What is WHOIS, and why is most of it hidden now?
WHOIS is the long-standing public directory of domain registration details — and the information it once exposed has largely been withdrawn, primarily because of data protection law.
What it originally contained. For every domain: the registrant's name, organisation, postal address, telephone number and email, plus administrative and technical contacts, the registrar, creation and expiry dates, and the name servers. All publicly queryable by anyone, without authentication.
Why it was built that way. WHOIS dates from an era when the network was small and operators needed to contact each other about technical problems. Publishing contact details was a practical necessity among a community that largely knew one another.
What changed. The GDPR, applying from 2018, made publishing the personal data of private individuals without a lawful basis untenable. Registries and registrars responded by redacting personal fields from public output, generally replacing them with a generic message or an anonymised forwarding address.
Privacy and proxy services had already been widely used by registrants who did not want their home address published — a reasonable concern given that domain registration for a personal website exposed exactly that.
What you can still see: the registrar, creation, update and expiry dates, name servers, domain status codes, and — usually — details for domains registered to organisations rather than individuals, since organisational contact data is not personal data in the same way.
How to reach a registrant now: most registrars provide an anonymised contact form or forwarding email, so communication is still possible without disclosure. Requests for the underlying data can be made to the registrar with a stated lawful basis, and law enforcement and intellectual property routes exist.
RDAP — the Registration Data Access Protocol — is the modern replacement for the WHOIS protocol itself. It provides structured, standardised responses and, crucially, supports differentiated access, so authenticated requesters with a legitimate purpose can receive more than anonymous ones. This is the direction of travel.
The continuing argument. Security researchers, brand protection teams and anti-abuse investigators argue that redaction has hampered work against phishing and fraud; privacy advocates argue publication was never proportionate. Both positions have merit and the balance is still being worked out through policy processes.