Last updated: June 2026
DMARC Engine is a hosted email-authentication platform that helps organisations configure, monitor and enforce DMARC, SPF, DKIM, MTA-STS and BIMI, including done-for-you progression to a p=reject enforcement policy. This Privacy Policy explains what personal data we collect when you visit our website, create an account or use the service, how and why we use it, who we share it with, how long we keep it, and the rights you have over it. It applies to our marketing website, the authenticated application, and the supporting infrastructure we operate. For the purposes of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where applicable, the EU General Data Protection Regulation (EU GDPR), DMARC Engine is the data controller for the personal data described in this policy unless we state otherwise below. If you have any questions about this policy or how we handle your data, you can contact us at privacy@dmarcengine.com. This policy should be read together with our Terms of Service and our Cookie Policy.
We collect different categories of data depending on how you interact with us:
We only process personal data where we have a lawful basis to do so under Article 6 of the UK GDPR. The bases we rely on are:
We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not sell your personal data.
For your account data, billing data, support correspondence, cookies, usage telemetry and server logs, DMARC Engine acts as a data controller because we determine the purposes and means of processing. For the DMARC report data and domain configuration data you bring to the platform, we generally act as a data processor acting on your instructions: you (or the organisation you represent) determine the purposes for which that data is processed, and we process it to provide the service to you under our Terms of Service and any applicable data-processing terms. Where we act as a processor, you are responsible for ensuring you have a lawful basis to provide that data to us, and we will process it only as needed to deliver the service, keep it secure, and comply with the law.
We rely on a small number of trusted sub-processors to operate the service. Our primary hosting and infrastructure provider is Cloudflare, whose D1 (database), R2 (object storage) and KV (key-value cache) products store and serve your data. We also use a third-party transactional email provider to send service notifications and alerts, and a third-party payment processor to handle subscriptions and billing. Where you have given consent through our cookie banner, we also use Google (Google Analytics 4 and Google Ads) for website and campaign analytics, conversion measurement (including Google's Enhanced Conversions, which shares a securely hashed, irreversible version of your email address to match ad conversions) and advertising; these services are engaged only with your prior consent and may involve transfers to the United States, for which we rely on Standard Contractual Clauses, the UK Addendum and Google's data-processing terms. A full, current list is available on our Sub-Processors page. Each sub-processor is engaged under contractual terms that require appropriate technical and organisational measures and that restrict their use of data to the provision of services to us. Because these providers operate global infrastructure, your personal data may be transferred to or accessed from countries outside the United Kingdom or the European Economic Area. Where we make such transfers, we put in place an appropriate safeguard recognised under the UK GDPR and EU GDPR, such as the International Data Transfer Agreement, the UK Addendum, or the European Commission's Standard Contractual Clauses (SCCs), together with any supplementary measures required to ensure your data continues to receive an adequate level of protection.
We share personal data only where necessary and only in the ways described in this policy: with the sub-processors listed in section 5; with professional advisers such as lawyers, auditors and accountants where required; with authorities, courts or regulators where we are legally compelled to do so; and with a successor entity in the event of a merger, acquisition or reorganisation, subject to the protections of this policy. We never sell, rent or trade your personal data to third parties for their own marketing purposes, and we do not share DMARC report data with anyone other than as needed to provide the service to you.
We retain personal data only for as long as necessary for the purposes for which it was collected:
When data is no longer required we securely delete or irreversibly anonymise it. You may request earlier deletion as described in section 9.
We apply technical and organisational measures appropriate to the risk. Passwords are never stored in plain text and are hashed using PBKDF2-SHA256 with per-user salts. Sensitive secrets, such as two-factor authentication secrets, single sign-on client secrets and notification-channel credentials, are encrypted at the application layer using AES-256-GCM, in addition to the platform-level encryption Cloudflare applies to all stored data. All connections to the service are encrypted in transit using TLS. We enforce role-based access controls so that staff and systems can only access the data they need, and we support two-factor authentication (2FA) and IP allow-listing to help protect your account. We also operate logging, monitoring and abuse-prevention controls. No method of transmission or storage is completely secure, so while we work hard to protect your data we cannot guarantee absolute security; we encourage you to use a strong, unique password and to enable 2FA.
Subject to the conditions and exemptions in the UK GDPR and EU GDPR, you have the right to: access the personal data we hold about you; have inaccurate data rectified; have your data erased (the right to be forgotten); restrict our processing in certain circumstances; receive your data in a portable, machine-readable format and have it transmitted to another controller; object to processing carried out on the basis of legitimate interests or for direct marketing; and, where we rely on consent, withdraw that consent at any time. To exercise any of these rights, contact us at privacy@dmarcengine.com. We will respond within one month, which we may extend by up to two further months for complex requests, and we will tell you if that is the case. We do not charge a fee for exercising your rights unless a request is manifestly unfounded or excessive. We may need to verify your identity before acting on a request. Where we act as a processor for DMARC report or configuration data, we will refer requests relating to that data to the relevant controller and assist them as required.
The service is intended for use by businesses and professionals and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, please contact us at privacy@dmarcengine.com and we will take steps to delete it.
We use strictly necessary cookies to keep you signed in and to protect against cross-site request forgery, and, where you consent, optional cookies for analytics and advertising and to remember your preferences. Our optional analytics and advertising cookies include third-party cookies set by Google (Google Analytics 4 and Google Ads) for measurement, conversion tracking and remarketing; these are set only with your prior consent (our Art. 6(1)(a) basis) via the on-site cookie banner, and you can decline or withdraw at any time. Strictly necessary cookies do not require consent because they are essential to providing the service you have requested. You can manage non-essential cookies through the cookie banner, any cookie controls we provide, or your browser settings. For full details of the cookies we use and their purposes and lifespans, please see our Cookie Policy.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements or the service itself. When we make material changes we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email or through the service. We encourage you to review this page periodically. Your continued use of the service after an update takes effect constitutes acceptance of the revised policy.
If you are unhappy with how we have handled your personal data, we would like the chance to put things right, so please contact us first at privacy@dmarcengine.com. You also have the right to lodge a complaint with a supervisory authority. In the United Kingdom this is the Information Commissioner's Office (ICO), which you can reach at ico.org.uk or by calling its helpline. If you are in the European Economic Area, you may complain to the data protection authority in your country of residence, place of work or where the alleged infringement occurred.
For any privacy-related questions, requests or concerns, contact our privacy team at privacy@dmarcengine.com. For general enquiries you can reach us at hello@dmarcengine.com. We will do our best to respond promptly and to resolve any issue you raise.