Domain dependency map

A working domain depends on several accounts at several companies, usually opened by different people over several years. Some of those people have moved on. This map names the accounts from public records and gives you a sheet to note who can still sign in to each.

Or try github.com, wikipedia.org

Accounts stacked on accounts

Think of a domain as a building with a main breaker and several circuits below it.

The registrar account is the breaker. Whoever signs in there can renew the name, let it lapse, transfer it away, or point it at different name servers. The DNS account comes next, and it decides which server receives web visitors and which one receives mail. Below DNS, the circuits run side by side: the web host, a CDN in front of it, the mailbox provider, and each newsletter, invoicing or help desk service that sends messages in your name.

The order matters on the day something goes wrong. A lost password for the newsletter tool is a nuisance. A registrar account tied to the personal email of someone who left three years ago can cost you the domain, because the renewal notice and the password reset both go to that address.

Where each line of the map comes from

We don’t need access to any of your accounts for this. Every line is worked out from what the domain already publishes.

RoleRead fromTypical clue
RegistrarThe registry’s RDAP recordRegistrar name, expiry date, transfer lock
DNSNS recordsns-123.awsdns-45.com is Amazon Route 53
Website hosting, CDNA record, the network that owns the IP address, its reverse name, the www CNAMEshops.myshopify.com, or an address inside Cloudflare’s network
EmailMX recordsaspmx.l.google.com is Google Workspace
Sending as the domaininclude: entries of the SPF record, followed one level downinclude:servers.mcsv.net is Mailchimp
DMARC reportsThe rua= address in _dmarcA mailbox at a reporting service
Accounts tied to the domainVerification TXT recordsgoogle-site-verification=…, MS=ms…

Roles held by the same company are merged into one account. DNS and CDN at Cloudflare, for example, are normally one login. An SPF entry the tool can’t put a name to is listed as unidentified. Ask your team about those, because each one is a service allowed to send mail as you.

Two things get flagged: an expiry date less than 60 days away (red under 30), and a domain without a transfer lock.

Filling in the access sheet

Under the map there’s a table with one row per account and four columns. Type into it or print it blank. What you type stays in the page in your browser and never gets sent to us.

Who has access
The names of the people who can sign in today. Try it for real, because a login nobody has used in two years may not work anymore.
Account in the name of
The email address the account is registered under. That’s where invoices and reset links go.
Two-step?
Whether signing in needs a second factor, and whose phone or key that is.
Password shared?
Whether more than one person can get to it, ideally from a shared vault. Never write the password itself on the sheet.

Three extra rows are there for what DNS never shows: the admin login of the website itself, and two free lines for things like analytics, the app store account or social profiles.

Repairing a fragile row

  • Account under a personal address. Change the account email to a role address on your domain, such as it@ or accounts@, delivered to at least two people.
  • One administrator only. Registrars and DNS hosts such as Cloudflare, GoDaddy and Namecheap let you invite a second user with a login of their own. Do that instead of passing one password around.
  • Registrar held by a former supplier. Ask for a transfer to an account you control. You’ll need the domain unlocked and its authorization code (also called EPP code). Start well before the expiry date, since a transfer can take up to five days.
  • A service nobody recognizes. If it really isn’t used anymore, remove its SPF include: or its verification TXT record. Check first with the SPF, DKIM and DMARC checkup that mail still passes.

The map is a first inventory, and it won’t be complete. A reseller can sit in front of the real registrar, a CDN hides the host behind it, and a spam filter hides the mailbox provider. Payment providers, analytics and most software subscriptions leave no trace in DNS at all.

Questions people ask

How do I find out who my domain registrar is?

Enter the domain above. The registrar comes from the registry’s public RDAP record, and the company named there is the one to contact, even if you paid a web agency or a reseller for the name.

How can I tell where a website is hosted?

The map looks up which network owns the site’s IP address and reads the www CNAME. If the site sits behind a CDN such as Cloudflare, the real host is hidden and you’ll only see the CDN. The hosting lookup gives more detail.

The person who registered our domain has left. What should we do?

Start with the registrar’s password reset on the account email, if your organization still controls that mailbox. If it doesn’t, contact the registrar’s support with proof that the organization is the registrant: invoices, company registration, the registrant name in the record. Do it before the expiry date, not after.

Why does the map show a service we stopped using?

Because its DNS record is still there. Hardly anyone cleans up verification TXT records and SPF includes when a subscription ends. Remove them once you’re sure the service is gone.

Is what I type in the access sheet stored anywhere?

No. The fields only exist in the page you have open. Closing or reloading the tab erases them, so print the sheet or save it as a PDF before you leave.