Private Web Hosting: Domains, Servers, and Payments
A private web stack reduces specific records: the registrant in WHOIS, the payment trail to the host, and the admin address in access logs. Njalla for the domain, FlokiNET or 1984 Hosting for the server, Monero for payment, Caddy for TLS, and SSH over Tor each address one of those records. What remains is documented below, because every provider in this stack keeps some data and says so in its terms.
Key points
- Njalla registers domains in its own name, so the customer does not appear in WHOIS. Signup still requires an email or XMPP address, and its terms allow disclosure under legal process.
- FlokiNET and 1984 Hosting accept Monero and take orders without identity documents. Both state in their policies that they log connection and device data and comply with lawful requests.
- Administering the server over Tor keeps the home address out of the provider's routine access logs. It does not remove the provider's other records.
- providers compared, none requiring identity documents to order
- 4
- Signup requirements on each service page
- accepted at all four compared providers
- XMR
- Provider payment pages and records
- records this stack reduces: WHOIS, payment trail, admin IP
- 3
- Provider terms linked below
What Each Layer Changes
A registrar or host in the US answers to US legal process, and its records include whatever the order form and logs collected. Moving the domain behind a registration proxy removes the registrant record. Paying with Monero removes the public payment trail. Hosting outside US or UK jurisdiction changes which legal process applies. None of these steps removes the provider's own records: Njalla's terms permit collection needed for legal compliance and disclosure under court orders, FlokiNET's privacy policy documents logging of IP addresses, visit times, and browser data, and 1984 Hosting documents logging of IP addresses and device information alongside bookkeeping records.
This stack reduces routine exposure: data-broker harvesting, WHOIS scraping, and casual correlation. A determined legal process reaching the providers obtains whatever they hold, and the linked policies state what that is.
Step 1 - Domain Registration Through a Proxy
Register through Njalla
Njalla (see service details) registers the domain in its own name and grants control through a service agreement, so the customer does not appear in WHOIS. A WHOIS query returns Njalla, not the customer.
The remaining records are stated in Njalla's terms: signup requires an email or XMPP address, the service collects what it needs for legal compliance, and it can disclose data under law-enforcement requests or court orders. Njalla accepts Monero, Bitcoin, and other coins, so the payment need not add a card record. A separate email alias for the account keeps the address from linking other accounts.
1984 Hosting also sells domains with crypto payment. Conventional registrars with bolt-on WHOIS privacy still hold the registrant data themselves; the proxy-registration model moves it out of the registrant field entirely, at the cost described in the trust note below.
Step 2 - Server Outside US/UK Jurisdiction
Pick a host and read its policy
The compared providers take server orders without identity documents and accept cryptocurrency. What differs is infrastructure range, locations, and exactly what each policy says it keeps.
1984 Hosting: Reykjavik, Iceland. Shared hosting, VPS, and domains, with Monero and Bitcoin accepted. Its privacy notes state it logs IP addresses and device information, retains bookkeeping records, and can transfer personal data to law enforcement under Icelandic process.
FlokiNET: locations in Iceland, Romania, and Finland, with a wider infrastructure range (VPS, dedicated, colocation) and Monero, Zcash, and Bitcoin accepted. Its privacy policy documents logging of IP addresses, visit times, page activity, and browser and operating-system information, and allows disclosure to law enforcement.
Njalla also offers VPS, which keeps domain and server under one account. That convenience concentrates both records with one operator; whether that is acceptable depends on the threat being addressed.
Step 3 - Payment Without a Public Trail
Use XMR where accepted; treat transparent chains as linkable
Monero (XMR) does not produce a publicly readable chain record: ring signatures, stealth addresses, and confidential amounts apply to every transaction. The provider still records the order and the payment event on its side. Acquisition routes without identity checks are documented in the Monero buying guide.
Zcash shielded payments are cryptographically private between shielded addresses, and FlokiNET lists ZEC among its accepted coins. Shielding must be explicit: wallets that default to transparent addresses produce ordinary public records.
Bitcoin is transparent by default, and a payment from an identified wallet links that identity to the server. Coordinator-based CoinJoin availability changed when the largest coordinator shut down, documented in the Wasabi coordinator shutdown article. Where only Bitcoin is accepted, the payment should be treated as linkable and the source of the coins chosen accordingly.
Step 4 - Connect It All
DNS → VPS → TLS
Once the VPS is provisioned and the domain registered:
- Set an
Arecord in the registrar's DNS manager pointing the domain at the VPS address. - SSH into the VPS and install a web server:
caddyornginx. - For TLS with Let's Encrypt:
sudo certbot --nginx -d yourdomain.tld, or let Caddy handle certificates automatically with its built-in ACME client. - Test DNS propagation with
dig yourdomain.tld +short. - Set up a firewall:
ufw allow 22,80,443/tcp && ufw enable.
Caddy suits solo operators: automatic HTTPS, automatic renewal, and a two-line Caddyfile for a basic site.
Operational Hygiene
The stack handles infrastructure records. The remaining exposure is operational, and each item below closes one correlation path rather than promising anonymity.
- Separate device: managing the infrastructure from a machine not used for personal accounts keeps browser sessions and cached logins from bridging identities.
- Separate email aliases: a different alias per provider means one breached or subpoenaed provider does not reveal the accounts at the others.
- No SMS recovery: a phone number on the account adds a carrier-linked identifier. TOTP two-factor avoids it.
- SSH key auth only:
PasswordAuthentication noin/etc/ssh/sshd_configremoves credential guessing and reuse. - Admin over Tor or a VPN: the provider's access logs then record the exit or VPN address instead of the home connection. FlokiNET and 1984 Hosting both document that access logging exists.
- No reused handles: a username shared between this infrastructure and public profiles is a direct correlation path.
The VPS address is public by nature: anyone who resolves the domain sees it. A proxy in front hides it from casual lookups. A Tor onion service alongside the clearnet site provides a reachability path with no registrar at all.
Provider Comparison
| Provider | Jurisdiction | XMR | No-ID order | Documented in record |
|---|---|---|---|---|
| 1984 Hosting | IS | Yes | Yes | Shared + VPS + domains; logs IPs and device data per policy |
| FlokiNET | IS | Yes | Yes | VPS to colocation; logs connection and browser data per policy |
| Njalla | CR | Yes | Yes | Proxy domain registration + VPS; email or XMPP required |
| OrangeWebsite | IS | Yes | Yes | Shared + VPS; Monero via payment processor |
A minimal setup: proxy-registered domain, Monero-paid server, Caddy for TLS, SSH keys only, admin over Tor. Each piece reduces one record. The providers' own policies, linked above, state what remains.
Sources
- Njalla terms of service (registration model, required contact address, disclosure conditions)
- FlokiNET privacy policy (logging and disclosure practices)
- 1984 Hosting privacy notes (logging, bookkeeping retention, disclosure)
- Monero project documentation (transaction privacy properties)
Information is provided for educational purposes. Provider terms change; the linked policies are the current record. Commercial disclosure.
Funding and incentives
Conventional ICANN-accredited registrars hold registrant identity and respond to legal process against it. Njalla's model of registering in its own name moves the customer out of the registrant record; its own terms then define what it holds and when it discloses.
- Domain registration
- A conventional registrar stores the registrant name, address, email, and phone at registration.
- WHOIS and RDAP
- Registrant data is queryable or held in escrow, reachable by data brokers and by legal process.
- Legal process
- Registrars respond to subpoenas and court orders against registrant records; the process required varies by jurisdiction.
- Proxy registration
- Njalla registers in its own name, requires an email or XMPP contact, and its terms allow disclosure under legal process. The registrant record moves; a smaller record remains.
Frequently Asked Questions
How does Njalla keep a registrant out of WHOIS?
Njalla registers the domain in its own name and grants the customer control through a service agreement, so the customer does not appear in WHOIS. Its terms still require an email or XMPP address, permit data collection needed for legal compliance, and allow disclosure under law-enforcement requests or court orders.
Do privacy-forward hosts keep logs?
Yes. FlokiNET states in its privacy policy that it logs IP addresses, visit times, page activity, and browser and operating-system information, and may disclose personal data to law enforcement. 1984 Hosting states that it logs IP addresses and device information and retains bookkeeping records. A privacy posture changes what is collected and how requests are handled, not whether records exist.
Why pay for hosting with Monero instead of Bitcoin?
Bitcoin payments are recorded on a public chain, so a payment from an identified wallet links that identity to the infrastructure. A Monero payment does not produce a publicly readable chain record. The provider still records the order and payment event on its side, so the improvement is the public trail, not the provider relationship.
Does hosting in Iceland protect a website legally?
Icelandic law applies to servers in Iceland, and providers there answer to local legal process rather than US or UK process directly. Providers state they comply with lawful orders, and international legal-assistance mechanisms exist. Jurisdiction changes which process applies; it does not remove legal reach.
What is a minimal private hosting setup?
A domain held through a registration proxy such as Njalla, a server at a provider that accepts Monero, TLS through Caddy or certbot, SSH with keys only, and admin access over Tor or a VPN so the home address stays out of routine access logs. Each piece reduces one specific record; none of them makes the operation anonymous.