The Dark Side of Cheap WHOIS Data: Fueling Spam and Telemarketing Nightmares
In today’s digital landscape, the importance of privacy and data security cannot be overstated. While technologies like WHOIS databases were initially designed to provide transparency in domain registration, the rise of easily accessible and affordable WHOIS data has inadvertently opened a Pandora’s Box of spam, telemarketing, and potential privacy abuses. This article delves into the troubling consequences of cheap WHOIS data and examines the ethical and legal implications for individuals and businesses alike.
I usually keep my iPhone on “do not disturb” mode at night, a practice many of us employ to safeguard our sleep. However, on one particular night, August 16th, I made an exception. My wife was traveling, and I wanted to ensure she could reach me in case of an emergency.
At 4:19 AM, my phone abruptly came to life, piercing the silence and jolting me awake.
It wasn’t my wife. Instead, it was an unsolicited text message.

The intrusive text message originated from Devan Crow, the owner of a Florida-based company called SkyNet Group LLC. Mr. Crow’s business model revolves around providing readily available WHOIS data for a fee – a mere $500 per quarter, or even less for extended subscriptions.
His service promises daily updates on fresh WHOIS data:
“The subscription provides full data going back more than a year. Updates are provided daily and include all new registration across the primary legacy extensions (com, net, info, us, org) and all of the 300+ new zones (xyz directory etc) along with all of the parsed Whois data for each domain. Includes registrar data and country of registrant for each domain as well and includes direct contact details for all registrants.”
In an email correspondence with Domain Name Wire, Crow defended his data practices, asserting that his data is not the primary driver behind the surge in domain registration spam:
“I know my clients well and I understand their specific use cases. I have & will cut off users who I know are using the data simply for unblatent/un-targeted marketing. This simply falls upon personal responsibility: I can not control my clients – nor any other human being for that matter – but I will cut their data off if necessary.) I do not provide refunds however in this case as stated in the contract that clients agree to/sign.”
However, the sheer scale of data acquisition and its potential for misuse raises significant concerns. It’s difficult to fathom amassing such a vast amount of data without the intention of employing it for extensive marketing campaigns, even if Crow claims to discourage spam.
Unfortunately, the relentless barrage of spam following domain name registration is a growing problem. Malicious actors are leveraging daily zone file and WHOIS comparisons to send unwanted solicitations. The more accessible and affordable this data becomes, the easier it is for spammers to exploit the system.
Crow maintains that his collection and sale of bulk WHOIS data does not violate any terms of service agreements with registries or registrars. In his defense, he indirectly acknowledges that the data is being utilized for telemarketing purposes:
“ICANN allow the collection of whois data if you enrich the data and inhance it with other data. The data as provided to clients is enriched. This allowance is true with many data handling licenses. An example of how the data is enriched for one of my clients requires that telephone records of US registrants be identified as wither a landline or cell phone. The accuracy of this data needs to include numbers that have been ported as well (ported from landline block to cellular OR from cellular blocks to landline.) Porting is a growing trend but currently effects around 3%. This same client also requires the number to be checked against state and federal do not call lists. This is important because MOST companies fail to access and check their data against state lists. You are familiar with Web.com doing the very same thing recently. They called a client who was not listed on the federal do not call list but was on a state do not call list. What most companies do not understand/realize is that laws requires a business to know if a number is on s do not call list simply for it being in their database. A very good reason why the scrubbing API that I built is so popular among my clients.”
This begs the question: Is the widespread harvesting of WHOIS data a contributing factor to the alarming increase in robocalls that many of us are experiencing?
Crow further references this ICANN page as justification for his practices.
However, it is crucial to note that the very page he cites explicitly states: “WHOIS may be used for any lawful purposes except to enable marketing or spam, or to enable high volume, automated processes to query a registrar or registry’s systems, except to manage domain names.” This directly contradicts the use of WHOIS data for marketing and spamming purposes.
It is important to acknowledge that Crow is not alone in the business of selling WHOIS data. Numerous companies offer similar services. However, the incredibly low price point at which Crow offers his data makes it exceptionally easy for marketers, including those with less ethical standards, to exploit the system and engage in spamming activities.
When confronted with my complaint about the ill-timed and unsolicited text message I received at 4:19 AM, Crow offered an unapologetic explanation:
“The only way to reasonably expect a person’s local time is their area code. Unless you are travelling and out of your normal area you would not have received a text at 4am. The only exception is where a wireless network delays the delivery of the message (similar to how email messages can temporarily soft bounce). (Ive had it where a person has sent me a text and I dont receive it until 12+ hours later.) While this can happen and still does from time to time it is pretty rare.”
The Ethical Quagmire of WHOIS Data
The accessibility of WHOIS data presents a complex ethical dilemma. While intended for transparency and accountability, the ease with which this information can be obtained and exploited for unsolicited marketing and spam raises serious concerns. The balance between legitimate uses of WHOIS data and the potential for abuse needs careful consideration.
The Need for Stricter Regulations and Enforcement
To mitigate the negative consequences of readily available WHOIS data, stricter regulations and enforcement mechanisms are essential. ICANN, registries, and registrars must collaborate to develop and implement policies that prevent the misuse of WHOIS data while preserving its legitimate applications. This may involve stricter data validation, limitations on bulk data access, and more robust enforcement of existing anti-spam regulations.
Protecting Your Privacy in the Age of Data Harvesting
In the face of increasing data harvesting and potential privacy violations, individuals must take proactive steps to protect their personal information. Utilizing privacy services offered by domain registrars to mask WHOIS data is one effective strategy. Furthermore, staying informed about data privacy regulations and advocating for stronger data protection laws are crucial steps in safeguarding personal information in the digital age.
Conclusion: Reclaiming Control Over Our Data
The proliferation of cheap, easily accessible WHOIS data has created a fertile ground for spam, telemarketing, and potential privacy abuses. While WHOIS databases serve a valuable purpose in promoting transparency in the domain name system, the current system needs to be re-evaluated and reformed to prevent its exploitation for malicious purposes. By implementing stricter regulations, enhancing enforcement, and empowering individuals to protect their privacy, we can strive to reclaim control over our data and create a safer, more secure digital environment.