Mendola.Tech
Providing Personal Service. Serious Technical Depth.

Fully managed websites for small businesses

Website, hosting, updates, SEO, local visibility, reputation management, and support—all handled by one accountable expert.

$299/month · $300 one-time setup · month-to-month

BASE: Zephyrhills, Florida, USAEMAIL: [email protected]
Technology Operations

How to Buy a Domain Name for a Small Business: An Ownership and Security Checklist

A registrar-neutral checklist for buying a business domain, documenting ownership, securing the account, and testing DNS and renewal recovery.

Reference guide — 2026-08-15. This is a registrar-neutral operating checklist, not legal, trademark, tax, security, or registrar-specific advice. Availability, prices, policies, privacy options, and transfer rules must be checked with the applicable registrar and registry before acting.

People often say they want to “purchase a website name.” The item being registered is a domain name: the address that can be connected to a website, email, and other services. Registration creates a time-limited contractual right to use the name under the registrar's agreement; it is not a permanent one-time purchase.

The safest small-business setup is simple to describe: the business is the registered name holder, the registrar account is business-controlled, at least two authorized people can recover it, and every renewal and DNS dependency is documented. The checklist below turns that principle into an acceptance test.

What matters most

  1. Ownership should be established before checkout. The business should decide which legal entity or authorized individual will be the registrant, which durable company email will receive notices, and who can approve account or DNS changes. A developer or agency can receive delegated access without becoming the sole owner.
  2. The advertised registration price is only one input. Compare renewal pricing, included privacy or proxy terms, multifactor authentication, recovery, DNS management, support, transfer instructions, expiration handling, and the complete registration agreement. ICANN says registrants are entitled to accessible information about those processes and terms.
  3. Availability is not clearance. A registrar search showing that a string is available does not determine whether using it conflicts with another party's rights, local naming rules, or a registry restriction. Escalate legal questions rather than treating checkout availability as approval.
  4. The acceptance test must include website and email dependencies. Changing nameservers or DNS records can affect the website, mail delivery, verification records, and third-party services. Record the baseline before a change and test each dependency afterward.
  5. Renewal and recovery are operational controls. Auto-renew can reduce accidental expiration risk only when the payment method, notices, account access, and recovery contacts remain current. A renewal checkbox without an owner and a review date is not a continuity plan.

How to use this checklist

This guide was prepared on 2026-08-15 from ICANN's registrant information, accredited-registrar information, registration overview, rights and responsibilities, locked-domain guidance, and transfer FAQs. The synthesis is deliberately registrar-neutral: it does not rank vendors, quote temporary prices, or assume that every top-level domain uses identical policies.

The contribution is a four-stage operating record—select, register, secure, verify—plus a two-person acceptance table. A business can save the completed record with its website runbook and repeat the verification at least annually and after any staff, agency, payment, registrar, DNS, or email change.

1. Select a name and define the owner

Write down the proposed name, intended use, preferred top-level domain, acceptable alternatives, and who is authorized to approve the choice. Check the spelling aloud, type it on mobile, and look for confusing hyphens, repeated letters, unintended word combinations, or a name that is hard to dictate by phone.

Before registration, record:

  • The intended registered name holder: business entity or authorized individual
  • A durable company-controlled registrant email and recovery phone
  • Primary and backup account custodians
  • The expected website, email, redirect, and subdomain uses
  • Any trademark, licensing, regulated-name, or local legal review required for the business
  • The date and person who approved the final name

Do not let a contractor register the domain only in the contractor's personal account as a convenience. If a provider administers the account, the business should still retain direct ownership, recovery, billing visibility, and a documented path to remove access.

2. Compare registrars as an operating service

For a generic top-level domain, confirm the registrar or the registrar behind a reseller through ICANN's current accredited-registrar information. Country-code domains can use different registry and registrar arrangements, so check the applicable operator's rules.

Use the same comparison columns for every candidate:

Decision field What to record
Registration and renewal Initial term, recurring renewal price, taxes or fees, grace or restoration information, and the date the quoted terms were checked
Account security Multifactor authentication options, recovery method, account-change notices, session or device controls, and delegated-user support
DNS control Nameserver editing, DNS record support, DNSSEC availability when relevant, export or documentation options, and change history
Registrant data Required contact data, privacy or proxy terms, disclosure process, and how the registrant updates information
Support and recovery Support channels, identity-verification process, escalation route, and what evidence is required when account access is lost
Transfer and exit Lock controls, authorization-code process, transfer instructions, restrictions, and any fees disclosed by the registrar
Bundled services Email, hosting, certificates, site builders, or security products that may create a dependency if canceled separately

Save or export the registration agreement and the specific terms accepted at checkout. ICANN describes the registration agreement as the contract between the registrant and registrar and says registrants should have information about registering, managing, transferring, renewing, and restoring the name.

3. Register in a business-controlled account

Create or use an account that the business can recover without a former employee, agency, or developer. Use a unique password stored in the approved password manager and enable the registrar's strongest practical multifactor authentication option. Give each person a named role when the platform supports delegated access; avoid a shared mailbox and password as the only control.

At checkout:

  1. Confirm the exact domain, top-level domain, registration term, renewal setting, and total.
  2. Confirm the registered name holder and required contact information are accurate.
  3. Review privacy or proxy terms without assuming they remove the duty to keep underlying data current.
  4. Use a business-controlled payment method and record its owner and expiration review date.
  5. Save the receipt, agreement, registrar name, account identifier, registration date, expiration date, and support route.
  6. Turn on account-change, transfer, DNS-change, and renewal notices when available.
  7. Keep the domain locked against unauthorized transfer when it is not actively being transferred.

ICANN notes that a locked domain may display a status such as registrar lock or client transfer prohibited. The lock is a protective control, not a substitute for securing the registrar account or recovery path.

4. Connect DNS without guessing

Before changing nameservers or records, capture the current state if the domain already exists. List every expected dependency: website, www, email, contact forms, verification records, analytics, advertising, customer portals, APIs, and any subdomain.

Use a change record with:

  • Exact old and new nameservers or DNS records
  • Record type, host, value, TTL, reason, approver, and change time
  • Expected website and email behavior
  • Test method and responsible person
  • Rollback value and decision deadline

Do not delete unfamiliar mail or verification records merely because they are not needed for the website. Test the apex domain, www, HTTPS, redirects, a real form submission with synthetic data, inbound and outbound mail, and important subdomains after the change. DNS caching means old and new answers can coexist temporarily; preserve the prior values until the agreed verification window passes.

5. Run a two-person acceptance test

The purchaser and a backup custodian should independently confirm the following without sharing a password:

Acceptance check Evidence to retain
Correct domain and registrant Registrar account view or receipt with sensitive values redacted in the operating record
Recovery works Date each custodian confirmed the recovery email, phone, security key, or approved backup method
Renewal is owned Expiration date, renewal setting, payment owner, notice recipients, and next annual review date
Transfer protection is understood Current lock status and the registrar's current unlock and authorization-code instructions
DNS authority is known Authoritative nameservers, DNS provider, account owner, and exported or transcribed baseline
Website works Apex and www status, canonical destination, HTTPS, redirect behavior, and monitoring owner
Email works Inbound and outbound tests for each business-critical sending path, without storing message contents unnecessarily
Vendor access is bounded Named role, business purpose, approver, review date, and removal trigger

Store this record with the website ownership inventory, not inside a public repository. Store passwords, recovery codes, and private keys only in the approved secret-management system.

What this checklist cannot prove

This checklist cannot determine whether a proposed name infringes a trademark or another legal right, whether a regulated business may use the name, or whether a particular registration agreement is appropriate. It does not cover every country-code registry, premium-name rule, aftermarket purchase, brokered transaction, dispute, court order, or abusive-registration process.

Registrar interfaces, prices, privacy services, security controls, grace periods, restoration terms, and transfer procedures can change. ICANN's transfer materials also describe circumstances that may prevent or delay a transfer, including some 60-day periods and lock states. Review the current registrar and registry terms before planning a time-sensitive move.

Passing the acceptance test does not guarantee uninterrupted DNS, email, hosting, certificate issuance, search visibility, or account recovery. It shows that the business has identified the controlling accounts, recorded the intended state, and tested the dependencies available at that time.

Put the checklist into practice

ICANN explains the registrar and registrant relationship and publishes registrant resources. Mendola.Tech adds a small-business operating artifact that connects the purchase decision to website continuity: a named owner, backup custodian, recovery check, renewal record, DNS change log, website/email tests, vendor-access boundary, and repeatable acceptance evidence.

The same table can be reused during a website launch or vendor handoff. Pair it with the website ownership handoff checklist so the domain, DNS, source code, hosting, analytics, forms, and recovery paths have one accountable inventory.

Official references

KEEP LEARNING
Technology Operations7 min read

Website Vendor Proposal Comparison Scorecard for Small Businesses

A line-by-line scorecard for comparing website proposals by ownership, scope, accessibility, performance, security, measurement, support, and exit terms.

  • Website prices are comparable only after proposals use the same inventory of pages, features, content responsibilities, integrations, and acceptance criteria.
  • Domain, DNS, content, data, analytics, and account ownership should be written into the agreement alongside export and transition procedures.
Read the research
Technology Operations8 min read

Small-Business Website Ownership Handoff: A Vendor-Exit Checklist

A verification-first checklist for transferring domains, code, hosting, content, analytics, business profiles, licenses, and operational knowledge.

  • A ZIP file is not a website handoff: control also depends on the domain, DNS, source history, deployment, data, third-party accounts, credentials, licenses, and operating knowledge.
  • The safest transfer gives the business owner primary control first, verifies a clean build and rollback path, and removes former access only after acceptance.
Read the research