Last updated: June 2026
This Cookie Policy explains how DMARC Engine uses cookies and similar technologies when you visit our website or use our hosted email-authentication platform. It describes what these technologies are, the specific categories we rely on, how long they last, the legal basis on which we set them, and the choices available to you for managing or withdrawing your consent. DMARC Engine is a done-for-you platform that helps organisations configure and enforce DMARC, SPF, DKIM, MTA-STS and BIMI, and move their domains safely to a policy of p=reject. To deliver that service securely and reliably we depend on a small number of cookies and on the browser's local storage. This policy should be read together with our Privacy Policy, which sets out in more detail how we collect, use and protect personal data. Where this policy uses the word "cookies", we mean cookies and the closely related storage technologies described below, unless we say otherwise.
A cookie is a small text file that a website asks your browser to store on your device. When you return to the site, the browser sends the cookie back, which allows the site to recognise your session, remember your preferences and keep you signed in. Cookies cannot run programs, read your hard drive or deliver malware; they are simply small pieces of data tied to a particular website.
Alongside cookies, modern browsers offer two related storage mechanisms that we also use. Local storage (localStorage) lets a website save data in your browser that persists between visits until it is explicitly cleared, and that data is never automatically transmitted to the server with each request. Session storage (sessionStorage) works in the same way but is cleared as soon as you close the browser tab. We use these web-storage mechanisms in preference to cookies wherever a value only needs to be read by the browser itself, for example to remember your cookie-consent choice or a small interface preference, because keeping that data out of network requests is more privacy-respecting and more efficient.
We keep our use of cookies and storage deliberately minimal and focused on running the service. In broad terms we use these technologies to authenticate you and maintain your signed-in session, to protect forms and requests against cross-site request forgery, to remember your consent and interface preferences, and to understand how the website and application are used and performing so that we can improve them and measure our marketing. Some of these uses involve third-party services from Google, namely Google Analytics 4 (analytics) and Google Ads (advertising, conversion measurement and remarketing). These non-essential cookies are set only with your prior consent, given through the cookie banner, and you can decline them without affecting your use of the service. We never set them before you consent, and we do not sell your personal data.
The technologies we use fall into the following categories. Understanding the difference matters because some are essential to providing the service you have asked for, while others are only set with your consent.
Strictly necessary. These are required for the platform to function and cannot be switched off without breaking core features. They include the session and authentication cookie that keeps you logged in as you move between pages, an anti-CSRF (cross-site request forgery) token that protects your account when you submit forms and make changes, and your cookie-consent preference, which we store in the browser's localStorage so that we do not have to ask you again on every visit. Because these are essential to deliver a service you have explicitly requested, they do not require consent.
Functional and preferences. These remember choices you make to give you a more consistent experience, such as your preferred display settings and similar non-essential preferences. They are not required for the service to work, but they make it more comfortable to use.
Analytics and performance. These help us understand how visitors use the website and application, for example which pages are most visited and where users encounter errors, so that we can diagnose problems and improve the product. In addition to our own first-party measurement, we use Google Analytics 4, a third-party analytics service provided by Google, which sets cookies to help us measure traffic and engagement. We enable Google's privacy controls (including IP handling and consent-gated data collection) and we do not sell this data. Google Analytics cookies are only set with your consent and can be declined.
Advertising. We use Google Ads to measure the effectiveness of our advertising, attribute sign-ups to campaigns (conversion measurement), and show relevant ads to people who have visited our site (remarketing). This can involve cookies set by Google. These advertising cookies are strictly non-essential and are set only with your prior consent; if you decline, we do not set them and, where advertising still applies, we instruct Google to operate in a consent-denied mode that limits data use. Where you have consented to advertising, our conversion measurement may use Google's Enhanced Conversions: when you complete a subscription while signed in, a securely hashed, irreversible version of your email address is sent to Google to match that conversion to your ad interaction; your email is never sent in plain text. You can decline or withdraw this consent at any time through the cookie banner.
The list below describes, in general terms, the name, purpose and duration of the main items we use. Exact names and lifetimes may vary slightly as the platform evolves, but the categories and purposes remain as described.
_ga cookie typically lasts up to 2 years and _gid up to 24 hours; retention of the underlying analytics data is configured to a limited period.A first-party cookie is set by the website you are visiting, in our case the DMARC Engine domain, and is used only by us. A third-party cookie is set by a different domain. The essential cookies and storage we rely on to run the service are first-party. The only third-party cookies we use are the consent-gated analytics and advertising cookies set by Google (Google Analytics 4 and Google Ads), and these are set solely with your prior consent; you can decline them and still use the service in full. Where we use infrastructure providers such as Cloudflare to deliver and secure the service, any operational cookie set in connection with that delivery is used for security and performance rather than for advertising or cross-site profiling.
Cookies are either session cookies or persistent cookies. Session cookies, including the cookies that keep you signed in, are temporary and are removed when you close your browser or when your session expires. Persistent cookies and stored preferences remain until they reach their expiry date or until you delete them, and we keep these lifetimes as short as is practical for their purpose. Values held in localStorage, such as your consent choice, persist until you clear your browser storage or change the setting. We periodically review the items we set and remove anything that is no longer needed.
Our legal basis for setting cookies depends on the category. Strictly necessary cookies are set on the basis of our legitimate interest in providing a secure service that you have requested, and under applicable electronic-communications and data-protection rules these do not require your consent because the service could not function without them. For functional, analytics and any other non-essential technologies, we rely on your consent. We ask for that consent through our on-site cookie banner before setting non-essential cookies, and we treat declining as a valid choice that we will respect. You are free to accept some categories and decline others, and you can change your mind at any time.
You are always in control of non-essential cookies. You can manage your choices in two main ways. First, you can use the on-site cookie banner and the cookie-preferences control to accept or decline categories of cookies, and to change a previous decision. Because your choice is stored in your browser, clearing your browser storage will reset it and the banner will appear again on your next visit.
Second, you can use your browser controls. Every major browser lets you view, block and delete cookies and clear local and session storage, usually from the privacy or security section of its settings, and you can set the browser to warn you before a cookie is stored. Please note an important limitation: if you block or delete strictly necessary cookies, including the session and CSRF cookies, you will not be able to sign in or use the authenticated dashboard, because those cookies are what keep your session secure. Blocking non-essential cookies, by contrast, will not stop you using the core service.
Some browsers can send a "Do Not Track" signal to indicate that you do not wish to be tracked across websites. There is no consistent industry standard for how sites should respond to this signal. Because our analytics and advertising cookies are non-essential and set only after you opt in through our cookie banner, you remain in control regardless: if you do not consent, no Google analytics or advertising cookie is set. Where your browser or local law treats such a signal as an opt-out of non-essential cookies, we will honour it.
We may update this Cookie Policy from time to time to reflect changes in the technologies we use, in our service, or in applicable law. When we make a material change we will update the "Last updated" date at the top of this page, and where appropriate we will ask for fresh consent through the cookie banner. We encourage you to review this page periodically so that you stay informed about how we use cookies and similar technologies.
If you have any questions about this Cookie Policy or about how we use cookies and similar technologies, please contact us at privacy@dmarcengine.com, or for general enquiries at hello@dmarcengine.com. For more information about how we handle personal data, please see our Privacy Policy.