hosting account, and the site login. Take a full backup. Only then start changing anything.

How a site ends up in your lap

Somebody built it and is no longer around.

A partner left, a staff member moved on, an agency relationship ended badly, or a business changed hands and the website came with it.

Occasionally the person who built it is a relative who did it as a favour in 2016 and has since stopped answering messages about it.

However it happened, the position is the same. There is a working website, it represents the business, and nobody currently knows how it fits together.

The first rule is to change nothing

The instinct is to start fixing the obvious problems, and the obvious problems are usually genuine.

Resist it for a few days.

A site you do not understand can break in ways you cannot reverse, and the moment you make the first change you lose the ability to tell whether a fault was yours or was already there.

Establish what you have first. The fixing is the easy part and it will still be there next week.

Ownership, which is not the same as access

Three separate things have to be tracked down, and people routinely assume one covers the others.

The domain registration, which is where the address itself lives.

The hosting account, which is the server the files sit on.

And the site login, which lets you edit pages.

Having the third does not give you the first two, and the first two are the ones that matter if a relationship turns sour.

Finding the domain

A public lookup will tell you the registrar and the expiry date, though the contact details are often masked.

The expiry date is the urgent part. A domain that lapses is a business that disappears from the internet on a specific afternoon, and recovering one after it drops is expensive and sometimes impossible.

If you cannot get into the registrar account, that becomes the single most important job on the list.

Everything else on a website can be rebuilt. The address cannot.

The access inventory

Write down every account the site depends on, and mark each one as held, recoverable, or lost.

Anything marked lost needs a recovery route identified now rather than during an emergency.

What is actually running it

You need to know whether it is a content system, a builder platform, or hand-written files, because the answer changes everything about what maintenance looks like.

A content system means updates, plugins, and a security responsibility that arrives every month whether you engage with it or not.

A builder platform means a subscription that somebody is paying and that will stop the site when it lapses.

Hand-written files mean no updates to worry about and no easy way for a non-technical person to change anything.

Back it up before you touch it

A full copy of the files and, if there is one, the database.

Not a backup held by the same host that holds the site, since a host account problem takes both at once.

A copy you personally hold, on your own machine or your own storage.

This single step converts most website disasters from a crisis into an inconvenience, and it is the one people skip because nothing has gone wrong yet.

What is connected to the site

Sites are rarely self-contained, and the connections are what break silently.

Contact forms send to an address that may belong to somebody who left.

Analytics reports to an account you may not be able to see.

Booking tools, payment processing, and mailing list signups all run through third parties with their own logins and their own billing.

Each one is a place where the site can appear to work perfectly while doing nothing useful.

A worked example

A small manufacturing firm bought out a competitor and inherited the competitor's website along with the customer list.

The site looked fine and they left it alone for four months while they dealt with more pressing matters.

The audit, when they finally did it, found three things.

The domain was registered to the former owner personally and expired in eleven weeks.

The contact form was delivering to an email address that had been shut off in the transition, so roughly a hundred enquiries had gone nowhere.

And the hosting was on a plan being paid by a credit card that had already been cancelled, with the account in a grace period nobody had noticed.

None of that was visible from looking at the website.

What the previous person was in the middle of

Half-finished work is normal and is worth identifying before you build on top of it.

Draft pages that were never published, a redesign that got to sixty percent, a plugin installed for a feature that was abandoned.

Some of it is useful and some of it is dead weight, but you want to know which is which before you spend a month extending something the last person had already decided to replace.

The counter-case

Sometimes the audit tells you the site is not worth keeping, and that is a legitimate outcome.

A site on an abandoned platform, with no access to the account, built on a system nobody supports, is not a foundation. It is a hostage situation.

In that case the audit still matters, but its purpose changes: you are no longer cataloguing what to maintain, you are cataloguing what to salvage before you rebuild.

The content, the images, the page addresses that have accumulated links, and the enquiry history are all worth extracting even when the site itself is not.

What not to change first

Not the design, which is visible and tempting and the least consequential thing on the list.

Not the page addresses, which are what search engines and other people's links point at.

Start with the things that fail quietly: forms, expiry dates, billing, and backups.

The audit, in order

  1. Find the domain and note the expiry date.
  2. List every account and mark it held or lost.
  3. Take a full backup you personally hold.
  4. Test the contact form and see where it lands.
  5. Identify what is running the site.
  6. Find who is paying for hosting and any subscriptions.
  7. Then start improving things.

The first six are an afternoon and they are the difference between owning a website and merely having one.

An older site that resists all of this is a different problem, covered in an old site you cannot update any more.


Frequently asked questions

What should I check first on an inherited website?

The domain registration and its expiry date. Everything else on a site can be rebuilt; the address cannot be recovered easily once it lapses.

Is having the site login enough?

No. The admin login lets you edit pages. It does not give you the domain or the hosting account, which are the two things that matter if access is ever disputed.

Why not fix the obvious problems immediately?

Because once you make a change you can no longer tell whether a fault was yours or was already there. Establish the position first, then fix.

What breaks most often on an inherited site?

The contact form, because it delivers to an address belonging to whoever left. The site looks fine and the enquiries go nowhere.

Do I need my own backup if the host has one?

Yes. A backup held by the same host fails at the same time the host account does. Keep a copy you personally control.

When is an inherited site not worth keeping?

When you cannot get access to the platform account and nobody supports the system it runs on. Then the audit becomes a salvage list instead of a maintenance plan.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Just taken over a website?

Find the domain, list the accounts, take a backup, test the form. One afternoon, before anything else.

Start a Conversation