WHOIS Privacy Is a Double-Edged Sword

GDPR redacted WHOIS for everyone in 2018 — grandma and the phishing operator got the same anonymity on the same day. The access system meant to balance it was estimated at $27M, then shelved. Only one edge of the sword ever shipped.

For about twenty years, registering a domain meant publishing your home address to the entire internet. Name, street, email, phone — typed into a WHOIS record that anyone could query over an unauthenticated TCP connection on port 43, no account, no log, no rate limit that mattered. Spammers wrote scrapers against it in an afternoon. The “privacy” industry that grew up around this — proxy services that would put their address in the record instead of yours, for a yearly fee — existed only because the default was so aggressively hostile to the people it described. You paid a middleman to undo a design decision from 1982.

Then, on May 25, 2018, the default flipped for the entire world in a single day, and it flipped by accident of jurisdiction.

GDPR did in one week what ICANN couldn’t do in a decade

The General Data Protection Regulation took effect and made publishing an EU resident’s personal data to an open directory legally radioactive. ICANN, whose contracts had required registrars to publish exactly that data, had days to avoid ordering thousands of companies to break European law. So it adopted the Temporary Specification for gTLD Registration Data on May 17, 2018 — an emergency rewrite of the rules that told every registrar to redact personal fields from public WHOIS and expose only the skeleton: sponsoring registrar, domain status, creation and expiration dates.

Here’s the part worth sitting with. GDPR only protects people in the EU. But maintaining one redacted output for Europeans and a second exposed output for everyone else was more engineering and more legal risk than it was worth, so most registrars just redacted everyone, everywhere. A German regulation written for German citizens became the privacy policy for a domain registered in Ohio by an American company. The paid privacy-proxy business had its core product handed away for free, overnight, to the whole planet — including the planet’s scammers.

That’s the first edge of the sword, and it’s genuinely good. Individuals stopped broadcasting their home address to register a blog. Stalkers lost a free lookup. The absurd 40-year default — to own a domain you must dox yourself — finally died. I don’t want it back, and neither do you.

The other edge got handed to everyone too

WHOIS was never only a privacy disaster. It was also the fastest, cheapest accountability layer the internet had. A brand-protection lawyer chasing a counterfeit storefront, a security team pivoting across a phishing campaign’s infrastructure, an abuse desk trying to reach a domain’s actual owner — all of them did it with a one-line WHOIS query, at scale, for free. Redaction didn’t carve out an exception for them. The phishing operator registering forty lookalike domains got exactly the same blanket anonymity as the individual blogger, on the same day, from the same policy. There is no “legitimate investigator” bit in the protocol.

The redesign was supposed to fix precisely this. The plan — the System for Standardized Access/Disclosure, SSAD — was a centralized gateway where an accredited requester with a legitimate purpose could ask for the redacted data and get it through a standardized, accountable process. Privacy by default, access by credential. That’s a coherent bargain, and if it existed, this essay wouldn’t.

It doesn’t exist. In January 2022, ICANN’s own operational assessment priced SSAD at roughly $20–27 million to build over three to four years, with per-query fees that would fund it and years before it answered a single request. By early 2023 the community had quietly shelved it as a white elephant and fell back to the Registration Data Request System (RDRS) — not the promised standardized-access machine, but a ticketing pilot that routes a disclosure request to a registrar who then decides, by hand, whether to answer. No guarantee, no SLA, no scale.

Only one edge of the sword shipped

Sit with the asymmetry, because it’s the whole argument. The privacy side of this bargain deployed globally, for free, in about a week, driven by the hard forcing function of a law with real fines. The access side — the part that was supposed to keep redaction from becoming blanket cover for abuse — was estimated in the tens of millions, dragged through years of committee, and then abandoned for a manual fallback. One edge of the sword was forged and swung on day one. The other is still an IOU seven years later.

RDAP, the structured JSON protocol that formally replaced WHOIS for gTLDs on January 28, 2025, was engineered to do tiered access properly — authenticate the requester, return more fields to those with standing. The plumbing supports the good version of this. But a protocol that can differentiate access doesn’t differentiate anything until someone builds and funds the authority that decides who gets what — and that authority is the exact piece that got shelved. So RDAP mostly returns the same redacted skeleton to everyone, over HTTPS instead of port 43. Better transport, same policy gap. The Registration Data Policy that became binding on August 21, 2025 made the redaction permanent consensus policy — locking in the edge that shipped while the missing edge stayed missing.

So when someone tells you WHOIS privacy is an unqualified win, they’re describing one edge of a sword that was designed to have two. The privacy is real and I’d defend it. But “double-edged” was never a warning that privacy is bad — it’s a description of a tool built with a cutting side and a guard, where only the cutting side was ever attached. We redacted the world’s registration data in a week because a law made us. We were supposed to build the accountable way back in. We estimated the cost, flinched, and didn’t. The sword works fine. It’s the handle that’s missing.

Continue the conversation

← Back to Blog