A clinic website or email outage often exposes a deeper problem: nobody can clearly identify who owns the domain, controls DNS, administers email, or receives renewal notices. Recovery starts by separating those systems and proving control one layer at a time.

Understand the separate control points

  • The domain registrar controls registration and renewal.
  • The DNS provider controls records that direct the website, email, and verification services.
  • The website host publishes the site but may not own the domain.
  • Microsoft 365 or Google Workspace controls user accounts and email administration.
  • Billing access may be held by a different person or reseller than technical administration.

Start with evidence, not guesses

  • Collect invoices, renewal notices, historic emails, browser password records, and account recovery messages.
  • Use public registration and DNS information to identify providers, while recognizing privacy services may hide personal details.
  • Confirm which organization-owned email addresses and phone numbers can receive recovery challenges.
  • Open provider recovery cases using business documentation when self-service recovery is unavailable.

Rebuild ownership correctly

  • Place the registrar and critical cloud services under a clinic-controlled owner account.
  • Keep the owner password, MFA method, billing access, and recovery information private and under clinic control.
  • Give employees, ClinicsIT, web designers, and other providers separate named accounts through delegated access whenever the service supports it.
  • Assign only the permissions each person needs, and remove access when responsibilities change.
  • Document registrar, DNS, website, email, billing, renewal dates, owner identities, delegated administrators, and recovery methods.
  • Test both owner access and delegated administrator access before closing the recovery project.
Ownership rule: The clinic owner should not have to disclose the primary password to receive technical help. A properly designed service allows the owner to retain private control while inviting named administrators whose permissions can be limited, audited, and revoked.

Verified examples of delegated administration

Delegation terminology differs by vendor, but the security principle is the same: the clinic retains the primary owner or super-administrator identity, while each authorized person uses a separate account.

  • Squarespace: Website owners can invite contributors and select the permissions they need. Squarespace domains can use domain managers, and ownership can be transferred to an accepted contributor or domain manager when responsibility changes. A domain attached to a Squarespace website may share that site's contributor permissions, so the exact setup should be verified before changes are made.
  • Cloudflare: A Super Administrator can invite account members and assign account-, domain-, or resource-scoped roles. This is appropriate for DNS, Workers, Pages, redirects, SSL, and related controls without sharing the owner's Cloudflare password.
  • Microsoft 365 and Microsoft Entra: The organization can assign separate administrative roles such as Exchange Administrator, User Administrator, Helpdesk Administrator, Authentication Administrator, Global Reader, or Global Administrator. Microsoft recommends using the least-permissive role needed and maintaining protected emergency-access accounts.
  • Google Workspace: The organization can use prebuilt or custom administrator roles so staff or providers can manage only the services and settings assigned to them while the clinic retains its Super Administrator accounts.
  • Zoho Mail: The clinic can retain the Super Administrator role while assigning general or custom administrator roles to other users for selected administrative responsibilities.
  • Zoho WorkDrive: Super Admins and Team Admins can add members and assign Team Folder roles such as Admin, Organizer, Editor, Commenter, or Viewer, keeping organization-owned files under team control rather than one person's private storage.

ClinicsIT recommended ownership model

  1. Clinic-controlled owner: The primary owner account uses an organization-controlled address, clinic-controlled MFA, and clinic-controlled billing and recovery information.
  2. Clinic-controlled emergency owner: A second tested recovery or break-glass administrator is retained for loss of access.
  3. Named delegated administrators: ClinicsIT, office managers, web providers, or other authorized people receive individual accounts rather than the owner's credentials.
  4. Least privilege: Each delegated account receives only the roles required for its work.
  5. Documented offboarding: Delegated access can be revoked without changing the clinic owner's identity or password.
  6. Regular review: The clinic reviews administrators, MFA methods, billing contacts, and recovery information at least annually and after staffing or vendor changes.

Avoid repeating the problem

  • Do not allow a web designer, former employee, or single outside vendor to remain the sole owner.
  • Do not use a departing employee’s personal email or phone as the only recovery method.
  • Review domain and cloud ownership at least annually and whenever leadership or IT support changes.

Related ClinicsIT guidance

Practical note: Technology, licensing, and regulatory requirements vary by organization. Confirm the current configuration and applicable obligations before making changes.

Understand the dependency chain

The registrar controls the domain registration. DNS directs services such as the website and email. Hosting platforms serve the site or application. Microsoft 365, Google Workspace, Zoho, and other cloud systems use the domain but are separate administrative systems. Recovering one layer does not automatically recover the others.

A safe recovery order

First establish business ownership and authorized contacts. Recover the registrar and secure its recovery methods. Export or document current DNS before changing nameservers. Confirm website and email records. Recover cloud administration. Replace personal recovery methods with clinic-controlled methods. Finally, document and test the completed ownership model.

Protect against preventable outages

Enable auto-renewal with a current clinic payment method, registrar lock, MFA, and renewal notifications sent to more than one authorized person. Store transfer codes only when needed and never leave them in ordinary email.

DNS records to document

Record nameservers, A and CNAME records, MX records, SPF, DKIM, DMARC, verification records, and any application-specific entries. Capture the exact value and purpose of each record before changing providers.

Need help applying this to your clinic?

ClinicsIT can review the current environment and build a practical, documented next-step plan.

Request a consultation