Privacy Policy
Last updated: July 2026
dmarco ("we", "us", "our") operates the dmarco platform at dmarco.email and app.dmarco.email. This Privacy Policy explains how we collect, use, and protect your information when you use our services.
Information We Collect
Account information: When you create an account, we collect your name, email address, and organization details through our authentication provider (Kinde).
DMARC report data: We collect and process DMARC aggregate reports from IMAP inboxes you configure. These reports contain email authentication metadata — specifically IP addresses, sending domains, SPF/DKIM results, and message volume counts. DMARC aggregate reports do not contain personal email content, subject lines, or message bodies.
Header analyzer submissions: The header analyzer works on an individual email you give it — pasted into the public analyzer, forwarded to an analysis address, or sent from the Outlook add-in. Submitted text is handled in two parts. The header block is what the analysis is recorded from; it includes sender and recipient addresses, routing (Received) headers, authentication results, and any mailing-list or ARC headers. A message body, when you include one, is used only to check what the body claims and where its links and images point — it is then discarded. We do not store message bodies. Findings derived from a body, such as link hostnames and the sender display name a reader would see, are part of the saved analysis.
Usage data: We collect standard usage information such as pages visited, features used, and browser/device information to improve our service.
Payment information: If you subscribe to a paid plan, payment processing is handled by our payment provider. We do not store credit card numbers or bank account details on our servers.
How We Use Your Information
We use your information to:
- Provide, operate, and maintain the dmarco platform
- Process and analyze DMARC aggregate reports for your domains
- Analyze individual messages you submit to the header analyzer and return a verdict on them
- Identify and attribute email senders through IP enrichment and DNS lookups
- Send you service-related notifications and alerts you have configured
- Respond to your requests and provide customer support
- Improve and develop new features for the platform
The Header Analyzer
You can use it without an account. The public analyzer at app.dmarco.email/header-analyzer requires no login, and submissions made through it are not linked to a user, an organization, or an email address. Requests are rate-limited by IP address to keep the endpoint from being abused.
What we keep, and for how long. Every analysis leaves a summary record: the sending address and domain analyzed, the verdict, the DMARC, SPF and DKIM results, a one-way hash of the submitted header block, and a timestamp. The submitted header block itself and the detailed finding trail are kept for 90 days by default, then automatically cleared while the summary record remains. Message bodies are never stored at all.
You can shorten that window. The public analyzer lets you pick a shorter retention period before you submit, including an option that stores none of your submitted content — only the verdict summary. The analyzer tells you which of these applied to your submission on the results page.
What we cannot do. Because public submissions carry no account, email address, or other identifier, we have no way to connect one to you after the fact and therefore cannot answer an access or deletion request for an individual public submission. The retention choice at submit time is the control that governs it. Analyses run from a signed-in organization or from the Outlook add-in are linked to that organization and are covered by the rights described below.
How the verdict reaches you. In the public analyzer the verdict is shown on the page and goes nowhere else. On the forward-to-analyze and Outlook add-in paths it is emailed back to the address that submitted the message, and to a security-team address as well where your organization has configured one. That email carries the analyzed sender and domain, the verdict, and the recommendation text, and it is delivered through our email provider — see Third Parties below.
Links we resolve during analysis. Checking a message means looking up DNS records for the domains involved, and, for shortened links on a small curated list of shortener services, following the link to find its true destination. Those requests go out from our servers, so the destination host may see our server's address rather than yours. They are made over HTTPS only, carry no cookies or credentials, and are blocked from reaching private or internal network addresses. We do not fetch arbitrary links from a message body — only the shortener services on that list.
Data Storage & Security
Your data is stored in secure, managed databases. We implement appropriate technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction.
DMARC report data is retained according to your plan's retention period. The current retention period for each plan is listed on our pricing page; report data beyond it is automatically deleted. Separately, the original XML attachment each report arrived as is discarded after 90 days, while the parsed records from it remain available for your plan's retention period.
Header analyzer submissions follow the retention rules described in the section above, not your plan's report retention period.
Credentials you give us are stored encrypted at rest. This covers IMAP credentials for your DMARC inboxes and, where your organization configures its own email delivery provider, the API key or SMTP credentials for that provider.
Third Parties
We do not sell, rent, or share your personal information or DMARC data with third parties for marketing purposes.
We use the following third-party services to operate the platform:
- Kinde — Authentication, user management, and subscription billing. Kinde uses Stripe as its payment processor.
- Stripe — Payment processing for subscription plans (accessed via Kinde, or directly for annual billing arrangements).
- SendGrid (Twilio) — Email delivery. Alert notifications and header analyzer verdicts are sent through SendGrid, so the recipient address and the contents of those messages pass through it. Organizations that configure their own email provider send that mail through their own provider instead, and it is not routed through ours.
- Sentry — Error tracking and application monitoring. Sentry collects technical error data (stack traces, browser information, request metadata) to help us identify and fix issues. Authentication cookies and credentials are stripped before an error report is sent. In normal operation Sentry does not receive DMARC report contents or header analyzer submissions.
- MaxMind — IP geolocation and ASN data for sender enrichment. IP addresses from DMARC reports are looked up locally against a MaxMind database. No data is sent to MaxMind.
- Infrastructure providers — Cloud hosting, database, and DNS services.
These providers only access your data as necessary to perform their services and are bound by their own privacy policies.
Cookies
We use cookies that are strictly necessary for the platform to function. We do not use third-party tracking cookies, advertising cookies, or analytics cookies.
Cookies we use:
- Session cookies — Used to maintain your authenticated session. These are httpOnly, secure, and expire when your session ends or after the configured session duration.
- Authentication cookies — Set by our authentication provider (Kinde) during the login flow to manage your identity and organization context. These are httpOnly and expire after 29 days.
Because we only use essential cookies required for the service to function, we are not required to obtain cookie consent under GDPR/ePrivacy regulations. We display a brief informational notice about our cookie use for transparency.
Your Rights
You have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your account and associated data
- Export your DMARC report data
- Object to processing of your information
To exercise any of these rights, contact us at the email address below.
These rights apply to data we can connect to you. As described under The Header Analyzer, a submission made through the public analyzer without an account carries no identifier that links it to you, so we cannot retrieve or delete an individual one on request.
Contact
If you have questions about this Privacy Policy or how we handle your data, contact us at: