Skip to content

Domain privacy and DNSSEC

Every domain has a public record, often called WHOIS, that lists who registered it and how to reach them. Without privacy, anyone can look up the owner’s name, address, phone number and email address.

WHOIS privacy replaces your personal details in that public record with privacy details, so they are not published. Sheernox includes it at no extra cost, for as long as the domain is registered with us, wherever the extension allows it.

  • You still own the domain. Your real details stay on the registration; only the public record is masked.
  • Your details must still be correct. Registries can suspend a domain whose owner details are false, even when they are hidden. See Keep your contact details up to date.
  • Some extensions do not allow it. Each registry sets its own rules. Where an extension does not allow privacy, its public record shows what that registry publishes.

For .ca domains, the registry (CIRA) hides the contact details of individuals by default. Organizations’ names can be published.

DNS translates your domain name into the addresses of your website and mail server. DNSSEC adds a digital signature to those answers, so a visitor’s network can check that they really came from your domain’s DNS and were not changed on the way. It protects against attacks that send visitors to a fake copy of your site.

Sheernox domains include DNSSEC at no extra cost.

DNSSEC ties the domain to the DNS provider that signs its records. If you move a DNSSEC-signed domain to other nameservers, its records stop validating and the domain can stop working for many visitors.

You turn DNSSEC on or off for a domain in the client portal. Before changing the nameservers of a domain that uses DNSSEC, turn DNSSEC off there first. Turn it back on once the new nameservers are working.