You are not Safe from “.np” ccTLD domain

Kiranghimire
2 min readJun 10, 2023

--

Domain Quest

Most of you guys, especially in the IT field, always wanted to get their own domain.

Maybe your friends or colleagues told you that you can get a free “.npccTLD domain. Mercantile Communication Pvt Ltd is administrating the free domain service.

You can register for “.np” from here for free: https://register.com.np/.

They provide services for both personal use and organizations

These are the detail you need to fill up (“*” indicates the required field not optional ) when you are requesting a domain for the first time.

Problem

So this information needs to be private, right?

No Merchantile provides this information for you all. It gives the information about your “.np” domain including those administrative information.

If you want to access the whois database, you can click on this link: https://register.com.np/whois-lookup.

Example:

I searched for my own domain name, and the following information was revealed in the Whois search results.

  1. My Registrant Email
  2. Name
  3. Administrative Email
  4. Telephone number
  5. Address
  6. Company

Prevent yourself.

When I registered for the first time, I had no idea about this. As per my understanding, you can do the following things.

  1. When you are registering for the first time, ensure that you are using a secondary email or an email that you don’t mind exposing it.
  2. You can put fake information for those above fields. However, you cannot hide or change your “Registrant Email” and “Contact Person”.
  3. Try to avoid domains from Merchantile if you are not following above 2 points.
  4. Buy “.com/.*” and add extra security layer for your domain information privacy (Some providers by default enable for you while some may charge some amounts for getting such security layer)…

If someone knows anything related to this topic please comment. I would love to include here.

If you are thinking that it is valid to show domain aggressive details ,please go through below links.

https://www.worldtrademarkreview.com/article/enforcement-in-era-of-data-privacy-and-redacted-whois

https://developers.cloudflare.com/registrar/get-started/whois-redaction/

http://domainincite.com/23007-icann-approves-messy-unfinished-whois-policy?fbclid=IwAR2bZv3x1FFTDzxi0M1kaAAH9NTg5cdF0Xi4gKWJy03JnOES89COhqzsxDI

https://whois.icann.org/en/basics-whois?fbclid=IwAR1uj6jwpDLCZEEjZZS3Kp-5K3lAEvPJi8ABWV4Eu7sPZ3EE_YpEB0IJ2ng

--

--