Privacy Policy

Last updated: 27 August 2026

1. Controller and contact

checkdmarc is operated by an independent sole operator based in Türkiye, acting as data controller for the data described below. For any question or request relating to your data, write to support@checkdmarc.net. We answer data requests at that address.

2. What we hold

DataWhyKept for
Your account email addressTo sign you in and send your summaries While the account exists
The domain names you monitorTo match incoming reports to you While the domain is in your account
Aggregated report figures (message counts, authentication results, sending IP addresses)To produce the summaryIndefinitely, in aggregated form
Raw report emails as receivedTroubleshooting and reprocessing 30 days, then deleted automatically
Billing dataHeld by Polar, not by usPer Polar's policy

3. Aggregate reports do not contain message content

DMARC aggregate reports (RFC 9990) contain counts and authentication outcomes grouped by sending IP address. They do not contain message subjects, bodies, attachments, or the addresses of individual recipients. RFC 9990 §7.2 addresses this directly: aggregate reporting is designed so that it does not expose per-message information.

Failure reports are out of scope. We do not accept, request or process ruf failure reports (RFC 9991). Those are a different format and can contain message headers, subjects and recipient addresses. Reports sent to an address we allocate are only ever used for aggregate data; anything else is discarded. We do not ask you to publish a ruf= tag and we recommend you do not point one at us.

4. Sending IP addresses

Aggregate reports include the IP addresses of servers that sent mail using your domain. These are infrastructure addresses, not individual users' addresses, and we process them only to tell you which sources are failing authentication.

5. Where the data is

ProcessorRoleLocation
CloudflareHosting, mail receipt, storage, database Global network, including the United States
Resend (uses Amazon SES)Sends your summary email Currently Asia Pacific (Tokyo) region
Polar Software Inc.Payments and billingUnited States

Using the Service therefore involves transferring data outside your country. If you are in the EEA or the UK, these transfers rely on the processors' own standard contractual clauses. If you are in Türkiye, the same transfer is covered by KVKK art. 9.

6. What we do not do

7. Your rights

You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to support@checkdmarc.net. Deleting your account removes your account record, your domains and their aggregated figures. Raw report emails expire on their own 30-day schedule.

8. Security

Reports are only accepted from senders that pass DMARC authentication, which is what stops a third party from injecting fabricated reports into your summary (RFC 9990 §8.2). Data is held on Cloudflare infrastructure and reached over TLS.

9. Changes

If we change this policy in a way that affects how your data is used, we will email account holders before the change takes effect.