The name is the softest part of the stack
A server in Reykjavík paid for in Monero with no account and no identity check is genuinely hard to take away from you. The company that rents it to you is in one country, the hardware is in another, the payment left no name, and anyone who wants the machine turned off has to persuade a court in a jurisdiction chosen specifically because it is unhelpful to that request. That is the part of the stack the offshore hosting industry has spent twenty years getting right.
The domain is not like that at all. You do not own a domain — nobody does. You hold a renewable lease, recorded by a registrar, delegated by a registry, under a contract you clicked through, and every party above you in that chain can act on the name without your involvement and usually without a judge. The asymmetry is the whole story: reaching the host means a foreign court order and months; reaching the registrar means a complaint form and, on a bad day, an afternoon.
This matters for entirely ordinary projects. Independent journalism, mirrors of material that somebody would rather stayed offline, archives, adult businesses that are legal everywhere they operate, security research, commentary that annoys a company with a legal department — none of that is illegal, and all of it attracts pressure that is aimed at whichever link in the chain is cheapest to bend. That link is almost never the offshore host. It is the registrar, and it is reached by email.
So this guide is not about hiding from law enforcement, which is a different problem with a different answer and is not one hosting can solve. It is about two narrower and more achievable things: not handing a stranger with a grievance the ability to learn who you are from a public lookup, and not being one unreviewed complaint away from losing the name your entire project answers to.
The order of operations that follows is deliberate, because most advice on this subject starts and ends with "turn on WHOIS privacy" — which is, of the six decisions that matter, comfortably the least load-bearing. The registry's jurisdiction comes first, the registrar's temperament second, the registration model third, the payment rail fourth, the DNS operator fifth, and the archives that remember everything sixth.
What WHOIS still records after it stopped publishing
In 2018, European data-protection law collided with a public database that had published every domain owner's name, postal address, email and telephone number since the 1980s, and the public part lost. Look up a generic top-level domain today and you get the registrar, the creation and expiry dates, the nameservers, the status codes and an anonymised relay contact. The personal fields say REDACTED FOR PRIVACY.
Read that carefully, because it is a change in publication policy and not in data policy. The registrar still collects your name, address, email and phone. It still has your payment instrument, the IP address you signed up from, and the IP address of every login since. Its accreditation contract obliges it to collect that data, to keep it, and to verify at least the email address. Redaction moved the record behind a counter; nothing was deleted, and the counter has staff.
The lookup protocol changed too. The port-43 text service that everybody calls WHOIS has been superseded for generic domains by RDAP, a structured JSON interface with something the old protocol never had: an authenticated tier. Accredited requesters can be served fields the anonymous public query never sees. You can try the public view yourself at ICANN Lookup; assume that view is the floor of what is disclosed, not the ceiling.
The part people forget entirely is history. Commercial archives have been snapshotting registration records continuously for two decades, including the years when everything was published in full. If a name of yours was ever registered openly — a hobby project in 2015, a company domain, anything sharing your email address — that record is retrievable, permanently, by anyone willing to pay for a lookup. Redaction protects what you register tomorrow. It does nothing whatsoever about what you registered before you started caring.
Country-code extensions sit outside all of this. They are not bound by the generic-domain policy, and each registry sets its own rules: some publish the registrant in full, some publish nothing, and several impose a residency or local-presence requirement that is an identity check wearing a different hat. The .eu registry demonstrated exactly how sharp that can be when tens of thousands of names held by UK registrants stopped meeting the eligibility rule after Brexit and were withdrawn. Eligibility rules are enforced by checking who you are.
The practical consequence is a rule worth internalising before you spend a cent: check what is already public about every identifier you are about to reuse. An email address you have used on a previously public registration links the new name to the old one in a single query, and no amount of redaction on the new record undoes it.
Who can take the name, and what each of them answers to
There are four parties above you, and they respond to different pressures at different speeds. Knowing which is which is the difference between answering a notice correctly and losing a name you could have kept.
The registrar is the fastest and the least reviewable. It can suspend or delete under its own acceptable-use policy, and it does not owe you a hearing — a complaint, an automated abuse pipeline, or a payment dispute is enough at some companies. This is the layer where reputation is worth paying for, because the only meaningful defence is having picked a registrar that reads complaints before acting on them.
The registry sits above the registrar and applies status codes that no registrar can lift. A name placed on registry hold — the serverHold status — still belongs to you in every formal sense and resolves nowhere at all, which is the same thing as being gone. Registries act on court orders in their own jurisdiction and on their own published policies, and in some countries on an explicit administrative procedure written into national law.
Then there are the dispute procedures, which exist for trademark conflicts and are aimed at the name rather than what you publish on it. The Uniform Domain-Name Dispute-Resolution Policy can transfer a name to a complainant in a matter of weeks, decided by a panel, on paper, with a response window you must not miss. Its faster sibling suspends rather than transfers. Neither is a court, both are binding on your registrar, and both are used tactically by parties whose actual objection is to your content.
Finally, seizure. Any court with jurisdiction over the registry can order a name transferred or held, regardless of where the registrant lives or which registrar sold it. This is the fact that decides the next section: because the operator of the world's two largest extensions is a company in Virginia, every .com and every .net in existence is within reach of a United States court order. The EFF's archive of domain seizures is the long-form version of that sentence.
Put together: your registrar determines how easily the name is lost to a complaint, and your registry determines which courts can take it. Those are two separate decisions, and you make them both at the moment of purchase, usually without noticing that you made either.
Picking the extension is picking a jurisdiction
This is the highest-leverage decision in the whole exercise, it costs nothing, and almost nobody makes it deliberately. The method is thirty seconds of work: look the extension up in IANA's root zone database, read the sponsoring organisation and its address, and accept that its country's courts are now part of your threat model.
The results surprise people. Extensions that feel technical, international or vaguely alternative are frequently operated by large American companies — the developer-favourite two-letter extensions ended up under United States corporate ownership through a series of acquisitions, and a great many of the newer generic extensions sit with a single American registry group. Feeling like an alternative to .com is branding. Sharing .com's jurisdiction is a legal fact.
Country-code extensions vary as much as countries do, and the useful axis is not "which country has the best privacy reputation" but "what procedure exists, and who can invoke it". Iceland's registry is well regarded because its published position is that it acts on Icelandic court orders and not on foreign correspondence — see ISNIC for the current rules. Switzerland has strong privacy law and a documented administrative blocking route written into its domain ordinance, which is exactly what rule of law looks like and is also a procedure that exists. Good law is not the same as no procedure, and you want to know which you are buying.
Weigh the boring operational properties at the same time, because they bite later: whether the registry supports registry lock and DNSSEC, whether the extension carries a residency requirement, what renewals cost in year three, and how politically durable the string is. An extension delegated on behalf of a territory can change hands, change policy, or become entangled in someone else's diplomacy. That is not an argument against using one — it is an argument against building an identity you cannot move.
| Extension family | Registry operator sits in | Practical consequence | When it is still the right pick |
|---|---|---|---|
| .com and .net | United States | A US court order reaches the name whatever your registrar or your own country | Commercial projects where recognisability genuinely outweighs jurisdiction |
| .org, .info and most new generic extensions | United States | Same reach; the alternative feel of a new extension is marketing, not law | When you want a descriptive name and have accepted that reach |
| Two-letter technical favourites | United States operator, territory-linked string | US reach plus the political risk of a string tied to a territory | Developer-facing products that could survive being renamed |
| Icelandic and Nordic country codes | The country itself | Registry policy centred on domestic court orders; strong speech protections | Publishing, journalism and archival projects wanting a legible home |
| Swiss and Liechtenstein country codes | Switzerland, Liechtenstein | Strong privacy law alongside a defined administrative blocking route | Long-lived projects that value stability and accept a known procedure |
| EU member-state country codes | The member state or an EU body | Residency or local-presence rules are an identity check; EU-wide instruments apply | Only when you are genuinely established there |
| .us | United States | A nexus requirement plus a long-standing policy against proxy registration | Effectively never, for anything in this guide |
One more consideration that is easy to miss: the extension is also a signal. A brand-new generic extension with a low renewal price attracts abuse, and mail from it is treated worse by spam filters as a direct result. If the name will ever send email, that reputational drag is real and you will feel it long before you feel any jurisdictional question — the mail-server guide covers what it takes to be delivered at all.
Privacy service, proxy, trustee: three things sold under one word
"Private registration" is sold as a single product and is really three different arrangements with three different failure modes. Being clear about which one you are buying is most of the work.
A privacy or WHOIS-proxy service substitutes the registrar's own forwarding contact for yours in the public record. It hides you from a casual lookup and from nobody else: the registrar knows exactly who you are, a subpoena to the registrar produces you, and an authenticated query may produce you. On a generic extension, where the fields are redacted by default anyway, paying extra for this is largely paying for something policy already gives you.
A proxy or trustee registration is a different animal. A third party becomes the registrant of record and licenses the use of the name to you under contract — the model Njal.la made mainstream. The registry and registrar records name them, not you, and there is genuinely less for anyone to disclose because there is less on file. It is the strongest of the three, and it costs you something real: you are not the legal holder. You cannot invoke a dispute process against your own trustee, and you are relying on a contract and on the operator's willingness to hold the line.
Registering to an entity you control is the third route: a company in a jurisdiction that does not publish beneficial ownership becomes the registrant. It is durable, it survives the operator of a proxy service losing interest, and it comes with its own disclosure regime, its own filing obligations and its own agent who can be compelled. A company that files public accounts naming its directors has not solved the problem, it has relocated it.
Whichever you pick, three questions decide whether it is worth what you paid. What data does the intermediary actually hold about you, given that it can only be compelled to produce what it has? What is written down about transfers out, if the intermediary is pressured, changes policy, or simply stops answering email? And could you move this name yourself, today, without their cooperation, if you had to? Get those answers before you rely on the arrangement, not during the week you need it.
| Model | Who the record names | Who still knows it is you | Where it fails |
|---|---|---|---|
| Plain public registration | You | Anyone with a lookup tool, permanently | Immediately, and irreversibly — the archives keep it |
| Default redaction on generic extensions | Redacted fields, relay contact | Registrar, and authenticated requesters | Any lawful demand to the registrar; it is a default, not a service |
| Paid privacy add-on | The registrar's forwarding contact | Registrar, and authenticated requesters | Same place redaction fails, for extra money |
| Third-party proxy or trustee registrant | The proxy company | The proxy company and its payment rail | The proxy is pressured, folds, or disagrees with you |
| Entity you control | The entity | Your incorporation agent and its regulator | Ownership registers, filing duties, a compelled agent |
One thing that is never a strategy: inventing the details. Giving a registrar deliberately false contact data breaches the registration agreement, and the enforcement mechanism is a verification email that, when it goes unanswered, suspends the name. The whole point of the proxy and entity models is that they let the record be accurate and not be about you. Lying gets you the worst of both — identifiable through the payment trail, and cancellable on a technicality.
Paying for the name without undoing everything above it
A card payment collapses the entire chain. The registrar's payment processor holds a fully verified identity, sits in a compliance regime that no registration policy touches, and retains records for years by law. If a registrar's only payment rail is cards, then whatever it says about privacy, the identity check simply moved upstream — the same argument that makes crypto-only hosting coherent applies here without modification.
So pay in cryptocurrency where the registrar accepts it, and prefer Monero over Bitcoin for the same reason as everywhere else: a transparent ledger publishes an amount, a time and an address that can be linked to whatever exchange you bought from, and a private one does not. The trade-offs are laid out in full in the Bitcoin versus Monero comparison; the summary is that for a recurring, small, identity-relevant payment, Monero is the better instrument.
The renewal is the failure mode nobody plans for and everybody eventually experiences. A domain that lapses is a takedown you performed on yourself, and expiring names are bought within seconds of dropping by automated services that resell them back at a markup — assuming they resell them to you at all. Register for several years up front, keep the expiry in a calendar that does not live on the domain, and make certain the reminder mail arrives somewhere you will still be reading in three years.
Anonymity also does not survive the support channel. A refund conversation, a chargeback, a ticket opened from a personal address, an invoice forwarded to an accountant — each of them attaches a name to a record that had none. Decide once which identity owns this domain, and never touch the account from any other one, including on the day something breaks and you are in a hurry.
Budget honestly. A trustee registration runs several times the price of a bulk generic name, multi-year prepayment is money out early, and a spare name at a second registrar is another small annual cost. Call it a few tens of currency units a year in total. Set against the cost of losing the address every link, every bookmark, every mail record and every search result points at, it is the cheapest insurance in the entire stack.
The registrar account leaks more than the public record ever did
Everything in the paragraphs above concerns what strangers can look up. The richer target is your account at the registrar, which holds a current email address, a password-reset path, the IP address of every login, and the full text of every support ticket you have opened. That file is more complete, more current and more useful than the unredacted WHOIS record ever was.
The email address is the master key, because whoever controls it controls the domain: password resets, transfer approvals and change-of-registrant confirmations all arrive there. Use an address that exists for this domain and nothing else, on infrastructure you run or a provider that does not demand a phone number. If you want that mailbox on hardware you control, the self-hosted mail guide is the honest account of what that involves. What you must not do is host the mailbox on the very domain it protects — when the name is suspended, so is your ability to recover it.
Turn on two-factor authentication with time-based codes from an authenticator app, and specifically not with SMS. A phone number is simultaneously an identity document and the single most reliable account-takeover path in existence, and handing one to a registrar to improve security is a poor trade. Keep the recovery codes offline and somewhere that does not depend on the account they recover.
Then there is correlation, which is the quiet way most of this fails. The same email on the hosting account and the registrar account. The same password. The same browser session logging into both within a minute. The same handle on the forum where you announced the project. Any one of those turns two carefully separated anonymous accounts into one identified person, and none of them are visible in any public record — which is exactly why they get overlooked. The traceability guide walks the same problem from the server side.
Finally, set the transfer-prohibited status (clientTransferProhibited) on the name, and take registry lock if the registry sells it. Registrar lock is one click and blocks the common theft path; registry lock adds an out-of-band verification step before any change reaches the registry at all. The overwhelming majority of domains that get stolen are not seized by courts — they are transferred out by whoever got into the mailbox, and both locks exist because of that.
DNS hosting is a second takedown surface
Registering a name and answering queries for it are two different jobs, usually done by two different companies, and people who choose the first carefully often let the second default to whatever was free. That is a gap: the operator answering for your zone can stop answering, and a name that resolves nowhere is off the internet just as thoroughly as one that was seized. Large providers have abuse desks, and abuse desks act.
The two defensible answers are to run authoritative DNS yourself on a server you already pay for, or to use an operator whose jurisdiction you picked on purpose for the same reasons you picked the registry's. Running it yourself costs you an operational responsibility — two nameservers in different places, monitored, patched — and buys you the certainty that no third party can pull the zone out from under you at short notice. For a project where the name is the asset, that is usually the right trade.
Your zone also publishes things about you. The NS records name your operator. The SOA record carries an email address, which should be a role address and not a person. And a zone with transfers left open to the public internet hands over every hostname you have, including the ones you thought were private — check that yours refuses them, because the default in some configurations is more permissive than people expect.
DNSSEC is worth enabling and is frequently misunderstood: it authenticates answers, it does not conceal them. With the original denial-of-existence records, a signed zone can be walked to enumerate every name inside it, which is precisely why NSEC3 was specified. If your subdomains are not meant to read as a directory of your internal systems, use it.
And assume the resolution history is permanent. Passive-DNS aggregators record every address your name has ever pointed at — including the one you set for ten minutes while testing, including the one that pointed at your home connection before the server was ready. There is no expiry and no takedown for that data. The rule that follows is absolute: never point a real name at anything you would not publish deliberately, not even briefly, not even on a Sunday. The anonymous hosting walkthrough covers the rest of that layered problem.
Keep the time-to-live low on the records that matter — five minutes is a sensible working value — so that moving registrar, moving provider or moving server is a change measured in minutes rather than days. You will be glad of it exactly once, under pressure, which is the only time it counts. The migration playbook has the full cutover sequence.
The public archives that reattach a clean name to a person
Suppose the registration is clean, the payment left no trail and the DNS is yours. There is still a set of permanent, public, freely searchable archives that have been quietly recording your infrastructure the whole time, and they are how attribution actually happens in practice.
Certificate transparency is the biggest one and the least appreciated. Every publicly trusted certificate issued for your name is submitted to append-only public logs — that is the entire design of the system, browsers require it, and the ecosystem is deliberately open. Every certificate you request for a specific hostname publishes that hostname to the world within minutes, permanently. Request one for a wildcard instead and you publish only the parent. The internal hostname you certified once, in a hurry, in 2024, is still there.
Reused identifiers correlate sites far more reliably than any registration record. The same analytics property on two sites, the same advertising account, the same self-hosted metrics instance, the same certificate reused across two hosts, the same SSH host key, the same distinctive ordering of HTTP response headers, the same favicon. Commercial indexes and internet-wide scanners keep all of it and let anyone pivot from one property to another in a single query — this is routine work, not an exotic capability.
Content is its own channel and is untouched by anything at the domain layer. Writing style, the time of day your commits land, an announcement post from an account with your real name on it, a photograph with location metadata intact, a PDF carrying an author field from the word processor that produced it. No registrar decision defends against any of that.
| Public source | What it retains | For how long | What to do about it |
|---|---|---|---|
| Registration-history archives | Every record ever published, including pre-redaction ones | Permanent | Check before assuming a clean start; a burned identifier stays burned |
| Certificate transparency logs | Every hostname you ever certified | Permanent, append-only by design | Prefer wildcard certificates; never certify an internal hostname publicly |
| Passive DNS | Every address the name ever resolved to | Years, with no removal process | Never point a real name at a personal address, not even for a test |
| Internet-wide scanners | Banners, certificates, favicon hashes, header order | Continuous, with history | Keep the public surface unremarkable; never reuse a fingerprint across identities |
| Analytics and advertising identifiers | Which sites share an account | As long as the index is maintained | One identity, one account, no reuse anywhere |
The useful habit is to run the check on yourself before you launch rather than after somebody else does. Look your name up in a registration-history archive, search the certificate logs for it, query a passive-DNS tool, and scan your own address the way a scanner would. Twenty minutes of looking at your own project through a stranger's tooling finds the staging subdomain, the stray certificate and the forgotten test record while they are still cheap to fix.
The escape hatch, and the plan for the day a notice arrives
There is exactly one kind of name nobody can take, and it is the one nobody issues. An onion address is derived from a key you generate on your own machine: there is no registry, no registrar, no renewal and no annual invoice, so there is nothing to seize and nobody to pressure. It costs you discoverability, memorability and the ordinary web audience, so it is not a replacement for a clearnet name — it is the fallback that still works on the morning the clearnet one is suspended. The onion service guide is the full build.
Run both, and advertise the fallback while everything is calm. A single response header — Onion-Location — lets a clearnet site announce its onion address to Tor Browser automatically, which means the audience that will one day need the alternative already has it, rather than having to find it during the week your main address stopped resolving.
Register a spare name too, at a different registrar, under a different registry's jurisdiction, pointing at the same server. It costs a few units of currency a year. Acquiring one under pressure — with the primary suspended, your mail flowing through it and your users asking questions in public — is an entirely different and much worse afternoon.
Keep the recovery kit somewhere the incident cannot reach: a current export of the zone, the registrar credentials and recovery codes stored outside the mailbox that depends on the domain, the transfer authorisation code, and a written answer to the question "if this name disappears at three in the morning, what do we say, and where do we say it?" A plan that lives only in your head is not one.
Know the transfer rules in advance, because they are the constraint that ruins improvised plans. A name is locked against transfer for sixty days after registration and again after a change of registrant under the transfer policy, so "we will move it if there is trouble" is not available to you in the first two months, nor immediately after you have just moved it. Do the moving while nothing is wrong.
When something does arrive, read what it actually is before reacting. A complaint to your registrar is not a court order and often deserves a short factual reply rather than silence. A dispute filing is a procedure with a deadline that will be decided against you by default if you ignore it. A registry hold is not something your registrar can argue away. The DMCA explainer covers how notices flow across offshore infrastructure and which ones have force where. And keep the paperwork: the record you might need to show is the one you will be tempted to delete.
Where does the host fit in all this? We sell the machine, not the name — there is no domain product here, and this guide would be worse if there were. What the hosting layer contributes is that the thing your carefully chosen name points at is itself in a jurisdiction you picked, paid for without an identity check, and provisioned in about forty seconds from four locations. Get the naming layer right and the two halves finally match; get it wrong and the strongest server in Reykjavík is reachable through a form on a website in another hemisphere.