dmarcproof dmarcproof Sign in
Home / Transparency
Transparency

What we collect — and what we never touch

We never read your reports

The DMARC report XML is discarded unread — never parsed, never stored. We characterize only the sending server's connection.

What we collect (per connection)

Source IP, ASN, network prefix, reverse-DNS/FCrDNS result, HELO/EHLO, TLS handshake details and a fingerprint, the verifying DKIM d= domain, the envelope SPF result, the per-tenant recipient address, and timestamps.

What we never collect

Message bodies, the report XML payload, or forensic (RUF) reports.

What we discard, and when

FAQ

Do you read or store the DMARC report contents?

No on both counts. We never parse the XML payload and never persist it. The report is a transport carrier; we extract connection metadata about the sending server and the payload is discarded unread.

Why trust the source IP but not the report contents?

A completed TCP + TLS + SMTP exchange can't spoof its source address — the connecting IP is ground truth. The XML is trivially forgeable; the connection is not.

Can someone poison the data with fake reports?

They can send fabricated reports, but those arrive from infrastructure that fails transport authentication and never appears across many unrelated domains, so they never earn confidence in the published list. Per-tenant addressing and DNS-level authorization further limit who can reach us at all. And note what the list asserts: confidence that a sender is a legitimate reporter — not a determination that any given connection is malicious. A source merely absent from the list has simply earned no confidence yet; absence is not an accusation.

Is the published list a hard allow/block gate?

No. It's a high-confidence scoring and triage input, not a 100% failsafe — infrastructure churns and shared cloud space is ambiguous. Treat it as a strong signal, not an absolute verdict.

What about GDPR — aren't connecting IPs personal data?

They can be. We minimize by design (transport metadata only, never message content) and rely on a documented legitimate-interest assessment. Raw connection data is kept only for a short rolling window and then automatically purged — data minimization by design — leaving only a minimal, low-identifiability aggregate. Published data carries a dispute/takedown process.

Is dmarcproof free?

Yes — free to use, non-commercial.

Disputes & takedowns

Believe a published entry about your infrastructure is wrong, or want it removed? Every published entry has a dispute/takedown path.

Start a dispute or takedown →