Skip to main content
.com domains from $2.99 — free WHOIS privacy on every name

Registrant record · Beginner · 2 min

How to enable whois privacy — Mask the Registrant, Keep the Approval Path Working

You want your home address off a public database without breaking the mail path that domain transfers and certificate validation both quietly depend on.

The short answer

Turn privacy on in the domain's settings and the public record shows a proxy instead of your name, address and phone number. What it does not do is remove the record: registry status, creation and expiry dates and your nameservers all stay visible, because they have to be.

The part worth attention is the relay address that replaces your email. Transfer approvals and some certificate validation messages travel through it, so it is now on your critical path. Send a message to it and time the reply before you need it in anger.

By the HostingFast team · Reviewed 24 August 2026

Beginner

Skill floor

4

Stages start to end

Free

Support, every tier

Proven

Run on the live stack

Two minutes in the client area, per domain. There is nothing to break and nothing to wait for; the public record updates on the registry's own refresh.

Worth doing on every name you hold rather than just the flagship, because a single unmasked domain in the same account is enough to link the rest of them.

What stays visible after you switch it on

Privacy swaps the registrant, admin and technical contacts for a proxy service. Everything structural remains: the registrar of record, the creation, updated and expiry dates, the registry status codes such as clientTransferProhibited, and the nameservers you have delegated to.

That matters because the visible half is the half an attacker uses. Nameservers tell them who runs your DNS. Status codes tell them whether the domain is locked. Expiry tells them when to watch. Privacy is worth having, and it is not a disguise.

The relay address is now on your critical path

Once privacy is on, the address in the public record is the proxy's, and it forwards to you. Domain transfer approvals go through that relay. So do some certificate authority validation emails, and so do registry notices. If the relay silently drops mail, you find out during a transfer with a clock running.

Test it deliberately: send a message from an outside account to the relay address shown in WHOIS and time how long it takes to reach you. Do it again after any change to your own mail setup, because a new SPF or DMARC policy on your side can start rejecting relayed mail that used to arrive.

Where privacy is unavailable, or already the default

It is not universal. Some registries publish certain fields regardless, and some ccTLDs impose their own rules on what a registrant may withhold. Nominet, for example, already withholds a private individual's address for a .uk domain used non-commercially, so paying for a proxy there buys you very little.

Check the specific TLD before assuming. The general shape is that gTLDs support proxy services broadly and ccTLDs each have their own policy, which is exactly the kind of detail that only shows up when the record does not look the way you expected.

What the account handles around this

Certificates issue and renew themselves, so the one routine job that depends on domain validation mostly happens without a human. ImunifyAV+ sweeps sites for malware, DDoS filtering is absorbed at the network edge, and daily backups mean a bad day is a restore rather than a rebuild.

Support is staffed at any hour, which matters here because relayed approval emails have short lifetimes and a habit of arriving out of office hours.

The network filtering that soaks up attacks before they reach a site

The stack these steps were measured on

Every walkthrough here is run against the platform we operate — cPanel, LiteSpeed in front of NVMe, Softaculous, WP-CLI over SSH — so the field names in the instructions are the field names on your screen.

Support is a human being at any hour, and the scope covers the awkward practical questions other hosts bounce straight back at you.

  • What is hidden, and what plainly is not
  • The relay treated as a live dependency
  • Verification commands, not hopeful refreshing
  • Engineers on support at any hour

Why HostingFast

Standard on every plan

Honest about the limits

The page lists what stays public — status codes, dates, nameservers — instead of implying that privacy makes the record disappear.

The relay treated seriously

Transfer approvals and validation mail travel through the proxy address, so testing it is a step rather than an afterthought.

Registry differences named

Some TLDs already withhold an individual's address by default, and the page says so rather than selling you something you have.

4 steps, no padding

Four actions, each finishing in something you can see, including a before-and-after look at the public record.

Applied across the account

The sequence covers every name you hold, because one unmasked domain in the same account undoes the rest.

Engineers on call

Approval mail through a relay arrives at awkward hours; support is staffed for all of them.

Quick Start

From order to online

  1. 1

    Read the current record before you change it

    Run whois yourdomain.com from a machine and note exactly which fields are populated. This is your before shot, and it tells you whether the registry already withholds what you were about to pay to hide.

  2. 2

    Enable privacy on every name in the account

    Switch it on domain by domain in the client area, not just for the main brand. A single name still carrying your details is enough to associate every other domain registered against the same contact set.

  3. 3

    Keep the underlying registrant data accurate

    The proxy sits in front of your real details; it does not replace them. Registries require accurate registrant data, and a domain with false information behind the mask can be suspended, which is a far worse outcome than being findable.

  4. 4

    Send a message to the relay and time the reply

    Read the proxy address out of the fresh whois output, mail it from an outside account, and note how long it takes to reach you. Repeat after any change to your own SPF or DMARC policy, because a stricter policy can start rejecting relayed mail.

Built In

Loaded onto every plan

  • Mailboxes that run on your own domain name
  • Support staffed by humans, every hour of the day
  • Spam and virus screening on every mailbox as standard
  • Free SSL on every plan, renewed before it can lapse
  • NVMe storage on every tier, not only the expensive ones
  • Per-site PHP version switching in the control panel
  • WordPress and 400+ other applications in one click
  • DDoS filtering absorbed at the network edge
  • Webmail in the browser plus IMAP, POP and SMTP
  • Staging environments for testing before you ship

Frequently Asked

What people ask us most often

Will privacy stop a domain transfer from completing?

It should not, but it adds a hop that can fail. The auth code and the approval request go to the proxy address and are relayed to you, so a relay that drops or delays mail costs you the approval window. Some registrars also require privacy to be lifted for the duration of an outbound transfer. Test the relay first, and be ready to switch privacy off for a day if the code never arrives.

Can a certificate authority still validate my domain?

Yes. DNS-based and HTTP-based validation never look at WHOIS at all, and those are what automated issuance uses, so AutoSSL is unaffected. Only the older email validation method reads the registrant address, and with privacy on it goes to the relay. If you are ever asked to receive a validation email, that relay is the address to watch.

Does privacy hide my nameservers or my server IP?

No, and it was never meant to. Nameservers are published in the delegation because resolvers need them, and your A record maps the name to an address for the same reason. Anyone can read both with dig. If hiding the origin matters, that is a job for a proxy or CDN in front of the site, not for the registrant record.

Is privacy worth paying for on a .uk domain?

Often not. Nominet already withholds a private individual's address for a .uk name that is not being used for business, so the details you were worried about may not be published in the first place. Run whois against the domain and look at what is genuinely there before buying a proxy for it.

Keep reading

Changing hosts? Run through our checklist first.

A straightforward sequence for a switch your visitors never feel: which files move first, how to shift email across without losing a single message, the right moment to repoint DNS, and the two mistakes behind almost all the downtime we get asked to rescue.

You'll get the checklist email, then occasional pointers on keeping a site running fast. Unsubscribe the moment you want out — the privacy policy covers the rest.

Keep the record private, the site quick.

Every plan carries the essentials other hosts bill as extras, and the support queue is answered by engineers rather than a macro.

View Dedicated Cloud plans