When you register a domain, you have to give the registrar your name, address, email and phone number. Historically, much of that was published for anyone in the world to read. WHOIS privacy is the umbrella term for the ways that information is now kept out of public view, either by your registrar automatically or by a privacy service you choose. It is worth understanding exactly what is hidden, what is not, and what trade-offs come with it.
What is in a domain registration record?
A registration record typically contains three types of information:
- Technical data: registrar, creation and expiry dates, status codes and name servers. This is always public, because the internet needs it to function and to resolve disputes.
- Registrant data: the legal owner's name, organisation, postal address, phone and email.
- Other contacts: administrative and technical contacts, which older registrations often filled in with the web designer's or IT company's details.
You can see what is currently shown for any domain with our WHOIS lookup. For generic domains such as .com the data now comes from RDAP, the structured successor to the original WHOIS protocol, but the content is broadly the same.
Two kinds of WHOIS privacy
Redaction by the registrar
Since the EU's General Data Protection Regulation came into force in May 2018, ICANN's policies have allowed, and in practice led to, registrars redacting personal data from public records. Many registrars apply redaction to every customer, not just Europeans. A redacted record shows text such as "REDACTED FOR PRIVACY" in place of the name and address, and offers a web form or anonymised email address instead of your real email. The registrar still holds your real details.
Privacy and proxy services
A privacy service publishes alternative contact details, while you remain the registrant. A proxy service goes further: the service itself becomes the registrant of record and licenses the domain to you. Both are often sold as "domain privacy protection" or included free by the registrar. The practical difference matters if there is ever a dispute, because with a proxy the legal registrant is, on paper, someone else.
What WHOIS privacy hides, and what it does not
| Hidden from public view | Still visible |
|---|---|
| Your personal name (for individuals) | Registrar name and abuse contact |
| Street address and phone number | Creation, update and expiry dates |
| Your direct email address | Name servers and domain status |
| Technical and admin contact details | Often the registrant's country and state, and sometimes the organisation name |
Privacy also does not hide anything you publish elsewhere. Your website's contact page, the company name in an organisation-validated SSL certificate (visible with any SSL checker), your DNS records and historical WHOIS archives from before redaction can all identify you. If anonymity really matters, think about all of those, not just the registration record.
Why WHOIS privacy matters
- Less spam and fewer scams. Published registrant emails and phone numbers were harvested for spam, and for scam "domain renewal" invoices from companies that are not your registrar.
- Personal safety. For sole traders, freelancers and anyone running a business from home, a public home address is a genuine risk.
- Competitive discretion. Registering domains for an unannounced product is less visible when the record does not name your company.
The downsides to be aware of
- Proving ownership can be harder. If your registrar account is ever compromised, or a former agency claims the domain, you want clear evidence that your company is the registrant. Keep invoices and make sure the underlying record (the one only the registrar sees) names your organisation.
- Forwarded mail can be missed. Messages sent through privacy forwarding addresses, including legitimate ones about transfers or disputes, may be filtered or ignored. Make sure the real registrant email is monitored.
- Trust signals. Some customers and security tools look at registration data when judging whether a site is legitimate. For an established business, showing the organisation name is a small trust signal; many registrars let you show the organisation while hiding the individual.
- Transfers. Some registrars require privacy to be switched off temporarily before a domain transfer, or handle it automatically. Check before you move a domain.
Is WHOIS privacy legal and allowed everywhere?
For most generic domains, yes. Some country-code extensions have their own rules: certain registries do not allow proxy services, require accurate public data for business registrants, or apply their own privacy defaults. The extension's registry policy is the authority here. What is never allowed is giving false details: registration agreements require accurate contact information, and inaccurate data can be grounds for suspending a domain. Privacy hides correct information; it does not replace it.
Privacy also does not put you beyond reach. Registrars and privacy services will disclose underlying data in response to valid legal requests, and under ICANN processes for parties with a legitimate interest, such as intellectual-property holders. Using privacy to shelter abuse does not work for long.
What should a business do?
- Register domains in the company's legal name, with a role-based email address (for example, a domains or IT mailbox).
- Keep privacy or redaction on for any personal data, especially if the company is small or home-based.
- Decide deliberately whether to show the organisation name; many businesses are happy to.
- Review your domains once a year: correct owner, current contacts, auto-renew on.
- Be sceptical of unsolicited "renewal" or "SEO registration" letters. Renew only through your actual registrar.
Key takeaways
- WHOIS privacy hides personal contact details but never the registrar, dates or name servers.
- Most registrars now redact personal data by default; privacy and proxy services add another layer.
- Your real details must still be accurate and are disclosed for legitimate legal requests.
- For businesses, the bigger risk is unclear ownership, so register in the company's name and keep contacts monitored.