WHOIS privacy in 2026: what’s actually public

Updated 2026-08-23

GDPR redacted most WHOIS data years ago, WHOIS itself gave way to RDAP, and “privacy protection” add-ons mean less than they used to. What still shows, and what to check.

What changed

Two shifts made the old advice stale. First, since GDPR (2018), registries and registrars redact personal contact data from public records by default for most registrations — the fields that used to leak your home address now typically read “REDACTED FOR PRIVACY”. Second, the WHOIS protocol itself was sunset for gTLDs in January 2025 in favor of RDAP, a structured JSON lookup.

What a lookup still reveals

  • The registrar of record and its IANA ID — how tools (including our DNS checker) identify where a domain is registered.
  • Registration, expiry, and update dates.
  • Domain status codes (clientTransferProhibited and friends).
  • Nameservers — which reveal your DNS provider.
  • Sometimes the registrant’s state/country and organization, depending on registrar policy.

So is a “privacy” add-on worth paying for?

Mostly it shouldn’t cost anything anymore: Cloudflare, Porkbun, Namecheap, NameSilo, Dynadot, Squarespace, and Hover all include redaction or privacy free (their own sites, checked 23 August 2026 where noted on our compare pages). If a registrar still charges for it, that’s a signal about the whole pricing model.

One honest caveat: redaction hides data from the public record. Registrars still hold the real data and must disclose it under legal process — privacy services are a shield against scrapers and spammers, not against subpoenas.

Check any domain’s provider concentration in ten seconds — free, no signup.

Run the DNS checker