Who owns your Cloudflare account? Your DNS lives there.
Cloudflare is the most consequential account most business owners have never logged into. If your nameservers point there — and for a huge share of small-business sites they do — then Cloudflare is where your DNS actually lives: one dashboard controls where your website loads from and where your email is delivered.
And because Cloudflare is a developer tool, it's usually a developer who set it up — sometimes under your company's account, often under their own. Those are very different situations. Here's how to tell which one you're in, and the official fix for each.
Situation 1: it's your account, wrong person in charge
Cloudflare accounts have members with roles; the one that matters is Super Administrator — all privileges, including billing and member management. Check yours in the dashboard under Manage Account → Members.
- 1Add a company-controlled memberInvite an email the business owns and assign the Super Administrator role. (Managing members itself requires Super Administrator.)
- 2Then remove or demote the previous oneThis is Cloudflare's documented order for changing super admin: add the new one first, remove the old one second.
- 3Keep more than oneCloudflare's own recommendation: more than one Super Administrator, so a lost login never strands your DNS.
Situation 2: your domain lives in their account
If the developer added your domain as a zone in *their* Cloudflare account, no role change inside it saves you — you need to move the domain to an account you own. Cloudflare documents this as a zone move, and the order of operations matters because DNS mistakes here take your site and email down.
- 1Create your own Cloudflare accountOn a company mailbox. Free plan is fine to start.
- 2Export the DNS records firstFrom the old account while you still have cooperation — every record, especially MX. This is the safety net for everything that follows.
- 3Clear the blockersDNSSEC must be disabled at the old account before the move, and paid add-ons/subscriptions on the zone need removing.
- 4Add the domain to your account and re-point nameserversYour new account issues you new Cloudflare nameservers; update them at the registrar (this is why you fix domain ownership first).
- 5Recreate and verifyImport the DNS records, reissue SSL/TLS certificates, then verify the site loads and a test email arrives before you call it done.
Set it up properly
- The Cloudflare account is created and owned by the business; developers get member roles scoped to what they need.
- Two Super Administrators, both on company-controlled emails with 2FA.
- Keep a current export of your DNS zone with your backups — it turns every migration and recovery from surgery into a paste.
- Put Cloudflare in the asset register next to the registrar — they're two halves of the same single point of failure.
The free scan maps your domain, email, cloud, social and tools from public records — and shows what you'd lose access to tomorrow. No login, nothing to install.
Check my business