SnoopTool
Domains and WHOIS

Is WHOIS information public?

WHOIS is public and private at the same time, which is why the answers people get contradict each other. The precise split is written into ICANN contracts, and it is worth knowing exactly where the line falls.

Partly. The operational fields — registrar, creation and expiry dates, name servers, domain status and the abuse contact — are public by contract and always will be. The registrant’s name, email, postal address and phone have been withheld from public WHOIS since 25 May 2018, when GDPR took effect. The withheld data is still collected and retained by the registrar and can be obtained through defined channels: law enforcement, a court order, or ICANN’s Registration Data Request Service for a documented legitimate interest.

Worked out 2026-09-10 (IST) · ICANN gTLD contracts; ccTLD policies vary by registry

The line, drawn precisely

Public by contract, or withheld
DataStatusWhy
Domain name and IDN variantsPublicIdentifies the record
Registrar name and IANA IDPublicAccountability — you must be able to find who to complain to
Creation, updated and expiry datesPublicOperational; no personal data
Name serversPublicOperational; needed to diagnose the internet
Domain status (EPP) codesPublicOperational
DNSSEC signing statusPublicSecurity
Registrar abuse email and phonePublic and mandatoryRequired by the Registrar Accreditation Agreement
Registrant nameWithheldPersonal data under GDPR
Registrant emailAnonymisedPersonal data; a forwarding channel is provided instead
Registrant address and phoneWithheldPersonal data
Registrant state and countryUsually publicJudged not to identify an individual on its own
Registrant organisationOften publicA company is not a natural person

Who can get the withheld data

Disclosure routes
RequesterRouteRealistic outcome
Law enforcementDirect request to the registrar, or a court orderDisclosed
A courtOrderDisclosed
A trademark ownerICANN Registration Data Request Service, or a UDRP filingCase by case; UDRP reveals the registrant to the panel
A security researcherRegistration Data Request Service with a stated legitimate interestCase by case
A journalistRegistration Data Request ServiceCase by case, often refused
A member of the publicThe anonymised forwarding addressYou can send a message; you do not learn a name
A marketerNo route. This is the outcome the policy was designed for.

What this means in practice

If your question is operational — who runs this domain, when does it expire, is it locked, who do I report abuse to — WHOIS still answers it completely and instantly. If your question is identifying — what is this person’s name — the public directory has not answered that since 2018 and no lookup tool of any kind can change that, because the data is not in the response to begin with.

Sources: ICANN Registrar Accreditation Agreement 2013, ICANN Transfer Policy, ICANN Expired Registration Recovery Policy, ICANN Registry Agreement Specification 4 (RDAP), IETF RFC 9083 and RFC 5731 (EPP status codes), and the EU General Data Protection Regulation as applied by ICANN’s Registration Data Policy.

Check your own numbers

See for yourself which fields a given domain publishes.

Frequently asked

Can I opt out of WHOIS entirely?

You cannot opt out of the operational fields - registrar, dates, name servers and status are published whatever you do, because the directory exists to make the domain system accountable. The personal fields are already withheld by default for gTLDs, so for most registrants there is nothing left to opt out of.

Does WHOIS privacy hide me from law enforcement?

No, and no reputable service claims otherwise. Privacy and proxy providers publish their own details in place of yours but keep your real data and disclose it on a valid legal request. They are a shield against bulk scraping and cold sales calls, not against a subpoena.

Do ccTLDs like .in follow the same rules?

No. Country-code registries are not bound by ICANN's gTLD contracts and each sets its own disclosure policy. Some publish more registrant detail than any gTLD would; others publish almost nothing and have done so for years. Check the specific registry rather than assuming .com behaviour.

Is scraping WHOIS data allowed?

Bulk scraping is restricted. Registry and registrar terms prohibit mass collection, particularly for marketing, and rate limits are enforced in practice. Individual lookups are fine and are the intended use; automated harvesting of thousands of records is a terms violation and, for the personal fields, a data protection problem as well.

Related answers

Need domain and DNS checks inside your own product?

We build WHOIS, RDAP, DNS and SSL lookups as embeddable widgets or a plain JSON API in your branding, wired to your own lead form. Tell us which checks you need and we will send a working demo.