UAE VAT invoice requirements for online stores in Dubai: what your checkout has to produce
What a VAT registered online store in the UAE must show on its tax invoices, and how the electronic invoicing rollout affects web shops.
Read the articleWeb Services
A working website handover checklist covering the domain registrant and registrar account, DNS, hosting, CMS logins, the code repository, analytics and Search Console, email and SSL, with how to check each one yourself.

A website handover checklist for a UAE business needs to cover nine things: the domain registrant and the registrar account it sits in, the DNS records, the hosting account, the CMS administrator login, the code repository for anything custom built, the Analytics and Search Console properties, the email accounts tied to the domain, the SSL certificate, and the backups. Most of these can be checked in minutes once you know where to look. When an agency built the site, the honest question to ask is not “do we have a login” but “whose name is on each of these nine things, and can we act on it without asking anyone”.
This article explains how the .ae domain registry, Google’s tools and WordPress describe ownership and access in general terms. It is not legal advice. For a dispute over a domain, account or contract, speak to a lawyer.
Key points
A website handover checklist should start with the domain, because everything else points to it. For a .ae domain, TDRA’s domains authority, aeDA, works through accredited registrars, and its own published guidance is direct on this point: only the registrant can transfer a domain name, cancel it or change who the registrant is. If your business paid for the domain but the registrant field shows your agency’s name, its personal email or its own registrar account, your business does not control the domain, whatever the invoice says.
Check it yourself in two steps. First, look up the domain through the registrar’s own account panel or a public Whois lookup and read the registrant name and organisation. Second, log in to the registrar account that holds the domain and confirm you, not the agency, can see it there. A domain bought “for you” through an agency’s own reseller account is still, in registry terms, controlled by whoever holds that account.
DNS rarely gets its own line on a website handover checklist, yet it sits next to the domain and is just as easy to lose track of. DNS is the set of records that points your domain at your website, your email and any other service, such as MX records for mail or a CNAME for a subdomain. If DNS is managed inside the registrar account, confirming registrant access covers it. If it has been moved to a separate DNS provider or the hosting company’s nameservers, ask for login access to that panel too, and write down what each record does before you change anything.
Hosting is the item a website handover checklist most often skips, because the site works whoever holds the account. The hosting account is where the website’s files, database and server settings actually live. It is a different thing from the domain and from the CMS login, and a business can easily hold one without the other two. Ask for the hosting provider’s name, the account holder’s name and email, and the billing method, then log in yourself and confirm you can see the site’s files, the database and any control panel settings such as PHP version or SSL.
Two arrangements are common and both are worth naming plainly. In the first, the agency’s own account holds several clients’ sites, and yours is one of many, which means you cannot act without the agency. In the second, a separate account exists in your business name but the agency kept the only login. Either way, the fix at handover is the same: the hosting account should be registered to your business, with your business email as the account owner, and the agency added as a collaborator if it continues to do maintenance work.
A CMS login is the item most businesses assume covers the rest of a website handover checklist, and it is usually the weakest assumption on the list. Being able to log in to WordPress is not the same as owning the site. WordPress’s own documentation on roles and capabilities sets out six built in roles, from Subscriber up to Administrator, and the difference matters at handover. An Administrator can manage plugins, themes, updates and other users. An Editor can publish and edit content but cannot touch plugins, themes or user accounts. If a website handover only gives your team an Editor or Author login, you can update the blog but you cannot add a form plugin, change a theme setting or remove the agency’s own access later.
Ask for an Administrator account created under a business email address you control, not a personal address that belongs to whoever built the site. If the agency needs ongoing access for maintenance, that is a normal and reasonable arrangement, but it should be a second Administrator account, added after yours exists, not the only one. The same logic applies to any other CMS or ecommerce platform: find the equivalent of the top role, and confirm it sits with your business first.
A website handover checklist for a custom build has to name the code repository specifically, because nothing else on the list stands in for it. For a template driven CMS site, most of the value lives inside the CMS itself, so the repository matters less. For a custom built website or a web application, such as a booking system or a client portal, the code repository on GitHub, GitLab or a similar service is the only complete copy of the work, including version history, configuration and anything that is not visible from the browser. Seeing the site work in production is not the same as having the source.
Check for a repository link in the project documentation or ask the developer directly whether the project sits under your organisation’s account or theirs. If it is under a personal or agency account, ask for the repository to be transferred, or at minimum for your business to be added as an owner with the ability to clone and fork it. Without that, a future developer taking over the project has to work from what the live site shows rather than from the actual codebase, which is slower and more error prone than starting from the source.
Analytics and Search Console are two separate Google products with two separate ownership layers, and a website handover checklist needs to treat them as such. Google’s Search Console guidance describes a verified owner as someone who proved ownership with a token such as an HTML file, a meta tag or a DNS record, and a delegated owner as someone a verified owner has granted the same status to without a token. Below that sit full users and restricted users, who can view data but cannot manage who else has access. Google is explicit that a property must always keep at least one verified owner, or nobody retains access to it.
Analytics works on two levels rather than one. Google’s own access guidance describes account level access, which reaches every property inside that account, and property level access, which is scoped to a single property. An agency that set up your Analytics inside its own account, rather than a property under your own account, can technically see every other client alongside yours, and moving your property out later needs its cooperation.
Ask for two things at handover: your business email added as a verified owner in Search Console, and Administrator access at the account level, not just the property level, in Analytics. Log in yourself afterwards and check that you, not only the agency, appear in the owners or users list for each property.
A website handover checklist should also name email, since a domain sale or migration can silently break every mailbox on it. Email accounts on your domain, such as info@ or sales@, usually sit inside the same hosting or DNS setup covered above, so once you hold that account the mailboxes generally come with it. The exception is a separate email service, such as a hosted mail platform bought and billed by the agency. Confirm which is the case, and if mail is billed separately, get the account moved into your business’s own billing profile.
SSL is the quietest item on a website handover checklist, because it usually renews itself until the day it does not. An SSL certificate secures the padlock in the browser address bar. Most modern hosts issue and renew SSL automatically as part of the hosting plan, in which case owning the hosting account is enough. If the certificate was bought separately from a certificate authority, confirm who holds that purchase and when it expires, because a certificate that lapses without your knowledge takes the whole site offline for visitors.
Backups are the part of a website handover checklist most businesses only think about after something breaks. Ask where backups are stored, how often they run, how far back they go, and whether you can download a copy yourself rather than having to request one. A backup that only exists inside an agency’s own internal tools is not really your backup, because you cannot reach it if the relationship ends.
If you read through the sections above and recognise your own website in several of them, the fix is rarely dramatic. Most agencies are willing to move accounts into a client’s name; the issue is usually that nobody asked clearly and in writing. Send a single message covering the domain registrant, the registrar account, DNS, hosting, the CMS Administrator login, the code repository if one exists, Analytics and Search Console ownership, the email accounts and the SSL and backup arrangements, and ask for each one by name.
Where a domain, a Search Console property or an Analytics account genuinely cannot be moved, for example because the previous developer is unreachable, treat it as a project in its own right: register a fresh property or account in your business’s name, redirect what you can, and keep the old one on file as a record rather than leaving the question open indefinitely.
Handover is part of how we approach every build, not an afterthought: the client approves the design before development begins, and the client owns the domain, hosting, CMS logins and code, backed by training and a recorded walkthrough, as set out on our website development page. If you already have a site and are not sure what you actually hold, our website maintenance team can review the accounts above and help you request what is missing. Before choosing who builds or rebuilds a site, our guide to choosing a website company in Dubai covers the questions worth asking up front, including this one. See the full range of work across design, development and marketing on our web services page, or send us a note about your current setup and we will return a written fixed price proposal within 45 minutes during business hours.
Straight answers
Under the aeDA's rules the registrant is the party recorded as controlling the domain, and only the registrant can transfer it, cancel it or change the registrant. If your agency's name or account sits in that role, your business does not control the domain even though it paid for it.
Yes, but only from whoever holds verified or delegated owner status in Search Console, or administrator access in Analytics. Google's own guidance says a property must always keep at least one verified owner, so ask the agency to add your business email at that level rather than only sharing reports.
Agencies typically work as Administrator while building the site. At handover, ask for your own Administrator account, created under your business email, in addition to any account the agency keeps for support work.
For a template based CMS site it matters less, because the CMS itself holds the content. For a custom built site or web application, the repository is the only complete copy of the work, so losing access means a future developer starts from what is visible in the browser rather than the real source.
Confirm who owns the SSL certificate or whether it renews automatically through the host, and confirm where backups are stored, how often they run and whether you can download one yourself. Neither should exist only inside an agency's internal tools.
No. This article explains how common platforms and the .ae domain registry describe ownership and access in general terms. It is not legal advice. For a dispute over a domain, account or contract, speak to a lawyer.
Sources
Fixed price, in writing
Got it. Your quote is being written now.
In business hours you will have it within 45 minutes. Check your inbox for the confirmation.
Keep reading

What a VAT registered online store in the UAE must show on its tax invoices, and how the electronic invoicing rollout affects web shops.
Read the article
What UAE policy says about digital accessibility, what WCAG 2.2 AA asks of a business website, and the checks to run first.
Read the article
What a written scope, a real portfolio and a fair proposal look like before you hire a website company in Dubai.
Read the article