SnoopTool
Domains and WHOIS

Why does WHOIS say “Redacted for Privacy”?

The redaction is not the registrar being unhelpful and it is not a paid privacy add-on. It is the default, applied by ICANN policy to almost every generic domain in the world.

Because the EU’s General Data Protection Regulation took effect on 25 May 2018, and ICANN responded by requiring registrars to stop publishing the registrant’s name, email, address and phone number in public WHOIS. The data still exists — the registrar collects it, verifies the email under the 2013 Registrar Accreditation Agreement, and discloses it to law enforcement or to a documented legitimate interest. It is simply no longer printed for anyone who asks. This is separate from a paid privacy service, which replaces the data rather than hiding it.

Worked out 2026-09-10 (IST) · ICANN Registration Data Policy, in force for all gTLDs

Hidden, anonymised or still public

The distinction matters: redacted means the field is withheld, anonymised means you get a working substitute that reaches the owner.

WHOIS fields after GDPR
FieldTreatmentWhat you get instead
Registrant nameRedactedThe literal string REDACTED FOR PRIVACY
Registrant organisationKept if the registrant is a legal entityOften the real company name
Registrant emailAnonymisedA forwarding address or a web contact form
Registrant street, city, postcodeRedactedNothing
Registrant state and countryKeptUsually the real state and country
Registrant phoneRedactedNothing
Admin and tech contactsRedactedNothing; the fields may be removed entirely
Abuse contactPublic and mandatoryA monitored registrar mailbox and phone

The timeline, so you can date what you are looking at

How WHOIS got quiet
DateWhat happened
Before 25 May 2018Full registrant name, email, postal address and phone published for almost every gTLD
25 May 2018GDPR applies; ICANN adopts the Temporary Specification and redaction begins within days
2019–2021The EPDP process turns the temporary rules into permanent consensus policy
2023ICANN launches the Registration Data Request Service for documented disclosure requests
28 January 2025gTLD registries and registrars may retire the old port-43 WHOIS service; RDAP becomes the required protocol

That last line explains something people often hit: a lookup that worked a year ago may now return nothing over port 43 while the same query over RDAP returns a full record. If a tool reports “no data” for a domain that plainly exists, it is usually still speaking the retired protocol.

Sources: ICANN Registrar Accreditation Agreement 2013, ICANN Transfer Policy, ICANN Expired Registration Recovery Policy, ICANN Registry Agreement Specification 4 (RDAP), IETF RFC 9083 and RFC 5731 (EPP status codes), and the EU General Data Protection Regulation as applied by ICANN’s Registration Data Policy.

Check your own numbers

See exactly which fields a given domain still exposes.

Frequently asked

Does redaction apply to non-EU domain owners too?

In practice yes. ICANN applied the policy globally rather than trying to work out where each registrant lives, because getting it wrong once carries GDPR-scale penalties. A registrar in India or the United States redacts a .com registered by a local individual in exactly the same way as one registered in Germany.

Is a paid WHOIS privacy service still worth buying?

Usually not for a personal domain, because the default redaction already hides the same fields for free. It still matters in two cases: some ccTLD registries publish registrant details in full and a proxy service is the only way to avoid that, and a proxy service also shields you from bulk data that predates 2018 or leaks through registry escrow.

How do I get the real registration data?

ICANN operates the Registration Data Request Service, a standard form for requesting non-public gTLD registration data with a stated legitimate interest. Law enforcement and courts have their own direct channels. For abuse - phishing, malware, trademark - the registrar's mandatory abuse contact is faster than any disclosure request, because the registrar can act without telling you who the registrant is.

Why do some domains still show a full name and address?

Either the registrant is an organisation that opted to stay public, or the registry sets its own policy outside ICANN's. Country-code TLDs are not bound by ICANN contracts, so their disclosure rules vary widely - and a few of them still publish everything.

Related answers

Need domain and DNS checks inside your own product?

We build WHOIS, RDAP, DNS and SSL lookups as embeddable widgets or a plain JSON API in your branding, wired to your own lead form. Tell us which checks you need and we will send a working demo.