Anyone who registers their domain with a domain registrar is required to submit contact in­for­ma­tion. This contact in­for­ma­tion may then be publicly ac­ces­si­ble. If you want more autonomy, security and privacy when it comes to your data, you’ll need to take some steps to ensure domain privacy pro­tec­tion. Domain privacy allows you or your domain registrar to delete publicly available data about you or your business from the WHOIS entry on your domain.

What is domain pro­tec­tion?

Domain privacy pro­tec­tion refers to the pos­si­bil­i­ty for anonymity and privacy when reg­is­ter­ing a domain. Anyone who registers a domain is required to submit various kinds of in­for­ma­tion in order to of­fi­cial­ly purchase the domain. That in­for­ma­tion includes personal data, business data and contact in­for­ma­tion. More specif­i­cal­ly, some examples are:

  • Name
  • Email address(es)
  • Business address(es)
  • Phone number

So what’s the problem with that? The personal in­for­ma­tion that’s connected to a domain isn’t private. It’s openly available via the WHOIS database, unless the domain registrar or reg­is­trant took specific steps to ensure WHOIS privacy. With domain privacy pro­tec­tion, the in­for­ma­tion connected to your domain is anonymized or replaced with in­for­ma­tion from your domain or hosting provider. That way you can protect your personal or company data.

What is WHOIS?

Domains, along with their IPs and the personal/company data connected with them, are managed by the ICANN (Internet Cor­po­ra­tion for Assigned Names and Numbers) in name­spaces. In order to co­or­di­nate IP addresses and domain name servers (DNS), the ICANN has de­ter­mined how domains can be reg­is­tered. It also manages the as­sign­ment of DNS, IP and as­so­ci­at­ed data under the umbrella of IANA.

When reg­is­ter­ing a domain, customers hand over personal data to reg­is­trars and reg­istries, which are then publicly ac­ces­si­ble via the WHOIS database. WHOIS is an internet registry that contains all the available in­for­ma­tion about a domain. The main reason this data is collected is to verify the le­git­i­ma­cy of each domain reg­is­tra­tion. WHOIS entries are meant to ensure that it’s possible to contact domain owners in the event of legal or technical problems or other issues.

The following in­for­ma­tion is part of a WHOIS entry in the WHOIS database:

  • Domain name
  • Domain registrar
  • DNS entries/DNS servers
  • Date of reg­is­tra­tion
  • Ex­pi­ra­tion date for domain reg­is­tra­tion
  • In­for­ma­tion about the reg­is­tra­tion’s renewal date
  • Status of the domain
  • Admin-C and Tech-C
  • Contact in­for­ma­tion (email, phone number, address, name) for the domain owner

The scope and content of WHOIS in­for­ma­tion will vary depending on domain type/domain ending, as different reg­istries might be re­spon­si­ble for different domain types. Due to the European GDPR, many WHOIS entries in the EU are au­to­mat­i­cal­ly anonymized or are only revealed in response to le­git­i­mate inquiries.

Domain Checker

What is a WHOIS lookup?

Anyone who visits a website or wants to get in­for­ma­tion about a domain can do a WHOIS lookup. A WHOIS lookup shows when a domain was reg­is­tered and which person or company it was reg­is­tered to. Depending on the scope of the WHOIS entry, there might also be contact in­for­ma­tion or personal data about the domain owner. Lookups are free and can be done using various domain ad­min­is­tra­tors, including:

The ad­van­tages of WHOIS lookups include:

  • Checking and proving the le­git­i­ma­cy and unique­ness of a domain
  • Col­lect­ing in­for­ma­tion about a domain before reg­is­ter­ing a new one
  • Making it possible to contact domain owners in the case of technical or legal problems
Tip

Looking for a free and easy way to find out who a domain belongs to? Use the IONOS WHOIS Domain Lookup and get all the publicly ac­ces­si­ble in­for­ma­tion about a domain.

How does the GDPR affect domain privacy?

The GDPR was in­tro­duced in Europe in 2018 and strictly regulates the pro­cess­ing, pub­lish­ing and storage of personal data. But while it is an EU-based reg­u­la­tion, the GDPR has far reaching con­se­quences for users and companies around the world. In the case of domain privacy, many reg­is­trars have made their processes GDPR compliant for everyone.

So what does GDPR com­pli­ance look like in the context of domain privacy? For one, it means that reg­is­trars are required to delete or anonymize personal data in WHOIS entries for top level domains (gTLDs and EU ccTLDs. It also applies to privacy in the context of domain man­age­ment.

According to the GDPR, domain providers are required to delete personal data from publicly ac­ces­si­ble WHOIS entries, unless a domain owner indicates otherwise. These days, many domain reg­istries offer their own services for domain privacy pro­tec­tion. Those services include:

  • Anonymized for­ward­ing addresses for WHOIS lookups
  • WHOIS entries about domain owners are replaced with in­for­ma­tion from domain provider or a third-party provider
  • Selected WHOIS privacy for selected domains
  • Two-factor au­then­ti­ca­tion and private WHOIS man­age­ment

What are the ad­van­tages of domain privacy pro­tec­tion?

When con­sid­er­ing this question, it’s important to strike a balance between the benefits of WHOIS entries and better domain privacy. Having your in­for­ma­tion publicly ac­ces­si­ble means that visitors to your site can approach you with questions or concerns. In general, it means that anyone is able to find out who owns a domain.

On the other hand, the ad­van­tages of domain privacy pro­tec­tion include:

  • Anonymiz­ing sensitive personal or company in­for­ma­tion
  • Pre­vent­ing the misuse of publicly available contact data, e.g. in the form of spam or phishing
  • Pre­vent­ing domain and identity theft
  • Enabling contact to domain owners using an anonymized for­ward­ing address

Can WHOIS privacy be used for any top-level domain?

Whether domain privacy pro­tec­tion is possible will mostly depend on the domain provider. The terms and con­di­tions should state whether domain privacy is an option or not.

Note that for .us domains, domain privacy is not allowed. This means that you are required to enter your contact in­for­ma­tion when reg­is­ter­ing a .us domain and that that in­for­ma­tion cannot be anonymized or falsified.

For country-specific domains in the EU, the GDPR will apply to domain reg­is­tra­tion via reg­istries like ICANN.

Tip

Benefit from com­pre­hen­sive pro­tec­tion for your domain with Domain Security by IONOS. We offer reliable pro­tec­tion against unwanted access with two-factor au­then­ti­ca­tion, DNSSEC en­cryp­tion and official domain owner cer­ti­fi­ca­tion.

Go to Main Menu