WHOIS Privacy and REDACTED FOR PRIVACY: What They Mean
Why WHOIS shows REDACTED FOR PRIVACY, how redaction differs from privacy and proxy services, what stays visible, and how to contact or identify a hidden owner.
Published: · 7 min read
"REDACTED FOR PRIVACY" in a WHOIS record means the registrar or registry has withheld the registrant's personal data from the public output, as ICANN policy has allowed and required since 2018. It is not a product, it costs nothing, and the registrar still holds the real data. A privacy or proxy service is something different: a service whose contact details are published in place of yours. The two are often confused, and the difference matters when you buy a domain, run into a dispute or lose access to an e-mail address. This guide explains both, what remains visible in either case, and the legitimate ways to reach an owner you cannot see.
Two different reasons the owner is hidden
Redaction (policy)
The EU's General Data Protection Regulation took effect on 25 May 2018. In the same month ICANN adopted a Temporary Specification under which gTLD registries and registrars redact the personal data of registrants in public WHOIS and RDAP output. It was succeeded by ICANN's Registration Data Policy, which became effective on 21 August 2025 and keeps the same principle.
Redaction means the fields exist but are not shown. The output says REDACTED FOR PRIVACY, Data Protected or similar. Nobody has been inserted in your place: you are the registrant, and the registrar has your name, address, e-mail and phone number on file. Many registrars redact for every customer regardless of country, because sorting customers by applicable privacy law is error-prone.
Privacy and proxy services (a product)
These existed long before 2018. ICANN's definitions distinguish two kinds:
- A privacy service shows the registrant's name, but replaces the contact details (address, e-mail, phone) with those of the service.
- A proxy service is itself the registered name holder and licenses the use of the domain to its customer. The record shows the proxy provider's name and contact details only.
The second point is worth reading twice. With a proxy service, the provider is legally the registrant of record, and your right to the domain rests on your contract with that provider. That matters in disputes, in a sale, and on the day the provider stops operating or you lose access to the account there. Many registrars include such a service at no charge; some sell it as an add-on.
| Redaction | Privacy service | Proxy service | |
|---|---|---|---|
| What it is | Policy applied by registrar/registry | Service, often from the registrar | Service, often from the registrar |
| Registrant of record | You | You | The proxy provider |
| Name shown | Redacted (organisation sometimes shown) | Yours | The provider's |
| Contact details shown | Redacted; relay e-mail or web form | The service's | The provider's |
| Cost | None | Free or paid, depends on registrar | Free or paid, depends on registrar |
| Who holds your real data | Registrar | Registrar and service | Provider (and registrar) |
| Main risk | Few; keep your data accurate | Depends on the service's terms | Your rights depend on the provider |
In practice the two layers often stack: a proxy service's details may themselves appear partly redacted.
What stays visible
Neither mechanism hides the registration itself. For a typical gTLD the public record still shows:
- the sponsoring registrar and its abuse contact
- creation, updated and expiry dates
- status codes such as
clientTransferProhibitedorclientHold - the nameservers
- the DNSSEC state
- often the registrant's country and state or province, and sometimes the organisation
Legal persons are a special case. Data protection law protects individuals, not companies, so an organisation's name may be published, either by registrar policy or because the registrant agreed to it. If the "organisation" field holds a private person's name, that name can end up public: fill the field only if you are registering for an organisation.
How to read it in WHOIS and RDAP
$ whois example.com | grep -i -E 'registrant|registrar:'
Registrar: Example Registrar, Inc.
Registrant Name: REDACTED FOR PRIVACY
Registrant Organization: REDACTED FOR PRIVACY
Registrant State/Province: Istanbul
Registrant Country: TR
Registrant Email: Please query the RDDS service of the Registrar of Record
In RDAP the same information is structured. rdap.org is a public bootstrap redirector that sends you to the responsible RDAP server:
$ curl -sL https://rdap.org/domain/example.com | jq '.entities[] | {roles, remarks}'
{
"roles": ["registrant"],
"remarks": [
{
"title": "REDACTED FOR PRIVACY",
"description": ["Some of the data in this object has been removed."]
}
]
}
{
"roles": ["registrar"],
"remarks": null
}
Look at entities (contacts with a role such as registrant, registrar, abuse) and at remarks that mention redaction. A privacy or proxy service looks different: the registrant entity is filled in, but with the name and address of the service. Both outputs above are illustrations, not real lookups. The protocol background is in WHOIS vs RDAP.
How to reach an owner you cannot see
- Use the relay. Registrars must provide an anonymised e-mail address or a web form that forwards your message to the registrant without revealing the address. Whether the registrant answers is up to them.
- Use the website. A contact page, an imprint or a for-sale notice is often faster than anything in registration data.
- Abuse goes to the registrar. For phishing, malware or spam, write to the registrar's abuse contact, which is part of the public record, and to the hosting provider.
- Request disclosure through RDRS. ICANN launched the Registration Data Request Service in November 2023: a central system for submitting requests for non-public gTLD registration data to participating registrars. Participation by registrars is voluntary, and each registrar decides each request under the law that applies to it. There is no guaranteed disclosure. For a registrar that does not participate, you send the request to that registrar directly.
- Trademark disputes do not need the name. A UDRP complaint can be filed against a domain whose registrant is hidden; the procedure works against privacy-protected domains.
No lookup site can reverse redaction, because the data is removed at the source. Sites that claim to show the "real owner" display historical records collected before the data was hidden, or guesses.
Country-code domains
The rules above are ICANN rules and apply to gTLDs. Country-code TLDs set their own policies: many publish nothing at all about private individuals, some publish more than gTLDs do. For .tr, registration data is available through the TRABİS query service, and personal data is limited under Turkish data protection law (KVKK); see .tr domain registration rules.
The downsides of being hidden
Hiding the data does not remove your obligations, and it creates a few new risks:
- The underlying e-mail address must keep working. Transfer approvals, expiry notices and the annual WHOIS data reminder that ICANN requires registrars to send all go to the address on file. An abandoned mailbox behind a privacy layer is the classic way to lose a domain by expiry.
- The data must be accurate. Privacy is not permission to enter false details. Inaccurate registration data can lead to suspension of the domain.
- With a proxy, someone else is the registrant. Read the terms: what happens on non-payment, on a complaint, and when you transfer the domain to another registrar (a service tied to the old registrar does not move with the domain).
- Buyers cannot find you. If the name might be for sale, put a contact page or a for-sale lander on it.
- Some checks look at registration data. Validation for organisation-validated and extended-validation certificates, and some business verifications, may consult it. A record that shows nothing, or a proxy's name, can mean extra paperwork.
What privacy does not hide
Registration data is only one source. Still public are: the IP address and hosting network of the site, the mail provider named in the MX records, every certificate issued for the domain and its subdomains in Certificate Transparency logs, and historical WHOIS records that archives collected before the data was hidden. If anonymity matters, think about all of them, not just the WHOIS record.
Common mistakes
- Paying for "WHOIS privacy" on a gTLD domain without checking that the record is already redacted at no charge.
- Treating redaction and a proxy service as the same thing, and being surprised that the proxy provider is the registrant of record.
- Letting the contact e-mail lapse because "nobody can see it anyway".
- Entering invented contact details instead of using privacy.
- Putting a personal name in the organisation field.
- Believing a site that promises the real owner of a redacted domain.
- Assuming gTLD rules apply to a ccTLD.
Check it with OrbitProbe
The OrbitProbe WHOIS lookup queries RDAP and shows what is public for a domain: registrar, dates, status codes, nameservers and DNSSEC state, with the source server and the time of the query. Redacted fields are shown as redacted; OrbitProbe does not guess at owners and has no way around redaction. Run it on your own domain to see exactly what the world sees, and to confirm that the parts that must be right (registrar, expiry, locks) are.