WhoisGuard Privacy Protection is now free
namecheap.com
namecheap.com
I can't imagine many industries getting away with that except for registrars due to how the whois system has worked historically, but it's basically just extortion, keep paying us or you're doxxed. Whois privacy should be the default everywhere for no additional charge, so I guess this is a change in the right direction.
You do get crushing medical debt, though. Which my advice would be to declare bankruptcy and/or not pay it.
HOWEVER, due to the GDPR, ICANN's "Temporary Solution" to the GDPR changes a lot of these requirements. One of the changes is that the requirement to make the contact info publicly available via whois has been removed. Registrars now are only required to show the state+country of the registrant, as well as some anonymized way to contact the domain owner (e.g.: via an anonymous email, or, via a web form).
For transfers of domain names between registrars, this also means the gaining registrar no longer is required to email you asking for authorization to transfer the domain (because the gaining registrar does not have access to the email addresses any longer). ICANN is working on a replacement for whois called RDDS which has tiered, authenticated access, as well as an accredidation process for people that need access to the real contact info such as law enforcement. However, they haven't worked out all of the details on this yet.
ICANN has also said regsitrars are not required to distinguish between an EU customer or a non EU customer when applying this rule.
So essentially, ICANN's temporary solution to the GDPR makes a lot of the reasons for "Whois Guard" or proxy registrations less useful.
See: https://www.icann.org/resources/pages/gtld-registration-data...
And again, you don't have to buy a domain. Or you can go through the same steps I've can to (eg) mask the sale of land and property with an intermediary company.
People's recent outbursts at the WHOIS system strike me as odd. It's been this way for two decades. It's really very similar to other public records.
Grandpa Joe's understanding of it all is completely separate from any "class" considerations.
There just seems to be this recent backlash against public records. In the UK, you buy a house and your name goes on the public record (along with the sale price). This seems very similar and useful for similar reasons.
No disagreement that it can also give you an involuntary spamgasm but that's just a symptom of another problem. Cold calling and spamming people still pays the bills.
But at the same time, I reflect upon the days of the phone book, which most people on this board likely never knew. Your phone number and address would be listed by the phone company as part of your phone number subscription - an unlisted number would cost you more.
While times of change, and the searchability of the digital world does raise some other concerns, I still wonder how big a deal it is for ICANN to require this. Is it really revealing "all of your personal information" if you reveal the PO box, spam-trap "domains@" email address, and phone number of the domain owner?
If the registrar were revealing other info, I'd say "it's pretty absurd." But by default allowing people the info to contact you, as the owner of a domain name? That doesn't seem like extortion. Heck, if you own any real estate in the U.S., your contact info is listed in the tax assessor's database for all to find, same as in the WHOIS database.
Regardless, definitely an interesting topic to chew on.
You can allow people to contact an owner without giving out their information. Craigslist does it.
The question comes down to: is owning a domain like owning a computer (a commodity)? Or is owning a domain more akin to owning a phone (landline), or real estate, or a business?
If the former, privacy should generally be assumed by default. If the latter, I think it's worth questioning whether it should be.
To your point, the price doesn't escalate to $250/yr. It escalates to $10/year plus ~$2-5/yr for privacy protection. That's what we've been talking about this whole time - SHOULD you have to pay a premium for an "unlisted number"?
Luckily for those concerned with privacy, companies like Namecheap, Google, Namesilo, and a few others are now offering this by default, making that discussion irrelevant.
No. Google Voice numbers are free, I use one as the throwaway phone number for my personal domains.
Not to mention the chilling effect on speech it would have.
I was showing a non-technical colleague only two weeks ago how doing a whois query on our company's .co.uk domain showed our company address and the individual responsible for registration. I just checked again now and pretty much all the useful info has gone.
The same restriction also applies to other name registrars like Gandi: https://wiki.gandi.net/en/domains/private-registration
See http://www.ownit.nyc/faq, under "WILL PROXY REGISTRATIONS, SOMETIMES CALLED “DOMAIN PRIVACY” BE ALLOWED ON MY .NYC DOMAIN NAME?"
Basically, it's the registrar's policy to prohibit obfuscating the actual domain owner. Resellers like Namecheap have to abide by these policies.
I can't speak for EU domains, or for the reasoning behind the .NYC policy.
Currently you can query for generic data and an abuse email address but the contact details are only revealed if you are the domain holder or have a solid reason[1].
> In all other cases, DENIC will generally not provide information. Instead, if you think that the contents of a website that can be accessed via a domain may be illegal, you should send an e-mail reporting the matter to the e-mail address for abuse reports (Abuse). You find the e-mail address on the domain query page. Moreover, the imprint, if any, of the website concerned will inform you who is the operator of the website.
To add some additional context, a proper, up-to-date imprint, including a postal address (no P.O.) and in most cases a phone number, is legally required for practically every website in Germany
[1] https://www.denic.de/en/service/whois-service/third-party-re...
Anyway, if you have any questions regarding domain registration in Germany or which registrars worked well for me, feel free to contact me, my details are in my profile.
Most of those listed TLDs likely have requirements about who can register domains on that TLD, so they need that info for verification purposes. That doesn't mean that they're publishing it in WHOIS though; many are not.
I can't recall the .vote/.voto policies (haven't work for a registrar in a year), nor those for .asia.
Edit: spelling
29th May 2018: $10.98 (+0.11) for .com and 0.18 ICANN'T fee ($11.16 total).
So it's $0.71 cheaper without whoisguard. So that margin (increase in .com) probably covers the actual whoisguard cost, the $1 fee was pretty much pure profit.
For my same .com:
2017 New registration $10.69
2018 Renewal $12.98
Only when we can stop profiting from selling privacy services because of a new law that came into effect a few days ago.
I'd have believed them if they did this 2 years ago once GDPR was announced. Already moved my domains from namecheap since they are not the cheapest and didn't offer free whois until now.
On the "Create new account" page, their captcha is just a table with black/white background colors to create the letters. Never seem something like that before, and it can be trivially bypassed.
I created it for myself, but feel free to use.
Why not just let me click a single button, Namecheap?
I wish a new registrar would come in with good service and UX and eat every other registrar's lunch. There aren't any registrars that easily let me manage my domains without trying to sell me tons of stuff every time I need to make a simple change. I've switched to Cloudflare for DNS because their UI is no-nonsense, I half wish they just sold me the domain as well.
You might be able to see room for improvement but they're better than 90% of the other registrars.
Because whois, along with the many people who scrape it, provide a public record of my domain ownership. With privacy protection it is a lot harder to prove ownership if the registrar makes a balls up.
Route53 (using now) just makes more sense: easy programmatic access, unified billing with other services, included domain privacy, and no games with renewal pricing/discounts.
It was basically a tossup between Porkbun and Namesilo, so I went with the service with the more modern interface even though I don't interact with it much.
I take it as a deceiving advertising.
Teddy from Namecheap
I for one am glad of this upgrade and I have dozens of domains, makes a difference.
I will be checking and awaiting for update on your website, but I won't hold my breath honestly.
(Perhaps that's why I'm a customer - moved most of my domains from name.com over the past year).
That and your attention to social media marketing/community management = you're my kind of company.
Some people just can't recognize a good thing as a good thing. As a Namecheap customer, though, I'm pretty darn happy at this news!
No, I don't as I am not Namecheap employee. I don't work or approve off companies that serve US-based clientele, but constantly outsource their customer support to Eastern-block countries and hire people that barely speak English. I think its anti-american frankly speaking, but I don't think you are American citizen anyways so this doesn't apply.
But I do chose who competes for my dollars, so its unfair to show me competitors that you know don't have certain features, while you purposely avoiding those who do have those features. Unless you so out of touch with supposedly your market (anyone can create HN account with "CEO" in it) that you are not aware Dreamhost and Namesilo are offering these services for FREE for many years by now.
And if you really happen to be a Namecheap CEO (highly doubt and scary to think a CEO has time to post on HN) then I'm glad you posted this, as you are only reassuring me in my decision to move out all my domains long time ago.
And when you click on the link you yourself provided, who is the FIRST company in the first column right in your face?? Yeah, you heard about those guys?
NameSilo provides free Whois Guard at least since I moved my domains out of Namecheap some 7 years ago when my disgruntled employee claimed domains zoned with you are his just because he knew my first name, last name and my DOB. Although they were not taken offline, but certainly froze for a week or so before I wasted many hours to try and clear the situation out. Since then I strongly oppose your "security logic" and proudly had at least 4 people move all their domains out. Although frankly I still have fun locking my ex employee out of his own Namecheap account, simply because I happen to know his username and that's all you need to lock someone out attempting wrong password a few times :)
Anyways, let's end this time-consuming worthless conversation, because frankly you are shooting yourself in the foot.
Edit: from the link you provided and clicking on NameCheap name, did you read the February 22nd review about deleting someones 75 domains and not even having phone support to discuss the issue?? Jesus man; how do you sleep with yourself knowing how much stress you have cause another human-being?? :facepalm
Now that this is mentioned, I revisited WordPress' instructions page and it says: "Most domain names registered at WordPress.com have GDPR protection, which means registrant contact information is not visible publicly, regardless of whether or not the domain has Privacy Protection in place. For these domains, disabling privacy will not result in contact info being publicly published."[0] Does this mean the process doesn't really need it but they registrars require it for some odd reason? If they can work it out without disabling privacy feature to comply with GDPR, why can't they do the same for everyone?
[0] https://en.support.wordpress.com/move-domain/transfer-domain...
From the Domain Tools point of view the transfer should look like Old Whois Privacy LLP on SomeRegistrar transferred a domain to New Whois Privacy Corp on NewRegistrar
Besides I still have fun blocking my ex-employer namecheap account time to time. All you need is provide their username with wrong password 4 times and account is locked. You have to go thru extensive re-verification process. Its hilarious and totally unnecessary in the times of 2FA.
Besides namecheap has a long tradition of not standing up for your domain name. If they are pressed by someone offended by your content, they will take down your domain and take over it. That was few posts on Web Warrior I found years ago from terrorized people that made me change all my domains to namesilo.
The solution I’m using is MyPrivacy.ca. It’s not a 1:1 replacement for WHOIS privacy but solves the Spam problem very well, it’s easy to set up and it works for all TLDs.
It is basically an opt-in email forwarder with a customizable whitelist of common registrars and NICs. So you will never miss an important mail from your registrar while most Spam will never make it through the challenge/response process.
It’s completely free and run by the guy behind easydns.ca (Mark Jeftovic).
You might pay slightly more, but I believe Gandi operate a significantly better service, catering to shrewd users (I don't work there or have any financial interest in the matter, just a happy customer).
In fairness, Namecheap seem like a pretty decent second-choice, and most of my ire is reserved for all the 'baby's first domain name' bottom feeders out there.
This finally solves that problem.
--
P.S. TO NAMECHEAP (who sometimes surfs HN, IIRC): PLEASE make sure that WhoisGuard is reliably renewed with this change in place.
Given the occasional glitches I've seen in your systems in the past, I want to emphasize this. It would be most unfortunate if a glitch exposed contact information: Once out, you can't take it back.
It took a long time for me to decide to try/trust autorenew. I'm worried I may now need to go back to manually signing in at each renewal, to make sure nothing has gone sideways.
I was also emailed:
At Namecheap, we care about your privacy and are now giving ALL our Namecheap customers FREE WhoisGuard for life, when they register a domain* with us. This important change supports our strong belief in privacy, security, freedom and the equal treatment for all internet users.
Suddenly, they care about my privacy, whereas all the previous years they were soliciting subscriptions to their WhoisGuard service with each new registration or renewal order.
What a coincidence! And what an unfortunate choice of wording to their existing customers. (Apparently, I was very upset when I got this emailed)
Cheap and transparent pricing with free WHOIS privacy.
So is the market not as competitive as it looks, or is there something else going on?
Read this UDRP decision, they found that using Njallas proxy service constitutes bad faith.
While this was a terribly misguided decision, UDRP cases rely heavily on precedent, so it'd be tricky to get this reversed.
Don't get me wrong though, most of the time njal.la is pretty nice and I have tens of domains with them. I just wouldn't use them for anything very important.
Most registrars are already redacting whois output to comply with GDPR.
Registrars that aren't doing this for non-EU costomers (e.g.: godaddy) are the exception. The only reason for this is to push sales of their privacy/proxy registration service.