Skip to main content

The Public Record

Domain privacy vs public WHOIS — what the record really shows since GDPR

The database that once printed every registrant's home address now mostly says 'redacted for privacy'. What is left visible, what a privacy service still adds, and who can see through both.

The short answer

Take the privacy service — here it is included free on endings that permit it — because it replaces your details with a forwarding proxy even in the channels GDPR redaction does not reach: escrow-fed lookalike databases, ccTLDs with different defaults, and the disclosure paths registrars operate. Public WHOIS is the right choice only for the narrow cases where being verifiable is the point: some businesses prefer their trading identity visible on names they defend.

The bigger correction this page makes: post-2018, the choice is no longer 'privacy or the world sees your address'. Redaction did most of that work. Privacy services now earn their keep at the edges — spam harvesting, historical snapshots, and endings whose registries publish more than the gTLD default.

By the Hosting & Domains team · Reviewed 25 August 2026

2018

GDPR resets the WHOIS default

RDAP

The protocol replacing WHOIS

Free

Privacy here, where registries allow

Layered

Redaction plus proxy, not either-or

For its first two decades, WHOIS was the internet's most casually invasive database: register a name, and your name, address, phone and email went into a publicly queryable record, harvested nightly by marketers and worse. Privacy services grew up as the fix — a proxy identity in the public field, your real details held by the provider.

Then GDPR landed in 2018 and rewrote the default. Registrars serving European data-protection law began redacting personal data from public output wholesale, ICANN's temporary specification made redaction the working norm across gTLDs, and the old protocol itself is giving way to RDAP, which supports tiered access. The comparison today is between two layers of protection, not between protection and exposure — and it pays to know what each layer actually covers.

What a lookup actually returns now

Query a typical gTLD name today and the personal fields come back redacted or withheld: no registrant name, no street address, an anonymised contact route instead of a bare email. What remains public is the operational skeleton — registrar, creation and expiry dates, nameservers, status codes.

That skeleton is genuinely useful and worth being comfortable with: it is how buyers verify a seller controls a name, how administrators debug delegation, and how anyone checks an expiry before making an offer.

ccTLDs write their own rules. Nominet withholds individuals' addresses on .uk names but shows trading names; other country registries publish more or less by their own law. The gTLD default is not a universal one.

What a privacy service still adds

Redaction is a display rule applied by the registrar; a privacy service changes what identity is on the registration's public face at all, substituting a proxy contact that forwards to you. That distinction matters in the places display rules do not reach.

It covers the endings and edge cases where redaction is weaker, keeps your details out of the third-party WHOIS-history services that archived the old public records, and gives spam harvesting nothing to work with even when data flows through channels the display layer does not govern.

The forwarding contact is the working part: registries and registrars must remain able to reach the registrant, and a decent privacy service passes genuine correspondence — transfer confirmations above all — while absorbing the rest.

Who sees through both layers

Neither redaction nor a proxy makes a registration anonymous to everyone. The registrar always holds the true registrant record — accuracy there is a contractual requirement — and discloses it on lawful request: courts, law enforcement, and dispute panels under the UDRP all have routes through.

That is by design, and it is why privacy services are compatible with running an honest business: your customers cannot harvest your home address, but a trademark panel can still find the respondent.

The practical consequence for owners: the mailbox behind the registration must work. Redacted or proxied, the registrant contact is where transfer approvals, validation checks and expiry notices go, and a dead mailbox there is how names get lost or stuck.

When public is the better setting

Some registrants want to be findable on the record: a company holding its brand portfolio may prefer its corporate identity visible, so counterparties, buyers and infringers all see exactly who owns the name.

Escrow-style verification is the other case — certain marketplaces and counterparties read the record as part of proving control, and a proxy adds a step of explanation.

Note the endings where the choice is made for you: a few registries, .us among them, do not permit privacy or proxy registration at all. If publishing details is unacceptable for a given project, that constraint belongs in the ending decision itself.

The filtering that absorbs an attack well before it reaches the site

The record is a contact route, not just an exposure

Owners think of WHOIS as the thing that leaks their address; registries think of it as the thing that guarantees someone answerable exists behind every name. Both are right, and every rule in this area — redaction, proxies, accuracy obligations, disclosure routes — is a compromise between those two readings.

Hold your side of the compromise and the system works for you: real details on file with the registrar, a privacy layer on the public face, and a monitored mailbox on the contact route. That combination survives audits, transfers and disputes, while giving harvesters nothing.

  • Privacy included at no charge where the registry permits it
  • True details held accurately, disclosed only through lawful routes
  • Forwarding contact that passes transfer mail reliably
  • Endings that forbid privacy flagged before you register

Why Hosting & Domains

Standard on every plan

Privacy as the default, not an upsell

On endings that allow it, the proxy goes on at registration for nothing — privacy sold as an extra is a relic of the pre-2018 market.

The exceptions surfaced early

Registering an ending that prohibits privacy, like .us, you will know before checkout — not when the record goes live.

A contact route that works

Forwarded correspondence reaches you, transfer confirmations included, so the privacy layer never becomes the reason a move fails.

Quick Start

Order placed to site online

  1. 1

    Decide what the public face should say

    Proxy for individuals and most small firms; visible corporate identity where being findable is part of the strategy.

  2. 2

    Keep the true record accurate

    Real registrant details with the registrar, always — accuracy is a condition of holding the name, privacy layer or not.

  3. 3

    Monitor the contact mailbox

    Whatever address the record routes to, someone must read it: approvals, validations and expiry notices all arrive there.

Built In

Fitted to every plan

  • Privacy service active on every ending that permits one
  • Registrant details real and current behind the proxy
  • The contact mailbox monitored and kept working
  • ccTLD publication rules checked for non-gTLD names
  • WHOIS-history exposure considered for older registrations
  • Disclosure and dispute routes understood before conflict

Frequently Asked

The questions that come up most

Is WHOIS even public any more?

The database exists and answers queries, but for most gTLD names the personal fields are redacted since GDPR — a lookup shows the registrar, dates, nameservers and status, not the registrant's identity. The protocol itself is being replaced by RDAP, which formalises tiered access. Country-code endings set their own publication rules, so check the specific ending.

If redaction is the default, why bother with a privacy service?

Redaction governs display on the main record; a privacy service changes the identity presented at all, which also covers historical-snapshot services, endings with looser defaults, and data paths a display rule does not touch. Since decent registrars include it free where permitted, the marginal cost of the second layer is nothing — take it.

Can someone still find out who owns a domain if they really need to?

Through lawful routes, yes — registrars disclose the true record to courts, law enforcement and UDRP dispute panels, and that answerable-party principle is the deal that keeps privacy services legitimate. What the layers stop is casual harvesting: marketers, scrapers and strangers no longer read your home address off a lookup.

Will privacy protection interfere with selling or transferring my domain?

Not with a competent service. Transfer confirmations pass through the forwarding contact, and you can lift the proxy temporarily if a buyer or marketplace wants control verified against the record. The failure mode to avoid is a privacy service whose forwarding silently drops mail — test it with a routine message before relying on it in a sale.

Why does my .us domain show my details when my .com does not?

The usTLD's policy prohibits privacy and proxy registration, so .us records publish registrant data the gTLD default now redacts. A handful of other registries take similar positions. If that exposure is unacceptable, the honest fix is choosing a different ending for that project — no registrar can lawfully proxy an ending that forbids it.

Keep reading

  • Domain Transfer vs Renewal

    Where the contact route matters most — approvals and codes all pass through it.

  • Domain Names

    Registration with privacy included where the registry permits, at no extra charge.

  • Jargon Buster

    WHOIS, RDAP, redaction, proxy, registrant — the vocabulary of the record, defined.

  • How-To Guides

    Step-by-step walkthroughs for the record checks this page recommends.

Changing hosts? Run through our checklist first.

A plain order of work for a move nobody visiting will notice: which files go over first, how to carry the mail across without losing a message, when exactly to repoint DNS, and the two mistakes behind nearly every outage we are asked to rescue.

What arrives is the checklist, and then the occasional note on keeping a site quick. Leave whenever you like; the privacy policy covers the rest.

A private face, an answerable record.

Privacy included free where registries allow it, true details held accurately behind it, and the exceptions flagged before you buy.

View Domain Names plans