All documentation

WHOIS, registration data, and what privacy actually hides

WHOIS privacy takes your contact details out of the public record. It does not remove them, and it does not hide you from the registrar, a court, or a dispute.

WHOIS, registration data, and what privacy actually hides

WHOIS privacy is the most oversold feature in domain registration. It does something real and specific — it takes your contact details out of the public record — and then a lot of buyers assume it does considerably more than that. Here is the line, drawn precisely.

What WHOIS is now

Every domain registration carries a registrant contact, and for most of the internet's history that contact was published by the registry and queryable by anyone. The original protocol on port 43 is being replaced by RDAP, which returns the same data as structured JSON and can answer differently depending on who is asking.

The public data is also thinner than it used to be, and privacy law deserves the credit rather than registrar generosity: most registries now redact registrant contact fields by default. A requester who can demonstrate a legitimate interest — law enforcement, intellectual property, a dispute proceeding — may still be given more than the public sees.

What is in the record

FieldWith WHOIS privacy onNote
Registrant name and organisationReplacedThe privacy service appears instead of you.
Registrant emailReplaced with a relayMail to it is forwarded, and relays get switched off when they are abused.
Phone and postal addressReplacedThe provider's address appears instead.
Administrative and technical contactsReplacedLargely vestigial on gTLDs, still present on some TLDs.
Registrar of recordStill publicWho you registered with, and their abuse contact.
Creation and expiry datesStill publicUsed to establish seniority in a dispute.
Domain status codesStill publicclientTransferProhibited and its relatives — genuinely worth reading.
NameserversStill publicWhich is why DNS is never a secret, whatever privacy you buy.

That last block is the part most explanations skip. Privacy redacts your contact details. It does not redact the existence of the registration, who administers it, when it expires, or where its DNS points.

What WHOIS privacy does

It substitutes a proxy contact in the public record and runs a mail relay in front of your real address. Someone who looks your domain up finds the privacy service instead of your name, your inbox and your home address. Someone who genuinely needs to reach you about the domain — an abuse report, a dispute notice — still can, through the relay.

The concrete benefit is not legal anonymity. It is that your email address stops being harvested from a public, machine-readable database by people selling hosting, search optimisation and web design.

What it does not cover

You might assumeWhat is true
My registrar cannot see my detailsThey can, and they must. Accurate registrant data is a condition of holding a domain. Privacy governs publication, not possession.
It protects me from legal processIt does not. A subpoena, a court order or a lawful request reaches the registrar or the relay provider, and both have obligations that outrank the privacy layer.
It keeps me anonymous in a disputeIt does not. A proceeding under the UDRP or its equivalents has to identify the registrant, and the panel is given the underlying data.
It makes inaccurate contact data safeThe opposite. Inaccurate registrant data is grounds for suspension, and privacy does not change your obligation to keep it current.
It hides who runs the websiteYour website says who runs the website. So do your invoices, your certificate transparency logs and your mail headers.

Why accuracy still matters

Your registrant email is where expiry and renewal notices go, and it is the recovery path when something goes wrong: a payment that did not clear, a transfer you did not start, a registry audit. A domain with an unreachable registrant email is a domain you can lose while everything looks normal, because every warning went to an address nobody reads.

That is also why a relay is not a set-and-forget convenience. If you change your email address, change it with the registrar too — the relay only forwards to wherever you told it to.

A short checklist

  • Use an address you will still read in five years, not a project alias.
  • Check the public record once, after registering, and confirm the relay is in

place.

  • Keep the registrant contact accurate even with WHOIS privacy on.
  • Read the status codes before you attempt a transfer. See also: the domain

transfer guide.

  • Do not buy privacy expecting anonymity from a court. That is not the product.

WHOIS privacy is included with Domain Registration here, and it is applied by default wherever the registry allows it — a handful of TLDs have their own rules about what may be redacted. It is a real protection against a real problem, and the problem is unsolicited mail, not subpoenas.