Why does WHOIS say “Redacted for Privacy”?
The redaction is not the registrar being unhelpful and it is not a paid privacy add-on. It is the default, applied by ICANN policy to almost every generic domain in the world.
Because the EU’s General Data Protection Regulation took effect on 25 May 2018, and ICANN responded by requiring registrars to stop publishing the registrant’s name, email, address and phone number in public WHOIS. The data still exists — the registrar collects it, verifies the email under the 2013 Registrar Accreditation Agreement, and discloses it to law enforcement or to a documented legitimate interest. It is simply no longer printed for anyone who asks. This is separate from a paid privacy service, which replaces the data rather than hiding it.
Worked out 2026-09-10 (IST) · ICANN Registration Data Policy, in force for all gTLDsHidden, anonymised or still public
The distinction matters: redacted means the field is withheld, anonymised means you get a working substitute that reaches the owner.
| Field | Treatment | What you get instead |
|---|---|---|
| Registrant name | Redacted | The literal string REDACTED FOR PRIVACY |
| Registrant organisation | Kept if the registrant is a legal entity | Often the real company name |
| Registrant email | Anonymised | A forwarding address or a web contact form |
| Registrant street, city, postcode | Redacted | Nothing |
| Registrant state and country | Kept | Usually the real state and country |
| Registrant phone | Redacted | Nothing |
| Admin and tech contacts | Redacted | Nothing; the fields may be removed entirely |
| Abuse contact | Public and mandatory | A monitored registrar mailbox and phone |
The timeline, so you can date what you are looking at
| Date | What happened |
|---|---|
| Before 25 May 2018 | Full registrant name, email, postal address and phone published for almost every gTLD |
| 25 May 2018 | GDPR applies; ICANN adopts the Temporary Specification and redaction begins within days |
| 2019–2021 | The EPDP process turns the temporary rules into permanent consensus policy |
| 2023 | ICANN launches the Registration Data Request Service for documented disclosure requests |
| 28 January 2025 | gTLD registries and registrars may retire the old port-43 WHOIS service; RDAP becomes the required protocol |
That last line explains something people often hit: a lookup that worked a year ago may now return nothing over port 43 while the same query over RDAP returns a full record. If a tool reports “no data” for a domain that plainly exists, it is usually still speaking the retired protocol.
Sources: ICANN Registrar Accreditation Agreement 2013, ICANN Transfer Policy, ICANN Expired Registration Recovery Policy, ICANN Registry Agreement Specification 4 (RDAP), IETF RFC 9083 and RFC 5731 (EPP status codes), and the EU General Data Protection Regulation as applied by ICANN’s Registration Data Policy.
Check your own numbers
See exactly which fields a given domain still exposes.
Frequently asked
Does redaction apply to non-EU domain owners too?
In practice yes. ICANN applied the policy globally rather than trying to work out where each registrant lives, because getting it wrong once carries GDPR-scale penalties. A registrar in India or the United States redacts a .com registered by a local individual in exactly the same way as one registered in Germany.
Is a paid WHOIS privacy service still worth buying?
Usually not for a personal domain, because the default redaction already hides the same fields for free. It still matters in two cases: some ccTLD registries publish registrant details in full and a proxy service is the only way to avoid that, and a proxy service also shields you from bulk data that predates 2018 or leaks through registry escrow.
How do I get the real registration data?
ICANN operates the Registration Data Request Service, a standard form for requesting non-public gTLD registration data with a stated legitimate interest. Law enforcement and courts have their own direct channels. For abuse - phishing, malware, trademark - the registrar's mandatory abuse contact is faster than any disclosure request, because the registrar can act without telling you who the registrant is.
Why do some domains still show a full name and address?
Either the registrant is an organisation that opted to stay public, or the registry sets its own policy outside ICANN's. Country-code TLDs are not bound by ICANN contracts, so their disclosure rules vary widely - and a few of them still publish everything.
Related answers
Need domain and DNS checks inside your own product?
We build WHOIS, RDAP, DNS and SSL lookups as embeddable widgets or a plain JSON API in your branding, wired to your own lead form. Tell us which checks you need and we will send a working demo.
Request received
Thanks — we will reply within one business day. Meanwhile, all 164 tools are free to use, no signup.