Hacker News new | ask | show | jobs
by lamlam 2952 days ago
I like what CIRA (the .ca registration authority) does. The default is for them to hide your contact information. You have to opt-in to make it public.

They then handle all communications people want to send to you. More registration authorities should take stances like this.

Now if only they could get DNSSEC support...

3 comments

I emailed them about this just last week:

Me: Are people who are not Canadian citizens able to purchase/register .ca domains? I've read that a Canadian phone number is needed for registration. Additionally, can a non-Canadian citizen get CIRA's WHOIS privacy for their domain?

Their Response: Thanks for getting in touch with CIRA, [redacted]. CIRA has 18 Canadian Presence categories, we require full contact information when an individual or a business is registering a .CA domain name. That doesn't mean you have to be in Canada to hold a .CA domain, many Canadian live all over the world and registered .CA domain names. A non Canadian could hold a .CA domain name but that would require them to either register a Canadian Trade Mark, Canadian Corporation, or hold a Permanent Resident card. The WHOIS information is "masked" or "privacy protected" when the .CA category of "Canadian Citizen - Individual" is selected.

So it looks like WHOIS privacy is not easily available if one isn't a Canadian citizen. I still like the model, however.

I like how people responsible for .pl (Poland) domain handle this. First of all, they list only very basic data, with no names, addresses, etc. when you query their whois. To see the full data, you have to go to their website and type the captcha, which filters out at least some of the bots. But even there they display the data if it belongs to a company, they won't show any details if it's registered to a private person.
Seems like it's the same for .eu domains, and (I think) some other EU countries. For private persons you only see the email, and that's after entering the captcha.
> you have to go to their website and type the captcha

I'd prefer that they'd charge me 5 eurocents per query rather than using my time and effort to feed Google's AI.

Not sure why you are saying this, when the site uses a "usual" captcha (that can probably be solved easily, but that's another thing): https://www.dns.pl/cgi-bin/en_whois.pl

See also https://www.denic.de/webwhois-web20/ for the .de registry's captcha.

CIRA has had DNSSEC support since 2014. https://cira.ca/dnssec-faqs

I use Google Domains and it supports DNSSEC on my .ca domains.

Huh. This is great! Might be a NameCheap (my registrar) limitation. The way it's worded in the management page on NameCheap is that DNSSEC is not supported for .ca period. Definitely something I'll look into. Thanks!
Probably. I had to move to baremetal.ca to get DNSSEC support, and even then I had to email the info to their tech support team as the web interface didn't support it