DEV Community

Memo
Memo

Posted on

WHOIS Redaction & Agency Risk: Why You Need to Track Real Domain Registrants

Article image
WHOIS Redaction & Agency Risk: Why You Need to Track Real Domain Registrants
For nearly three decades, managing domain names was a relatively transparent process. If a digital agency needed to know who owned a domain, when it expired, or which email address was tied to the registration, a public WHOIS query usually answered the question. WHOIS, formalized in 1982 under RFC 812, was a plain-text directory service running over an unencrypted port with no authentication and no structure — anyone could query any domain and get back whatever the registrar chose to publish.

That era is now fully over, and it closed in stages rather than all at once. The General Data Protection Regulation (GDPR), which took effect on May 25, 2018, made it unlawful to publish the personal data of EU residents by default, and WHOIS's open publication model put it in direct conflict with that rule. The Internet Corporation for Assigned Names and Numbers (ICANN) responded with a Temporary Specification that required registrars to redact registrant names, emails, and phone numbers from public view. Then, on January 28, 2025, ICANN went a step further and formally sunset the WHOIS protocol itself for generic top-level domains (gTLDs), replacing it with the Registration Data Access Protocol (RDAP).

The core privacy issue for agencies hasn't changed: almost all meaningful registrant data is now hidden from public view by default. But two things have changed since the original transition, and both raise the stakes for web design agencies, MSPs, and freelancers who manage domains on behalf of clients — a 2025 policy update that ties legal domain ownership directly to a specific data field, and the first real enforcement actions against registrars that don't comply. This guide walks through both, and why "we'll just look it up if we need to" is no longer a viable domain management strategy.


  1. The WHOIS-to-RDAP Transition Is Now Complete — and Enforced RDAP isn't just WHOIS with a privacy filter bolted on. It's a structurally different protocol: it returns machine-readable JSON instead of unstructured plain text, it runs over encrypted HTTPS instead of unauthenticated port 43, and it natively supports tiered, differentiated access — meaning a registrar can show the general public one view, an authenticated registrant a fuller view, and law enforcement or accredited requestors something closer to complete.

The transition has moved faster than many agencies realize:

The sunset is real and largely finished. By February 2025, 74 gTLD registries had already shut down their WHOIS services following the January 28 deadline. By September 2025, that number had climbed to 374 gTLDs with WHOIS disabled entirely.
RDAP query volume overtook WHOIS in June 2025. According to ICANN's own monthly registry activity reports, gTLD RDAP queries rose from roughly 7 billion per month in January 2025 to about 65 billion per month by August 2025, crossing WHOIS query volume for the first time that June.
Enforcement has teeth now. In January 2026, ICANN terminated the accreditation of a small US-based registrar, Brennercom, after it missed its remediation deadline for implementing RDAP — the first registrar accreditation revoked specifically over RDAP non-compliance. It's a small case (reports differ on whether the registrar managed a few dozen or just over 100 domains), but it establishes a precedent: RDAP compliance is now a termination-level contractual obligation for registrars, not an aspirational goal.
Coverage still isn't universal. RDAP is effectively mandatory for gTLDs (.com, .net, .org, and the newer generic extensions), where adoption sits above 99%. Country-code domains (ccTLDs) are a different story — ICANN doesn't control them directly, and independent tracking as of mid-2026 puts RDAP adoption among ccTLDs at under a third, with major holdouts including .de, .jp, .io, .co, and .us. If your agency manages a client's country-code domain, don't assume RDAP applies; WHOIS may still be the only lookup option, and it's still built on the old unauthenticated, unencrypted model.
Accessing non-public gTLD registration data now runs through ICANN's Registration Data Request Service (RDRS) — but agencies should go in with realistic expectations about what that service can and can't do for them (more on that below).


  1. The Policy Change That Actually Matters Most: August 2025's Ownership Rule This is the update that most agencies still haven't fully absorbed, and it changes the entire risk calculus of this article.

On August 21, 2025, ICANN's new Registration Data Policy took effect, replacing the interim rules that had governed redaction since 2018. Buried in the policy is a change with outsized consequences: the "Registrant Organization" field is no longer just a label — it now determines who is legally recognized as the domain's owner.

Here's how it works in practice:

If the Organization field on a domain's registration record is filled in, that organization is treated as the Registered Name Holder — the legal owner — regardless of whose name sits in the individual registrant field.
If the Organization field is left blank, the named individual becomes the legal owner by default.
Changing or removing the Organization field is now treated as a change of ownership at many registrars, which can trigger a mandatory transfer lock (commonly 60 days) before further changes or transfers are permitted.
The policy also moved the industry to a "thin" data model: registries and registrars are no longer required to collect or store separate Administrative, Billing, or Technical contact records — only the Registrant data set, trimming what even exists to potentially dispute over.
This turns Section 3 of the old playbook — "always list the client as Registrant Organization as a best practice" — from good advice into a legally load-bearing decision. It's no longer a matter of internal hygiene. The literal contents of that one field is now the first place a registrar, a court, or a UDRP panel will look when ownership is disputed. An agency that registers a client's domain with the Organization field blank, or filled in with the agency's own name "to keep things simple," may have just made itself the legal owner of someone else's intellectual property without realizing it.


  1. The Core Agency Risk: Three Ways This Goes Wrong Risk Vector A: The Rogue (or Simply Departed) Employee An agency builds a client's e-commerce site and tasks a developer with registering the domain. The developer registers it under a personal email, leaves the Organization field blank or fills it with their own freelance business name, and leaves the company two years later. When the agency goes to renew or transfer the domain, they don't have the registrar login — and under the August 2025 policy, the registration record may now show that former employee (or their business) as the legal owner, not just the technical contact. RDAP will show "REDACTED FOR PRIVACY" to the public, but internally, the agency has no clean record of who was supposed to be listed and who actually got listed. That gap is now a legal ownership gap, not just an access inconvenience.

Risk Vector B: The Client Dispute
If a client terminates the relationship, the agency is expected to hand over the assets the client owns. If the RDAP output just shows a generic privacy-proxy name and the agency's internal records are thin, a dispute is close to guaranteed. This isn't hypothetical — courts have ruled against agencies and developers who held onto client domains after a relationship ended. In one instructive case, a law firm representing an online travel company won a six-figure judgment against a web development firm that had hijacked the travel company's domains and diverted its revenue, later enforcing that judgment by having the domains seized through a court-appointed receiver. Without a clean internal paper trail showing the client was always the intended legal registrant, an agency accused of withholding a domain has a much weaker position — especially now that the Organization field itself is treated as ownership evidence.

Risk Vector C: Expiration and Hijacking
Registrars send renewal warnings to the Registrant Contact on file. If that's an old employee's inbox or a monitored-by-no-one alias, the warnings go unseen, the domain lapses, and it can be re-registered by someone else within hours. Recovering a lapsed or hijacked domain isn't simple: WIPO-administered UDRP disputes report roughly an 85% success rate for clear-cut cases, typically resolved in 45–60 days, with administrative fees in the $1,500–$4,000 range before legal costs. But UDRP requires proving the domain was registered and used in bad faith — a much harder bar to clear if the domain simply expired and was picked up by an unrelated buyer rather than a targeted squatter. Prevention is far cheaper than recovery in every one of these scenarios.


  1. Getting Non-Public Data Back: What RDRS Actually Delivers If your agency does need to formally request non-public registrant data — say, to resolve a dispute or investigate a hijacking — ICANN's Registration Data Request Service (RDRS) is the sanctioned channel. It's worth understanding its real limitations before counting on it:

RDRS finished a two-year pilot (November 2023–November 2025) and, in October 2025, the ICANN Board voted to extend it in its current pilot form through December 2027 rather than adopt a permanent replacement system yet.
Participation is voluntary for registrars, and it isn't universal. Registrar participation peaked at 95 registrars covering 60% of domains under management in February 2025, and had settled to roughly 78–80 registrars covering 46–47% of domains under management by the end of the pilot. If your client's registrar isn't a participant, RDRS simply doesn't apply.
Of requests submitted during the pilot, only about 26% were approved outright; 55% were denied, and the remaining ~19% were partially approved or found to involve data that was already public.
RDRS exists to serve requestors with a "legitimate interest" — law enforcement, intellectual property professionals, cybersecurity researchers, and similar categories. An agency trying to confirm which client owns a domain, absent something like an active legal dispute or IP claim, is not a strong fit for the service, and denial is a real possibility.
In May 2026, ICANN added a requirement for a 24-hour response window on "urgent" disclosure requests tied to imminent threats to life or safety — but this applies only to authenticated law enforcement requestors, and ICANN is still finalizing the authentication mechanism before that clock formally starts.
The takeaway: RDRS is a real but narrow tool, built mainly for legal and security professionals, running on a system that denies a majority of the requests it receives. It is not a safety net an agency can rely on to reconstruct lost ownership records after the fact.


  1. The Myth of the "Agency-Owned" Domain Some agencies simplify operations by registering every client domain under the agency's own name and Organization field. This was already a bad practice under the old rules — it made the agency legally liable for how the domain was used, and it created friction whenever a client wanted to migrate providers. Under the August 2025 policy, it's a bigger mistake, because the Organization field is now the authoritative signal of legal ownership that registrars, courts, and dispute panels will check first.

Best practice remains the same, but it now carries more legal weight than before: the client's legal business entity should be listed as the Registrant Organization. The agency should appear only as a Technical Contact where the registrar still supports one, or manage the domain through a delegated-access model that keeps operational control with the agency without making it the owner of record.


  1. The Solution: Deliberate Internal Tracking with InstaRenewal The end of public WHOIS lookups, combined with a policy that ties legal ownership to a specific field on the registration record, means agencies can't afford to manage domain data casually — a fragmented spreadsheet or "someone on the team probably remembers" isn't a real system. This is the exact gap InstaRenewal is built to close for domain, SSL, hosting, and plugin-license asset tracking.

How InstaRenewal helps:

A dedicated internal record of true ownership. When an agency registers or takes over a domain, it can log the actual Registrant Name, Organization, and contact email in InstaRenewal — independent of whatever the public RDAP output shows. Even with the registry record redacted, the agency has its own accurate reference on file, and a record of what should be in the Organization field versus what actually is.
A "who pays" vs. "who owns" ledger. InstaRenewal can separate billing responsibility from legal ownership, documenting that the agency covers the renewal invoice while the client remains the legal registrant — which is exactly the distinction that matters most under the current ownership rule.
Access and delegation notes. InstaRenewal tracks where a domain is actually registered and how the agency has operational access to it (for example, "registered at [registrar]; agency holds delegated access via [admin email]"), which is useful context during offboarding or ownership questions.
Renewal alerting independent of the registrar. Because renewal notices sent to a redacted or unmonitored proxy inbox are easy to miss, InstaRenewal's own alerting can flag upcoming expirations on a fixed schedule rather than relying on the registrar's outreach reaching the right person.
InstaRenewal is scoped specifically to renewal tracking and asset/ownership visibility across domains, SSL certificates, hosting, and plugin licenses — it's not a credential vault, a uptime or security monitoring tool, or a general SaaS spend platform, so it pairs well with (rather than replaces) your existing password manager and security tooling.


  1. Conclusion: Own Your Records, Not Just Your Code Public domain transparency isn't coming back, and as of August 2025, the stakes for getting registration data wrong went up: the Organization field on a domain record is no longer just a courtesy label, it's the field a registrar or a court will look to first when ownership is contested. RDAP query lookups will show you a redacted record; RDRS will deny a majority of the requests it receives; and UDRP recovery, while it has a strong success rate for clear-cut cases, takes weeks and real money to run. None of those systems exist to bail out an agency that never wrote down who actually owns what.

Treat domain registrant data as core business record-keeping, not an afterthought buried in a registrar login. Get the Organization field right at the moment of registration, keep an internal record that's independent of whatever the public registry shows, and use a dedicated tracking system like InstaRenewal so that "who owns this domain" is never a question your agency has to guess the answer to.


Sources
ICANN, "ICANN Update: Launching RDAP; Sunsetting WHOIS", January 27, 2025
IETF, "The current state of RDAP", February 2026
APNIC Blog, "The current state of RDAP", February 10, 2026
ICANN, "ICANN Registration Data Policy Now In Effect for Contracted Parties", August 21, 2025
ICANN, "Registration Data Policy: Frequently Asked Questions", August 21, 2025
CSC, "ICANN's Updated Registration Data Policy Explained"
Wix Help Center, "About ICANN's Registration Data Policy Update August 2025"
ICANN, "Registration Data Request Service (RDRS) Two-Year Pilot Summary Report", February 27, 2026
ICANN, "ICANN's RDRS Two-Year Pilot: What We Learned and Where We Go Next", March 3, 2026
Dreyfus, "How will ICANN's Registration Data Request Service (RDRS) reshape access to non-public WHOIS data through 2027?", January 6, 2026
ICANN, "ICANN Adds Urgent Requests Requirement to Registration Data Policy", May 12, 2026
Domain Incite, "No RDAP? No accreditation", January 2026
NetworkCheckr, "How to Read a WHOIS Lookup: RDAP Guide for 2026", June 10, 2026
Kronenberger Rosenfeld, LLP, "Domain Hijacking" (case summaries)
ObscureIQ, "When Your Domain Gets Hijacked: Expired Domains, Recovery & Security Guide", December 29, 2025

Top comments (0)