Every domain you register comes with a public registration record attached to it — your name, address, phone number, and email. For most of the web’s history, that record sat in a WHOIS lookup anyone could search, and people often only found out once a spam call or a phishing email showed up referencing the exact address they used to buy a domain three years earlier.
That landscape changed materially in the last two years, and most guides to this topic haven’t caught up. On 28 January 2025, ICANN formally launched the Registration Data Access Protocol (RDAP) as the authoritative replacement for WHOIS across generic top-level domains, and by September 2025 over 370 gTLDs had disabled their public WHOIS service entirely. Under RDAP, redaction of most personal registrant data is now the default state for a gTLD domain — whether or not you’ve bought a privacy add-on from your registrar. That doesn’t make domain privacy protection irrelevant, but it does change what it’s actually protecting you from in 2026.
Quick Answer
As of the RDAP transition, most personal contact details on a standard .com, .net, or .org domain are already hidden from public lookups by default — you no longer have to buy separate privacy protection just to keep your name and address off the public record for those extensions. What registrar-level privacy protection still adds: consistency across country-code domains that haven’t adopted RDAP (many .de, .fr, and similar ccTLDs still run voluntary WHOIS with weaker default redaction), a forwarding contact address so renewal and legal notices still reach you, and protection against the tiered access model that lets verified parties — law enforcement, security researchers, trademark holders in a UDRP dispute — request your full unredacted record through ICANN’s Registration Data Request Service.
What Changed, and Why It Happened
The old WHOIS system required every registrant’s contact information to sit in a publicly searchable database, a rule that predates GDPR and was originally meant to let domain disputes and abuse be traced back to a real owner. GDPR’s 2018 enforcement forced an interim fix — ICANN’s “Temporary Specification” redacted EU registrants’ data while the rest of the world’s data stayed exposed. RDAP is the permanent, structural replacement: instead of one flat public record, it returns a redacted response to ordinary public queries and a full response only to parties who authenticate through the tiered access system, regardless of where the registrant is based.
Practically, this means the old warning — “data harvesting bots scrape WHOIS constantly, so an unprotected domain triggers a spike in spam calls within days” — describes a risk that’s now much smaller for a standard gTLD registered after the transition, since there’s usually nothing exposed for a bot to scrape in the first place. The risk hasn’t disappeared, though. It’s shifted to three places: domains registered before the transition that were never re-checked, ccTLDs outside ICANN’s contractual reach, and registrars that implemented RDAP redaction inconsistently in the rollout’s early months.
Where Registrar Privacy Protection Still Earns Its Place
Country-Code Domains (ccTLDs)
RDAP is mandatory for gTLDs because ICANN’s contracts require it. Country-code registries — .de, .fr, .co.uk, .nl, and others — aren’t bound by those contracts, so their move to RDAP-style redaction is voluntary and uneven. If your site runs on a ccTLD, don’t assume the default-redaction protections above apply. Run an actual lookup and check what’s genuinely visible before relying on the new baseline.
Domains Registered Before Early 2025
If you registered a domain years ago and never touched the privacy setting, don’t assume the RDAP transition silently fixed it for you. Run a fresh lookup on your own domain and confirm what’s actually showing before treating this as settled.
Keeping a Working Forwarding Contact
RDAP redaction hides your details from public view, but renewal notices, transfer-approval emails, and required legal communications still have to reach somebody. A registrar’s privacy service typically layers a proxy contact address that forwards to your real inbox, which is tidier and more reliable than relying on RDAP’s redaction alone with no forwarding mechanism behind it.
How to Check and Enable It
Step 1: Run a Fresh Lookup on Your Own Domain
Use your registrar’s own lookup tool or a public RDAP client to see exactly what’s currently visible on your domain’s record. This replaces the old assumption that privacy protection is either fully on or fully off — check the actual current state instead of guessing.
Step 2: Locate the Privacy Setting
Log in to your registrar’s dashboard and look for a setting labelled Domain Privacy, WHOIS Privacy, ID Protection, or RDAP Privacy — naming varies, but it’s almost always on the domain’s overview or management tab. Most major registrars (Namecheap, Hostinger, GoDaddy among them) bundle this free with every new domain by default now.
Step 3: Enable It and Confirm the Contact Change
Turn the setting on. Some registrars apply it instantly; others queue a short propagation delay of a few hours. ICANN rules require an email confirmation to your registered address during this window — don’t ignore this message, since failing to confirm contact details within the required window can suspend the domain.
Step 4: Repeat for Every Domain and ccTLD You Manage
Privacy settings are per-domain, not account-wide. If you manage domains for multiple clients or projects, check each one individually, and pay particular attention to any ccTLDs in the list — they’re the ones least likely to already be covered by the new default.
Practical Tips
- Don’t assume every domain you own is now automatically protected just because you’ve heard WHOIS was replaced — the transition was rolled out gTLD by gTLD and registrar by registrar, so verify rather than assume.
- If a registrar still charges extra for privacy protection on a gTLD, treat that as a signal to compare pricing with a competitor rather than paying — the underlying redaction is now standard infrastructure, not a premium add-on, for most gTLDs.
- Keep your actual contact email current with the registrar even after enabling privacy, since renewal notices and legal communications still route through it behind the redaction layer.
- Some ccTLDs have registry-level rules that limit or exclude privacy protection outright — check this before assuming it’s available for every domain type you register.
Common Mistakes
- Assuming the RDAP transition automatically protects every domain you own, including ccTLDs and pre-2025 registrations that were never re-checked.
- Ignoring the ICANN contact-verification email that arrives after registering or updating a domain — missing this can suspend the domain regardless of privacy settings.
- Registering a client’s domain using your own personal contact details on a ccTLD without privacy protection, then transferring ownership later without ever fixing the exposed record in between.
- Assuming privacy protection hides the domain from search engines or visitors — it only affects the registration record, not anything visible on the website itself.
When to Use This vs Alternatives
For a standard gTLD registered today, RDAP’s default redaction already covers the core exposure risk — registrar privacy protection is still worth enabling for the forwarding-contact convenience and belt-and-braces consistency, but it’s no longer the single thing standing between your address and the public internet the way it was before 2025. For a ccTLD, or a domain registered before the transition, treat privacy protection as essential rather than optional until you’ve personally verified what’s showing in a live lookup.
If you’ve already worked through choosing the right domain name and pointing that domain at your hosting, checking your registration record’s current exposure is the natural next step before the site goes fully live. It’s a different concern from ownership itself — if you’re planning to move a domain between registrars, see the step-by-step guide to transferring a domain name to a new registrar, since privacy settings typically need re-confirming after a transfer completes.
For background on the registry structure WHOIS and RDAP both sit within, see the step-by-step guide to making a website alongside IANA’s domain name services overview.
Conclusion
The RDAP transition genuinely improved the default privacy picture for most standard domains since January 2025, but it’s not a blanket fix — ccTLDs, older registrations, and inconsistent early rollout are the real gaps left behind. Run a live lookup on every domain you own or manage, don’t assume the old advice or the new headline covers your specific case, and treat registrar privacy protection as the belt-and-braces layer it now is rather than the last line of defence it used to be.

Etienne Basson works with website systems, SEO-driven site architecture, and technical implementation. He writes practical guides on building, structuring, and optimizing websites for long-term growth.