How Agencies Should Manage Client Domains

5 min readExamfy Software

Domains are the least interesting thing an agency manages and the most damaging when they go wrong. Nobody is thanked for a renewal. But a client domain that lapses on your watch is a phone call that starts with a dead website and ends with a question about whether you're still the right agency — regardless of whose card was on file.

The difficulty is structural. Client domains are scattered across registrars you didn't choose, registered under accounts you may not control, on renewal dates nobody scheduled, with contact addresses pointing at people who left. Here's a system that holds up.

1. Settle ownership before anything else

For each client domain, write down the answer to three questions:

  • Who is the registrant? The legal owner. This should be the client, essentially always.
  • Who controls the account? Whoever can log in and move the domain.
  • Whose card renews it? Frequently a different party from both of the above.

The trouble comes when these diverge silently. A domain registered under the agency's account with the agency's card, for a client who believes they own it, is a dispute waiting for a relationship to end. It's also a single point of failure: one lapsed agency card takes down multiple clients at once.

Default recommendation: the client is the registrant and owns the registrar account; the agency has delegated access. Less convenient day to day, far cleaner at handover, and it means the domain survives you.

2. Take an inventory you didn't inherit

Most agencies think they know their client domains and are describing the ones with websites on them. The rest — redirects, campaign domains, misspellings bought defensively, the old brand name from a rebrand — are exactly the ones that lapse, because nothing breaks visibly when they do until someone notices the redirect died.

Build the list from evidence rather than memory:

  • Every domain pointing at infrastructure you run
  • Every domain in every registrar account you have access to
  • Anything found in the client's DNS that you didn't set up
  • Subdomains with their own certificates — our subdomain finder reads Certificate Transparency logs and will surface hosts nobody remembers deploying

3. Group by client, not by registrar

The unit that matters to an agency is the client, but registrars organise by account. If Client A has domains at two registrars and Client B at a third, no registrar dashboard shows you a client's exposure.

Whatever you use to track this needs to group by client, so you can answer "what does Client A own, and when does any of it expire?" in one place. In DomainChest that's what lists are for — tag each domain with the client, filter or group the dashboard by it, and generate a per-client report you can actually send.

That last part matters more than it sounds. "Here is everything you own, when it renews, and what it costs" is a genuinely useful artifact for a client, and almost no agency produces one.

4. Watch expiry independently of the registrars

Registrar reminders are the standard fallback and they fail in predictable ways for agencies specifically:

  • They go to the registrant email, which may be a client address nobody monitors, or a former employee's mailbox.
  • They arrive per-registrar, so nothing gives you one view.
  • They stop being useful when the card fails — and auto-renew is only an instruction to charge, so an expired card means the domain lapses while every setting still reads "on" (why auto-renew fails).

An independent tracker reading each domain's registry expiry date directly fixes all three: one list across every registrar, alerts to your address, and no dependency on the client's inbox. Why registrar renewal reminders aren't enough goes into the detail.

5. Track certificates too — including the ones you didn't issue

Certificate expiry breaks a client site just as visibly as a lapsed domain, and it happens more often because certificates renew far more frequently. Automated renewal handles most of it until the day it doesn't — a changed DNS record, a failed validation, a CDN reconfiguration.

Two things worth watching beyond your main hostnames:

6. Make offboarding a checklist

The moment a client leaves is when domain problems become expensive, because responsibility gets ambiguous exactly when attention is lowest. Have a fixed list:

  1. Transfer registrar account ownership, or confirm the client already holds it.
  2. Remove agency users from the account.
  3. Move billing to the client's payment method.
  4. Update registrant, admin and technical contacts away from agency addresses.
  5. Hand over the domain inventory — everything they own, with dates.
  6. Remove them from your monitoring so you stop being alerted for domains you no longer manage.
  7. Note the 60-day transfer lock that some registrars apply after contact changes, which can block a transfer you're trying to complete this week.

Step 4 is the one most often missed, and it's the one that has you receiving expiry warnings for a client you parted with two years ago — or worse, not receiving them while the client assumes you still are.

The short version

Client domains fail for boring reasons: nobody owns the list, reminders go to the wrong inbox, and a card expired. The fix is equally boring — one inventory grouped by client, expiry tracked independently of any registrar, and a handover checklist.

You can check any single domain free, no signup, with our domain and SSL expiry checker, or see how the agency setup works if you want the whole portfolio in one place.

Track every domain and SSL certificate you own

Store your domains in a chest, so you never forget one again.

Start free — 3 domains