PrivacyDomain RegistrationIndiaWHOISData Protection

Domain Registration Privacy in India: What the New WHOIS Rules Mean

Scan My ShadowSeptember 14, 20265 min read

TL;DR: A December 2025 Delhi High Court ruling targeting phishing and brand-impersonation domains introduced sweeping new directives for how registrars verify and disclose domain owner identity in India — including mandatory e-KYC at signup. If you own or plan to register a domain, here's what's actually changing and what it means for your own privacy as a registrant.

👉 Check what's already exposed about you — free 30-second scan →

If you've ever registered a domain name, you've made a choice — knowingly or not — about how much of your identity sits in the domain's public WHOIS record. That choice is now being reshaped by an Indian court order aimed at a very different problem: phishing and brand-impersonation domains, and the anonymity that's historically made them hard to trace.

What actually happened

In December 2025, Delhi High Court issued a ruling targeting over 1,100 phishing and brand-impersonation domains, built around the reasoning that domain registrant anonymity was enabling fraud at scale. The ruling reportedly included 14 directives aimed at reshaping how registrars handle identity verification and privacy for domains connected to India — with mandatory government-ID e-KYC at signup among the most consequential changes, rather than the self-declared registration details that have historically been standard practice.

Because major registrars operate globally rather than purely within Indian jurisdiction, industry commentary has noted the order's implications may extend beyond domains narrowly targeted at India, given how registrars typically apply compliance changes across their broader systems rather than maintaining fully separate country-specific processes.

What this means for WHOIS privacy specifically

WHOIS is the public lookup system showing a domain's registrant details — historically, many registrars have offered "WHOIS privacy" or proxy services that mask a registrant's real name, address, phone, and email behind the registrar's own placeholder details, specifically to prevent exactly the kind of full public disclosure this ruling now pushes toward. The core tension is straightforward: privacy protection for legitimate registrants versus traceability for enforcement against fraudulent ones — and this ruling weights firmly toward traceability.

What this means if you own or plan to register a domain

What you can actually do about it

The bigger picture

This ruling is a clear example of a privacy tradeoff made in the name of fraud prevention — less anonymity for domain registrants overall, in exchange for better traceability against phishing and impersonation domains specifically. Whether that tradeoff feels reasonable likely depends on whether you're a legitimate registrant weighing your own exposure, or someone who's been targeted by a phishing domain and wanted better enforcement against it. Both perspectives are valid, and the rule affects everyone registering a domain connected to India regardless of which side of that tradeoff feels more pressing to you personally.

If domain WHOIS exposure is one piece of a wider concern about your personal information circulating online, it's worth checking the fuller picture. Scan My Shadow checks your phone number and email across 1,500+ sources for a clearer view of what's actually out there.

Related Reading

FAQs

Does this ruling apply to all domains, or only .in domains?

The order specifically targeted domains connected to India, but because major registrars often apply compliance and identity-verification changes across their broader systems rather than maintaining fully separate processes per country, the practical effect may extend beyond strictly .in domains. Check your specific registrar's current policy for exact scope.

Can I still keep my WHOIS details private after this ruling?

This is still settling as registrars implement the new requirements — some privacy-proxy options may remain available for certain domain types while becoming restricted for others. Confirm directly with your registrar rather than assuming your existing privacy setting still applies unchanged.

Why did the court target domain anonymity specifically?

The ruling was built around over 1,100 identified phishing and brand-impersonation domains, with the reasoning that registrant anonymity was a significant enabling factor in making these fraudulent domains harder to trace and act against.

Does this affect domains I already own, or only new registrations?

Based on how registrar compliance changes typically roll out, both new registrations and existing domains (at renewal, or through a retroactive compliance update) are likely affected, though exact timing depends on each registrar's own implementation.

Curious what's already out there about you? Scan My Shadow checks your phone number and email across 1,500+ sources and sends you a clear report — no guesswork, just facts. Start your scan.

Phone + email scan · 1,500+ data sources worldwide · Full report
₹498one-time
Scan My Digital Footprint
Secure payment via Razorpay
  • Results within about 5 minutes
  • Clear, plain-English report
  • Delivered straight to your inbox
  • No login or passwords required
  • Scan data deleted after report is generated