Domain name security, theft, recovery and disputes
Abstract contour line illustration representing WHOIS Privacy and Redaction

LayerRegistrar

WHOIS Privacy and Redaction

Governing policy
ICANN Registration Data Policy
Window
Two business days for registrar verification in a UDRP
Layer
Registrar
Authority
ICANN Registration Data Policy, effective 21 August 2025

Redaction protects you from harvesting and targeting — and removes the public evidence that the domain is yours

Three different things are called WHOIS privacy

Conflating them is the source of most of the confusion in this area, and occasionally of a lost domain.

A privacy service leaves you as the registrant of record — the party the registry and registrar formally recognize as holding the domain — and substitutes the service's contact details in published data. Your own name may or may not remain in the underlying record the registrar holds.

A proxy service is a materially different legal posture. A third party is the actual registrant of record, and licenses use of the name to you. The domain is registered to somebody else. That is not a presentational detail; it is who the registrar's records say owns the name.

Mandatory redaction is neither of those and does not require buying anything. Since 2018, registrars have redacted most registrant contact data from public registration output by default. If you have never purchased privacy for a gTLD domain, your contact details are very probably not public anyway. A good deal of money is spent on privacy products that duplicate a redaction which already happened.

What redaction removed, and what stayed public

The Temporary Specification for gTLD Registration Data was adopted by the ICANN Board on 17 May 2018 and took effect on 25 May 2018 — the day the GDPR became applicable — because without the changes, in ICANN's own words, "ICANN, Registry Operators, and Registrars would not be able to comply with both the law and ICANN agreements." It required redaction of most registrant contact data unless the registrant consented: name, street address, postal code, phone and fax, and email, the last replaced by an anonymized forwarding mechanism that "MUST NOT identify the contact email address or the contact itself." It also required "reasonable access to Personal Data in Registration Data to third parties on the basis of a legitimate interests pursued by the third party."

The Temporary Specification gave way to the Interim Registration Data Policy, which carried its requirements from 20 May 2019 to 20 August 2025, and then to the Registration Data Policy, effective 21 August 2025 after a transition period beginning 21 August 2024.

Under the current policy, a contracted party that redacts must both omit the value and indicate that redaction occurred. Elements that must be redacted include Registry Domain ID, Registrant Name, Street, Postal Code and Phone, and Registry Tech ID and Tech Name; registry operators must redact Registrant Email and Tech Email; Registrant Organization and City may be redacted. What remains published is the useful residue: Domain Name, Registrar, Registrar IANA ID, Registrar URL, Creation Date, Registry Expiry Date, Domain Status, and the Registrar Abuse Contact Email and Phone.

The trade-off that matters: you lose the evidence too

Here is the part that is worth the page. The same redaction that protects a registrant from harvesting, spam and targeted social engineering also removes the public evidence that the registrant is the registrant.

After a hijack, the fastest thing a registrar or registry can act on is a documented, continuous chain showing who held the name and when. Public WHOIS history used to supply that chain in a single screenshot. It no longer does. The public record now shows redacted values for every period — before and after the theft — so the historical record does not distinguish the rightful holder from the thief. Both look identical. Both look like nothing.

The burden therefore shifts entirely onto private evidence: registrar account records, renewal invoices, payment records, and transaction correspondence. That evidence is straightforward to assemble in advance and painful to assemble under time pressure, which is precisely when anyone needs it. In my experience the registrants who recover quickly are the ones who already had the file, not the ones who built it after the loss.

Proxy registration compounds the problem. Under a proxy, the registrant of record legitimately is somebody else, so establishing that you are the beneficial owner depends on the proxy provider's cooperation and the provider's own records — a dependency on a third party at the exact moment speed matters most.

The countervailing case is equally real, and this is not an argument for publishing your details. A public home address and personal phone number invite harassment, doxxing, and highly targeted social-engineering attacks against your registrar account — which is itself among the most common hijacking vectors. The answer is not to expose yourself. The answer is to keep privacy and keep an independent, dated ownership file, because the public record is no longer doing that job for you.

In a dispute, the registrant surfaces only after filing

In a UDRP proceeding, the complainant frequently does not know who the respondent is at the moment of filing, because the public data is redacted or shows a proxy. The UDRP Rules handle this at paragraph 4. The dispute resolution Provider sends a verification request to the registrar for the full registration data and for a lock on the domain; the registrar must respond within two business days with that data and confirmation that the lock is applied, and may not notify the respondent until the lock is in place. The Provider then has three calendar days from receipt of fees to forward the complaint to the respondent and the registrar.

The practical effect is that a complainant commits to a proceeding without knowing who they are proceeding against. The identity arrives afterward. That cuts both ways, and the second direction gets less attention: a legitimate holder sitting behind privacy can find themselves named as a respondent in a case constructed entirely on assumptions about who they must be.

Note also the respondent's clock. A response is due within twenty days, with an optional automatic four-day extension on request. If the registrant contact is an anonymized forwarder that nobody monitors, that is the window that quietly expires. Anything involving a filed dispute is work for counsel; the point here is only that the notice arrives through a channel privacy has made easy to ignore.

Notice is the failure mode nobody plans for

When the published contact email is an anonymized forwarder and nobody watches where it forwards to, the things that go missing are not marketing messages. They are expiry reminders, transfer confirmations, change-of-registrant approvals and dispute notices. Missed notice is how a recoverable situation becomes an expiry, and how a transfer that a single reply would have stopped completes on schedule.

Two related traps. First, a privacy service tied to a registrar account can complicate account recovery if the registrant's own contact details underneath the privacy layer were never kept current — that underlying data is what the registrar will check when you call. Second, turning privacy off in a hurry immediately before a sale or transfer publishes whatever stale contact data was sitting under it, which is rarely what anyone intended to publish.

Privacy and proxy providers are not operating under a common standard

The GNSO's Privacy and Proxy Services Accreditation Issues working group produced a Final Report on 7 December 2015 recommending an accreditation program for privacy and proxy providers. As of March 2023, the Governmental Advisory Committee was still advising the ICANN Board to prioritize the related assessment and to monitor implementation of those recommendations, with ICANN organization anticipated to begin an impact assessment that quarter — more than seven years after the Final Report.

Whether that program has since come into force is not something I can confirm here, and I would treat any claim that a given provider is ICANN-accredited as needing verification. The consequence for you is concrete: privacy and proxy providers operate under their own terms of service rather than a uniform standard, so what happens to your ownership evidence at the moment you need it depends on the individual provider's contract. Read that contract before you need it, particularly the clauses on disclosure requests, on what happens if the provider ceases business, and on how you get the name back out.

Common mistakes

  • Letting privacy hide the registrant from the registrant — never keeping an independent, dated record of who owns the name.
  • Leaving the anonymized forwarding address unmonitored, so expiry and transfer notices go unread.
  • Using a proxy service without understanding that the proxy is the registrant of record, and without a written agreement covering non-cooperation or the provider's insolvency.
  • Relying on public WHOIS history as ownership evidence. Post-2018 there is usually nothing there to rely on.
  • Assuming privacy prevents disclosure. It does not: registrars disclose to requesters with a legitimate interest, to dispute resolution providers, and in response to legal process.
  • Switching privacy off immediately before a sale or transfer and exposing stale contact data in the process.

What good practice looks like

  • Keep privacy on for exposure reasons, and maintain a private, dated ownership file independent of registration data: registrar account records with dates, renewal invoices, payment records, the original purchase or escrow record, and periodic authenticated screenshots of the registrar account showing the domain under it.
  • Record RDAP output periodically even though it is redacted. RDAP — the Registration Data Access Protocol, the structured HTTP and JSON successor to WHOIS — still exposes registrar of record, creation date and domain status, and those fields establish continuity.
  • Use a role-based, monitored mailbox as the registrant contact rather than a personal address, and confirm that the anonymized forwarder actually delivers to it.
  • Keep the registrant contact data accurate underneath the privacy layer even though it is not published. That is the data a registrar will check.
  • If using a proxy, get in writing how disclosure requests and ownership disputes are handled, and how the name is released back to you.
  • Consider disabling privacy briefly and deliberately at moments where public attribution is useful, such as immediately before a documented transfer, rather than leaving it off permanently.

Frequently Asked Questions

Does WHOIS privacy make it harder to prove I own my domain?

Yes, and this is the trade-off nobody discloses at checkout. Public registration history used to show a continuous chain of who held a name, which is the fastest evidence a registrar or registry can act on after a theft. With redaction, the public record shows redacted values for every period, both before and after the theft, so it no longer distinguishes the rightful holder from the thief. The burden moves entirely to private evidence: registrar account records, renewal invoices, payment records and transaction correspondence. Assemble that file before you need it.

What is the difference between a privacy service and a proxy service?

Under a privacy service you remain the registrant of record and the service's contact details are substituted in published data. Under a proxy service the provider is the actual registrant of record and licenses the name to you, which means the domain is registered to someone else. The difference is invisible in day-to-day use and decisive in a dispute or a recovery, because establishing that you are the beneficial owner behind a proxy requires that provider's cooperation and records. Read the provider's terms on disclosure, insolvency and release before relying on it.

Is my registration data hidden because I bought privacy, or automatically?

Very likely automatically. Since the Temporary Specification took effect on 25 May 2018, and now under the Registration Data Policy effective 21 August 2025, registrars redact most registrant contact data from public output by default: name, street, postal code, phone and email among them. A purchased privacy product may add little to that for a gTLD registration. What stays public either way is domain name, registrar, registrar IANA ID and URL, creation date, expiry date, domain status, and the registrar abuse contact.

Can anyone still find out who owns a domain?

Yes, through defined channels rather than a public lookup. Registration data policy requires reasonable access for third parties asserting a legitimate interest, subject to a balancing test. Dispute resolution providers obtain the full registration data from the registrar during a UDRP verification, and legal process reaches it as well. Privacy limits casual public visibility and harvesting. It is not a shield against disclosure, and if you chose it on the assumption of permanent anonymity, you have misread what it does.

How does a UDRP complainant find out who the respondent is?

Through paragraph 4 of the UDRP Rules, after filing rather than before. The dispute resolution Provider sends a verification request to the registrar seeking the full registration data and a lock on the domain. The registrar must respond within two business days with that data and confirmation the lock is applied, and may not notify the respondent until the lock is in place. The Provider then has three calendar days from receipt of fees to forward the complaint. The complainant therefore commits to the proceeding before knowing who they are proceeding against.

What should I keep as proof of ownership if the public record is redacted?

A dated file kept independently of registration data. That means registrar account records showing the domain under your account with dates, renewal invoices, payment records, the original purchase or escrow documentation, any transfer correspondence, and periodic authenticated screenshots. Add periodic RDAP snapshots: the contact fields will be empty, but registrar of record, creation date and domain status remain visible and establish continuity over time. Keep it somewhere that does not depend on the domain or the registrar account you may lose access to.

Is WHOIS still available?

It is being retired in favor of RDAP, the Registration Data Access Protocol, which returns structured JSON over HTTP. Since 28 January 2025, RDAP is the definitive source for gTLD registration data: all gTLD registries and registrars must provide RDAP using the gTLD RDAP Profile, and they are no longer required to provide WHOIS services, with .com, .name and .post excepted. If any of your tooling parses port-43 WHOIS output, it is running on a service most registries are no longer obliged to operate.
Keep reading

Read the guides

The entries describe what a mechanism is. The guides describe what to do with it, in sequence, and where each route closes.

This is a reference, not a practice. Hartzer.net sells nothing, takes no engagements, and is not legal advice. Nothing here creates any relationship or preserves any deadline.

Top