The Whole Truth About WHOIS and Domain ID Protection

When a user registers a domain name, information about it is entered into the domain zone registry and becomes available via WHOIS. This is a publicly accessible database, so anyone can access it.

In addition to the domain’s technical details, it may also contain information about the person to whom it is registered, including first name, last name, address, email, and phone number. The classic WHOIS protocol does not hide this information at all, but how secure is that?

In the past, no one was concerned about privacy, and the internet was as open an environment as possible. Information about domain owners was publicly available, but over time it became clear that spammers, hackers, and even competitors were exploiting it.

As a result, many domain owners began using special protection services that hide or replace contact information in WHOIS records. Only technical information remains publicly available, while confidential details are replaced with a message such as REDACTED FOR PRIVACY.

In this article, we’ll take a detailed look at what WHOIS is and why it no longer complies with modern data protection regulations. We’ll also discuss how a domain ID protection service helps you maintain your privacy.

What is WHOIS and what information does it display?

WHOIS is a protocol that allows you to retrieve information about registered domains. It does not store any information on its own but serves solely as a tool for accessing the domain zone registry’s database.

WHOIS records let you find out who the domain registrar is, when the domain expires, its current status, which DNS servers it is delegated to, and much more. This information can be useful in many situations:

To check if a domain is available. For example, if you want to purchase the domain espresso.xyz, you can use WHOIS to find out if it’s still available. The records also indicate the domain’s expiration date. If you want to register this domain for yourself, you can try to snap it up via a backorder after it expires.

Find the registrar. This may be necessary, for example, to report that a website has been hacked or that a legal issue has arisen. Such inquiries are typically directed to the registrar.

Check the domain’s status. Administrators and technical support staff often use WHOIS to check the current status of a domain. For example, pendingDelete indicates that the domain is in the final stage of deletion from the registry.

The data displayed in a WHOIS record depends directly on the rules of the specific domain zone registry. For example, the .eu domain automatically hides the contact information of individuals who register this national domain.

Although the format and set of fields may vary, most WHOIS records contain similar basic information. Here, we’ll look at an example in which all fields are fully accessible after domain registration:

Domain Information

This section contains three groups of fields:

Domain Name: Twain.TLD
Registry Domain ID: A1234567-TLD
Registrar WHOIS Server: whois.site-twain.tld
Registrar URL: https://www.site-twain.tld
Updated Date: 2026-05-14T09:31:45Z
Creation Date: 2010-01-08T10:25:16Z
Registry Expiry Date: 2027-01-08T10:25:16Z

Registrar: OOO Registrar Company
Registrar IANA ID: 1234567
Registrar Abuse Contact Email: [email protected]
Registrar Abuse Contact Phone: +1.8011223344

Domain Status: clientTransferProhibited
Domain Status: clientUpdateProhibited

Domain. This section lists the domain name, its unique identifier in the registry, the WHOIS server address, and the registrar’s website. It also includes important dates: the domain’s creation date, the last update date, and the registration expiration date.

Registrar. This section lists the name of the company through which the domain is registered, its IANA identifier, and contact information.

Statuses. These are labels that indicate the domain’s current status and any possible restrictions. In our example:

  • clientTransferProhibited — a restriction preventing the domain from being transferred to another registrar.
  • clientUpdateProhibited — the registry automatically rejects all requests to modify the domain.

Domain Owner Information

The next section contains the owner’s personal information. Here’s an example where these fields are publicly visible:

Registrant Name: Mark Twain
Registrant Organization: OOO Twain & CO.
Registrant Street: Street, 10 A
Registrant City: Washington
Registrant State/Province: Washington Region
Registrant Postal Code: 20059
Registrant Country: US
Registrant Phone: +1.8012345678
Registrant Email: [email protected]

This is exactly what the WHOIS response used to look like. Today, this format is found only in specific domain zones whose rules do not require the concealment of personal data.

This section contains the domain owner’s contact information: name or organization name, mailing address, ZIP code, city, region, country, phone number, and email address.

Similarly, the WHOIS may include sections for Administrative Contact and Technical Contact. These contain the contact information for the administrator and the technical contact responsible for the domain.

Technical Information

WHOIS also includes a separate section listing the DNS servers to which the domain is delegated:

Name Server: ns01.example.tld
Name Server: ns02.example.tld
DNSSEC: unsigned

This information can be useful when diagnosing website performance, checking domain settings, or analyzing its configuration. You can also often determine which hosting company serves a domain by looking at its DNS servers.

What is RDAP, and will it replace WHOIS?

WHOIS has existed since the early days of the Internet and, for a long time, was the only technology that allowed users to retrieve domain data. However, we’ve already established that the format in which WHOIS provided this data violated the privacy of domain owners.

In 2018, the General Data Protection Regulation (GDPR) came into effect, prohibiting the public disclosure of EU citizens’ personal data. As a result, the classic WHOIS format not only posed risks to domain owners but also failed to meet modern privacy requirements.

Since then, registries have begun to hide information about domain owners on a massive scale. Instead of:

Registrant Name: Mark Twain
Registrant Phone: +1.8012345678

began to appear:

Registrant Name: REDACTED FOR PRIVACY
Registrant Phone: REDACTED FOR PRIVACY

However, this is more a matter of preference for specific registries than a rule. A number of domain zones still do not hide this data in WHOIS queries. Therefore, even after the implementation of the GDPR, the need for a more secure solution remained—and RDAP became that solution.

We discussed other issues with the WHOIS protocol that RDAP has resolved in a previous article.

RDAP is a new protocol for retrieving domain data, designed with modern personal data protection requirements in mind. Unlike WHOIS, it allows for flexible control over access to information and restricts what is displayed based on user permissions.

Registries and registrars are gradually transitioning to the new protocol, and ICANN, the international organization that manages the global domain name system, has already made the switch. However, this does not mean that WHOIS is now banned. It continues to be used for several reasons:

  • many systems and scripts have not yet been adapted to the new protocol;
  • users are accustomed to working with WHOIS and existing domain-checking tools. And anything new is always difficult;
  • WHOIS still works, so why go to the trouble of switching to the new protocol?

The transition to RDAP is only a matter of time. Gradually, registrars will switch to the new protocol when it becomes economically and technically feasible. However, for now, this is a fairly gradual process without strict deadlines, so you need to be prepared to use both protocols simultaneously.

Is the privacy service still relevant?

Registries continue to use WHOIS, so there are still domain zones where the confidential information of their owners is not hidden. This poses a risk that personal data will fall into the hands of malicious actors and be used for spam or fraud.

But even with the transition to RDAP, which automatically hides data, the privacy service remains relevant. This is because RDAP only allows you to manage access to data; it does not guarantee its confidentiality. The registry and registrar directly decide what specific data to display and to whom to grant access.

Therefore, the domain ID protection service remains relevant to this day. It helps hide or change your contact information (depending on the registrar and domain zone). This helps reduce the risk of spam and the collection of personal data by third parties.

With the privacy service, your personal data will look like this:

Registrant Name: REDACTED FOR PRIVACY
Registrant Organization: REDACTED FOR PRIVACY
Registrant Street: REDACTED FOR PRIVACY
Registrant City: REDACTED FOR PRIVACY
Registrant State/Province: REDACTED FOR PRIVACY
Registrant Postal Code: REDACTED FOR PRIVACY
Registrant Country: US
Registrant Phone: REDACTED FOR PRIVACY
Registrant Email: REDACTED FOR PRIVACY

You can ensure your privacy using the ID Protection service right when you register your domain. Simply check the box next to this optional service. If you need ID Protection for a domain you’ve already registered, just email us

Let’s summarize

Although registries and registrars are actively transitioning to RDAP, WHOIS hasn’t been forgotten and is still widely used. So if you don’t want your domain registration information to be accessible to third parties, we recommend using the ID Protection service. With it, you’ll gain an additional layer of privacy and be able to restrict access to your contact information in public domain records.