Choosing a supplier
Getting your website logins back
Getting your website logins back — the four accounts that matter, how to check who controls each, and what a host needs before handing back control.
Four accounts actually matter, and they are not equally hard to recover. Rank them by how hard each one is to replace if you cannot get it back. The domain comes first, because it cannot be rebuilt. Hosting is next, then the CMS admin login, then source files, which can sometimes be recreated at a cost if genuinely lost.
The four accounts, ranked by how urgent each one is
| Account | Why it ranks where it does | How to check who controls it |
|---|---|---|
| 1. Domain registrant | Cannot be rebuilt if permanently lost — it is a licence held by whoever the registrant is | auDA .au WHOIS lookup, or the registrar’s public lookup for a non-.au domain |
| 2. Hosting account | The site’s actual files and any database live here; losing it risks losing the built site entirely | Try logging in directly at the host’s website with your own email, not a link supplied by the developer |
| 3. Website admin (CMS) login | Needed to edit content and settings day to day, but the underlying site can survive without it if hosting is secure | Try the CMS login URL directly (commonly a /admin or /wp-admin path) |
| 4. Source files / design files / code repository | Useful for future changes but recoverable at a cost if lost, unlike the domain | Ask for a repository link, or a full file and database export |
Start with the registrant record, every time
Look your domain up through auDA’s public .au WHOIS service, or the equivalent lookup for a non-.au domain. The registrant field is the one that decides who holds the licence — not the technical contact, not the administrative contact, not the name on an old invoice. If your business is recorded as the registrant, you are in a workable position regardless of what else has gone wrong. If it is your supplier or their agency, that is the single most urgent thing on this page to fix, because everything else — hosting, the CMS, the site itself — depends on control of the domain to actually matter.
What a registrar typically needs to reassign a domain
Requirements vary by registrar. They commonly include an invoice or signed agreement showing your business commissioned the domain, evidence of your business’s registration (ACN or business registration matching the domain’s intended registrant), and a formal request through the registrar’s own registrant-transfer or dispute process. Contact the registrar directly rather than the supplier — most registrars have a documented path for exactly this situation because it is common enough to warrant one.
Recovering hosting access
If you cannot log in to the hosting account directly, contact the host’s support with proof that your business is the one paying for or otherwise entitled to the service. That proof can be an invoice, a bank statement showing the subscription, or a contract naming your business. Hosts vary in how quickly and how far they will go here; a clear, documented ownership case with your business name attached is the strongest position to start from.
Recovering the CMS admin login: password resets and locked-out accounts
This is usually the easiest of the four to work around. Most content management systems allow a password reset via the registrant email address, and a competent developer can often set up a fresh admin account once the hosting account itself is secured, without needing the old login at all. Try the CMS login page directly (commonly a /admin or /wp-admin path) before assuming a reset is required. Do not let a lost CMS password become the reason you delay securing the domain and hosting first — it is the least urgent of the four.
Regain access after a lockout: passwords, credentials and the FAQ registrars actually ask
A genuine lockout is a different problem from a registrant dispute. It usually comes down to one of a small number of common problems: an old recovery email address nobody can access any more, a password reset link that only ever goes to the developer’s inbox, or login credentials that were never handed over at all. A registrar’s own FAQ page is usually the fastest way to confirm exactly what evidence it wants before you call, because the answer differs enough between registrars that guessing wastes a cycle. Regaining access this way is faster than any dispute process, provided the account was never actually reassigned to someone else.
If source files or login credentials cannot be recovered at all
A site built on a common platform — WordPress, Shopify, Squarespace and similar — can usually be rebuilt from what is visible on the live site plus your own content. That is possible at a cost, even without the original design files. A custom-coded site with no accessible repository is a harder loss, because bespoke functionality may not be reproducible without the original code. This is precisely why it is worth insisting, in writing, that you receive the code repository or a full export at project milestones — not only at the very end — for any custom build. This is covered in who owns your website.
What this situation is worth pursuing further for
If the amount involved and the difficulty of recovery both justify it, can you sue a web designer sets out what a realistic path to a remedy looks like. In most cases, though, securing the domain and moving forward with a new supplier is faster and cheaper than pursuing the old one. The order of operations for that decision is in what to do if your web developer disappears.
What to do next
Check the domain’s registrant record today, using auDA’s public lookup or the relevant registrar tool. That single fact — whose name is actually on the licence — determines how the rest of this situation unfolds.
The individual pieces of work involved in getting a site back to a working state — rather than a full rebuild — are covered on the separate pieces of a website project.
Evidence for this page
This page exists because the demand below was measured, not assumed. The figures are search-market data about the topic — they are not prices.
- Entity this page targets
- getting your website logins back
- Measured Google volume
- no data
- Keyword difficulty
- no data
- Advertiser cost per click
- no data
- AI assistant volume
- no data
- Advertiser competition
- no data
- Measured on
- 31 July 2026
- Search results inspected for intent
- No
2 other phrasings resolve to this same page
how do i get my website logins back · recover website admin access
"how do i get my website logins back" is recorded in TOPICAL-MAP.md §2.2 (attribute A30) as measured null. No AI-assistant volume recorded either.
Source: research/national-volume-au.json · DataForSEO Labs, location_code 2036 (Australia), language en — measured null. · pulled 31 July 2026.
Provenance
Written by Australian Website Design. Published 2026-08-03, last updated 2026-08-03.
Sources
- auDA .au WHOIS lookup (accessed 2026-08-03)
- Copyright Act 1968 (Cth) (accessed 2026-08-03)