Spurlock Studios
Contact
Share LinkedIn X
A locked drawer. Thesis: WEB DESIGNER DISAPPEARED GET WEBSITE.

You get the website back by taking six doors in this order: domain registrar, DNS, host, CMS, repo, billing. Platforms move a project when a living owner starts a transfer you can accept; they do not award you a vanished freelancer’s Workspace because you paid an invoice. This is recovery operations, not legal advice — a clause without logins is still a paper win. Archive the live site today, then work the doors you can still prove. This spoke sits under Websites That Feel Like Films.

The short answer

  • Registrar, DNS, host, CMS, repo, billing — in that order. The hostname is useless if DNS still points at a card that will die. A repo without the name is a rebuild with the wrong URL.
  • Archive first. Screenshot, crawl, and Save Page Now while the site still loads. A dead host plus a vanished designer is a screenshot problem.
  • Transfer buttons need an owner who clicks. Webflow, Framer, Netlify, Vercel, Squarespace, and Wix document owner-started transfers. Ghosting removes the person who can start them.
  • Billing is a bridge, not a trophy. If you can keep their card from failing, do it while you copy content. Then move payment onto an account you control.
  • I will not invent a recovery clock. Lock windows, redemption flags, and unreachable Workspace owners have no honest SLA I can quote. Measure by doors you now control.
DoorYou are recoveringYou are not done until
Domain registrarRegistrant + login or a documented dispute pathYou can open the registrar without them
DNSZone you can editApex, www, MX, and verification TXT are yours
HostTeam / Workspace / projectTheir card is not the thing keeping production up
CMSOwner or admin seat you controlYou can publish and invite a second person
RepoOrg-owned source, or a clone you can rebuild fromA future studio can deploy without archaeology
BillingPayment method on your teamRenewals hit a company card and a company inbox

Waiting is not a recovery strategy. A live site you cannot log into is a countdown.

What does “my designer disappeared” actually mean?

Disappeared is not one event. It is a stack of unanswered doors, and any one of them can keep the rest of the house.

What you still haveWhat it feels likeWhat it actually is
Live URL, no logins“The site is still up”A countdown on their card and their renewal email
Editor seat only“I can change the headline”You cannot transfer, export, or add a new studio
Invoices and a ZIP“I paid for the site”A souvenir. Production still lives in their account
Domain on your registrar, site on theirs“We own the name”They still hold DNS, host, and CMS
Their personal GitHub, you as collaborator“We have the code”They remain the owner. Collaborator is not transfer
Nothing but Instagram“We’ll rebuild from memory”You already lost the archive window

I have shipped hundreds of production sites. The dirty exits rhyme: hosting on a personal card, domain on a personal Gmail, sole admin on the Workspace, repo on a personal GitHub, forms to an inbox nobody monitors.

Pick the row you are in before you open a ticket. Support asks for proof of the door you claim, not for a feeling that you paid.

Decision list:

  1. If the public site still loads, archive it before you poke DNS.
  2. If email still works, do not “fix DNS” until you have exported MX.
  3. If you have any login, use it to export — then change passwords you actually own.
  4. If you have only invoices, gather them. Do not expect a vendor to treat a PDF as a transfer button.

First hour, before you “take the site back”:

  1. Save the homepage, contact, shop/tour, and legal pages at web.archive.org/save.
  2. Screenshot those same URLs on a phone. Timestamp them.
  3. Send one written ping to every address you have for them: email, invoice CC, the project Slack. Ask for registrar login, DNS, host, CMS, repo, and billing — the six doors, named.
  4. Do not change DNS, cancel a card, or dispute a charge in that hour.
  5. Write down the last date they replied. Support will ask. Your memory will lie by Friday.

If they answer, you are no longer in recovery. You are in a handoff. Get the transfers completed, not promised. If they do not answer, you already started the paper trail vendors want.

What is the recovery order for the six doors?

Work the doors in this sequence even if you are angry about the design. Hostname, mail, and a host you pay beat a prettier 404.

  1. Domain registrar. Find who is listed as registrar. You cannot move hosting with a name you cannot renew.
  2. DNS. Copy the zone before anyone “points it at the new host.” MX and verification TXT die in that minute.
  3. Host. Identify Netlify, Vercel, Webflow, Squarespace, Wix, or a VPS from the DNS targets. Keep it alive if you can.
  4. CMS. Owner seat, export, or admit you only have screenshots.
  5. Repo. Clone what you can. Do not wait for GitHub Support to gift you a private repo.
  6. Billing. Put a card you control under the team you now own. Kill their leftover access last, not first.
  • Registrar identified via ICANN Lookup (RDAP)
  • Status flags copied (clientTransferProhibited, redemptionPeriod, pendingDelete, clientHold)
  • DNS records exported (A/AAAA/CNAME/MX/TXT, nameservers)
  • Host product named (not “the website”)
  • CMS: owner vs editor written down
  • Repo: URL, org vs personal, whether you can clone
  • Billing: whose card, which inbox gets the dunning mail
  • Archive of homepage, key inner pages, and legal/contact
  • Form destination tested with a real submit you can see

Skip a door and you will “recover” a pretty page that still dies on their Amex.

How do I recover the domain at the registrar?

Find the registrar of record. Then ask that registrar — not the designer’s Instagram — what restore or transfer path exists.

Look the name up at ICANN Lookup. RDAP replaced the old port-43 WHOIS habit for this job. Note registrar, creation date, and status flags. Read the live ICANN Transfer Policy for gTLDs. I will not quote a recovery ETA off a lock you have not confirmed, and I will not pretend ccTLDs (.uk, .ca, .io as a special case) follow the same script.

RDAP / EPP flag you might seeWhat it usually meansWhat you do
clientTransferProhibitedRegistrar lock is onAsk the registrar how the registrant unlocks it
serverTransferProhibitedRegistry-side lockRegistrar of record; not a tweet to the designer
redemptionPeriodName is in redemption after delete/expiryRestore with the registrar of record if they will talk to you
pendingDeleteDrop windowDo not assume you can still restore. Ask today
clientHold / serverHoldResolution may already be deadBilling, verification, or a dispute — not a redesign

Procedure:

  1. Search the name in ICANN Lookup. Screenshot the result.
  2. Identify the registrar, not the reseller brand on a three-year-old invoice.
  3. Find every email that might be the registrant contact — company inbox, old Gmail they used “for convenience,” a catch-all.
  4. If you are the registrant and only lost the password, use the registrar’s account recovery. That is the cheap path.
  5. If they are the registrant, you are in a transfer or dispute. Outcomes vary. Have counsel if the name is the business. This post is not that counsel.
  6. Do not start a transfer you cannot finish while a lock flag is showing. A failed attempt can add delay. I will not invent the delay.

Cloudflare’s registrar FAQ still documents a lock after registration, registrar change, or WHOIS contact change (Cloudflare Registrar FAQ). Confirm the current rule on the account that holds the name. Policy text moves. RDAP flags do not care about your launch date.

If the name is already yours at the registrar, skip the drama and go to DNS. The hostage is often the zone, not the registration.

How do I recover DNS without killing email?

Copy the zone before you change nameservers. Registrar ownership and DNS hosting are not the same login. Plenty of brands “own the domain” at Namecheap and still point nameservers at a vanished agency’s Cloudflare.

If they control DNS, they can park the apex, break MX, and yank the Search Console TXT in one save.

RecordJobIf you edit it blind
A / AAAAApex siteSite 404s or hits the wrong host
CNAMEwww, app, cdnwww diverges from apex
MXInboxEmail dies the same afternoon as the “fix”
TXT (SPF/DKIM/DMARC)Mail authOutbound starts landing in spam
TXT (google-site-verification=…)Search Console / WorkspaceYou cannot prove the domain to Google
CAAWhich CAs may issue certsSSL issuance surprises on the new host

Checklist:

  • You know where DNS is hosted (registrar, Cloudflare, the host, leftover agency)
  • Nameservers are written down
  • A/AAAA/CNAME/MX/TXT exported — screenshot plus a zone file if the UI offers one
  • DNSSEC state is known. Some moves require DNSSEC off first
  • You can log into that DNS host, or you have admitted you cannot
  • Mail is tested after any change (send and receive, not “the site loaded”)

Netlify-registered names have their own transfer path, and Netlify will not accept inbound registrar transfers from other registrars — you delegate DNS instead (transfer a domain). Know which product you bought: registration, DNS, or hosting. They are three invoices people collapse into “the website.”

If you still have the zone and lose the host, you can point at a new host. If you lose the zone and keep the host, you can still 404 the brand by accident. DNS is the door teams skip because it looks like plumbing. It is the one that takes email with it.

How do I recover hosting when their card is on the account?

Name the host. Then keep it alive while you copy, or cut over only after you have a copy.

DNS targets tell you the product: *.netlify.app, *.vercel.app, *.webflow.io, Squarespace, Wix, a Lightsail box, a random VPS. dig on the apex and www is enough to start.

HostTransfer mechanic (when someone can click)If they already vanished
NetlifyTransfer project into a team you own (docs)Support talks to the team owner. Billing failure takes the site down
VercelTransfer project; docs describe a zero-downtime cutover (docs)Same pattern: owner of the source team has to start it
WebflowFreelancer/Agency transfer into your Workspace; you must accept (docs)If you cannot verify Workspace ownership, Webflow’s own ownership article is blunt — see the CMS section
FramerFile → Transfer Project; you accept and pay the Site plan (docs)No owner, no transfer. Plan credits go to the original owner
SquarespaceOnly the current owner transfers via Permissions (docs)Contributor is not owner. Deceased-owner requests are a separate, documented path — ghosting is not
WixOwner starts transfer; recipient accepts (premium, free)Invite windows expire. No owner, no click

Preferred recovery if the host is still up:

  1. Identify the host from DNS. Write the project URL.
  2. If you have any team invite pending, accept it now.
  3. If you can pay the invoice without becoming “the owner,” do that as a bridge. Then export.
  4. Stand up a host you own in parallel. Do not delete the old project first.
  5. Cut DNS only after the new host serves a real page on a temporary hostname.

A site that dies when their card fails was never yours in practice. That sentence is still true after they disappear. The only change is you are now on the clock they set by ignoring dunning mail.

How do I recover the CMS if I only have an editor seat?

An editor seat is not an exit. Publish rights without transfer rights is how brands stay trapped on a pretty Tuesday.

Webflow. Sites are owned by the Workspace they sit in, not by whoever pays a card. Billing access is not ownership — Webflow says so in Site ownership. If the site lives in a freelancer’s Workspace and they are unreachable, Webflow cannot transfer that account or export the site to you. They may let you update billing to keep it online. If billing dies, the site goes away. An Editor seat on their Workspace is not a recovery plan.

Workspace-owner-left is a different article: there is no guarantee Support can move a Workspace you cannot prove (owner left the organization).

Framer. Project owner or workspace admin starts File → Transfer Project. You accept from email. If they never start it, you do not get a back door.

Squarespace. Only the current owner can change the site owner. Administrators cannot. Squarespace documents a deceased-owner request path on that page. A freelancer who stopped answering is not that path. After a real transfer, billing does not update by itself — taking over a site tells the new owner to put a card on file.

Wix. The owner starts Transfer Site. Recipients get a short accept window (Wix documents three days on free-site transfers). A pending invite you never saw is already dead.

CMS / builderWhat “enough” looks likeWhat is not enough
WebflowSite in your Workspace after an accepted transferEditor on their Workspace
FramerYou accepted Project Transfer; you pay the Site plan“We’ll stay owner for convenience”
SquarespaceYou are Owner, not AdministratorBilling permission on their login
WixYou accepted ownership; you pay PremiumCo-owner leftover on their account
WordPress on their hostYou have admin and the hostwp-admin on a box you cannot SSH

Checklist while any seat still works:

  • Export CMS collections (CSV/JSON) or native export
  • Download every image that is not on a CDN you will lose
  • Copy form destinations and notification emails
  • List fonts and stock licenses — your use, not their dropbox
  • Attempt to invite a second email you control. If the UI refuses, you are not owner

If the UI will not let you invite, stop decorating the CMS. You are documenting a hostage.

How do I recover the repo if it lives on their GitHub?

If you can clone it, clone it today. If you cannot, do not assume Support will transfer a private personal repo because you paid for a website.

On GitHub, transferring a repository requires admin on the source and permission to create repos in the destination (transferring a repository). That is a person with keys, not a vibe.

GitHub’s account recovery policy is explicit: if the owner lost recovery methods, Support will not restore the account, and Support will not recover the contents of a locked user or organization account. Public content you may clone or fork. Private content on a vanished personal account is often gone. The deceased-user policy is a separate, documented path with legal paperwork (deceased user policy). Ghosting is not death paperwork.

SituationWhat you can doWhat you probably cannot
You have clone URL + credentialsClone, push to your org, attach a new hostPretend their personal repo is now yours
Public repoFork or clone; preserve historyDemand they delete the original
Private repo, you are collaboratorClone while the seat exists; copy issues if you mustTransfer without an admin click
Private repo, no seatScreenshots and the live siteGitHub Support inventing admin for you
Org with one owner — themIf you are also an owner, add a second owner nowContinuity after they vanish (GitHub’s own warning)

Procedure:

  1. Find the remote. Check old emails for github.com/… links, deploy logs, Netlify/Vercel Git settings if you can open them.
  2. If you can clone, create a company org with two owners and push there.
  3. Rotate deploy keys and env vars off their laptop. A recovered repo with their Heroku key is a second hostage.
  4. If you cannot clone, your source of truth is the archive plus whatever CMS export you stole in time.
  5. Do not pay a stranger for “I can get the repo.” Document. Sometimes a small transfer fee to a reachable human is pragmatic. Sometimes it is a pattern.

A ZIP of dist/ is a souvenir. A company org is an asset. This is still not legal advice about who owns the copyright. Access control is the practical law until counsel is in the thread.

How do I keep billing alive without confusing it for ownership?

Pay to keep the lights on only while you copy. Then move the project. Then remove their payment method.

Squarespace is explicit that ownership transfer does not swap the card (taking over a site). Webflow may let a client update billing without transferring the Workspace. That is a stay of execution, not a win.

You can payWhat that buysWhat it does not buy
Their host invoiceDays or weeks of uptime (vendor-defined, not a promise I will date)The right to export or transfer
Domain auto-renew on their registrarThe name does not enter redemption this cycleRegistrant status
Google Workspace on their cardMail keeps flowingAdmin that can add your users
Nothing — card already deadHonestyA live site. Start the temporary page today

Procedure:

  1. Find the last receipt. Host, registrar, Google Workspace, and the CMS plan are often four vendors.
  2. If a dunning email still hits a shared inbox, pay it. Screenshot the confirmation.
  3. Open a ticket with that vendor: “I will put a card on file. I also need ownership transfer.” Attach invoices and domain proof. Expect them to follow their published policy, not your urgency.
  4. When the project sits in your team, add your card, then remove theirs.
  5. Rotate secrets. Their Stripe key in an env var is how “we recovered the site” still dumps new orders into a closed account.

Email suites ride the same mistake. Google Workspace or Microsoft 365 billed to their card, with them as the only Super Admin, is a second hostage sitting behind MX. Paying that invoice keeps mail alive. It does not make you admin.

Mail / identityBridgeOwnership
Google WorkspacePay the invoice; do not delete MXSuper Admin on a company domain you control
Microsoft 365SameGlobal admin in your tenant
Registrar WHOIS mailboxKeep it receivingA company inbox, not their Gmail
Form notificationsChange the endpointA recovered site posting into /dev/null

If you cannot add a user, you do not own the suite. Treat it like Webflow: billing-only is a stay of execution.

Do not cancel their plan as a punishment while production still points at it. Spite is not a cutover plan.

What proof should I collect before I open support tickets?

Vendors ask for the same pile. Gather it once. This is still not legal advice; it is the packet Support already knows how to reject.

  • Legal business name and the public URL
  • Government ID / business registration if the vendor’s form asks
  • Invoices: designer, host, registrar, CMS plan — dates and last four of the card if shown
  • ICANN Lookup screenshot with registrar and status flags
  • DNS export
  • Emails showing you were the client (SOW, launch thread, “the site is live”)
  • List of people who ever had a seat, if you know them
  • Archive links (Wayback + your own screenshots)
  • A written timeline: last reply, last deploy, last invoice paid
  • What you want: transfer, billing-only, or confirmation they will not move it so you can rebuild
TicketSend thisDo not send this
RegistrarLookup + proof you should be registrantA Figma file
HostProject URL + invoices + team emails“They ghosted me, please reset 2FA”
Webflow / FramerWorkspace clues + billing + domainA demand to export someone else’s Workspace
GitHubOnly what their policies allow (deceased vs recovery)A story about unpaid invoices as if it were admin
GoogleSearch Console / Workspace verification docsA request to hijack their personal Gmail

One ticket per vendor. One ask per ticket. “Give me the whole internet” is how you get a template no.

If they say no, that is data. Rebuild on accounts you own. Do not sit in the queue performing hope.

What usually fails first in a recovery?

The failure mode is almost never “we could not find a new designer.” It is a self-inflicted outage while people “take back the site.”

DNS edited before the zone was copied

Someone points the apex at a new Netlify site and blows MX. The homepage is “recovered.” Nobody can log into the inbox that held the registrar reset mail. You now have two outages.

Hosting card cancelled as punishment

You dispute the freelancer’s charge or they ignore dunning. The host suspends the project. You had no archive. The Wayback copy is a homepage without CMS entries. Rebuild starts from Instagram.

Registrar ticket opened inside a lock you did not read

RDAP already showed a transfer-prohibited flag. You start a transfer anyway. The attempt fails. You now wait on whatever lock the registrar actually applies. I will not invent that wait. Read the flags first.

CMS “cleanup” on an editor seat

You delete collections to “simplify” while you still do not own the Workspace. You cannot export what you deleted. The only copy was production.

Forms still posting to their inbox

The site looks recovered. Leads go to a Gmail that auto-replies nothing. Conversion did not survive. You will not notice until next month’s “why is the phone quiet.”

FailureImmediate symptomWhat you do instead
Blind DNS cutoverSite up, mail deadExport zone; change host on a staging hostname first
Card cancelled early404 / suspendedPay the bridge; archive; then cut
Lock ignoredTransfer deniedRead RDAP; ask the registrar of record
Editor-seat demolitionEmpty CMSExport first; never delete on a hostage
Form to vanished inbox“No leads”Change the endpoint the same day you change the host
No archiveRebuild from memorySave Page Now before the ticket

Bravery is not a restore strategy. Neither is rage-canceling the only card that still pays production.

How do I stand up a temporary site without the old accounts?

Put a page you control on a host you pay, then point the name only when DNS is yours. The temporary page is not the film. It is a phone number, the next date, and a sentence that you are still here.

Internet Archive’s Save Page Now captures one URL at a time, including images and CSS for that page — not a full-site crawl (Save Pages in the Wayback Machine). Use web.archive.org/save on homepage, contact, tour, shop, and the legal pages. Completeness varies. Some sites block the crawler. Treat Wayback as a gift, not a backup product.

You still controlTemporary moveDo not do
Domain + DNSNew host; copy the hero, phone, and form to an inbox you ownRedesign for six weeks while production rots
Host only, name hostageNew brand subdomain or a temporary domainPromise Google the old URL
Archive onlyStatic rebuild of the money pagesClaim the archive is legally identical to their project
Nothing liveSocial bio + Google Business Profile + a one-pagerPretend the old URL is “coming soon” for a quarter

Procedure:

  1. Create a host team you own. Netlify, Vercel, Squarespace, whatever you can actually log into next year.
  2. Ship a one-pager: who you are, phone, email, the next real CTA. Mobile first. No hero video.
  3. Point a new hostname at it (go.brand.com or a temporary domain) and test.
  4. Point the public name only when MX is preserved or mail has already moved.
  5. Put a form on your endpoint. Submit it. Watch the inbox.
  6. Then decide rebuild vs recovery of the old CMS. The one-pager buys you the room to think.

This is also when hire a designer vs a DIY builder stops being theoretical. A hostage Webflow and a dead card is not “stay on the builder to save money.” It is a forced rebuild. DIY is fine for the one-pager. The replacement film is a different purchase.

How does a vanished designer wreck conversion?

A hostage site converts like a disconnected phone. The URL can still rank. The form can still look like a form. The lead still dies in an inbox nobody opens.

Conversion doorWhat ghosting doesRecovery test
Phone CTANumber on a page you cannot editCall it from a second phone today
Contact formPosts to their Gmail / old Netlify FormsSubmit; see the message in your inbox
Booking / tourDates rot; Bandsintown embed is their accountNext date is correct on a phone
CheckoutStripe/Shopify tied to their loginPlace a $1 test if you have a shop
Ads / pixelsPixel in their Meta Business ManagerEvents fire on an account you admin
Search ConsoleVerification TXT they can deleteDomain property verified on your DNS

GA4 history in their Google account is gone for arguments about “the redesign killed conversions.” Recreate the property under a company Google account when you can. Baselines start at the day you own measurement. That is ugly and true.

Search Console Domain properties need a DNS TXT you control (verify site ownership). URL-prefix file uploads vanish in a rebuild. If you are already in a DNS fight, verification is downstream of the zone, not a separate miracle.

Checklist:

  • A real person can complete the money action on a phone
  • The form lands where staff will answer
  • The booking path does not require their CMS login
  • You can change the CTA without them
  • Analytics, if you still have any, is not the only proof the business exists

Conversion is not a vibe about the old hero. It is whether a tired person can still reach you after the designer blocked you.

When is a rebuild cheaper than chasing recovery?

Rebuild when the doors you need are documented dead ends, or when the name was never the asset. Recover when the hostname is the brand and RDAP still shows a path.

A custom site is worth the recovery fight when the URL is how customers find you, the inbox is how they pay you, and a new domain would reset years of maps, ads, and word of mouth. It is not worth a registrar war if the business is still validating and the old site never earned customers — that is the same honesty as hire vs DIY: do not spend five figures to rescue a URL that was never doing the job.

Recover the old projectRebuild on accounts you own
You are (or can become) registrantThey are registrant and the registrar has already said no
Host/CMS has a published transfer and someone who can start itWebflow/Framer/Squarespace owner is unreachable and Support’s article says they cannot move it
You can clone the repoPrivate GitHub, no seat, recovery policy is a wall
Archive is thin but CMS export existsArchive is the homepage and three JPEGs
Name is the brandName was a typo they registered for “convenience”

If you rebuild, do not recreate the hostage. Put the next site in your registrar, your DNS, your host team, your CMS Workspace, your GitHub org with two owners, your card. Lock layout in a small marketing-site system so the next editor cannot invent a fold — that is the point of design systems for marketing sites, not a UI-kit cathedral. A recovered or rebuilt site without those limits is how you get ghosted twice.

Rebuild order once you have chosen it:

  1. New registrar account in the company name. If the old name is lost, pick the temporary hostname now so print and bios can move once.
  2. New DNS zone you can export. Recreate MX only from the copy you made — never from memory.
  3. New host team. Deploy the one-pager first, then the real pages.
  4. CMS in your Workspace from day one. Editor seats only for staff.
  5. GitHub org with two owners, or a platform project that already transferred.
  6. Forms, pixels, GA4, and Search Console under company accounts.
  7. Cut the public name only after a phone can complete the money action on the new host.

Do not run this list in parallel with a registrar fight you have already lost. Pick a lane. Split brains are how both the old URL and the new one stay half-dead.

What to ask the next designer, in writing, before anyone opens Figma:

  1. Whose name is on the registrar at kickoff?
  2. Whose card pays hosting in month two?
  3. Will I be Workspace/org owner, or only an editor?
  4. What is the transfer button called on this platform, and who clicks it?
  5. Where do form submits go on week one?
  6. If you become unreachable, which vendor article describes what they will not do?

Vague answers are answers. “We’ll take care of it” is how you rent a site that looks owned.

Film-grade craft without keys is a beautiful leash. The websites lane is built to ship both — start at /websites if you want the build and the exit.

FAQ

My web designer disappeared — how do I get my website back?

Take six doors in order: domain registrar, DNS, host, CMS, repo, billing. Archive the live pages today, then work the doors you can still prove. Platforms transfer when an owner starts a flow you can accept; they do not invent a login from an invoice. This is recovery operations, not legal advice.

How do I measure whether recovery is actually working?

You can log into each door without them, publish a trivial change, and the public hostname still resolves to a host you pay. Conversion is a phone number or a form that lands in an inbox you own. Pageviews on a URL you cannot edit are not a recovery metric.

What usually fails first when teams try this?

DNS edits that break MX, or killing their hosting card before an archive exists. Teams also open registrar tickets without reading RDAP flags, or they delete CMS collections on an editor seat. The classic pair is the site going dark and email dying the same afternoon.

How long does this take to show results?

I will not invent a recovery clock. Owner-started transfer buttons can complete as soon as both sides click; registrar locks, redemption flags, and unreachable Workspace owners have no honest SLA I can quote. Measure by doors you now control and by a form that hits your inbox, not by a calendar promise.

What should I skip if I only have a week?

Skip the IP argument and skip a full redesign. Archive, keep billing alive if you can, stand up a one-pager on a host you own, and open registrar and platform tickets with invoices attached. Change the form endpoint the same day. Redesign after the hostname is yours.

When is this not worth doing yet?

If the URL never earned customers and the business is still validating, a clean rebuild on accounts you own can be cheaper than a registrar fight. If the name is the brand, recover the name first and put a temporary page behind it. Do not spend a custom-site budget rescuing a hostage you already outgrew.

CTA

Get the keys. Then argue about the film.

Explore /websites or book a Website sprint at /contact?intent=websites-sprint.

FAQ

What questions does this article answer?

My web designer disappeared — how do I get my website back?
Take six doors in order: domain registrar, DNS, host, CMS, repo, billing. Archive the live pages today, then work the doors you can still prove. Platforms transfer when an owner starts a flow you can accept; they do not invent a login from an invoice. This is recovery operations, not legal advice.
How do I measure whether recovery is actually working?
You can log into each door without them, publish a trivial change, and the public hostname still resolves to a host you pay. Conversion is a phone number or a form that lands in an inbox you own. Pageviews on a URL you cannot edit are not a recovery metric.
What usually fails first when teams try this?
DNS edits that break MX, or killing their hosting card before an archive exists. Teams also open registrar tickets without reading RDAP flags, or they delete CMS collections on an editor seat. The classic pair is the site going dark and email dying the same afternoon.
How long does this take to show results?
I will not invent a recovery clock. Owner-started transfer buttons can complete as soon as both sides click; registrar locks, redemption flags, and unreachable Workspace owners have no honest SLA I can quote. Measure by doors you now control and by a form that hits your inbox, not by a calendar promise.
What should I skip if I only have a week?
Skip the IP argument and skip a full redesign. Archive, keep billing alive if you can, stand up a one-pager on a host you own, and open registrar and platform tickets with invoices attached. Change the form endpoint the same day. Redesign after the hostname is yours.
When is this not worth doing yet?
If the URL never earned customers and the business is still validating, a clean rebuild on accounts you own can be cheaper than a registrar fight. If the name is the brand, recover the name first and put a temporary page behind it. Do not spend a custom-site budget rescuing a hostage you already outgrew.
Sources

Last reviewed

More from this lane

Websites

All →
Start a sprint