Why You Get Spam Calls Right After Buying a Domain (And How to Stop Them)
You register a domain for a new project, and by the next day your phone is ringing with calls about SEO services, website design, and business loan offers — for a business that, as far as you're concerned, only exists as a domain name so far. It feels like surveillance, and in a real sense, it is.
Where Are They Actually Getting Your Number?
Every domain registration includes contact information stored in WHOIS, the public directory of domain registrants, unless privacy protection is specifically enabled to mask it. Without that protection, your name, business, email, and often phone number are published openly the moment your registration completes.
Automated scraper bots continuously monitor new domain registration feeds precisely because this data is fresh and highly targetable — someone who just registered a domain is, almost by definition, actively starting or building something, which makes them a valuable lead for web design agencies, SEO resellers, and less scrupulous marketers alike. That data gets sold and resold, which is why the calls often continue even after the initial source seems to dry up.
Why Doesn't Every Registrar Turn WHOIS Privacy On by Default?
For most generic extensions (.com, .net, .org, and similar), ICANN has required registrars to offer WHOIS privacy since 2013, but "offer" is not the same as "enable automatically." Some registrars turn it on by default and treat it as a baseline part of the service; others leave it off by default and either sell it as an add-on or bury the toggle in account settings, because privacy-protected WHOIS records slightly complicate their own upsell and affiliate-tracking data. Country-code extensions are the bigger exception — many ccTLD registries (some European and Asia-Pacific ones in particular) either don't permit WHOIS privacy at all or require you to prove a specific legal basis for it, since local privacy law sometimes conflicts with the registry's own public-record requirements. If you register a lot of domains across different extensions, checking each registry's actual privacy policy — not just your registrar's marketing page — is the only reliable way to know where you stand.
How Do You Stop It?
- Enable WHOIS privacy protection immediately if it wasn't already turned on at registration — most registrars let you do this retroactively from the domain's management settings.
- Confirm it's actually active by running your own domain through a public WHOIS lookup and checking whether your real contact details still show or have been replaced with the registrar's privacy proxy information.
- Choose a registrar that includes privacy free by default going forward — this varies significantly between providers, and it's worth checking before your next registration rather than after.
- Block and report numbers as they call, which won't stop new scrapers but reduces repeat contact from the same source.
- Avoid using a personal cell number for future domain registrations where possible — a business line or a number you don't mind being public limits the personal impact even if privacy settings ever lapse.
Is There Anything Illegal Happening Here?
Usually not in the way people assume. WHOIS data being public was, for a long time, an explicit design choice by domain registries — the theory being that anyone should be able to identify who controls a domain. Scraping public WHOIS data and using it for marketing calls sits in a legal gray area rather than a clear violation on its own, though the calls themselves can separately break robocall and telemarketing rules (like the U.S. TCPA) depending on how they're placed. That distinction matters practically: reporting the calls to a regulator addresses the calling behavior, but it does nothing about the underlying data exposure — only WHOIS privacy fixes that part.
Is It Too Late If You Already Got Calls?
Turning on privacy protection now stops new scraping of your current details, but it won't retroactively remove data that's already been collected and resold — some residual contact may continue for a while even after you lock things down. That's the reality of how broadly this data spreads once it's public, which is exactly why enabling privacy from the very first registration, rather than adding it after the calls start, is the more effective long-term habit. If you're choosing a registrar for future domains, factor free WHOIS privacy into that decision the same way you'd weigh price or support quality; our guide to choosing a registrar covers what else is worth checking.
Quick Answers
Never lose a domain again
Track every domain you own in one dashboard. Free for up to 15 domains.
