If a church website changes in a way nobody expected, the useful question is not who edits the pages but who holds the accounts that carry the domain: the registrar, the DNS zone, and the hosting or content management login. Those three decide what the site can publish and where its mail is delivered. Most church sites are kept by volunteers on donated time, so the first moves after a surprise are the same ones this desk recommends for any administrative account: secure the recovery route, find out who else has access, and write down what changed before changing anything else.
This guide is written for the volunteer who inherited the job, the treasurer who holds one of the passwords, and the minister who has been asked to approve a rebuild. It covers which accounts matter first, what a public page should say before it says anything else, and what to record when something goes wrong.
The public side of that housekeeping, from what a home page should say to whether every member can use it, is treated at length by church website design and accessibility, a practical magazine about church websites written for the volunteer teams that keep them.
Which accounts decide what happens to a church website?
The domain registration is the first. Whoever controls it can point the site and the mail elsewhere, so it belongs to the church or the wider body rather than to one volunteer's personal account, and the renewal date should sit in a shared calendar. The DNS zone is the second, because the records that carry the church's email live there: a change of web host can quietly break or redirect correspondence. The hosting or content management login is the third, and the mailbox published on the contact page is the fourth.
Each of these accounts deserves its own login, a second factor where the provider offers one, and a recovery address that still works when the person who set it up has moved on. Where a team shares one login for convenience, the recovery route often points at somebody's old phone number, and the site's protection is only as good as that number.
Where do donation pages and mailing lists change the picture?
Money and correspondence move the exposure. A giving page linked from the site is usually handled by a third party, so the church's own accounts hold no card data, and the checks that matter sit on the platform account: who can change the payout bank details, who can issue refunds, and whether a change of bank details notifies a second person. A mailing list holds the addresses of people who trusted the church with them, so the list login is an administrative account rather than a shared password in a drawer.
Look for the pattern rather than the platform. A message that asks for a change of bank details, a new invoice, or a password reset is the same pattern described in our first response guide for a clicked phishing link, and it reaches churches for the same reason it reaches firms: the request arrives through a channel the sender controls.
What should be recorded before anyone changes a password?
Write down the date and time the change was noticed, the page or setting that looks different, who has been told, and what the provider's dashboard shows for recent sign-ins or sent messages. Screenshots help when they are safe to take. If the site runs on a managed platform, that platform keeps its own history, and an editor revision may already exist for the page; note the revision before it is overwritten.
Accessibility belongs in the same first pass. A short introduction from the W3C Web Accessibility Initiative explains why contrast, labels and keyboard access decide whether members can use the site at all, which is worth remembering when a rebuild is discussed in the same week as a security problem. Preservation is not an accusation either: it is the record that lets a provider, a diocesan IT office, or the volunteer who takes over next month understand what happened. The same discipline covers the ordinary paperwork around a congregation, as in our note on small business grant paperwork.
What limits the exposure
A site with individual accounts, working second factors and a shared record of who holds what is ordinary to maintain; the failure mode is one volunteer holding everything with an unreachable recovery address. If the site carries a giving page or a members' area, or if the change affects mail the congregation relies on, hand the record to the responsible body rather than improvising alone. Nobody needs to be a security professional to get the first hour right.
Related dispatches
Small business grants in Scotland and the records they require · Small business incident response plan · Cybersecurity incident first steps · How Security, Applied works
