Domain Registration Privacy in India: What the New WHOIS Rules Mean
TL;DR: A December 2025 Delhi High Court ruling targeting phishing and brand-impersonation domains introduced sweeping new directives for how registrars verify and disclose domain owner identity in India — including mandatory e-KYC at signup. If you own or plan to register a domain, here's what's actually changing and what it means for your own privacy as a registrant.
👉 Check what's already exposed about you — free 30-second scan →
If you've ever registered a domain name, you've made a choice — knowingly or not — about how much of your identity sits in the domain's public WHOIS record. That choice is now being reshaped by an Indian court order aimed at a very different problem: phishing and brand-impersonation domains, and the anonymity that's historically made them hard to trace.
What actually happened
In December 2025, Delhi High Court issued a ruling targeting over 1,100 phishing and brand-impersonation domains, built around the reasoning that domain registrant anonymity was enabling fraud at scale. The ruling reportedly included 14 directives aimed at reshaping how registrars handle identity verification and privacy for domains connected to India — with mandatory government-ID e-KYC at signup among the most consequential changes, rather than the self-declared registration details that have historically been standard practice.
Because major registrars operate globally rather than purely within Indian jurisdiction, industry commentary has noted the order's implications may extend beyond domains narrowly targeted at India, given how registrars typically apply compliance changes across their broader systems rather than maintaining fully separate country-specific processes.
What this means for WHOIS privacy specifically
WHOIS is the public lookup system showing a domain's registrant details — historically, many registrars have offered "WHOIS privacy" or proxy services that mask a registrant's real name, address, phone, and email behind the registrar's own placeholder details, specifically to prevent exactly the kind of full public disclosure this ruling now pushes toward. The core tension is straightforward: privacy protection for legitimate registrants versus traceability for enforcement against fraudulent ones — and this ruling weights firmly toward traceability.
What this means if you own or plan to register a domain
- Expect mandatory identity verification at signup or renewal for domains connected to India, likely including government ID submission as part of standard registrar onboarding going forward.
- WHOIS privacy protection may become less available or less effective for India-linked domains specifically, even where a registrar previously offered it as a standard add-on.
- If you run a small business, blog, or personal site under your own domain, your registered name, address, phone, and email could become more consistently visible in public WHOIS lookups than it has been under privacy-proxy arrangements many registrants have relied on.
- This is a genuinely new and evolving situation — specific registrar implementation details are still settling as of this writing, so checking your own registrar's current privacy policy directly is the most reliable way to know exactly what applies to your domain today.
What you can actually do about it
- Check your domain's current WHOIS listing yourself (most registrars have a lookup tool, or use a general WHOIS lookup service) to see what's currently visible for your domain specifically.
- If your registrar still offers a privacy-proxy add-on, confirm whether it's still active on your renewal, since some registrars have quietly adjusted these arrangements amid the changing requirements.
- For a personal or small-business domain where you'd rather not have your home address in a public record, consider using a registered business address, virtual office address, or your registrar's own address (where legitimately permitted) rather than your home address, if your registrar's current terms allow it.
- Stay generally aware that this is an evolving area — the specific mechanics of e-KYC enforcement and WHOIS display are still being implemented across registrars as of this writing.
The bigger picture
This ruling is a clear example of a privacy tradeoff made in the name of fraud prevention — less anonymity for domain registrants overall, in exchange for better traceability against phishing and impersonation domains specifically. Whether that tradeoff feels reasonable likely depends on whether you're a legitimate registrant weighing your own exposure, or someone who's been targeted by a phishing domain and wanted better enforcement against it. Both perspectives are valid, and the rule affects everyone registering a domain connected to India regardless of which side of that tradeoff feels more pressing to you personally.
If domain WHOIS exposure is one piece of a wider concern about your personal information circulating online, it's worth checking the fuller picture. Scan My Shadow checks your phone number and email across 1,500+ sources for a clearer view of what's actually out there.
Related Reading
- What GST and Company Registration Expose Publicly — a similar public-registration exposure pattern for small business owners.
- Freelancers and Gig Workers — relevant if you run a business site under your own domain.
- Property Registration Records: How Public Are They in India? — another public-by-design record type worth understanding.
- The DPDP Act: What Rights Do You Have? — the broader data-protection framework this ruling intersects with.
FAQs
Does this ruling apply to all domains, or only .in domains?
The order specifically targeted domains connected to India, but because major registrars often apply compliance and identity-verification changes across their broader systems rather than maintaining fully separate processes per country, the practical effect may extend beyond strictly .in domains. Check your specific registrar's current policy for exact scope.
Can I still keep my WHOIS details private after this ruling?
This is still settling as registrars implement the new requirements — some privacy-proxy options may remain available for certain domain types while becoming restricted for others. Confirm directly with your registrar rather than assuming your existing privacy setting still applies unchanged.
Why did the court target domain anonymity specifically?
The ruling was built around over 1,100 identified phishing and brand-impersonation domains, with the reasoning that registrant anonymity was a significant enabling factor in making these fraudulent domains harder to trace and act against.
Does this affect domains I already own, or only new registrations?
Based on how registrar compliance changes typically roll out, both new registrations and existing domains (at renewal, or through a retroactive compliance update) are likely affected, though exact timing depends on each registrar's own implementation.
Curious what's already out there about you? Scan My Shadow checks your phone number and email across 1,500+ sources and sends you a clear report — no guesswork, just facts. Start your scan.
- Results within about 5 minutes
- Clear, plain-English report
- Delivered straight to your inbox
- No login or passwords required
- Scan data deleted after report is generated