Skip to content

WHOIS privacy failed and my home address is now on a scam site

Domain Names by Chen 23 replies 2K views
11 #1

Eh bro my home address now on scam site lor

I use whois privacy for my domain then suddenly got email from someone say they found my house. Check online my real address there leh. The privacy service I pay for what for??

I call registrar they say "your privacy service expired" but I never get email about this. Now my address on some "domain investor" site that scrape WHOIS data. Can I sue or not? How to remove?

#2

The "privacy" layer and redaction are different things. Many registrars now redact personal data by default under GDPR, but this is not the same as a privacy service. Privacy services substitute their own contact data; redaction simply hides yours.

If your registrar is in a jurisdiction without mandatory redaction, and you did not explicitly renew the privacy add-on, your data goes back to public WHOIS. The virtualization tax of domain management: you pay for abstraction that should be baseline.

Check if your TLD offers free redaction independently.

virsh list --all | wc -l: 47
#3

This happened to my coworker. Ngl they thought they had privacy but never actually toggled it on during checkout. The checkbox was like "add privacy protection" and they assumed it was default enabled.

Turns out it was opt-in and they just... never opted. Their address was public for 2 years before they noticed. Wild.

CUDA cores are my love language
1 #4

I SNAPPED UP A DOMAIN LAST YEAR AND THE REGISTRAR CHARGED ME $8/YR FOR PRIVACY!! ARE YOU KIDDING!! THEN I FOUND OUT THE REGISTRY REDACTS FREE!! THEY WERE SELLING ME NOTHING!! LITERALLY NOTHING!!

I got 3 years refunded after I threatened chargeback. Privacy upsell is the oldest scam in the game.

world record: 4min Arch install
#5

I've seen scrapers resell WHOIS history going back to 2017.

Your options:
- Submit GDPR deletion request to each scraper (hit rate ~60%)
- File ICANN complaint if registrar misrepresented service
- Move to registry with native redaction (most gTLDs now)

Some scrapers honor robots.txt for removal. Most don't. The data is commodity at this point.

zfs send | zfs receive. repeat.
#6

Same thing happened to me with a .io domain lor

#7

60% hit rate for GDPR? Source on that number?

phở at 3AM, deploy at 4
#8
minh1987 said:
60% hit rate for GDPR? Source on that number?

Personal experience running deletion requests for a client last year. 14 of 23 scrapers complied within 30 days. The rest either ignored or demanded proof of EU residency. It's not a published study.

The real problem is the ones that comply just remove the web view. The raw data is already in a dozen other databases.

zfs send | zfs receive. repeat.
9 #9

I don't think GDPR helps me in Vietnam. My address is on those sites too but no European connection. What do I do?

phở at 3AM, deploy at 4
#10
minh1987 said:
I don't think GDPR helps me in Vietnam.

Correct. GDPR has no extraterritorial effect for non-EU data subjects. However, some scrapers apply their GDPR process globally because it's cheaper than maintaining two workflows. Worth trying even without legal standing.

For .vn domains specifically, VNNIC redacts registrant data by default since 2021. If your data is visible, check whether your registrar is proxying through a non-VNNIC reseller.

virsh list --all | wc -l: 47

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft