Originally published at https://monstadomains.com/blog/domain-registrar-id-verification/
Would you hand a company your passport to buy a website address? That question stopped being hypothetical this year. Porkbun, a registrar with more than three million domains under management, now asks a subset of new customers to submit a government photo ID before a purchase completes. India made domain registrar ID verification mandatory for .IN registrants. Europe wrote registrant verification into law. Three separate forces, no coordination between them, and one direction of travel.
Porkbun Quietly Made Photo ID A Condition Of Purchase
Porkbun’s own knowledge base is blunt about the reasoning. The registrar says it requires verification to combat “fraud, abuse, and other misuse” and to “comply with ICANN and other contractual obligations that require every account has correct and verifiable contact information.” Only “a subset of new Porkbun accounts” is affected, selected by “geographic regions and other signals.” Submissions are routed through Veriff, a third party identity vendor, and Porkbun states it retains them for fifteen days before deletion. After that, the only trace is a flag confirming the account passed.
The framing is careful and the retention window is shorter than most. It is still a registrar that reached three million domains under management in October 2025 deciding that domain registrar ID verification is an acceptable cost of entry. Scale is the point. When a price leader adopts a practice, competitors stop treating it as extreme and start treating it as a benchmark.
Why The Self Hosting Community Pushed Back
The backlash was immediate, and it was not about fraud. People who run their own infrastructure do so precisely to avoid depositing identity documents with corporations. Critics noted that no law obliges a registrar to collect a passport or driving licence; ICANN requires accurate contact data, not verified identity documents. They also made the argument every security engineer makes: every company promises encryption right up until the breach notification goes out. Domain registrar ID verification does not remove that risk. It creates a fresh pool of documents worth stealing.
India Turned Domain Registrar ID Verification Into Law
India’s NIXI went further than any commercial policy has. Under the 2026 rules for .IN and .BHARAT domains, registrants must complete identity verification within seven days of registration or renewal. Indian residents verify through DigiLocker using Aadhaar, PAN or passport. Foreign registrants must supply a verified passport copy plus documentation proving a legitimate business link to India. Miss the window and the domain is suspended, which takes the site offline in full.
The privacy provisions are the sharper edge. Registrant name, city and state become publicly visible. Disposable and temporary email providers are barred in favour of a permanent contact address. Registrations attempted through high anonymity VPNs may trigger manual review. Domain registrar ID verification in this form is not a fraud filter. It is a deliberate policy decision that anonymous publication under a .IN domain should not be possible at all.
NIS2 Made Europe The Template For Registrar Checks
Article 28 of the EU’s NIS2 directive obliges registries and registrars to collect and maintain accurate registration data, including registrant name, contact email and phone number, and to publish clear verification policies. Registries must answer lawful data requests within 72 hours. The transposition deadline passed in October 2024, and by mid 2025 several member states still had not implemented it, which is why domain registrar ID verification is arriving late and unevenly across the bloc.
NIS2 never says passport. It says verification, and leaves the method to registrars. Compliance vendors filled that gap with exactly what you would expect: document scans, selfie matching, database cross checks. This is how domain registrar ID verification becomes standard without a single lawmaker voting for it. A vague statutory verb becomes a product category, and the product category becomes the industry default.
What The Domain Registrar ID Verification Wave Reveals
Read the three events together and the pattern resolves. Porkbun acted on fraud economics. NIXI acted on national policy. NIS2 acted on security regulation. None of them coordinated, and none set out to end anonymous domain ownership, yet the combined effect is a market where domain registrar ID verification is the assumed baseline and its absence is what needs justifying. That inversion is the real news here. The burden of proof moved from the party demanding documents to the person declining to supply them.
The wave also reveals how poorly the checks match the stated problem. A fraudster buying domains at scale can source or synthesise documents, and that industry is mature and cheap. The person genuinely deterred by domain registrar ID verification is the journalist in a hostile jurisdiction, the activist, the researcher publishing something an employer would punish. The EFF has argued for years that anonymity is a shield from the tyranny of the majority. Verification mandates remove that shield from precisely the people who cannot replace it.
The Breach Math Nobody Runs Before Uploading A Passport
Porkbun’s fifteen day retention is a real mitigation and deserves credit. It is also not the general case. Most domain registrar ID verification flows involve at least three parties: the registrar, the identity vendor, and whatever cloud storage sits behind them. Each is a separate breach surface with its own logging, its own subprocessors, and its own retention policy that can be revised without ever notifying you.
A passport scan is not a password. You cannot rotate it after a leak. Its value to an attacker climbs as more services accept it as proof of identity, so a document exposed in 2026 stays useful for a decade. Earlier registrar security failures showed how much damage flows from one compromised account. Domain registrar ID verification raises the ceiling on that damage considerably, because the loot is now identity itself.
Why Domain Registrar ID Verification Breaks WHOIS Privacy
Plenty of owners assume WHOIS privacy already solves the domain registrar ID verification problem. It does not. WHOIS privacy masks what the public sees. It does nothing about what the registrar holds. Once verification sits in the chain, the registrar has a verified legal identity bound to the domain, and that record is what answers subpoenas, court orders and the 72 hour disclosure requests NIS2 created. India removed even the public mask by keeping name, city and state visible.
Masking Versus Never Collecting
The distinction that matters is between data that is hidden and data that was never gathered. We have written before about the limits of WHOIS privacy, and domain registrar ID verification makes that point unavoidable. A registrar that never held your passport cannot lose it, sell it, or be compelled to produce it. Data minimisation is the only control that survives both a breach and a warrant, because it removes the thing being sought.
What Domain Owners Should Do About This Now
Read your registrar’s published verification policy before your next renewal rather than after a suspension notice. Porkbun applies domain registrar ID verification to new accounts by region and risk signal, so existing customers may be unaffected today and in scope tomorrow. If you hold .IN or .BHARAT names, treat the seven day window as real and decide now whether that namespace still fits your threat model.
For anything genuinely sensitive, choose the registry and the registrar before you choose the name. A registry with a national identity mandate cannot be worked around at the registrar level, no matter who you buy through. If your work requires you to register a domain without ID checks, that call has to be made at registration, because moving a name that already carries a verified identity record does not erase the record.
Audit What You Have Already Handed Over
If you have already completed domain registrar ID verification somewhere, ask for the retention policy in writing and ask which subprocessors received the documents. Under GDPR and comparable state privacy laws you can usually demand deletion once the check has cleared. It is a tedious request to file and most people never bother. It is also the only way to shrink an exposure you have already created for yourself.
The Takeaway
Three unrelated decisions in three jurisdictions turned domain registrar ID verification from an outlier into a default, and none were debated as the privacy change they actually are. The checks stop few determined fraudsters and reliably deter the people whose safety depends on publishing without a name attached to it. Every submitted document creates a permanent, unrotatable liability spread across parties the registrant never chose.
The useful response is not outrage, it is minimisation: pick registries and registrars that never collect what they cannot later be forced to disclose. That premise is the whole reason MonstaDomains exists, so if you want a name that carries no verified identity record at all, begin with anonymous domain registration instead of trying to undo one later.




