Turn it on before you register, not after. Domain registration records have historically been public, and registrant data is a standard harvesting source โ which means registering a domain for email privacy without WHOIS privacy trades an email exposure for a name-and-postal-address one. Most registrars now include privacy protection free. It's a checkbox, and it matters more than almost anything else in the setup.
What WHOIS exposes
WHOIS is the public directory of domain registration. Historically a lookup returned the registrant's name, postal address, phone number and email โ for anyone who asked, at no cost, in bulk.
That's an obvious harvesting target, and it has been harvested for decades. It's also why registering a domain often produces an immediate wave of unsolicited mail offering SEO services and web design: those senders are reading the registry.
What changed
The GDPR forced significant redaction of personal data in WHOIS for registrants in scope, and many registrars now redact by default regardless of jurisdiction. Combined with registrar privacy services, the raw exposure is far smaller than it was a decade ago.
Two reasons not to rely on that alone: coverage varies by registrar and by TLD, and some extensions have their own rules. Turning privacy on explicitly costs nothing and removes the uncertainty.
How privacy protection works
The registrar substitutes its own details โ or a proxy service's โ for yours in the public record. Queries return the proxy's contact information, and legitimate correspondence is forwarded on to you.
Usually free now, and a paid add-on at a minority of registrars. If yours charges meaningfully for it, that's a reasonable prompt to compare registrars.
What it doesn't do
- Your registrar still knows who you are. Privacy protection hides you from the public, not from the company you bought the domain from.
- It can be pierced legally. Court orders and valid legal process can compel disclosure. It is not anonymity.
- Some TLDs don't allow it. A few country-code extensions require public registrant data. Check before choosing an extension if this matters.
- Historical records may persist. If a domain was ever registered without privacy, archived WHOIS data may still exist elsewhere.
- It doesn't hide the domain. That you own it and that mail flows to it is still observable.
The specific risk if you skip it
You register a domain to stop giving companies your real email address. Without privacy, the registration publishes your full name, home address and phone number โ data that's harder to change than an email address and more useful to a data broker.
That's a strictly worse position than where you started, arrived at while trying to improve things. It's the single most avoidable mistake in the whole custom-domain approach.
The setup, in order
- Check privacy protection is included before choosing a registrar.
- Enable it during registration, not afterwards โ even brief public exposure gets scraped.
- Verify with a WHOIS lookup a day later that your details aren't showing.
- Use a dedicated address as the registrant contact, not your primary โ the proxy forwards to it, and it will attract solicitation.
- Turn on auto-renew. Unrelated to privacy, but a lapsed domain takes every alias with it.
The honest framing
A custom domain gives you control over your email namespace and costs you a little anonymity: the domain is registered to someone, and it's a consistent identifier across every service you use it on. WHOIS privacy closes the first half of that gap. The second half is inherent. What aliases do and don't hide