Every domain registration requires contact details: name, address, phone number, email, and by default those appear in the public WHOIS record that anyone can look up. WHOIS privacy replaces them with a proxy service's details while you remain the legal owner.
What is actually public without it
Your full name, your postal address, your phone number and your email address, all queryable by anyone who types your domain into a WHOIS lookup.
For a registered company this is usually already public information. For an individual running a site from home, it is publishing a home address alongside a name and phone number, which is a meaningfully different thing.
What it prevents in practice
Automated harvesting. The address in a WHOIS record is scraped continuously, and it is why a domain registration is reliably followed by spam.
Fraudulent renewal notices. A specific and effective scam: an invoice-looking letter or email quoting your real domain and expiry date, from a company you have never used. Public WHOIS is where they get the details.
Cold outreach. Design, SEO and hosting sales calls that begin the day a domain is registered.
Casual identification. Anyone who dislikes something you published can look up who you are and where you live in about ten seconds.
What it does not do
It is not anonymity, and treating it as such is a mistake.
Your registrar and the registry still hold your real details. A valid legal request or court order reveals them. Privacy protects you from casual lookup and automated scraping, not from anyone with legal standing.
It also does not affect how the domain works. No impact on the website, on email, or on search ranking. A persistent myth with nothing behind it.
Where it is included and where it is not
Some extensions include privacy at no cost, some charge for it, and some do not permit it at all.
Several country extensions require genuine public contact details as a registry policy. If privacy matters to you, check before registering rather than after: it is not something a registrar can add later on an extension that forbids it.
Turn it off before a transfer
This is the practical catch, and it stalls more transfers than anything else.
The transfer approval email is sent to the WHOIS contact address. With privacy enabled, that is a forwarding address belonging to the proxy service, and the message frequently does not reach you.
So before starting a transfer: turn privacy off, request the EPP code, complete the transfer, then turn privacy back on. Transferring your domain goes over the rest of the sequence.
Keep the underlying details accurate
Privacy hides your details from the public. It does not excuse you from having correct ones on file.
Registries require accurate registration data, and deliberately false details can result in suspension. More practically: the email address behind the privacy service is where verification messages and expiry warnings go, and if that address is dead you will miss both.
Check it once a year, at the same time you check the expiry date.
Whether you need it
Yes, if the domain is registered to you personally and your address would otherwise be public, or if you would rather not receive the sales and scam volume that a public listing generates.
Probably not, if the domain belongs to a registered company whose address is already public, and you would rather people could find your contact details.
Note that some businesses deliberately keep WHOIS public as a trust signal. That is a legitimate choice instead of an oversight.
The one situation where it genuinely matters is a personal site run from a home address. There, the default of publishing that address alongside your name and phone number is worth changing.
Domains held for the future are the ones most easily forgotten, and the ones most useful to a forger. How to Park or Hold a Domain Before You Use It deals with securing them.
Read what is published about your domain
The abstract question becomes concrete when you look at the actual record.
whois example.com | grep -iE 'registrant|admin|tech|email|phone|street|city' whois example.com | grep -iE 'privacy|proxy|redacted|not disclosed'
Read it for your own domains rather than assuming. What appears varies by extension and by registrar, and a domain registered years ago under a different policy may be exposing details the current one would not.
The fields worth checking are the postal address and the telephone number, since those are the ones with consequences beyond spam. An address published against a domain is an address anybody can find, and for a business run from home that is a different matter from an email address.
Some extensions publish regardless
Privacy is not available everywhere, and the exceptions catch people who assume it is a setting they can enable.
Several country level extensions require the registrant to be identifiable, and some publish the details in full as a condition of registration. Others make privacy available only to individuals and not to companies, or the reverse.
whois example.co.uk | grep -iE 'registrant|opt-out|type'
Check before registering rather than after, particularly when the extension is being chosen for its association with a country. Discovering the rule afterwards leaves a choice between publishing details and abandoning a name you have already built on. Understanding domain extensions covers the differences.
It hides you from the public, not from the process
Privacy protection is worth understanding as a filter rather than as anonymity.
The registrar holds the real details, the registry may hold them, and both disclose them in response to a valid legal request. A trademark dispute, a court order or an abuse investigation all reach the underlying record.
The practical implication is that privacy is protection against bulk collection, unwanted contact and casual lookups. It is not protection against being identified by anyone with a legitimate route, and treating it as the latter leads to decisions that do not hold. Unverified contact details deals with why those underlying details still have to be correct.