Domain Privacy and the Registration Record, Without the Scare Stories
Privacy services are sold with a story about spam and stalkers. The real reason to understand them is duller and more important: privacy sits between you and the one email that lets you move your name.
Domain privacy is sold at checkout with a small amount of theatre: a warning about your home address appearing in a public database, a tick box, a fee. The warning was once accurate, is now largely obsolete, and distracts from the only consequence of the setting that will ever affect you in practice.
Here is what is actually in the record, what privacy does to it, and the one thing to remember before you try to move a name.
What registration data is for
Every domain registration creates a record at the registrar containing the holder's contact details. The record exists so that somebody with a legitimate need — a registry, a registrar, a party in a dispute — can reach the holder of a name. It is not a directory and was never intended as one, though for a couple of decades it functioned as one by accident.
The lookup protocol most people have heard of is WHOIS. It has been progressively superseded by RDAP, which returns structured data and supports differentiated access, and the practical difference for you is nil: both answer the question "who is this name registered through, and when does it expire".
What a public lookup still shows
Under ICANN's current registration data rules, registrars redact most personal contact information from public responses. Providers do this by default — Squarespace's documentation states that it "generally redacts customers' personal contact information within registration data" when a public lookup is performed, and this is standard practice rather than a Squarespace feature.
What a lookup still shows, and what it now hides
So the personal fields are mostly already gone before any privacy service is involved. What a public lookup shows is the operational skeleton:
- the registrar of record and its website
- the creation, updated and expiry dates
- domain status codes, including transfer locks
- the nameservers currently answering for the name
- a way to contact the registrant, usually a web form or a forwarding address
That is genuinely useful information and none of it is private. The dates in particular are facts about your own asset that you should be able to read at any time.
What a privacy service adds
A privacy or proxy service goes a step further: it substitutes the provider's own details for yours in the record and, in many implementations, provides a forwarding address so that mail sent to the registrant contact reaches you without exposing your address.
Check which one you were sold
Privacy service
You stay the registrant. Your contact details are shielded.
Proxy service
The provider’s own entity is the registrant, and the name is licensed to you.
There are two distinct models and the distinction is the reason this card exists.
A privacy service keeps you as the registrant and shields the contact details. The registry still regards you as the holder.
A proxy service goes further and puts the provider's own entity in the record as the registrant, licensing the name to you. These have become rare among mainstream registrars, and for good reason: the arrangement puts a third party between you and the name you paid for.
Most consumer offerings today are privacy rather than proxy, and most reputable providers say which one they are selling. Check. The difference only reveals itself when something goes wrong, which is the worst possible moment to discover it.
The cost, and who includes it
Privacy is sometimes free and sometimes a line item. Squarespace's domains documentation states that domain privacy is included at no charge on all domains registered through Squarespace. Hostinger's support pages describe WHOIS privacy as included. Other providers sell it as a separate annual product, and the difference compounds over the decade a domain typically lives.
It is a reasonable thing to weigh when comparing where a name should live. It is not, on its own, a reason to pick a registrar.
Worth knowing: some country-code registries set their own rules, and a handful require registrant details to be published regardless of what a registrar would prefer. If you are registering outside the generic top-level domains, the registry's policy wins.
The part that actually matters
Here is the operational consequence, and it is the only one most people will ever meet.
Privacy off, transfer, privacy on
When you ask to move a domain to another registrar, the authorisation code is sent to the registrant contact email address on the record. If a privacy service is intercepting mail to that address and its forwarding is imperfect, the code does not reach you and the transfer stalls for reasons that are invisible from your side.
This is why Wix's transfer documentation instructs you to disable Private Registration before beginning a transfer, specifically so that you do not miss the transfer-related emails. It is not Wix being awkward; it is the predictable interaction between a forwarding service and a one-time secret.
The habit worth forming: privacy off, transfer, privacy on at the new registrar. It is off for a few days, during which the record shows contact details that were mostly redacted anyway, and the transfer completes without a mystery.
Privacy does not travel
A privacy service is a product sold by a registrar. It ends when your relationship with that registrar ends.
So a transfer leaves the name briefly unprotected, and nothing at the new registrar switches it back on unless you do. Add it to the list of things to reinstate on arrival, along with auto-renew and the transfer lock, which is also cleared by the move and should be re-applied once the dust settles. The full arrival checklist is in the transferring a domain away from a website builder guide.
What privacy will not do for you
It will not stop unsolicited mail about your domain. Registration-renewal scams and search-engine-submission letters have been sent to redacted domains for years, because the senders work from zone files and expiry data rather than from contact records.
It will not hide ownership from anyone determined and equipped. Registrars disclose to legitimate requesters under the applicable policies, and a court order reaches through a privacy service without difficulty.
It will not protect a name you have let expire. Once a registration lapses, privacy is beside the point and the clock described in expired domains and the redemption window takes over.
What it will do is keep a home address off a page anyone can load, which for a sole trader registering a business name from a kitchen table is a perfectly good reason to want it.
The short version
Turn privacy on if your registrar includes it, which several now do. Confirm it is privacy rather than a proxy arrangement that puts someone else's name in the registrant field. Turn it off before a transfer and on again afterwards. And never let it obscure the field it sits on top of: the registrant contact email address is the one that has to work, and checking it is covered in who owns the domain your builder registered.
Whether a provider includes privacy at all is one of the things worth comparing before you accept a domain as part of a plan, alongside what it registers and what it charges in year two — all of which is on free domain website builder plans.
Queries at the desk
Do I need to pay for domain privacy?
Does domain privacy stop a domain transfer?
What is the difference between a privacy service and a proxy service?
Will privacy stop spam about my domain?
Most people arrive at this desk while deciding whether to take a provider up on its domain offer. That decision is worked through in full on free domain website builder plans, which sets out what each provider registers, on whose behalf, and what happens in month thirteen.