Is WHOIS information public?
WHOIS is public and private at the same time, which is why the answers people get contradict each other. The precise split is written into ICANN contracts, and it is worth knowing exactly where the line falls.
Partly. The operational fields — registrar, creation and expiry dates, name servers, domain status and the abuse contact — are public by contract and always will be. The registrant’s name, email, postal address and phone have been withheld from public WHOIS since 25 May 2018, when GDPR took effect. The withheld data is still collected and retained by the registrar and can be obtained through defined channels: law enforcement, a court order, or ICANN’s Registration Data Request Service for a documented legitimate interest.
Worked out 2026-09-10 (IST) · ICANN gTLD contracts; ccTLD policies vary by registryThe line, drawn precisely
| Data | Status | Why |
|---|---|---|
| Domain name and IDN variants | Public | Identifies the record |
| Registrar name and IANA ID | Public | Accountability — you must be able to find who to complain to |
| Creation, updated and expiry dates | Public | Operational; no personal data |
| Name servers | Public | Operational; needed to diagnose the internet |
| Domain status (EPP) codes | Public | Operational |
| DNSSEC signing status | Public | Security |
| Registrar abuse email and phone | Public and mandatory | Required by the Registrar Accreditation Agreement |
| Registrant name | Withheld | Personal data under GDPR |
| Registrant email | Anonymised | Personal data; a forwarding channel is provided instead |
| Registrant address and phone | Withheld | Personal data |
| Registrant state and country | Usually public | Judged not to identify an individual on its own |
| Registrant organisation | Often public | A company is not a natural person |
Who can get the withheld data
| Requester | Route | Realistic outcome |
|---|---|---|
| Law enforcement | Direct request to the registrar, or a court order | Disclosed |
| A court | Order | Disclosed |
| A trademark owner | ICANN Registration Data Request Service, or a UDRP filing | Case by case; UDRP reveals the registrant to the panel |
| A security researcher | Registration Data Request Service with a stated legitimate interest | Case by case |
| A journalist | Registration Data Request Service | Case by case, often refused |
| A member of the public | The anonymised forwarding address | You can send a message; you do not learn a name |
| A marketer | — | No route. This is the outcome the policy was designed for. |
What this means in practice
If your question is operational — who runs this domain, when does it expire, is it locked, who do I report abuse to — WHOIS still answers it completely and instantly. If your question is identifying — what is this person’s name — the public directory has not answered that since 2018 and no lookup tool of any kind can change that, because the data is not in the response to begin with.
Sources: ICANN Registrar Accreditation Agreement 2013, ICANN Transfer Policy, ICANN Expired Registration Recovery Policy, ICANN Registry Agreement Specification 4 (RDAP), IETF RFC 9083 and RFC 5731 (EPP status codes), and the EU General Data Protection Regulation as applied by ICANN’s Registration Data Policy.
Check your own numbers
See for yourself which fields a given domain publishes.
Frequently asked
Can I opt out of WHOIS entirely?
You cannot opt out of the operational fields - registrar, dates, name servers and status are published whatever you do, because the directory exists to make the domain system accountable. The personal fields are already withheld by default for gTLDs, so for most registrants there is nothing left to opt out of.
Does WHOIS privacy hide me from law enforcement?
No, and no reputable service claims otherwise. Privacy and proxy providers publish their own details in place of yours but keep your real data and disclose it on a valid legal request. They are a shield against bulk scraping and cold sales calls, not against a subpoena.
Do ccTLDs like .in follow the same rules?
No. Country-code registries are not bound by ICANN's gTLD contracts and each sets its own disclosure policy. Some publish more registrant detail than any gTLD would; others publish almost nothing and have done so for years. Check the specific registry rather than assuming .com behaviour.
Is scraping WHOIS data allowed?
Bulk scraping is restricted. Registry and registrar terms prohibit mass collection, particularly for marketing, and rate limits are enforced in practice. Individual lookups are fine and are the intended use; automated harvesting of thousands of records is a terms violation and, for the personal fields, a data protection problem as well.
Related answers
Need domain and DNS checks inside your own product?
We build WHOIS, RDAP, DNS and SSL lookups as embeddable widgets or a plain JSON API in your branding, wired to your own lead form. Tell us which checks you need and we will send a working demo.
Request received
Thanks — we will reply within one business day. Meanwhile, all 164 tools are free to use, no signup.