Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Public who's details have become absurd. Register any domain and choose not to use domain privacy. Your inbox will fill up over the next hour with people wanting to sell you seo services or a new WordPress installation. I don't mean five or five or six spam emails, I mean you could see over a hundred umin the first hour . Such mailboxes are sure to become unusable .


If you register in a tld which doesn’t allow privacy (.net or .us? Forget which) everything leaks. Kiss goodbye to your phone number. I accidentally did this and got 50 calls within the first 8 hrs. It was insane.


It was .us, operated by GoDaddy ;)

Not surprised on this, especially on the GoDaddy part. Although .uk also has no-proxies rule, at least Nominet themselves don't reveal your details if you're an individual even before GDPR (the idea being that if you're a company you have enough money to handle public requests).


For what it's worth, .us is the ccTLD for the United States, and policies for it like "You can't hide your WHOIS info" would be set by the US government, not by GoDaddy. GoDaddy Registry as the backend registry service provider isn't setting the policies for a ccTLD.


> policies for it like "You can't hide your WHOIS info" would be set by the US government

I have actually checked this, and you're (partially) wrong on this one. To be fair, I was also wrong that GoDaddy (within limitations set by the Department of Commerce) has free reign here. The actual process is more boring: while the US DOC has veto powers, in practice it's the .US Stakeholder Council (https://www.about.us/stakeholders) which decides on matters about .US policies.

On that note, in the specific issue of no-proxies rule it was the US DOC who enforced it, not GoDaddy or Neustar (which was the previous operator): https://www.washingtonpost.com/wp-dyn/articles/A7251-2005Mar...


It's interesting to see the evolution of the .de whois. Germany is one of these countries that unsurprisingly doesn't allow domain privacy for various legal reasons, but this clashes with the equally strong privacy desire. Back in (not so) ancient times you just got all info with a normal whois, then the whois started giving you less info and told you to go to the registrar's website (denic.de) where you had to fill out a captcha. With GDPR came some checkboxes to verify you have legitimate reasons to get this info. Now even that is gone, you have to either send them an email or fill out a pdf, sign it and email it to them.


That’s exactly why I’ve used an “admin@“ address for decades now on email registrations. It has a filter that will then redirect anything from the registrar’s domain and junk anything else.


That's fun and I like the idea, until the ICANN decides you need to verify your domain or it'll be terminated within two weeks. Who knows what email sending service or domain they'll decide to use. (OVH, for instance, sent me this not only from a different domain, but from a different country TLD altogether than previous emails from them.)

Do you also have a dedicated phone number for your registrar to call? And home address? The whole thing is a bit iffy, I'd much rather that my personal information remains with the party that can relay any relevant queries.

Another problem with using an inbox @ your domain is that, when there's a problem with your domain... good luck receiving that email. I have two accounts with the registrar for different domains and they point to each other. Not great, perhaps I should open a hotmail for this that relays copies of any emails so I still get the notifications during normal times, but it's something.


> until the ICANN decides you need to verify your domain

ICANN don't do that. Your _registrar_ is required by ICANN policies (search for "Whois Data Reminder Policy") to send you notifications to ensure your contact information is current. Whether your domain gets terminated or not is largely down to your registrar, but if your contact details aren't accurate, you probably aren't getting billing notifications either.


Um, I can sign up as John Doe being the domain owner but it's not required that Ms. John also pays the bills upon renewals. Never had a problem with domains under anonymised names.

And it is ICANN policy, it's not the registrar doing this for fun and profit. Per their new-ish policy, it is that my registrar indeed sent that email from a random domain they had laying around.


sweet!

hoping your registrar does indeed send his 'very important mail' from that domain .


Don’t forget your physical mailbox too


I've received a few official-looking fake renewal notices over the years.


I've been using whois privacy for years mostly because of this, but IIRC the bulk of my spam was from Comcast Business. Because anyone who registers a personal website must need a business internet connection.


emails? I wish. I get random calls from India for “web site design and seo optimisation” that got my digits from whois info.


Choose to use domain privacy and you will receive the same spam but with your email proxied/obfuscated. Happened to me last week.


I haven’t experienced this with Google domains or Cloudflare.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: