Recover control of a website in a safe order without creating new lockouts, destroying evidence or trusting unverified requests.
FAULT / IMPACT / OWNER / STATUS
Stabilise the situation before attempting recovery
Job detail
Write down what is inaccessible: domain registrar, DNS, hosting, website administration, business email, analytics or a third-party service. Record the last known account name, supplier, renewal invoice and error message. Ask whether the site is merely inaccessible to staff or is also altered, offline or redirecting unexpectedly. If compromise is suspected, preserve messages and screenshots, use a clean device, and avoid repeated password guesses that may trigger a lockout. Do not send passwords or identity documents to an address supplied by an unverified caller.
Recover the controlling email first where possible
Job detail
Most resets depend on an email account, so establish who controls the recovery mailbox and its domain. Use the provider’s official sign-in page reached independently, not a link in an unexpected message. Try documented recovery options and check password managers or secure business records. If the mailbox belongs to a departed worker or former agency, do not impersonate them. Contact the provider through its published support route and be ready to prove authority using business records, invoices and account details appropriate to its process.
Work outward from domain to application
Job detail
The domain registrar and DNS can determine where the website and email point; hosting contains the files and database; the content management system controls page editing. They may be supplied by three different firms. Recover each through its own official procedure, beginning with the layer needed to restore the next. Changing nameservers, transferring a domain or creating a new administrator can have wide effects, so capture existing DNS records and take a backup before an authorised technician acts. Never delete an old administrator until the replacement access is tested.
Verify authority on both sides of the request
Job detail
A legitimate provider should have a documented way to handle lost access, though it may not accept every document offered. Confirm its web address and support channel independently. On the business side, nominate one authorised contact and supply the minimum evidence requested through the provider’s secure route. Company registration does not automatically prove ownership of a privately registered domain, while an old invoice alone may be insufficient. Keep a dated log of case numbers, documents shared, decisions and promised response times.
Rebuild access so the problem does not return
Job detail
Once inside, change compromised credentials, review recovery addresses, revoke unknown sessions and enable multi-factor authentication. Create named administrator accounts rather than a shared ‘admin’ login, give each person only the access needed and store recovery codes securely. Move key services into business-controlled ownership where contracts permit. Record suppliers, account identifiers, renewal dates and an emergency contact route. Finally, test access from a second authorised person and confirm that website, email and forms still work after any DNS or hosting change.
Practical steps
Lost-login recovery runbook
Follow in order, recording evidence and stopping before any change whose effect is not understood.
1 — Define the lossList inaccessible services, exact messages, affected people and whether the public website or email has changed.
2 — Open an incident logRecord time, screenshots, recent changes, case numbers and every person or provider contacted.
3 — Find account evidenceCollect contracts, invoices, renewal notices, account IDs, known usernames and supplier contacts without circulating passwords.
4 — Verify the providerReach the official website independently and use its published account-recovery or support route.
5 — Restore recovery emailRecover the controlling business mailbox through its provider before requesting downstream resets where practical.
6 — Secure domain and DNSRecover registrar access, export current DNS records and avoid transfer or nameserver changes unless specifically required.
7 — Recover hostingConfirm the hosting account and backup position; do not overwrite the live site merely to create access.
8 — Restore website administrationUse the platform’s official reset or have an authorised technician create a named account; test it before removing old access.
9 — Harden and verifyChange exposed credentials, enable MFA, review users and sessions, then test website, email, forms and backups.
10 — Document ownershipStore business-controlled account details, recovery codes, suppliers, renewals and two authorised contacts in a secure register.