Domain privacy protection explained
What WHOIS privacy protection is, why it matters, and how to check it's switched on at common registrars.
- Difficulty
- Beginner
When you register a domain name you have to give the registrar real contact details — name, address, email, and phone number. Some of that goes into the domain's public registration record, which anyone can look up. Domain privacy protection publishes a privacy service's details there instead of yours. This guide explains what it is and how to check yours is on.
Quick summary
Domain privacy (also called WHOIS privacy or private registration) replaces your personal contact details in the public registration record with a privacy service's. It cuts down spam, cold calls, and unwanted approaches. At Namecheap, GoDaddy, and Cloudflare it is now applied automatically to eligible domains — free at Namecheap and Cloudflare — so the job is usually checking it's on rather than buying it.
What is WHOIS?
WHOIS is the long-standing way of publishing the contact and nameserver details behind a registered domain. It is being replaced: ICANN says that as of 28 January 2025, RDAP (the Registration Data Access Protocol) is "the definitive source for delivering generic top-level domain name (gTLD) registration information in place of sunsetted WHOIS services". You will still see both names used, and most registrars still offer a WHOIS-style search. Either way, you can look a domain up with ICANN Lookup.
With privacy switched off, the public record can show:
- Your full name
- Your home or business address
- Your email address
- Your phone number
Exactly which fields appear depends on your registrar and on the rules for your domain extension. A few always stay public: Cloudflare lists registrant state/province and country as fields that keep showing because ICANN requires it, alongside nameservers, domain lock status, and the registration and expiry dates. Those aren't the sensitive ones.
Why this is a problem
Published contact details get scraped. This is the reason registrars give for hiding them: Cloudflare's own documentation says broadcasting registrant contact information "can cause spam mail to be delivered to your personal addresses", and GoDaddy warns that details left public "could be used for phishing or spam".
With your details out in the open you can expect:
- Spam email trying to sell you SEO services, website design, or domain renewals
- Cold calls from marketing companies
- Phishing emails pretending to be your registrar
- Potentially, physical mail
What privacy protection does
ICANN describes two related services, and registrars market both as "domain privacy":
- A privacy service leaves you listed as the domain's registrant, but publishes "alternate, valid contact information (such as a mail-forwarding service address)" in place of your own address.
- A proxy service goes further: the proxy provider "becomes the registered name holder of record, and its identity and contact information is displayed" instead of yours.
Either way, your registrar still keeps the real, unredacted record and you can update it whenever you like. ICANN also requires registrars to give third parties some way to reach you without revealing who you are — Cloudflare, for example, forwards messages submitted through a web form to the registrant email on file.
Your domain still functions exactly the same. Visitors still reach your website. Email still works. The only thing that changes is what shows in the public record.
How to enable domain privacy
Namecheap adds a free Domain Privacy subscription to every registration, renewal, transfer, and reactivation on eligible extensions, and it's enabled by default. The service used to be called WhoisGuard, so older guides and older screenshots use that name. To check it:
Sign in to your Namecheap account.
Go to Domain List in the left sidebar, then click Manage next to your domain.
Check the Protection toggle next to Domain Privacy, and switch it on if it isn't already.
Some extensions can't use it because of registry rules. Namecheap's Domain Privacy page lists which.
Common questions
Does WHOIS privacy protect me from legal inquiries?
No. The registrar keeps your real contact details and can be required to provide them. ICANN runs a Registration Data Request Service for people with a legitimate interest in non-public registration data — law enforcement, intellectual property professionals, consumer protection advocates, cybersecurity professionals, and government officials. Privacy protection is about reducing spam and casual snooping, not legal anonymity.
Does privacy protection affect how my website works?
No. Your website, email, and all DNS settings continue to work exactly the same. Privacy protection only changes what's visible in the public registration record.
I already have spam. Will enabling privacy help now?
Enabling it now prevents future exposure, but it won't erase your details from lists that have already collected them. GoDaddy is blunt about this: details that have been published "could be used for phishing or spam, even if you turn Domain Privacy back on." You'll see a reduction in new spam over time.
Is it required by law to have accurate WHOIS information?
It's a contract requirement rather than a law. ICANN's policy is that "when you register a domain name, you must give your registrar accurate and reliable contact details, and correct and update them promptly if there are any changes during the term of the registration period." Give wrong information on purpose, or ignore your registrar when it asks you to confirm your details, and your registration "may be suspended or even cancelled." Privacy protection doesn't change any of that — the registrar still holds your real details, and the privacy service passes messages on to you.
Related guides
- How to find where your domain is registered
- Who owns your domain (and why it matters)
- How to register a domain name
- Securing your domain name
Need a hand?
Learn more
Last updated