privacy/proxy service
A service that keeps a registrant The person or organization that holds a domain name registration. Full definition of registrant's personal contact details out of public registration data The information kept about a domain and its owner. Full definition of registration data. A privacy service lists the real registrant with other contact details. A proxy service registers the name itself and lets the customer use it. Details may still be disclosed, for example after legal requests.
- category
- Registration data and privacy
A privacy or proxy service keeps a domain owner’s own contact details out of the public registration Obtaining the right to use a domain name for a set period. Full definition of registration record and shows the service’s details instead. Messages can reach the owner through the service, and in some situations the owner’s identity can be revealed. The two kinds differ in who is legally the registrant.
What a privacy or proxy service is
It is an add-on to a domain name A readable internet name made of labels separated by dots. Full definition of domain name registration, offered by the registrar A company that registers domain names for customers with the registry. Full definition of registrar, a company affiliated with it, a reseller A business that sells domains using another registrar's accreditation. Full definition of reseller, or an unrelated company. Instead of the customer’s name, address, email and phone number, the public registration data (the RDDS Registration Data Directory Services ICANN's umbrella name for public lookup services for registration data, formerly WHOIS and now RDAP. Full definition of RDDS: today mainly RDAP Registration Data Access Protocol The modern protocol for looking up domain registration data, replacing WHOIS. Full definition of RDAP, historically WHOIS The legacy lookup service for domain registration data, now replaced by RDAP for gTLDs. Full definition of WHOIS) show the provider’s contact details.
For gTLD generic top-level domain A top-level domain not tied to a country, run under ICANN contracts. Full definition of gTLD, the rules are in the Specification on Privacy and Proxy Registrations, part of the RAA Registrar Accreditation Agreement The contract between ICANN and each accredited registrar. Full definition of RAA that every ICANN-accredited registrar signs (current text approved on 21 January 2024). For services offered by the registrar, its affiliates or resellers, the provider must publish its terms and price, a contact for reporting abuse or infringement of trademarks and other rights, and the circumstances in which it relays messages, ends the service and reveals the customer.
The registrar keeps the customer’s real contact details and includes them in its data escrow Backup copies of registration data held by an independent agent in case a registry or registrar fails. Full definition of data escrow deposits. Registrants are entitled to know which provider is affiliated with their registrar, and must not face deceptive notices or hidden fees.
What counts is how a service works, not its marketing name (“WHOIS privacy”, “ID protection”, “proxy”).
Privacy versus proxy: who is the legal holder
- Privacy service: the customer is the registrant. Only the contact details shown publicly belong to the provider.
- Proxy service: the provider is the registrant of record and licenses the use of the name to the customer, whose position depends on its contract with the provider.
As of October 2026, under the RAA, anyone who licenses a name to someone else remains the registrant of record and accepts liability for harm caused by wrongful use of the name, unless it discloses the licensee’s identity and contact details within seven days to a party that provides reasonable evidence of actionable harm.
How messages reach you
Relay means the provider forwards a third party’s message to the customer, or tells the customer that someone is trying to make contact. Under the current specification, each provider decides when it relays and publishes those circumstances.
The PPSAI Privacy and Proxy Services Accreditation Issues ICANN's long-running, unfinished effort to accredit privacy and proxy service providers. Full definition of PPSAI recommendations, adopted but not yet in force, would set common rules: relay every communication required by the RAA and consensus policy An ICANN community rule that gTLD registries and registrars must follow. Full definition of consensus policy, and either all other electronic requests (with spam Unwanted bulk messages, which count as DNS abuse only when used to deliver other abuse. Full definition of spam filters allowed) or at least those alleging domain name abuse. Requesters would be told about a persistent delivery failure.
A separate mechanism needs no privacy service. When a gTLD registrar redacts personal data under the Registration Data Policy ICANN's policy on collecting, publishing and disclosing gTLD registration data. Full definition of Registration Data Policy, it must publish an anonymized email address A forwarding address or web form that reaches a registrant without showing the real email. Full definition of anonymized email address or a web form that does not identify the contact. For a name using an affiliated privacy or proxy service, nothing is redacted: the provider’s full data are published, possibly with its pseudonymized email.
When your details can be revealed
Reveal covers two actions: disclosure, to one requester, and publication, in the public record. Today each provider reveals according to its published terms. The PPSAI recommendations, not yet in force, would add a framework for requests from trademark and copyright owners; a future framework for law enforcement request A request from police or similar authorities for registration data or action on a domain. Full definition of law enforcement request would include an exception for the customer’s safety.
Another route is the UDRP Uniform Domain-Name Dispute-Resolution Policy ICANN's out-of-court process for trademark disputes over domain names. Full definition of UDRP: when a UDRP complaint names the privacy or proxy service, the registrar or the service may disclose the underlying registrant. WIPO World Intellectual Property Organization The United Nations agency whose center handles many domain name disputes. Full definition of WIPO passes those details to the complainant The party that files a domain dispute, usually a trademark owner. Full definition of complainant, invites it to amend the complaint, and notifies all contacts, including the underlying registrant.
An example: the registrant of example.com uses its registrar’s affiliated privacy service, so the RDAP record shows the service’s details. A trademark owner writes to the service’s abuse contact The published contact where registrars and registries receive abuse reports. Full definition of abuse contact, and the message may be forwarded according to its published relay terms. If the trademark owner then files a UDRP complaint against the service, the registrant’s details may be disclosed and, if the complaint is filed with WIPO, the registrant is notified.
The unfinished accreditation
The PPSAI policy work is meant to replace the specification with an accreditation program. The ICANN Board ICANN's board of directors, which adopts policies and approves key decisions. Full definition of ICANN Board adopted its 21 recommendations on 9 August 2016. Implementation paused in 2019 because of the GDPR General Data Protection Regulation The European Union data protection law that led to hiding personal data in WHOIS. Full definition of GDPR work and restarted in June 2024. ICANN Internet Corporation for Assigned Names and Numbers The nonprofit that coordinates the global DNS and gTLD policy. Full definition of ICANN published an Implementation Plan in January 2026; as of its May 2026 briefing, no draft consensus policy had been shared. One open question was whether a standalone program is needed at all. As of October 2026, no provider is accredited, and the RAA specification, first set to expire on 1 January 2017, still applies.
Is it still needed after the GDPR?
Under the Registration Data Policy (in force since 21 August 2025, revised on 12 May 2026), gTLD registrars must redact personal data where the law requires it and may do so in other cases. They may consider whether the registrant is a company and where it is located. redaction Hiding personal data from public domain registration lookups. Full definition of redaction is not guaranteed: the GDPR does not cover data about companies, and a registrant can consent to publication.
In the European Union (EU), the NIS2 Directive on measures for a high common level of cybersecurity across the Union A European Union cybersecurity directive with rules on accurate domain registration data. Full definition of NIS2 Directive requires registry The central database and system of a top-level domain, or loosely the organization that runs it. Full definition of registry and registrars, through each member state’s law, to collect accurate registration data, publish the data that are not personal, and answer access requests within 72 hours (as of October 2026). A privacy service does not change what the registrar must collect.
For an individual in the EU at a gTLD registrar, redaction already hides most personal data. A privacy or proxy service mainly adds a consistent masked contact, coverage where redaction is optional and, with a proxy, a different registrant of record. Country-code domains follow the rules each registry publishes.