Short answer
Whois privacy services replace the registrant's real name, email, phone and address with the proxy provider's own details, and GDPR redaction removes personal fields from many records entirely. A proxy-removed whois database strips these unusable rows before delivery, so you only pay for records that contain real registrant contact detail.
Key takeaways
- Privacy proxies and GDPR redaction remove exactly the fields commercial users need.
- Vendors quoting huge record counts are usually counting masked rows.
- Judge feeds on cost per usable record, not cost per row.
- Proxy detection is pattern work: known proxy strings, relay email formats, shared addresses.
- Always request the raw count and the proxy-removed count for the same day.
Two separate forces mask whois data: commercial privacy services that registrants opt into, and regulatory redaction that registrars apply by default. Both produce records that are technically present in the whois database and commercially worthless for outreach. Understanding the difference is the fastest way to stop overpaying for data.
What whois privacy services actually do
A whois privacy or whois guard service substitutes the proxy provider's contact details for the registrant's. The domain still resolves, the registration is still valid, and the record still exists — but registrant_name becomes the proxy company, registrant_email becomes a rotating relay address, and the postal address becomes the proxy's own office. Messages sent to a relay may or may not be forwarded, and are frequently filtered before they arrive.
How GDPR changed the public whois record
Since GDPR came into force, registrars serving European registrants routinely redact personal fields from public whois output regardless of whether the registrant paid for privacy. Redacted records typically retain the domain, registrar, nameservers and dates — genuinely useful for infrastructure and research work — while removing the personal contact block entirely. RDAP, the structured successor to whois, applies tiered access along the same lines.
| Record type | Domain & dates | Registrant identity | Contactable |
|---|---|---|---|
| Full public record | Present | Real name, email, phone, address | Yes |
| Privacy-proxied | Present | Proxy company details | Relay only, unreliable |
| GDPR-redacted | Present | Removed or 'REDACTED FOR PRIVACY' | No |
| Registry-thin | Partial | Not published at registry level | No |
The economics of masked rows
Consider two vendors. Vendor A advertises 200,000 records a day at $100 a month. Vendor B advertises 60,000 records a day at $150. If Vendor A's file is raw and roughly two thirds of it is masked, both vendors are shipping about the same number of contactable records — and Vendor A is shipping them mixed in with 140,000 rows you must detect and discard yourself, at your own cost, before your bounce rate tells you the hard way.
Ask any whois data vendor for two numbers on the same date: total records, and records with a populated non-proxy registrant email. The gap between them is the real product.
How proxy removal is done
- Known-proxy matching against a maintained list of privacy-service organisation names and their postal addresses.
- Relay-address pattern detection for the hashed or randomised email formats proxies generate.
- Redaction-string detection for values like 'REDACTED FOR PRIVACY', 'Not Disclosed', 'Data Protected' and their registrar-specific variants.
- Shared-address clustering, where thousands of same-day registrations resolve to one physical address.
- Field-completeness validation that discards records with structurally present but empty contact fields.
None of this is exotic, but it is continuous maintenance work: proxy providers change their strings and formats, registrars change their redaction wording, and new privacy services launch. That maintenance is a meaningful part of what you are buying from a data provider — and it is the part that quietly stops working at vendors who built the list once and moved on.
When you should keep the masked rows
Masked records are not universally worthless. For security, brand protection and market research, the domain name, registrar, nameservers and dates carry most of the value and the registrant block is a bonus. Best practice is to receive both outputs: the clean proxy-removed file for anything involving contact, and the raw file for infrastructure analysis and retrospective hunting.
GetWhoisData removes whois guard and privacy-proxy records from the daily database before delivery, and publishes raw and proxy-removed counts alongside email and phone coverage for the last ten days so you can see the ratio before subscribing.
Frequently asked questions
What is whois privacy?+
A service that replaces the registrant's real name, email, phone and postal address in the public whois record with the privacy provider's own details, usually with a relay email that may forward messages.
Does GDPR make whois data illegal to use?+
No. GDPR changed what registrars publish — many personal fields are redacted by default for European registrants — but the records that remain public can be used lawfully, subject to the marketing and privacy rules of the recipient's jurisdiction.
What percentage of whois records are privacy-protected?+
It varies by TLD, registrar and registrant country, but a substantial share of each day's registrations is masked by either a privacy proxy or registrar redaction, which is why raw record counts overstate usable volume significantly.
What does a proxy-removed whois database mean?+
It means privacy-proxy, whois-guard and redacted records have been detected and stripped before delivery, so the file you receive contains only records with real registrant contact details.
Should I still buy raw whois records?+
Yes if you do security, brand protection or infrastructure research, where the domain, registrar, nameserver and date fields carry the value. Use the proxy-removed file for anything involving contacting the registrant.