Registrant record · Beginner · 2 min
How to enable whois privacy — Mask the Registrant, Keep the Approval Path Working
You want your home address off a public database without breaking the mail path that domain transfers and certificate validation both quietly depend on.
The short answer
Turn privacy on in the domain's settings and the public record shows a proxy instead of your name, address and phone number. What it does not do is remove the record: registry status, creation and expiry dates and your nameservers all stay visible, because they have to be.
The part worth attention is the relay address that replaces your email. Transfer approvals and some certificate validation messages travel through it, so it is now on your critical path. Send a message to it and time the reply before you need it in anger.
By the HostingFast team · Reviewed 24 August 2026
Beginner
Skill floor
4
Stages start to end
Free
Support, every tier
Proven
Run on the live stack
Two minutes in the client area, per domain. There is nothing to break and nothing to wait for; the public record updates on the registry's own refresh.
Worth doing on every name you hold rather than just the flagship, because a single unmasked domain in the same account is enough to link the rest of them.
What stays visible after you switch it on
Privacy swaps the registrant, admin and technical contacts for a proxy service. Everything structural remains: the registrar of record, the creation, updated and expiry dates, the registry status codes such as clientTransferProhibited, and the nameservers you have delegated to.
That matters because the visible half is the half an attacker uses. Nameservers tell them who runs your DNS. Status codes tell them whether the domain is locked. Expiry tells them when to watch. Privacy is worth having, and it is not a disguise.
The relay address is now on your critical path
Once privacy is on, the address in the public record is the proxy's, and it forwards to you. Domain transfer approvals go through that relay. So do some certificate authority validation emails, and so do registry notices. If the relay silently drops mail, you find out during a transfer with a clock running.
Test it deliberately: send a message from an outside account to the relay address shown in WHOIS and time how long it takes to reach you. Do it again after any change to your own mail setup, because a new SPF or DMARC policy on your side can start rejecting relayed mail that used to arrive.
Where privacy is unavailable, or already the default
It is not universal. Some registries publish certain fields regardless, and some ccTLDs impose their own rules on what a registrant may withhold. Nominet, for example, already withholds a private individual's address for a .uk domain used non-commercially, so paying for a proxy there buys you very little.
Check the specific TLD before assuming. The general shape is that gTLDs support proxy services broadly and ccTLDs each have their own policy, which is exactly the kind of detail that only shows up when the record does not look the way you expected.
What the account handles around this
Certificates issue and renew themselves, so the one routine job that depends on domain validation mostly happens without a human. ImunifyAV+ sweeps sites for malware, DDoS filtering is absorbed at the network edge, and daily backups mean a bad day is a restore rather than a rebuild.
Support is staffed at any hour, which matters here because relayed approval emails have short lifetimes and a habit of arriving out of office hours.

The stack these steps were measured on
Every walkthrough here is run against the platform we operate — cPanel, LiteSpeed in front of NVMe, Softaculous, WP-CLI over SSH — so the field names in the instructions are the field names on your screen.
Support is a human being at any hour, and the scope covers the awkward practical questions other hosts bounce straight back at you.
- What is hidden, and what plainly is not
- The relay treated as a live dependency
- Verification commands, not hopeful refreshing
- Engineers on support at any hour
Why HostingFast
Standard on every plan
Honest about the limits
The page lists what stays public — status codes, dates, nameservers — instead of implying that privacy makes the record disappear.
The relay treated seriously
Transfer approvals and validation mail travel through the proxy address, so testing it is a step rather than an afterthought.
Registry differences named
Some TLDs already withhold an individual's address by default, and the page says so rather than selling you something you have.
4 steps, no padding
Four actions, each finishing in something you can see, including a before-and-after look at the public record.
Applied across the account
The sequence covers every name you hold, because one unmasked domain in the same account undoes the rest.
Engineers on call
Approval mail through a relay arrives at awkward hours; support is staffed for all of them.
Quick Start
From order to online
- 1
Read the current record before you change it
Run whois yourdomain.com from a machine and note exactly which fields are populated. This is your before shot, and it tells you whether the registry already withholds what you were about to pay to hide.
- 2
Enable privacy on every name in the account
Switch it on domain by domain in the client area, not just for the main brand. A single name still carrying your details is enough to associate every other domain registered against the same contact set.
- 3
Keep the underlying registrant data accurate
The proxy sits in front of your real details; it does not replace them. Registries require accurate registrant data, and a domain with false information behind the mask can be suspended, which is a far worse outcome than being findable.
- 4
Send a message to the relay and time the reply
Read the proxy address out of the fresh whois output, mail it from an outside account, and note how long it takes to reach you. Repeat after any change to your own SPF or DMARC policy, because a stricter policy can start rejecting relayed mail.
Built In
Loaded onto every plan
- Mailboxes that run on your own domain name
- Support staffed by humans, every hour of the day
- Spam and virus screening on every mailbox as standard
- Free SSL on every plan, renewed before it can lapse
- NVMe storage on every tier, not only the expensive ones
- Per-site PHP version switching in the control panel
- WordPress and 400+ other applications in one click
- DDoS filtering absorbed at the network edge
- Webmail in the browser plus IMAP, POP and SMTP
- Staging environments for testing before you ship
Frequently Asked
What people ask us most often
Will privacy stop a domain transfer from completing?
It should not, but it adds a hop that can fail. The auth code and the approval request go to the proxy address and are relayed to you, so a relay that drops or delays mail costs you the approval window. Some registrars also require privacy to be lifted for the duration of an outbound transfer. Test the relay first, and be ready to switch privacy off for a day if the code never arrives.
Can a certificate authority still validate my domain?
Yes. DNS-based and HTTP-based validation never look at WHOIS at all, and those are what automated issuance uses, so AutoSSL is unaffected. Only the older email validation method reads the registrant address, and with privacy on it goes to the relay. If you are ever asked to receive a validation email, that relay is the address to watch.
Does privacy hide my nameservers or my server IP?
No, and it was never meant to. Nameservers are published in the delegation because resolvers need them, and your A record maps the name to an address for the same reason. Anyone can read both with dig. If hiding the origin matters, that is a job for a proxy or CDN in front of the site, not for the registrant record.
Is privacy worth paying for on a .uk domain?
Often not. Nominet already withholds a private individual's address for a .uk name that is not being used for business, so the details you were worried about may not be published in the first place. Run whois against the domain and look at what is genuinely there before buying a proxy for it.
Keep reading
How to Install a LAMP Stack
Build the stack yourself on a fresh server, with the package choices and the first hardening pass explained.
How to Hide the WordPress Login Page
Move the login endpoint and cut the automated traffic hitting it, without locking yourself out.
Domain Privacy (Glossary)
The definition this page leans on, with the registry relationship spelled out.
Dedicated Cloud
Dedicated cloud resources when a shared account is no longer the right shape.
Charity Hosting
Discounted hosting for registered charities, on the same NVMe platform as everything else.
Changing hosts? Run through our checklist first.
A straightforward sequence for a switch your visitors never feel: which files move first, how to shift email across without losing a single message, the right moment to repoint DNS, and the two mistakes behind almost all the downtime we get asked to rescue.
Keep the record private, the site quick.
Every plan carries the essentials other hosts bill as extras, and the support queue is answered by engineers rather than a macro.
View Dedicated Cloud plans